Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] SSH tunneled DNS access & SSH/SSL muxing

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] SSH tunneled DNS access & SSH/SSL muxing


Chronological Thread 
  • From: Peter Green <peter AT greenpete.free>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] SSH tunneled DNS access & SSH/SSL muxing
  • Date: Mon, 12 Nov 2012 18:10:12 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Indeed, and I hope I haven't distracted you or anyone else from your
point :-/

A censorship free D.N.S. system is indeed a worthy objective!

Peter


On 12/11/12 18:07, Panesar, Amrit wrote:
> Haha, indeed and so far human nature has yet to surprise me,
> people are assholes. TQP clearly doesn't care weather our data goes
> out, on to the internet, 'naked' or not. It seems that they just
> want to make a quick buck - and even in 6 years, I don't believe
> they will be able to sue every single person that has come in
> contact with their technology and further emphasizes my idea that
> software patents should be abolished :P
>
> However, we shouldn't let that deter us from considering the
> possibility of a censorship-free DNS system
>
> On Mon, Nov 12, 2012 at 9:57 AM, Peter Green <peter AT greenpete.free>
> wrote:
>
> That's spooky, I was just reading this...
>
> http://it.slashdot.org/story/12/11/12/1237237/meet-the-lawyer-suing-anyone-who-uses-ssl?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29
>
> Peter
>
>
> On 12/11/12 17:55, Panesar, Amrit wrote:
>>>> I have come across a theory for universal, direct DNS
>>>> especially for those behind company or country bound
>>>> firewalls.
>>>>
>>>> I have recently come across SSHTTP
>>>> (https://github.com/stealth/sshttp). This program multiplexes
>>>> HTTP SSL with SSH because of banners, (there is a more
>>>> in-depth explanation on the project page). This would allow
>>>> an SSH daemon to run on the same port as HTTP-SSL, and
>>>> essentially 'trick' level 7 content filters that establish a
>>>> connection to the website to ensure it passes content
>>>> validation, else it resets the connection. (eg:
>>>> http://i.imgur.com/bQuk3.png &
>>>> http://i.imgur.com/97LWK.png). What we are to do is mux a
>>>> clean SSL site with SSH; thus, when the firewall goes to
>>>> probe the site, it returns a valid site and we will also be
>>>> able to SSH. With the help of your favorite ssh client, we
>>>> can tunnel your DNS packets over SSH on port 443 and be able
>>>> to evade all firewalls that stand in the way thus giving
>>>> everyone access to OpenNIC. We can even take it a step
>>>> further and add a SSH client-helper to a web browser (like
>>>> chromium/canary) to further integrate the experience.
>>>>
>>>> What are you thoughts on this?
>>>>
>>>>
>>>> Also I find this comedic, http://i.imgur.com/BSZgI.png
>>>>
>>>>
>>>> -------- You are a member of the OpenNIC Discuss list. You
>>>> may unsubscribe by emailing
>>>> discuss-unsubscribe AT lists.opennicproject.org
>>>>
>>
>>
>> -------- You are a member of the OpenNIC Discuss list. You may
>> unsubscribe by emailing
>> discuss-unsubscribe AT lists.opennicproject.org
>
>
> -------- You are a member of the OpenNIC Discuss list. You may
> unsubscribe by emailing
> discuss-unsubscribe AT lists.opennicproject.org
>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iQEcBAEBAgAGBQJQoTuAAAoJEPBKqeCz72c5juAH/Rxcbx/ZHNlk8IXus26bRbA3
7YfJmY95YDp0YbN4PT74gB+OJemVsEbzW3yj5+arCziSFUGvy67+8z9ERJPKg3cn
R3XofWp557VPSm0jN3Bh2HDX1Fc5iAvJZSyR+sxUukoTRtx6KrVO7cln3+PfsJeE
kwTRyWxhEM4XZffj3IjaRKKj7Do3ACVrZ1KWm4fCe5/5ZlkU4G/t0M0bI/G+k69c
zHau5Sx/CtCbGiVSWguvLqviC5SV31PWW6kDUHbIX/aPdtsyGbO2TTcGIt8J8vUq
r8wW/m+VtSJgxK3JDwf+2ewuwtk4lvQe+xJiRgPtW7wEbOVwtT5BGFIcAGBY7Oc=
=VLf4
-----END PGP SIGNATURE-----



Archive powered by MHonArc 2.6.19.

Top of Page