Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-06-2008, 12:58 AM
Magnus Warker
 
Posts: n/a
anonymizing proxy solution

Hi,

I am looking for a solution for an anonymizer problem. This is the
situation:

1. I regularly access arbitrary internet sites from unsecure working
stations, i. e. working stations located in networks that I do not know, e.
g. public internet access stations.

2. I have an own server in the internet.

Now I would like to use my own server as a proxy to the internet sites I
access from the unsecure networks:

1. The local web browser should access my proxy using an encrypted
connection.

2. My proxy should forward the requests coming from my browser to the final
recipients.

3. In effect, only the encrypted connection to my own server will be visible
in the unsecure network.

My question: How can I realize this? I prefer open source software running
on linux.

The only proxy I know is squid. Can I use it in my scenario?

Thanks,
Magnus
Reply With Quote
  #2 (permalink)  
Old 07-06-2008, 02:42 AM
Allan
 
Posts: n/a
Re: anonymizing proxy solution

Magnus Warker <warker@magnus.co> writes:

> Hi,
>
> I am looking for a solution for an anonymizer problem. This is the
> situation:
>
> 1. I regularly access arbitrary internet sites from unsecure working
> stations, i. e. working stations located in networks that I do not know, e.
> g. public internet access stations.
>
> 2. I have an own server in the internet.
>
> Now I would like to use my own server as a proxy to the internet sites I
> access from the unsecure networks:
>
> 1. The local web browser should access my proxy using an encrypted
> connection.
>
> 2. My proxy should forward the requests coming from my browser to the final
> recipients.
>
> 3. In effect, only the encrypted connection to my own server will be visible
> in the unsecure network.
>
> My question: How can I realize this? I prefer open source software running
> on linux.
>
> The only proxy I know is squid. Can I use it in my scenario?

Yes, squid is already used by some anonymizing network
applications. But what is so anonymous about your server if it is visible?

--
Allan
Reply With Quote
  #3 (permalink)  
Old 07-06-2008, 03:02 AM
Magnus Warker
 
Posts: n/a
Re: anonymizing proxy solution

>> The only proxy I know is squid. Can I use it in my scenario?
> Yes, squid is already used by some anonymizing network
> applications. But what is so anonymous about your server if it is visible?


The communication with the web sites behind it is invisible. Isn't it?

Magnus
Reply With Quote
  #4 (permalink)  
Old 07-06-2008, 05:06 AM
James T.
 
Posts: n/a
Re: anonymizing proxy solution

On Sun, 06 Jul 2008 02:58:08 +0200, Magnus Warker wrote:

> Hi,
>
> I am looking for a solution for an anonymizer problem. This is the
> situation:
>
> 1. I regularly access arbitrary internet sites from unsecure working
> stations, i. e. working stations located in networks that I do not know,
> e. g. public internet access stations.
>
> 2. I have an own server in the internet.
>
> Now I would like to use my own server as a proxy to the internet sites I
> access from the unsecure networks:
>
> 1. The local web browser should access my proxy using an encrypted
> connection.
>
> 2. My proxy should forward the requests coming from my browser to the
> final recipients.
>
> 3. In effect, only the encrypted connection to my own server will be
> visible in the unsecure network.
>
> My question: How can I realize this? I prefer open source software
> running on linux.
>
> The only proxy I know is squid. Can I use it in my scenario?
>
> Thanks,
> Magnus


Take a look at Privoxy (http://www.privoxy.org/). This is what I use &
its also a good web content filter (banners, pop-ups, etc...).
Reply With Quote
  #5 (permalink)  
Old 07-07-2008, 11:55 PM
Allan
 
Posts: n/a
Re: anonymizing proxy solution

Magnus Warker <warker@magnus.co> writes:

>>> The only proxy I know is squid. Can I use it in my scenario?

>> Yes, squid is already used by some anonymizing network
>> applications. But what is so anonymous about your server if it is visible?

>
> The communication with the web sites behind it is invisible. Isn't
> it?

Whether you use Privoxy, as mentioned in another post, or squid your
anonymity can be compromised by attacking the proxy itself. If this is
enough privacy for your purposes, fine. No anonymity scheme is
perfect and even if it was it would be impractical and unusable.

--
Allan
Reply With Quote
  #6 (permalink)  
Old 07-09-2008, 01:49 PM
Kadin2048
 
Posts: n/a
Re: anonymizing proxy solution

On 2008-07-06, Magnus Warker <warker@magnus.co> wrote:
> Hi,
>
> I am looking for a solution for an anonymizer problem. This is the
> situation:

[Protect machine on untrusted network using remote machine at home]
> My question: How can I realize this? I prefer open source software running
> on linux.
>
> The only proxy I know is squid. Can I use it in my scenario?


Just as a different solution, what I do is forgo the HTTP proxy
altogether and use the SOCKS forwarding feature of SSH instead.

As long as you have sshd running on your remote machine (the one in
your house, which is on a 'trusted' connection), and your travel
machine (the one you're using in the 'untrusted' network, like an
Internet cafe) has an SSH client -- available for basically every
platform -- you just open an SSH connection with the "-D {port}" flag,
and then point your browser at "localhost {port}", telling it to use a
SOCKS proxy.

This is in many ways a lot nicer than using an HTTP proxy. All web
traffic is forwarded from the browser to the port on the localhost,
and from there across the SSH tunnel to the remote machine, which
actually makes the connections for you.

It's dead simple to set up and works for web traffic, instant
messaging, and virtually any other application that can use a SOCKS
proxy (pretty much everything).

Googling "ssh socks forwarding" will turn up lots of HOWTOs for
various platforms. Here's just one, for Debian:
<http://www.debian-administration.org/articles/449>

I like this because it doesn't require installing or running anything
on your remote machine besides sshd, which chances are you're already
running as it is.

-Kadin.
Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:22 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
McDonalds | Mortgage Calculator | Cheap Car Insurance | Car Finance | Destin, Florida



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109