- 08 May, 2017 1 commit
-
-
vieira authored
This change makes the subnets with the most specific port ranges come before subnets with larger, least specific, port ranges. Before this change subnets with smaller swidth would always come first and only for subnets with the same width would the size of the port range be considered. Example: 188.0.0.0/8 -x 0.0.0.0/0:443 Before: 188.0.0.0/8 would come first meaning that all ports would be routed through the VPN for the subnet 188.0.0.0/8 After: 0.0.0.0/0:443 comes first, meaning that port 443 will be excluded for all subnets, including 188.0.0.0/8. All other ports of 188.0.0.0/8 will be routed.
-
- 07 May, 2017 1 commit
-
-
João Vieira authored
* Adds support for tunneling specific port ranges This set of changes implements the ability of specifying a port or port range for an IP or subnet to only tunnel those ports for that subnet. Also supports excluding a port or port range for a given IP or subnet. When, for a given subnet, there are intercepting ranges being added and excluded, the most specific, i.e., smaller range, takes precedence. In case of a tie the exclusion wins. For different subnets, the most specific, i.e., largest swidth, takes precedence independent of any eventual port ranges. Examples: Tunnels all traffic to the 188.0.0.0/8 subnet except those to port 443. ``` sshuttle -r <server> 188.0.0.0/8 -x 188.0.0.0/8:443 ``` Only tunnels traffic to port 80 of the 188.0.0.0/8 subnet. ``` sshuttle -r <server> 188.0.0.0/8:80 ``` Tunnels traffic to the 188.0.0.0/8 subnet and the port range that goes from 80 to 89. ``` sshuttle -r <server> 188.0.0.0/8:80-89 -x 188.0.0.0/8:80-90 ``` * Allow subnets to be specified with domain names Simplifies the implementation of address parsing by using socket.getaddrinfo(), which can handle domain resolution, IPv4 and IPv6 addresses. This was proposed and mostly implemented by @DavidBuchanan314 in #146. Signed-off-by:
David Buchanan <DavidBuchanan314@users.noreply.github.com> Signed-off-by:
João Vieira <vieira@yubo.be> * Also use getaddrinfo for parsing listen addr:port * Fixes tests for tunneling a port range * Updates documentation to include port/port range Adds some examples with subnet:port and subnet:port-port. Also clarifies the versions of Python supported on the server while maintaining the recommendation for Python 2.7, 3.5 or later. Mentions support for pfSense. * In Py2 only named arguments may follow *expression Fixes issue in Python 2.7 where *expression may only be followed by named arguments. * Use right regex to extract ip4/6, mask and ports * Tests for parse_subnetport
-
- 05 Apr, 2017 1 commit
-
-
vieira authored
netstat outputs some headers in BSD (that the Linux version does not) that are not tabular and were breaking our 'split line into columns and get nth column' logic. We now skip such headers. Should fix #141.
-
- 21 Feb, 2017 1 commit
-
-
S-trace authored
There was runtime failure on UDP or DNS processing, because "socket" was redefined to PyXAPI's socket_ext in tproxy.py, but still was plain Python's socket in client.py Fixed https://github.com/sshuttle/sshuttle/issues/134 for me
-
- 11 Feb, 2017 4 commits
-
-
vieira authored
-
vieira authored
-
vieira authored
`netstat` has been deprecated for some time and some distros might start shipping without it in the near future. This commit adds support for `ip route` and uses it when available.
-
Stephen Levine authored
-
- 28 Jan, 2017 1 commit
-
-
Ermal Luci authored
Sponsored-by: rsync.net
-
- 15 Jan, 2017 1 commit
-
-
vieira authored
PfSense is based on FreeBSD and its pf is pretty close to the one FreeBSD ships, however some structures have different fields and two offsets had to be fixed.
-
- 09 Jan, 2017 1 commit
-
-
vieira authored
We set it to true when we enable pf, but do not set it back to False after disabling. When using IPv4 and IPv6 we end up trying to disable twice which procudes an error while undoing changes in FreeBSD 11.
-
- 30 Oct, 2016 2 commits
- 29 Oct, 2016 1 commit
-
-
vieira authored
As it is only required to run the tests move pytest-runner from setup_requires to tests_require as suggested by @jonathanunderwood on #115.
-
- 28 Oct, 2016 1 commit
-
-
Jason Woods authored
-
- 24 Oct, 2016 1 commit
-
-
vieira authored
These changes introduce support for sdnotify allowing sshuttle to notify systemd when it finishes connecting to the server and installing firewall rules, and is ready to tunnel requests.
-
- 13 Oct, 2016 1 commit
-
-
Joao Vieira authored
This should fix an issue introduced in #117 where when no subnets are given via file (-s file) the variable is None instead of an empty list and the concatenation with the subnets given as positional parameters fails.
-
- 04 Oct, 2016 1 commit
-
-
Felix Dreissig authored
By just splitting at spaces, multi-word arguments are torn apart even if quoted. In case of custom ssh-cmd, this makes it practically impossible to set certian options through `ssh -o`. shlex splits arguments like a shell and e.g. respects quotes.
-
- 27 Sep, 2016 1 commit
-
-
vieira authored
This should fix #116. Handling this while still having the positional arguments and -s both write to the same list turned out to be more complicated than it's worth so each writes to their own variable and we merge them at the end.
-
- 05 Sep, 2016 2 commits
-
-
Brian May authored
requirements.rst: Fix mistakes
-
Richard Hartmann authored
-
- 01 Sep, 2016 2 commits
- 30 Aug, 2016 4 commits
- 06 Aug, 2016 2 commits
- 29 Jul, 2016 1 commit
-
-
Brian May authored
IPv6 support for OSX and BSDs
-
- 28 Jul, 2016 4 commits
- 25 Jul, 2016 3 commits
-
-
vieira authored
Adds IPv6 support for OpenBSD and OSX.
-
vieira authored
AF_INET is the same constant on Linux and BSD but AF_INET6 is different. As the client and server can be running on different platforms we can not just set the socket family to what comes in the wire.
-
vieira authored
We were always excluding 127.0.0.1/8 but sshuttle might be listening on other IP, e.g., ::1 for IPv6 or any other defined with -l
-
- 10 Jul, 2016 2 commits
- 17 Jun, 2016 1 commit
-
-
Huiqiang Liu authored
-