1. 29 Dec, 2020 2 commits
  2. 28 Dec, 2020 10 commits
  3. 16 Dec, 2020 4 commits
  4. 14 Dec, 2020 4 commits
  5. 16 Nov, 2020 2 commits
  6. 07 Nov, 2020 1 commit
  7. 06 Nov, 2020 1 commit
  8. 05 Nov, 2020 2 commits
  9. 04 Nov, 2020 6 commits
  10. 29 Oct, 2020 2 commits
  11. 27 Oct, 2020 2 commits
  12. 26 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      Intercept DNS requests sent by systemd-resolved. · 502960d7
      Scott Kuhl authored
      Previously, we would find DNS servers we wish to intercept traffic on
      by reading /etc/resolv.conf. On systems using systemd-resolved,
      /etc/resolv.conf points to localhost and then systemd-resolved
      actually uses the DNS servers listed in
      /run/systemd/resolve/resolv.conf. Many programs will route the DNS
      traffic through localhost as /etc/resolv.conf indicates and sshuttle
      would capture it. However, systemd-resolved also provides other
      interfaces for programs to resolve hostnames besides the localhost
      server in /etc/resolv.conf.
      
      This patch adds systemd-resolved's servers into the list of DNS
      servers when --dns is used.
      
      Note that sshuttle will continue to fail to intercept any traffic sent
      to port 853 for DNS over TLS (which systemd-resolved also supports).
      
      For more info, see:
      sshuttle issue #535
      https://www.freedesktop.org/software/systemd/man/systemd-resolved.service.html
      https://github.com/systemd/systemd/issues/6076
      502960d7
  13. 25 Oct, 2020 1 commit
  14. 24 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      Improve consistency of PATH, environments, and which() · 68c9c9bb
      Scott Kuhl authored
      This patch attempts to fix (or aid in debugging) issue #350.
      
      sshuttle didn't explicitly search /sbin and /usr/sbin and they may be
      missing in the user's PATH. If PATH is missing, these folders wouldn't
      be searched either. There was also a program_exists function which is
      redundant to which(). This consolidates everything into the helpers.py
      file.
      
      This patch introduces get_path() to return PATH + some extra hardcoded
      paths. A new get_env() function can be called to create a consistent
      environment when calling external programs. The new which() wrapper
      function also ensures we use the same set of paths.
      
      If -vv is supplied, messages clearly indicate the programs we are
      looking for, if they are found, and where we looked if we failed to
      find them.
      
      I haven't tested the changes to ipfw or pf.
      68c9c9bb
  15. 23 Oct, 2020 1 commit
    • Scott Kuhl's avatar
      nft IPv6 documentation (and other minor doc updates) · c02b93e7
      Scott Kuhl authored
      Update docs to indicate that IPv6 is supported with the nft method.
      
      - Adds nft into the requirements.rst file.
      
      - Update description of what happens when a hostname is used in a
        subnet.
      
      - Add ipfw to list of methods.
      
      - Indicate that --auto-nets does not work with IPv6. Previously this
        was only mentioned in tproxy.rst
      
      - Clarify that we try to use "python3" on the server before trying
        "python".
      c02b93e7