PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > comp.security.ssh > SSH port forwarding on shared server
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.security.ssh SSH secure remote login and tunneling tools.

SSH port forwarding on shared server

Réponse
 
LinkBack Outils de la discussion
Vieux 19/08/2007, 10h16   #1
codebeard@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut SSH port forwarding on shared server

Hi,

At uni I sometimes want to connect to things on my home server (web
server, etc).

I can do this using ssh with port forwarding (ssh -L ...), but the
problem is that the servers at uni run dozens of other terminal
clients, so everyone else gets access to my forwarded port!

Is there a way of making the local port secure in the sense that ssh
will only allow me to connect to it?

One idea I had is as follows:
- Wait until connection to local port
- Look through /proc for processes being run by the same user as ssh
- For each process owned by the user, look at any pipes it has open
- For each pipe, use fcntl or similar to find out if it's a TCP socket
- If it's a TCP socket, check if the source and destination hosts/
ports match the connection received by ssh
- If such a socket is found, forward the connection to the ssh'd host
- If no such socket is found, close the connection

Any ideas appreciated,
Codebeard.

  Réponse avec citation
Vieux 19/08/2007, 13h53   #2
purpmint008@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: SSH port forwarding on shared server

X-No-Archive: Yes

Only you want access to the forwarded port.
Use PuTTY, it has an option (under SSH, under Tunnels) that says:
"Local ports accept connections from other hosts."
Make sure that this option is unchecked.

That will solve your problem, nothing but your computer will have
access to this forwarded. Problem solved?
I don't know how this would work out under the OpenSSH ssh client,
which I assume you are using.

  Réponse avec citation
Vieux 19/08/2007, 13h53   #3
purpmint008@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: SSH port forwarding on shared server

X-No-Archive: Yes

Only you want access to the forwarded port.
Use PuTTY, it has an option (under SSH, under Tunnels) that says:
"Local ports accept connections from other hosts."
Make sure that this option is unchecked.

That will solve your problem, nothing but your computer will have
access to this forwarded. Problem solved?
I don't know how this would work out under the OpenSSH ssh client,
which I assume you are using.

  Réponse avec citation
Vieux 19/08/2007, 14h18   #4
codebeard@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: SSH port forwarding on shared server

On Aug 19, 9:53 pm, purpmint...@gmail.com wrote:
> X-No-Archive: Yes
>
> Only you want access to the forwarded port.
> Use PuTTY, it has an option (under SSH, under Tunnels) that says:
> "Local ports accept connections from other hosts."
> Make sure that this option is unchecked.
>
> That will solve your problem, nothing but your computer will have
> access to this forwarded. Problem solved?
> I don't know how this would work out under the OpenSSH ssh client,
> which I assume you are using.


Hi.

This would work, but the problem is that the unix servers at my
university are shared. That means that dozens of people can be using
the same host at once (everybody has a different screen and keyboard,
but are all sharing a big powerful server over the network). I already
have that option disabled (using openssh you enable it if you want
with the -g option), but it doesn't really fix the problem in this
case.

Codebeard.

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 05h09.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,09019 seconds with 12 queries