sslh -- an applicative-level protocol multiplexer

No ratings

Presented at Pass-the-SALT 2022 by

Once upon a time, corporate firewalls started to block port 22. But we could still ssh to port 443. sslh was originally written to listen to port 443, figure out the protocol between SSH and TLS, and forward it appropriately. 15 years in the making, sslh now supports many other protocols, including TLS SNI. We will cover the main functions and configuration of the tool, both for firewall evasion (its original, malicious use), service hiding and SNI frontend (its current, benign use).