Showing posts with label proxy. Show all posts
Showing posts with label proxy. Show all posts

Wednesday, September 7, 2011

Run free Google web proxy server

In our college someone or the other is always in a search for the ultimate Cyberoam 'bypasser'- something which is undetectable and can run all kinds of services. For all those unaware of Cyberoam, it is a network security product which (at the simplest level) can block websites and applications deemed harmful by the administration. Our administration has blocked most of the sites including rapidshare, torrent sites and many other. Obviously this can get annoying and frustrating especially when useful sites also get blocked. So far I have tried using simple web based proxy servers on the net(like hidemyass.com etc) as well as advanced VPN services like SecurityKiss and PingFu, but they have not lasted very long. The admin probably finds out by noting high network activity caused by such tunneling solutions and blocks the corresponding ip address and port rendering these services useless. Infact I have shared a few tricks/software to tunnel through Cyberoam and like network security products on this blog as well. I have provided links to those articles at the bottom.

Today I present to you yet another such software package with which you can hope to fool such firewalls. You might be surprised to know that Google provides applications which allow you to deploy proxy servers for (obviously) free! Ever heard of Google Apps Engine? It is a part of their cloud services where you can run your web applications on their infrastructure. Projects such as Mirrorrr have been developed which allow you to create a proxy server and deploy it on Google's servers. Surely no firewall in the world will block traffic to Google's trusted servers?!

Installation:

The first thing you need to do is to sign up with appengine.google.com and create an "application". The application identifier is basically the subdomain name that will host your proxy server.



Next you need to download python (preferably version 2.6). The link fo python 2.6.4: python 2.6.4 . Now download google apps engine sdk for python from code.google.com. Download the following zip file ( Google Apps Proxy Google Apps proxy ) which contains python scripts and a simple web page. The python scripts have been taken from project mirrorrr (http://code.google.com/p/mirrorrr/). This is a google apps engine application which mirrors the content of the supplied URL.

Deploying the application on the google server:


First edit the app.yaml file and edit the application field with the name of your application. Then, run the google apps engine program and click on edit-> preferences and fill in the fields. Click on File-> Add existing application. Browse to the 'proxy server settings' folder and click on OK.



Select the application and click on Deploy. You should see a python.exe cmd prompt appearing and another small console screen indicating the progress. Hopefully you will get a message that the application was successfully deployed.




Finally browse to http(s)://www.[application identifier].appspot.com. BTW Https also works! You can now freely access any site.

Obviously you cannot run any other blocked services such as a torrent client. Also not all web elements are supported and therefore some pages might not function properly. This might not be the ultimate solution to fool Cyberoam but is certainly a simple one and should not be detected by the admins quickly.

Important Links:

1. Download Google Apps Proxy files
2. Wiki on Google Apps engine
3. Google Apps homepage
4. http://www.labnol.org/internet/setup-proxy-server/12890/
5. Homepage of Cyberoam
6. Using PingFU to access blocked services
7. Hacking PingFU for unlimited access
8. Using VPN software to access blocked services

Wednesday, November 10, 2010

SSH forward and dynamic tunneling

SSH stands for Secure Shell and was designed to replace telnet since it provides remote control of a machine but with robust security. Linux users would have heard about this but if do not know how to run and use its features to the fullest then hop on.

SSH has evolved to incorporate features such as forward port tunneling, reverse port tunneling and dynamic port tunneling. This article will cover the basic setup and installation of SSH servers on Windows and Linux based Ubuntu. Steps will almost be the same on other distros.

Please note that port forwarding was originally introduced to allow incoming packets in a NAT environment but similar features were implemented in SSH and therefore the name SSH port forwarding.

SSH Forward Port forwarding


It can be visualized as an outbound tunnel where data is forwarded from the client 'towards' the server.

There are a few things to note:
1. First an SSH connection is set up therefore you need an SSH client and server running properly.
2. Once the forward tunnel has been set up , the data will pass through the tunnel and the receiving end will direct all the data to the mentioned port number.

Setting up port forwarding (WIndows)

Download FreeSSHD from the link posted below. This is a free software which runs SSH and telnet server. After installation you will be asked to generate a set of keys. Create them as they will be used to ensure integrity of the remote user.Now add a user account and assign a password. This account name will be used to login remotely.



If the SSH server is behind a NAT connection , eg home ADSL connection then you will need to allow incoming connections to port 22. Refer to this link if you want to have a brief idea on how to implement the aforementioned scheme (confusingly know as NAT port forwarding).

Try to establish a normal connection using putty, available in Windows and Linux.



Such a tunneling can be very useful if you want to access a remote service securely. Eg consider a scenario in which you need to access a remote web server securely. Then all you need to do is set up a forward ssh tunnel with the remote machine and entering the following configuration:


So when any data is sent to port number  it will be redirected through the ssh tunnel where the remote end will redirect the traffic to the destination address.
The above configuration will cause it to redirect all the traffic from local pc's port number 8080 to the remote machine through the ssh tunnel where the remote end will redirect the traffic to localhost , which means itself,  port 80. Clearly if the remote machine is running a web server all its content will pass through the ssh tunnel in encrypted, thus secure way.





Thus Forward tunnels have a very special use and can be used to bypass any firewalls or content filtering services and access remote machines with ease. The above schematic shows data transferred from local host to the remote server. Note how the data is internally directed from port 8181 to port 80.

More on Reverse Port tunneling and dynamic port tunneling in some later post.

Ubuntu users can install openssh server using the following command:
sudo apt-get install openssh-server(config files are stored in  /etc/ssh/sshd_config)
also a linux version of putty is available and can be obtained using synaptic package manager.

Some important commands:

Start OpenSSH Server:
sudo /etc/init.d/ssh start

Stop openssh server:
sudo /etc/init.d/ssh stop

Restart the server:
sudo /etc/init.d/ssh restart

Other Useful Links:


1. FreeSSHD homepage
2. Learn NAT Port Forwarding 
3.Wiki on SSH
4.More info

Tuesday, August 10, 2010

VPN introduced

Our institute recently banned facebook and other such sites in an effort to preserve bandwidth and although this was a very bad move we cannot do anything but find different ways to access the internet. There are web based proxy websites which fetch the page for you and then deliver them to your browser. They also allow the option of encoding the url so that administrators cannot monitor which site is being accessed. But these sites are really slow and unable to handle dynamic content effectively. So cgi proxies sites allow you to access facebook but it will not be able to load javascript or ajax content. Another solution is to use software such as PingFu, as explained before, which have developed their own set of proprietary protocols which encrypt data so that no one is able to 'read' it. 

The title is a bit misleading since this article is more about using third party software instead of complete understanding of VPN. VPN stands for Virtual Private Network and was initially designed to allow remote users to become a part the office LAN keeping a few things in mind

1.Data confidentiality
2.Authentication support
3.Compatibility with huge range of devices


Data confidentiality is provided by using high grade encryption. VPN services are quite robust and can be employed on NAT devices as well. VPN servers can be installed on backbone routers as well to interconnect two different LAN's over the Internet.

Nowadays VPN connections also allow you to access high speed Internet through their fast connection to it. One such service is provided by SecurityKiss Tunnel software. It is a software which like PingFu bypasses firewalls by routing traffic to its servers, the difference being this software uses certain standards defined by VPN. To be able to run it you will also have to install OpenVpn as well. It is a foundation on which different companies build customised VPN products.

Simply install and run SecurityKiss with administrator privileges.Click on connect and you're done.Till now I have received seamless connectivity to various social networking sites like facebook.  Moreover torrent files were being downloaded at around 10kbps which is very impressive considering I did not have a premium account. They probably achieve this by using an efficient traffic compression scheme.


At present SecurityKiss provides 50mb per day limit to free users but there must be other similar services which provide better speed and download limit.Please leave a comment if you find/know any such vpn service.

NOTE: Remember to install openvpn and securitykiss with admin privileges.If there is a problem in connectivity try to run the software with admin privileges as well.

Few important links:

1. Wiki on VPN
2. OpenVpn
3. SecurityKiss Homepage
4. Learn more about PingFu