- 28 Dec, 2020 8 commits
-
-
Scott Kuhl authored
Add an "is_supported()" function to the different methods so that each method can include whatever logic they wish to indicate if they are supported on a particular machine. Previously, methods/__init__.py contained all of the logic for selecting individual methods. Now, it iterates through a list of possible options and stops on the first method that it finds that is_supported(). Currently, the decision is made based on the presence of programs in the PATH. In the future, things such as the platform sshuttle is running on could be considered.
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
Samuel Bernardo authored
Add .gitignore .vscode/ path. Resolve the issue #374 adding tproxy mark option to allow different network mapping. Signed-off-by:Samuel Bernardo <samuel@lip.pt>
-
- 16 Dec, 2020 4 commits
-
-
dependabot-preview[bot] authored
Bumps [mock](https://github.com/testing-cabal/mock) from 2.0.0 to 4.0.3. - [Release notes](https://github.com/testing-cabal/mock/releases) - [Changelog](https://github.com/testing-cabal/mock/blob/master/CHANGELOG.rst) - [Commits](https://github.com/testing-cabal/mock/compare/2.0.0...4.0.3) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
Brian May authored
Bump pytest from 6.2.0 to 6.2.1
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.2.0 to 6.2.1. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.2.0...6.2.1) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
Brian May authored
Due to message from CI: DEPRECATION: Python 3.5 reached the end of its life on September 13th, 2020. Please upgrade your Python as Python 3.5 is no longer maintained. pip 21.0 will drop support for Python 3.5 in January 2021. pip 21.0 will remove support for this functionality.
-
- 14 Dec, 2020 4 commits
-
-
Brian May authored
Bump pytest from 6.1.2 to 6.2.0
-
Brian May authored
Bump setuptools-scm from 4.1.2 to 5.0.1
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.1.2 to 6.2.0. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.1.2...6.2.0) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
dependabot-preview[bot] authored
Bumps [setuptools-scm](https://github.com/pypa/setuptools_scm) from 4.1.2 to 5.0.1. - [Release notes](https://github.com/pypa/setuptools_scm/releases) - [Changelog](https://github.com/pypa/setuptools_scm/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pypa/setuptools_scm/compare/v4.1.2...v5.0.1) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 16 Nov, 2020 2 commits
- 07 Nov, 2020 1 commit
-
-
Brian May authored
Bump attrs from 20.2.0 to 20.3.0
-
- 06 Nov, 2020 1 commit
-
-
dependabot-preview[bot] authored
Bumps [attrs](https://github.com/python-attrs/attrs) from 20.2.0 to 20.3.0. - [Release notes](https://github.com/python-attrs/attrs/releases) - [Changelog](https://github.com/python-attrs/attrs/blob/master/CHANGELOG.rst) - [Commits](https://github.com/python-attrs/attrs/compare/20.2.0...20.3.0) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 05 Nov, 2020 2 commits
-
-
Brian May authored
Fix "DNS request from ... to None" messages.
-
Scott Kuhl authored
-
- 04 Nov, 2020 6 commits
-
-
Brian May authored
Intercept DNS requests sent by systemd-resolved.
-
Brian May authored
Improve nft IPv6 support.
-
Scott Kuhl authored
The server should just read from resolv.conf to find DNS servers to use. This restores this behavior after the previous commit changed it. The client now reads both /etc/resolv.conf and /run/systemd/resolve/resolv.conf. The latter is required to more reliably intercept regular DNS requests that systemd-resolved makes.
-
Scott Kuhl authored
This commit makes two fixes: 1. If an IPv6 DNS server is used, an nft rule had "ip6 protocol" in it which is invalid and caused sshuttle to exit. 2. I modified detection of udp vs tcp to follow the recommendation at https://superuser.com/questions/1560376/match-ipv6-protocol-using-nftables I also re-arranged the code slightly to reduce the number of if-statements.
-
Brian May authored
Improve consistency of PATH, environments, and which()
-
Scott Kuhl authored
-
- 29 Oct, 2020 2 commits
-
-
Brian May authored
Bump pytest from 6.1.1 to 6.1.2
-
dependabot-preview[bot] authored
Bumps [pytest](https://github.com/pytest-dev/pytest) from 6.1.1 to 6.1.2. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/master/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/6.1.1...6.1.2) Signed-off-by:
dependabot-preview[bot] <support@dependabot.com>
-
- 27 Oct, 2020 2 commits
-
-
Scott Kuhl authored
-
Scott Kuhl authored
Some methods are unable to determine the destination address of DNS packets that we capture. When this happens, change the message so it just shows where the DNS requests are from.
-
- 26 Oct, 2020 1 commit
-
-
Scott Kuhl authored
Previously, we would find DNS servers we wish to intercept traffic on by reading /etc/resolv.conf. On systems using systemd-resolved, /etc/resolv.conf points to localhost and then systemd-resolved actually uses the DNS servers listed in /run/systemd/resolve/resolv.conf. Many programs will route the DNS traffic through localhost as /etc/resolv.conf indicates and sshuttle would capture it. However, systemd-resolved also provides other interfaces for programs to resolve hostnames besides the localhost server in /etc/resolv.conf. This patch adds systemd-resolved's servers into the list of DNS servers when --dns is used. Note that sshuttle will continue to fail to intercept any traffic sent to port 853 for DNS over TLS (which systemd-resolved also supports). For more info, see: sshuttle issue #535 https://www.freedesktop.org/software/systemd/man/systemd-resolved.service.html https://github.com/systemd/systemd/issues/6076
-
- 25 Oct, 2020 1 commit
-
-
Brian May authored
IPv6 support in nft method.
-
- 24 Oct, 2020 1 commit
-
-
Scott Kuhl authored
This patch attempts to fix (or aid in debugging) issue #350. sshuttle didn't explicitly search /sbin and /usr/sbin and they may be missing in the user's PATH. If PATH is missing, these folders wouldn't be searched either. There was also a program_exists function which is redundant to which(). This consolidates everything into the helpers.py file. This patch introduces get_path() to return PATH + some extra hardcoded paths. A new get_env() function can be called to create a consistent environment when calling external programs. The new which() wrapper function also ensures we use the same set of paths. If -vv is supplied, messages clearly indicate the programs we are looking for, if they are found, and where we looked if we failed to find them. I haven't tested the changes to ipfw or pf.
-
- 23 Oct, 2020 1 commit
-
-
Scott Kuhl authored
Update docs to indicate that IPv6 is supported with the nft method. - Adds nft into the requirements.rst file. - Update description of what happens when a hostname is used in a subnet. - Add ipfw to list of methods. - Indicate that --auto-nets does not work with IPv6. Previously this was only mentioned in tproxy.rst - Clarify that we try to use "python3" on the server before trying "python".
-
- 22 Oct, 2020 2 commits
-
-
Scott Kuhl authored
This works for me but needs testing by others. Remember to specify a ::0/0 subnet or similar to route IPv6 through sshuttle. I'm adding this to nft before nat since it is not sshuttle's default method on Linux. Documentation updates may be required too. This patch uses the ipaddress module, but that appears to be included since Python 3.3.
-
Brian May authored
Make nat and nft rules consistent; improve rule ordering.
-
- 21 Oct, 2020 2 commits
-
-
Scott Kuhl authored
First, check if TTL indicates we should ignore packet (instead of checking in multiple rules later). Also, nft method didn't do this at all. Now, nft matches the behavior of nat. Second, forward DNS traffic (we may need to intercept traffic to localhost if a DNS server is running on localhost). Third, ignore any local traffic packets. (Previously, we ignored local traffic except DNS and then had the DNS rules). The nft method didn't do this previously at all. It now matches the behavior of nat. Lastly, list the subnets to redirect and/or exclude. This step is left unchanged. Excluding the local port that we are listening on is redundant with the third step, but should cause no harm. In summary, this ordering simplifies the rules in nat and eliminates differences that previously existed between nat and nft.
-
Brian May authored
Allow no remote to work.
-