Commit 7fa1c3c4 authored by Avery Pennarun's avatar Avery Pennarun

Listen on localhost:0 instead of 0.0.0.0:0 by default.

This avoids any possible problem caused by other people on your network
using you as a proxy.  If you want to allow this, you can force it back to
the old way using the --listen option.

Thanks to 'tass' on github for reporting portscans that revealed this
potential security problem.
parent cca69eb4
...@@ -49,7 +49,7 @@ sshuttle [-l [ip:]port] [-r [username@]sshserver[:port]] <subnets...> ...@@ -49,7 +49,7 @@ sshuttle [-l [ip:]port] [-r [username@]sshserver[:port]] <subnets...>
sshuttle --firewall <port> <subnets...> sshuttle --firewall <port> <subnets...>
sshuttle --server sshuttle --server
-- --
l,listen= transproxy to this ip address and port number [0.0.0.0:0] l,listen= transproxy to this ip address and port number [127.0.0.1:0]
H,auto-hosts scan for remote hostnames and update local /etc/hosts H,auto-hosts scan for remote hostnames and update local /etc/hosts
N,auto-nets automatically determine subnets to route N,auto-nets automatically determine subnets to route
python= specify the name/path of the python interpreter on the remote server [python] python= specify the name/path of the python interpreter on the remote server [python]
......
% sshuttle(8) Sshuttle 0.42 % sshuttle(8) Sshuttle 0.44
% Avery Pennarun <apenwarr@gmail.com> % Avery Pennarun <apenwarr@gmail.com>
% 2010-11-09 % 2010-12-31
# NAME # NAME
...@@ -41,7 +41,13 @@ entire subnet to the VPN. ...@@ -41,7 +41,13 @@ entire subnet to the VPN.
-l, --listen=*[ip:]port* -l, --listen=*[ip:]port*
: use this ip address and port number as the transparent : use this ip address and port number as the transparent
proxy port. By default sshuttle finds an available proxy port. By default sshuttle finds an available
port automatically, so you don't need to override it. port automatically and listens on IP 127.0.0.1
(localhost), so you don't need to override it, and
connections are only proxied from the local machine,
not from outside machines. If you want to accept
connections from other machines on your network (ie. to
run sshuttle on a router) try enabling IP Forwarding in
your kernel, then using `--listen 0.0.0.0:0`.
-H, --auto-hosts -H, --auto-hosts
: scan for remote hostnames and update the local /etc/hosts : scan for remote hostnames and update the local /etc/hosts
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment