开发者可以通过OpenSSH和Nginx的组合,搭建自托管的HTTP隧道服务。1该方案利用SSH远程转发功能,使用ssh -R 0:localhost:8080命令将本地服务暴露到互联网上的远程服务器。1Nginx则通过正则匹配p[port].ssh.luffy.cx域名格式的请求,将流量代理到对应的临时端口127.0.0.1:$port。1
为保障隧道安全性,该方案采用了Nginx的ngx_http_secure_link_module模块进行访问控制。1系统通过计算MD5哈希值,并将哈希值与过期时间戳通过HTTP Basic Auth的用户名字段传递,以实现基于哈希的认证机制。1生命周期设置为86400秒(24小时)。1为简化部署流程,辅助脚本可通过查找sshd-session进程来获取系统分配的临时端口。1
A technical approach to implementing self-hosted HTTP tunnels combines OpenSSH remote port forwarding with Nginx reverse proxying and access control mechanisms 1. The method leverages the ssh -R 0:localhost:8080 command to expose local services to the internet by forwarding them through a remote server 1. Nginx then handles incoming requests by matching domain patterns such as p[port].ssh.luffy.cx and proxying traffic to 127.0.0.1:$port 1.
Security is enforced through the ngx_http_secure_link_module, which implements hash-based access control using MD5 checksums 1. Access credentials—comprising hash values and expiration timestamps—are transmitted via the username field in HTTP Basic Authentication 1. The system sets a default token lifetime of 86400 seconds, equivalent to 24 hours 1. Supporting scripts automatically identify system-assigned temporary ports by locating the sshd-session process 1.
评论
还没有评论,欢迎留下第一条。