- 01 Jan, 2018 3 commits
-
-
kroozo authored
-
Becz Tamás authored
-
Dario Bertini authored
Swap hardcoded AF_INET(6) values for Python-provided values as they differ between Darwin and Linux (30 vs 10 for AF_INET6 for instance).
-
- 16 Nov, 2017 4 commits
- 13 Nov, 2017 2 commits
- 11 Nov, 2017 1 commit
-
-
Tony authored
When I starting sshuttle with option `--seed-hosts example.com`, got the following error: ``` hostwatch: Starting hostwatch with Python version 3.5.2 hostwatch: Traceback (most recent call last): ---> File "sshuttle.server", line 144, in start_hostwatch ---> File "sshuttle.hostwatch", line 272, in hw_main ---> File "sshuttle.hostwatch", line 234, in check_host ---> File "sshuttle.hostwatch", line 32, in _is_ip ---> File "/usr/lib/python3.5/re.py", line 163, in match ---> return _compile(pattern, flags).match(string) ---> TypeError: cannot use a string pattern on a bytes-like object Traceback (most recent call last): File "<string>", line 1, in <module> File "assembler.py", line 37, in <module> File "sshuttle.server", line 393, in main File "sshuttle.ssnet", line 596, in runonce File "sshuttle.server", line 324, in hostwatch_ready sshuttle.helpers.Fatal: hostwatch process died ``` It seems like the list of hosts is not properly decoded on the server side. This is an attempt to fix that.
-
- 09 Nov, 2017 2 commits
-
-
vieira authored
-
vieira authored
With this configuration it should be feasible to achieve a perfect score without contortion. Rules skiped for Bandit: B101: assert_used B104: hardcoded_bind_all_interfaces B404: import_subprocess B603: subprocess_without_shell_equals_true B606: start_process_with_no_shell B607: start_process_with_partial_path Rules skiped for pylint: - too-many-statements - too-many-locals - too-many-function-args - too-many-arguments - too-many-branches - bare-except - protected-access - no-else-return
-
- 08 Nov, 2017 3 commits
- 07 Nov, 2017 4 commits
-
-
vieira authored
-
vieira authored
-
vieira authored
-
vieira authored
As suggested by @colinmkeith the UDP and DNS proxies should listen on different ports otherwise the DNS proxy can get traffic intended to the UDP proxy (or vice-versa) and handle it incorrectly as reported in #178. At first sight it seems that we had the code in place to try another port if the one we are binding is already bound, however, with UDP and REUSEADDR the OS will not refuse to bind two sockets to the same socket address, so both the UDP proxy and DNS proxy were being bound to the same pair.
-
- 23 Oct, 2017 3 commits
-
-
vieira authored
-
vieira authored
-
vieira authored
Some Linux distros, like Alpine, Arch, etc and some BSDs, like FreeBSD, are now shipping with python3.6 as the default python3. Both the client and the server are failing to run in this distros, because we are specifically looking for python3.5. These changes make the run shell script use python3 if the version is greater than 3.5, otherwise falling back as usual. On the server any version of python3 will do, use it before falling back to python, as the server code can run with any version of python3.
-
- 21 Oct, 2017 2 commits
-
-
vieira authored
-
vieira authored
When the pf module is not loaded our calls to pfctl will fail with unhelpful messages. This change spares the user the pain of decrypting those messages and manually enabling pf. It also keeps track if pf was loaded by sshuttle and unloads on exit if that was the case. Also fixed the case where both ipv4 and ipv6 anchors were added by sshuttle but the first call of disable would disable pf before the second call had the chance of cleaning it's anchor.
-
- 19 Oct, 2017 2 commits
- 17 Oct, 2017 1 commit
-
-
vieira authored
Currently hostwatch only adds hostnames even when FQDNs are available. This commit changes found_host so that when the name is a FQDN, both the FQDN and an hostname are added, e.g., given api.foo.com both api and api.foo.com will be added. Fixes #151 if merged. N.B.: I rarely use hostwatch, it would probably be a good idea to get feedback from people who actually use it before merging. Not too sure about this...
-
- 15 Oct, 2017 1 commit
-
-
vieira authored
While with AF_INET sockaddr is a 2-tuple composed by (address, port), with AF_INET6 it is a 4-tuple with (address, port, flow info, scope id). We were always passing a 2-tuple to socket.connect which would fail whenever the address was, for instance, a link-local IPv6 address that needs a scope id. With this change we now use getaddrinfo to correctly compute the full tuple. Fixes #156.
-
- 17 Sep, 2017 1 commit
-
-
max authored
-
- 03 Aug, 2017 1 commit
-
-
- 29 Jul, 2017 1 commit
-
-
vieira authored
When doing port forwarding on lo0 avoid the special case where the traffic on lo0 did not came from sshuttle pass out rule but from the lo0 address itself. Fixes #159.
-
- 18 Jul, 2017 3 commits
-
-
Itamar Turner-Trauring authored
-
Itamar Turner-Trauring authored
-
Itamar Turner-Trauring authored
-
- 09 Jul, 2017 6 commits