tunneling ports

Valeri Galtsev galtsev at kicp.uchicago.edu
Fri Jan 13 15:45:38 UTC 2017


On Fri, January 13, 2017 4:46 am, Damien Fleuriot wrote:
> On 13 January 2017 at 11:13, Christoph Kukulies <kuku at kukulies.org> wrote:
>> I don't know if this could be easily achieved, but imagine the situation
>> that you are in a network and the only ports being allowed for outgoing
>> traffic into the Internet are ports 80 and 443.
>
> Well well... somebody's trying to circumvent their netadmin's
> firewalls are they not ?
>
> It is not my place to question your motives, all I can offer is
> technical advice along with a warning.
>
> If your netadmin has somewhat advanced measures in place such as a
> transparent SSL proxy, you will get caught.
> And if I caught you doing that, I'd nuke your account on the spot.
> Just FYI ;)

I would second that. I had a user on my server who was piercing firewall
of external place (at his new job) using ssh to my server with port
forwarding. I couldn't kick him out (sigh), but I disabled his ability to
forward ports on my server (sysadmins usually will take the side of
another sysadmin than rogue user). And restricted his account in many
other respects. You go some place to work at, you accept their rules, all
comes as a bundle.

Valeri

++++++++++++++++++++++++++++++++++++++++
Valeri Galtsev
Sr System Administrator
Department of Astronomy and Astrophysics
Kavli Institute for Cosmological Physics
University of Chicago
Phone: 773-702-4247
++++++++++++++++++++++++++++++++++++++++


More information about the freebsd-questions mailing list