<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Protecting your browsing with iPhone SSH tunnels</title>
	<atom:link href="http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/</link>
	<description>Because we&#039;re damned if we do, and we&#039;re damned if we don&#039;t!</description>
	<lastBuildDate>Thu, 04 Mar 2010 04:51:21 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Steve</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-985</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Thu, 04 Mar 2010 04:51:21 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-985</guid>
		<description>What&#039;s the advantage of this 3proxy approach over running squid on remotehost, setting up an ssh tunnel using

ssh -p 64000 -L 8080:localhost:3128 -l username remotehost -f -C -q -N

then setting the manual HTTP proxy localhost:8080 for the iPhone&#039;s Wi-Fi setting for the specific network?

I&#039;ve been using this squid approach successfully, but also have 3proxy and am wondering why I should use that.</description>
		<content:encoded><![CDATA[<p>What&#8217;s the advantage of this 3proxy approach over running squid on remotehost, setting up an ssh tunnel using</p>
<p>ssh -p 64000 -L 8080:localhost:3128 -l username remotehost -f -C -q -N</p>
<p>then setting the manual HTTP proxy localhost:8080 for the iPhone&#8217;s Wi-Fi setting for the specific network?</p>
<p>I&#8217;ve been using this squid approach successfully, but also have 3proxy and am wondering why I should use that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goran Cobanovic</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-456</link>
		<dc:creator>Goran Cobanovic</dc:creator>
		<pubDate>Sun, 06 Dec 2009 02:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-456</guid>
		<description>Great read, will come back for more soon, thanks</description>
		<content:encoded><![CDATA[<p>Great read, will come back for more soon, thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cedric</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-441</link>
		<dc:creator>Cedric</dc:creator>
		<pubDate>Sun, 22 Nov 2009 16:52:08 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-441</guid>
		<description>Can you give me the name of the hosted VPN service? I&#039;m searching besides 26c3 for a more secure dataconnection of my phone and it&#039;s hard to find a reliable and trustworthy service for 30$

Maybe you will add me at twitter @kernelpaniclite so we can DM?</description>
		<content:encoded><![CDATA[<p>Can you give me the name of the hosted VPN service? I&#8217;m searching besides 26c3 for a more secure dataconnection of my phone and it&#8217;s hard to find a reliable and trustworthy service for 30$</p>
<p>Maybe you will add me at twitter @kernelpaniclite so we can DM?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-440</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Sat, 21 Nov 2009 08:20:28 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-440</guid>
		<description>Due to router issues I went with 2 options. 1 was a Dreamhost server that runs my US SSH server. The other is a hosted VPN service that encrypts from the device to a central server, then directly connects to the web. The service was something like $30 for a year, and at the time it was a lot more cost effective than buying a new router, configuring and setting up the VPN over a weekend before Blackhat. Still, there&#039;s plenty of time before next years events to set something up ;) Problem is, iPhone doesn&#039;t support OpenVPN (yet).

If you&#039;ve got a DECT eventphone you can call me on extension 2252 (BAKA) or you can catch me on twitter as I&#039;ll be using that to setup meeting and posting information about the conference. I&#039;m @ChrisJohnRiley on Twitter.</description>
		<content:encoded><![CDATA[<p>Due to router issues I went with 2 options. 1 was a Dreamhost server that runs my US SSH server. The other is a hosted VPN service that encrypts from the device to a central server, then directly connects to the web. The service was something like $30 for a year, and at the time it was a lot more cost effective than buying a new router, configuring and setting up the VPN over a weekend before Blackhat. Still, there&#8217;s plenty of time before next years events to set something up <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Problem is, iPhone doesn&#8217;t support OpenVPN (yet).</p>
<p>If you&#8217;ve got a DECT eventphone you can call me on extension 2252 (BAKA) or you can catch me on twitter as I&#8217;ll be using that to setup meeting and posting information about the conference. I&#8217;m @ChrisJohnRiley on Twitter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cedric</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-439</link>
		<dc:creator>Cedric</dc:creator>
		<pubDate>Sat, 21 Nov 2009 07:37:24 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-439</guid>
		<description>Ah, ok.
What are do you have on the endside of the vpn? What hardware or software are you using?

Yes, i&#039;m heading for 26c3. Where can we find you?:-)</description>
		<content:encoded><![CDATA[<p>Ah, ok.<br />
What are do you have on the endside of the vpn? What hardware or software are you using?</p>
<p>Yes, i&#8217;m heading for 26c3. Where can we find you?:-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-438</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Fri, 20 Nov 2009 23:25:38 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-438</guid>
		<description>After updating to 3.1.2 I&#039;ve not had time to re-implement it on my iphone. There is however a new application in Cydia called &quot;Automatic SSH&quot; that is supposed to reconnect SSH sessions that drop. It could be interesting as one of the main issues is the SSH tunnel dropping and then traffic failing.

The main reason I&#039;ve not looked at this further however is the fact that not ALL traffic is protected. For my uses at conferences and the like, even 1 application not following the proxy rules is enough to make problems. I had to bite the bullet and go with a PPTP VPN solution for Blackhat/Defcon (although 99.9% of the time I was using 3G).

If you&#039;re headed to 26C3 remember to say hi ;)</description>
		<content:encoded><![CDATA[<p>After updating to 3.1.2 I&#8217;ve not had time to re-implement it on my iphone. There is however a new application in Cydia called &#8220;Automatic SSH&#8221; that is supposed to reconnect SSH sessions that drop. It could be interesting as one of the main issues is the SSH tunnel dropping and then traffic failing.</p>
<p>The main reason I&#8217;ve not looked at this further however is the fact that not ALL traffic is protected. For my uses at conferences and the like, even 1 application not following the proxy rules is enough to make problems. I had to bite the bullet and go with a PPTP VPN solution for Blackhat/Defcon (although 99.9% of the time I was using 3G).</p>
<p>If you&#8217;re headed to 26C3 remember to say hi <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cedric</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-435</link>
		<dc:creator>Cedric</dc:creator>
		<pubDate>Wed, 18 Nov 2009 19:52:04 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-435</guid>
		<description>26c3 is coming:-) Are still working on a solution for this?</description>
		<content:encoded><![CDATA[<p>26c3 is coming:-) Are still working on a solution for this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-315</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Thu, 27 Aug 2009 06:56:12 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-315</guid>
		<description>Hi.  I would to try this, but I am beginner at using the mobileterminal.  I don&#039;t exactly understand how to place 3proxy.cfg file on the Iphone and run 3proxy.  Also, I am using the iSSH on my iphone.  Do I just type in the command that you have provided?  Could you send me a more detailed set of instructions for a beginner?  Thanks.</description>
		<content:encoded><![CDATA[<p>Hi.  I would to try this, but I am beginner at using the mobileterminal.  I don&#8217;t exactly understand how to place 3proxy.cfg file on the Iphone and run 3proxy.  Also, I am using the iSSH on my iphone.  Do I just type in the command that you have provided?  Could you send me a more detailed set of instructions for a beginner?  Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-245</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Fri, 03 Jul 2009 03:43:04 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-245</guid>
		<description>Hi Bob,

I can try and help, but I&#039;m going to need some more information.

Are you getting any error messages when trying to start 3proxy / SSH / or when you try and browse ?

Some points to check.

- Connect to your SSH server using a standard SSH command and make sure it connects (using password or PKI)
- Run 3proxy without the forward through the SSH tunnel (comment out the parent line) and make sure your requests appear in the 3proxy log (should be somewhere in /var/logs)
- Make sure that your terminal program is setup to remain open in the background with something like backgrounder. If you use the new version you can set an icon overlay to show that it&#039;s still active.

If it&#039;s an SSH tunnel problem, but 3proxy is working, then you should get a plain text error page in Safari (not a popup). If 3proxy isn&#039;t listening then you&#039;ll probably get a popup. You can test this by just running the 3proxy without the SSH tunnel running and you should see the error page. 

Make sure you&#039;ve setup the SSH tunnel and it&#039;s running before you start 3proxy.

If that&#039;s doesn&#039;t help then shoot me an email (contact)(_at_)(c22)(dot)(cc) and I&#039;ll try and troubleshoot.</description>
		<content:encoded><![CDATA[<p>Hi Bob,</p>
<p>I can try and help, but I&#8217;m going to need some more information.</p>
<p>Are you getting any error messages when trying to start 3proxy / SSH / or when you try and browse ?</p>
<p>Some points to check.</p>
<p>- Connect to your SSH server using a standard SSH command and make sure it connects (using password or PKI)<br />
- Run 3proxy without the forward through the SSH tunnel (comment out the parent line) and make sure your requests appear in the 3proxy log (should be somewhere in /var/logs)<br />
- Make sure that your terminal program is setup to remain open in the background with something like backgrounder. If you use the new version you can set an icon overlay to show that it&#8217;s still active.</p>
<p>If it&#8217;s an SSH tunnel problem, but 3proxy is working, then you should get a plain text error page in Safari (not a popup). If 3proxy isn&#8217;t listening then you&#8217;ll probably get a popup. You can test this by just running the 3proxy without the SSH tunnel running and you should see the error page. </p>
<p>Make sure you&#8217;ve setup the SSH tunnel and it&#8217;s running before you start 3proxy.</p>
<p>If that&#8217;s doesn&#8217;t help then shoot me an email (contact)(_at_)(c22)(dot)(cc) and I&#8217;ll try and troubleshoot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Jones</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comment-244</link>
		<dc:creator>Bob Jones</dc:creator>
		<pubDate>Fri, 03 Jul 2009 03:02:39 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540#comment-244</guid>
		<description>Hey Mate,
Ive tried this many times :( doesnt ever seem to work for me can some one help me? :D

Thanks
Bob Jones</description>
		<content:encoded><![CDATA[<p>Hey Mate,<br />
Ive tried this many times <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  doesnt ever seem to work for me can some one help me? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Thanks<br />
Bob Jones</p>
]]></content:encoded>
	</item>
</channel>
</rss>
