1. 01 Jan, 2011 6 commits
    • Avery Pennarun's avatar
      Merge branch 'closing' · 33bc55be
      Avery Pennarun authored
      * closing:
        Correctly close server connection when client disconnects.
        "Too many open files" shouldn't be a fatal condition.
      33bc55be
    • Avery Pennarun's avatar
      Correctly close server connection when client disconnects. · c3204d27
      Avery Pennarun authored
      When the server disconnected, we were forwarding that information to the
      client.  But we weren't forwarding back the other way when the client
      disconnected since there was no callback in place to do that.
      
      Relatedly, when we failed entirely to connect to the server, we didn't notify the
      client right away.  Now we do.
      
      Thanks to 'Roger' on the mailing list for pointing out these bugs.
      c3204d27
    • Avery Pennarun's avatar
      "Too many open files" shouldn't be a fatal condition. · b1edb226
      Avery Pennarun authored
      It can happen if there are too many sockets open.  If that happens, just
      throw away any connections that arrive in the meantime instead of aborting
      completely.
      b1edb226
    • Avery Pennarun's avatar
      Listen on localhost:0 instead of 0.0.0.0:0 by default. · 7fa1c3c4
      Avery Pennarun authored
      This avoids any possible problem caused by other people on your network
      using you as a proxy.  If you want to allow this, you can force it back to
      the old way using the --listen option.
      
      Thanks to 'tass' on github for reporting portscans that revealed this
      potential security problem.
      7fa1c3c4
    • Avery Pennarun's avatar
      Don't allow proxying of connections to the proxy port. · cca69eb4
      Avery Pennarun authored
      Add some cleverness for breaking infinite loops.  Previously we'd only
      detect it successfully if you connected to exactly the same IP as we were
      listening on, but that was unreliable if we're listening on 0.0.0.0 and you
      connected to one of the IP addresses we haven't heard of.
      
      Now, if you try to connect to our listen port on *any* IP, we try binding to
      that IP as a local socket; if it works, that's a local IP, and therefore
      it's our socket, so reject the connection.  If it doesn't work, it's a
      remote IP, so forward it along.
      
      Thanks to 'tass' on github for noticing the problem.
      cca69eb4
    • Avery Pennarun's avatar
      91f65132
  2. 12 Dec, 2010 1 commit
  3. 10 Dec, 2010 5 commits
  4. 20 Nov, 2010 1 commit
    • Christopher Bowns's avatar
      Add support for IPv6 remote hosts. · 95c9b788
      Christopher Bowns authored
      Supported sshuttle commands for IPv6:
      
      ./sshuttle -r "IPv6:addr" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr]" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr]:22" 0.0.0.0/0 -vv
      
      Technically "invalid" address/port formats, but they can still be parsed because they’re unambiguous, so these also work:
      
      ./sshuttle -r "IPv6:addr]" 0.0.0.0/0 -vv
      ./sshuttle -r "IPv6:addr]:" 0.0.0.0/0 -vv
      ./sshuttle -r "IPv6:addr]:22" 0.0.0.0/0 -vv
      ./sshuttle -r "[IPv6:addr" 0.0.0.0/0 -vv
      
      (If you have a Mac with Back To My Mac, use dns-sd to discover the remote host's IPv6 address:
      dns-sd -G v4v6 <machine name>.<member name>.members.mac.com )
      95c9b788
  5. 09 Nov, 2010 4 commits
    • Avery Pennarun's avatar
      Add a sshuttle.8 manpage. · ef717518
      Avery Pennarun authored
      You need to have 'pandoc' installed in order to render it from sshuttle.md.
      ef717518
    • Avery Pennarun's avatar
      Add a new --ssh-cmd= option to let you override the ssh command. · 32b4defa
      Avery Pennarun authored
      Requested by Axel Beckert.
      32b4defa
    • Avery Pennarun's avatar
      Remove the --noserver option. · 8b7605cc
      Avery Pennarun authored
      It didn't work anyway.  Obviously it hasn't been tested (or apparently
      needed) in a long time.
      8b7605cc
    • Avery Pennarun's avatar
      Make password prompting more clear. · bcf18923
      Avery Pennarun authored
      Based on suggestions by Jason Grossman and Ed Maste on the mailing list.
      
      We now add a [local su] prefix to the 'su' password prompt (by cheating and
      printing it before calling su), and we replace the 'sudo' password prompt
      with '[local sudo] Password: ' (by using the little-known and
      hopefully-portable -p option).
      
      We no longer call sudo or su if the uid is already 0; otherwise the prefix
      on the 'su' prompt would look weird, since su wouldn't ask for a password in
      that case.
      
      We don't add a prefix to the ssh password prompt, because it's too hard to
      tell if there will *be* an ssh password prompt.  But people will probably
      assume that the password request is for the server anyway; few people are
      likely to think that 'sshuttle -r myhost.com' is going to prompt for the
      *local* password.
      
      Of course none of this is a problem on a modern OS, like Debian, that would
      say something like "Password for apenwarr@myhost.com:" instead of just
      "Password:".  MacOS doesn't do that, however, so I assume many other OSes
      also don't.  Let's try to help them out.
      bcf18923
  6. 17 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      firewall.py: don't die if a given sysctl doesn't exist. · fe742c92
      Avery Pennarun authored
      Instead, get a list of known sysctls in the interesting prefix (net.inet.ip)
      and check if there's an entry in the list for each sysctl we want to change.
      If there isn't, then don't try to change it.
      
      This fixes a problem with FreeBSD, which doesn't have
      net.inet.ip.scopedroute but also doesn't need it.  Probably also fixes MacOS
      10.5, which probably didn't have that either, but I don't know for sure.
      
      Reported by Ed Maste.
      fe742c92
  7. 06 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      ipfw: use 'delete' instead of 'del' to avoid a warning on freebsd. · 10ce1ee5
      Avery Pennarun authored
      'del' is an abbreviation that happened to work because of substring matching
      in earlier versions of ipfw, but apparently they're planning to remove the
      substring matching eventually.  In any case, 'delete' has always worked, so
      there's no downside to using that.
      
      Reported by Ed Maste.
      10ce1ee5
  8. 04 Oct, 2010 1 commit
    • Avery Pennarun's avatar
      server.py: don't send partial hostwatch lists. · a32305a2
      Avery Pennarun authored
      If hostwatch has a lot of stuff to say all at once, it would come in more
      than one recv() packet, and server.py would send each packet individually as
      a CMD_HOST_LIST message.  Unfortunately, client.py (rightly) expects each
      CMD_HOST_LIST message to be complete, ie. a correct sequence of rows.
      
      So now server.py makes sure of this.  If there's a leftover bit (ie. an
      unterminated line), it saves it for later.
      
      Bug reported by user "Duke" on the mailing list.
      a32305a2
  9. 03 Oct, 2010 3 commits
  10. 02 Oct, 2010 10 commits
  11. 01 Oct, 2010 5 commits
    • Avery Pennarun's avatar
    • Avery Pennarun's avatar
      BSD: sysctl net.inet.ip.forwarding=1 is not necessary. · f950a380
      Avery Pennarun authored
      If your machine is a firewall/router, it affects whether people behind the
      router can use your sshuttle connection - in the same way that it affects
      whether they can route *anything* through you.  And thus, it should be set
      by the admin, not by sshuttle.
      
      sshuttle works fine for the local user either way.
      
      (This also affects MacOS since it's a BSD variant.)
      f950a380
    • Avery Pennarun's avatar
      BSD ipfw: switch from 'established' to 'keep-state/check-state'. · 8b4466b8
      Avery Pennarun authored
      It turns out 'established' doesn't work the way I expected it to from
      iptables; it's not stateful.  It just checks the TCP flags to see if the
      connection *thinks* it's already established, and follows the rule if so.
      That caused the first packet of each new connection to set sent to our
      transproxy, but not the subsequent ones, so weird stuff happened.
      
      With this change, any (matching) connection created *after* starting sshuttle
      will get forwarded, but pre-existing ones - most importantly, sshuttle's own
      ssh connection - will not.
      
      And with this (plus the previous commit), sshuttle works on MacOS, including
      10.6!
      8b4466b8
    • Avery Pennarun's avatar
      ssnet: recover slightly more gracefully from an infinite forwarding loop. · 4bf4f70c
      Avery Pennarun authored
      If you 'telnet localhost 12300' weird things happen; someday we should
      probably auto-detect and avoid that altogether.  But meanwhile, catch EPIPE
      if it happens (it's irrelevant) and don't barf with a %d data type for a
      value that can apparently sometimes be None.
      4bf4f70c
    • Avery Pennarun's avatar
      Magic incantation to mostly fix MacOS 10.6. · 410b9d42
      Avery Pennarun authored
      It comes down to this:
         sysctl_set('net.inet.ip.scopedroute', 0)
      
      I say "mostly" because actually it doesn't fix it; sshuttle doesn't know
      what to do with the received connection, so there must be a minor bug
      remaining somewhere.  I'll fix that next.
      
      Thanks to dkf <dfortunato@gmail.com> on the sshuttle mailing list for
      suggesting the magic fix.  He points at this post in particular:
        http://discussions.apple.com/thread.jspa?messageID=11558355&#11558355
      that gave him the necessary clue.
      410b9d42
  12. 22 Sep, 2010 2 commits
    • Avery Pennarun's avatar
      latest options.py from bup, now with tty-width guessing. · 2ef1c6a4
      Avery Pennarun authored
      as of bup commit bup-0.19-2-gce2ace5.
      2ef1c6a4
    • Frederik Deweerdt's avatar
      hostwatch: add missing errno import · b35cfbd0
      Frederik Deweerdt authored
      If the ~/.sshuttle.hosts file does not exist, it triggers the following
      error:
      
             Traceback (most recent call last):
               File "./sshuttle", line 80, in <module>
                 sys.exit(hostwatch.hw_main(extra))
               File "/home/def/p/sshuttle/hostwatch.py", line 246, in hw_main
                 read_host_cache()
               File "/home/def/p/sshuttle/hostwatch.py", line 41, in read_host_cache
                 if e.errno == errno.ENOENT:
             NameError: global name 'errno' is not defined
      
      (This only happened if you run 'sshuttle --hostwatch' from the command line
      directly, without passing it through assembler.py.)
      b35cfbd0