Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go »
No member browsing this thread
Thread Status: Active
Total posts in this thread: 6
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 1128 times and has 5 replies Next Thread
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
WCG uses HTTPS 'CONNECT' method

I'm currently trying to use WCG through a Squid proxy but I think it uses HTTPS 'CONNECT' method to encapsulate its data.
This method is known to have security issue: setting up a tunnel with an external server, an internal user could use virtually any type of programs (IM, P2P, etc). In fact, many http-tunnelling-through-CONNECT programs exist (for instance, hopster).

Any suggestion?
[Jan 11, 2005 1:33:03 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: WCG uses HTTPS 'CONNECT' method

your could use http tunnel ng along with SocksCap V2, or ask your system admin to open the ports the gird agent uses..
[Jan 11, 2005 2:58:01 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Alther
Former World Community Grid Tech
United States of America
Joined: Sep 30, 2004
Post Count: 414
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: WCG uses HTTPS 'CONNECT' method

I'm currently trying to use WCG through a Squid proxy but I think it uses HTTPS 'CONNECT' method to encapsulate its data.
This method is known to have security issue: setting up a tunnel with an external server, an internal user could use virtually any type of programs (IM, P2P, etc). In fact, many http-tunnelling-through-CONNECT programs exist (for instance, hopster).

Any suggestion?

The Agent has to use the HTTPS CONNECT method if you have a proxy set up. It's the only way to make an SSL connection through a proxy.

I'm not sure what security issues you are talking about though. From the client side there shouldn't be any issues. The SSL connection is still made and the traffic flows between the client and server encrypted.

The example you list is a potential issue from the firewall admin's perspecitve. Since by definition they're not alllowed to view HTTPS CONNECT traffic and thus can't stop anything from being tunneled through it. It can be filtered on the server and port if you like.

Can you list your concerns in more detail?
----------------------------------------
Rick Alther
Former World Community Grid Developer
[Jan 11, 2005 4:32:05 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: WCG uses HTTPS 'CONNECT' method

I'm also the firewall admin :-)
And I hate to know that there are application tunnelling any type of traffic in HTTPS.
In any case, I'm unable to pass WCG traffic through my proxy (Squid), peraphs because have I an antivirus (Trend IWSS) along the chain?
[Jan 12, 2005 5:01:31 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Alther
Former World Community Grid Tech
United States of America
Joined: Sep 30, 2004
Post Count: 414
Status: Offline
Project Badges:
Reply to this Post  Reply with Quote 
Re: WCG uses HTTPS 'CONNECT' method

I'm also the firewall admin :-)
And I hate to know that there are application tunnelling any type of traffic in HTTPS.

You mean like a web browser? I still don't understand your concerns. It seems like you object to us sending the data back to our servers encrypted. This is done primarily so results can't be tampered with during communication.

The reason admins have some worries about ANY secure connection is because malicious programs can pump data through it and they can't look at it. But that's true for any secure connection (HTTPS, SSH, any SSL/TLS connection, etc.), regardless if it's proxied or not. Either they allow it or the shut off all secure communication out of the network. Except for closed networks, I've never seen anyone shut down secure communications. If you're that worried about bad programs on your system, you can always set up the proxy to allow only certain endpoints so that you allow known traffic through.
In any case, I'm unable to pass WCG traffic through my proxy (Squid), peraphs because have I an antivirus (Trend IWSS) along the chain?

As for why it can't connect, AV shouldn't be the culprit. Does it intercept all outgoing traffic? I would think any AV software would simply allow HTTPS traffic to go through since it can't possibly check it for virus'.

How about your proxy? What does it say regarding the connection? Does it deny it? Did you ever download a workunit? Did you set up the proxy information correctly in the Agent?
----------------------------------------
Rick Alther
Former World Community Grid Developer
[Jan 12, 2005 9:49:36 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: WCG uses HTTPS 'CONNECT' method

Ok, don't worry for my paranoic thoughts....

Now, I have no time to look in depth the problem with proxy. I disabled proxy for myself only and I'm running WCG without problems, because I like this project!

We can close this thread.
[Jan 14, 2005 5:06:50 PM]   Link   Report threatening or abusive post: please login first  Go to top 
[ Jump to Last Post ]
Post new Thread