Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Security arrow Security How To arrow How To Securely Browse from Anywhere using Hamachi and Squid
How To Securely Browse from Anywhere using Hamachi and Squid Print E-mail
Joseph Dabbs   
May 06, 2008
Slashdot
Digg
Technorati
Delicious
Stumble

Introduction

A mobile user relying on public Internet access has to accept certain inherent risks. Unscrupulous individuals can intercept and record your traffic, or even interpose themselves into the session, taking the place of any party. Your traffic can also be blocked or filtered at will, with little notice.

While these risks can never truly be mitigated, measures can be taken that reduce the potential for harm. This article will show you how to use two applications, Hamachi and Squid, to set up a secure connection to a web proxy that can be used for secure web browsing no matter where you are.

In-the-clear browsing can be monitored

Figure 1: In-the-clear browsing can be monitored

Figure 1 is a simplified diagram of normal Internet traffic, in this case HTTP. A user’s Internet browser sends a request for data to a web server, which then replies with the data requested. The Eavesdropper, an individual who gains access to the session traffic, is able to obtain passwords transmitted in plaintext, all without the knowledge or consent of the user.

If a wired connection is used, the Eavesdropper must have physical access to the network being used. A wireless network, however, such as a public Wi-Fi Hotspot can be monitored from afar with no physical connection.

Today, most e-commerce sites rely on SSL to encrypt passwords. But there are still many sites in use (forums and blogs being the most prevalent) that provide easy pickings for anyone with basic competency in packet sniffing. Although it would be ideal to have every site engage in secure communications with its users, the reality is that the responsibility of safeguarding credentials is too often placed squarely on the user.

If a secure session cannot be established between a site and user, the next best solution is to secure at least part of the connection. This is illustrated in Figure 2.

Secure connection to a Proxy server

Figure 2: Secure connection to a Proxy server

Figure 2 illustrates the data flow of a user relying on VPN to traverse an untrusted network. Instead of querying the web server directly (as in Figure 1), the Internet browser forwards the request to a proxy server, which then conducts a session with the web server on the client’s behalf.

Communication between the client and proxy (which should be all the HTTP traffic) is routed through the tunnel established by VPN software (Hamachi). Since this tunnel encrypts traffic passing through it, Eavesdropper is unable to obtain any plaintext data. Without the ability to read traffic, the risk of someone hijacking the session is sharply reduced, resulting in an overall improvement in security.



Comments (2)Add Comment

Write comment

busy

Tags: Hamachi, Proxy, Squid,

Related Articles:

How To Securely Web Browse via an SSH Tunnel
How To: Fixing DNS problems
Anthology Solutions Yellow Machine TeraByte Storage Appliance
SmoothWall Express 2.0
A DIY SSL VPN with SSL-Explorer - Part 1
 

Most Read

 
 

Over at the Forums

DIR-615 REVB2 with F/W 2.25 and DES-1105 Switch
I have a D-Link DIR-615 REVB2 Wireless Draft 2.0 802.11n router with F/W 2.25 and have enabled the QoS engine on the router and I am planning on...

NAS = High Margin?
It seems NAS are generally using Open Source OS and some cheap components. While the software may not be totally free. It still much cheaper then...

HTPC or Set Top Box
There doesn't seem to be any really good choices, or maybe there's too many, because I can't decide how I want to handle streaming from the Internet...

Putting together the SNB RAID NAS Explorer
Ok folks. I'm going to bite on the question that many of you have been asking: What are the factors in putting together a fast NAS? So I'm...

One Internet, Two Private LANs
I read with great interest the article about One Internet connection - Two Private LANs. I've wanted to do this very thing for some time and no...

Slideshows

Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router Adtran NetVanta 3120 Buffalo LinkStation Mini Intel Entry Storage System SS4200-E D-Link DAP-1522 Xtreme N Duo Wireless Bridge / Access Point More

Win This!

You could win this D-Link Xtreme N Duo Wireless Bridge / Access Point

Learn How!

 
Go Shopping with PriceGrabber

Get Email Updates

Enter your email address:

Delivered by FeedBurner once a day

 


This page took 2.04974102974 seconds to load.