An SSH tunnel configuration is a restricted Linux user that can only forward traffic β no shell and no admin rights. Apps such as HTTP Injector, HTTP Custom and NetMod use these accounts to route a phone's traffic through the server, optionally wrapped in SSL (port 443) or WebSocket (port 80) for networks that only allow web traffic.
How to use it
- Create an SSH configuration and note the host, port, username and password.
- In your tunnel app, add a new SSH profile with those details. Pick the SSL or WebSocket port if plain SSH (port 22) is blocked.
- Connect.
On a computer
A single command turns the account into a SOCKS5 proxy for your browser:
ssh -N -D 1080 username@server-address
Then set your browser's SOCKS5 proxy to 127.0.0.1:1080.
SSH tunnels are light and flexible but only carry what you send through them; for a full-device VPN use WireGuard, OpenVPN or V2Ray.