{"id":678,"date":"2007-12-06T23:43:22","date_gmt":"2007-12-07T04:43:22","guid":{"rendered":"http:\/\/www.bytebot.net\/blog\/archives\/2007\/12\/06\/secure-travelling-tips-with-iptables-and-ssh-port-forwarding"},"modified":"2007-12-06T23:48:27","modified_gmt":"2007-12-07T04:48:27","slug":"secure-travelling-tips-with-iptables-and-ssh-port-forwarding","status":"publish","type":"post","link":"https:\/\/www.bytebot.net\/blog\/archives\/2007\/12\/06\/secure-travelling-tips-with-iptables-and-ssh-port-forwarding","title":{"rendered":"Secure travelling tips with iptables and SSH port forwarding"},"content":{"rendered":"<p>The general paranoia at conferences is such that there almost always is WiFi, and there almost always is someone wanting to snoop your traffic. I guess, in a similar vein, this could also happen at Starbucks. So, on day 1, at foss.in I tried to recollect what I used to do, ages ago (when I used to run Fedora on my R51, before the disk died, and I realised I lacked a backup of \/root).<\/p>\n<p><strong>iptables<\/strong><br \/>\nFirewalls break networks? They also secure networks. I have access to some legacy POP servers, that don&#8217;t support SSL\/TLS like the IMAP servers I have access to. Firing up Thunderbird, to change the settings, to point to localhost, just seems like a waste of time. So the magic of iptables comes into play.<br \/>\n<tt><br \/>\niptables -t nat -A PREROUTING -p tcp -d my.pop.server --dport 110 -j DNAT --to-destination 127.0.0.1:1235<br \/>\niptables -t nat -A OUTPUT -p tcp -d my.pop.server --dport 110 -j DNAT --to-destination 127.0.0.1:1235<br \/>\n<\/tt><br \/>\nThe above, ensures that to access my.pop.server:110, the traffic is automatically routed now to localhost:1235. Clearly, I don&#8217;t run a POP server on my laptop, so this is where SSH port forwarding comes into play.<\/p>\n<p><strong>SSH port forwarding<\/strong><br \/>\nProvided you have access to a server via SSH, and you trust it, you can tunnel your traffic through it. Its made very easy by the:<br \/>\n-L localport:my.pop.server:foreignport<\/p>\n<p>So using the above example, that would be -L 1235:my.pop.server:110.<\/p>\n<p>Then, let&#8217;s not forget the useful -C option, to compress traffic.<\/p>\n<p>And hey, web surfing isn&#8217;t secure either, so lets create a SOCKS5 proxy while we&#8217;re at it. ssh supports the -D option, which works a charm. Use it such that you have something like:<br \/>\n-D 8188<\/p>\n<p>And now, configure your web browser, to use a SOCKS proxy, localhost:8188. You can also configure it in GNOME, under the Network Proxy, but it seems like not all applications respect it (for instance, I can get pidgin to segfault, and Liferea will not get RSS updates for some reason, etc.).<\/p>\n<p>So to sum it up, your SSH command should look something like:<br \/>\nssh -D 8188 -L 1235:my.pop.server:110 -C my.ssh.server<\/p>\n<p><strong>Discuss<\/strong><br \/>\nAm I missing something? Do you have an easier iptables rule? Yes, I realise I can also use a VPN. If you have other tips, please don&#8217;t hesitate to comment. Thanks.<\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/ssh\" class=\"performancingtags\" rel=\"tag\">ssh<\/a>, <a href=\"http:\/\/technorati.com\/tag\/iptables\" class=\"performancingtags\" rel=\"tag\">iptables<\/a>, <a href=\"http:\/\/technorati.com\/tag\/travel\" class=\"performancingtags\" rel=\"tag\">travel<\/a>, <a href=\"http:\/\/technorati.com\/tag\/tips\" class=\"performancingtags\" rel=\"tag\">tips<\/a>, <a href=\"http:\/\/technorati.com\/tag\/wifi\" class=\"performancingtags\" rel=\"tag\">wifi<\/a>, <a href=\"http:\/\/technorati.com\/tag\/open%20access%20points\" class=\"performancingtags\" rel=\"tag\">open access points<\/a>, <a href=\"http:\/\/technorati.com\/tag\/socks5\" class=\"performancingtags\" rel=\"tag\">socks5<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The general paranoia at conferences is such that there almost always is WiFi, and there almost always is someone wanting to snoop your traffic. I guess, in a similar vein, this could also happen at Starbucks. So, on day 1, at foss.in I tried to recollect what I used to do, ages ago (when I [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-678","post","type-post","status-publish","format-standard","hentry","category-general"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p4vJD-aW","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts\/678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/comments?post=678"}],"version-history":[{"count":0,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts\/678\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/media?parent=678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/categories?post=678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/tags?post=678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}