Remote Access and Support with ButConnect

ButConnect is an alternative remote access and support software solution that provides the opportunity to access computers and networks you don't have a direct or VPN connection to and hence anyway enables you to provide remote support in such a situation.

It works — similar to other remote connectivity tools — by collaborating with your communication partner: Only by sharing the credentials for a session he or she can enable you to connect.

ButConnect is a portable and cross-platform software. All you need is the same executables on both sides regardless of the operating system.
(Note: On systems other than Windows, Mono needs to be installed in order to run ButConnect.)

It works across firewalls. It's not necessary to adjust firewall or router settings on either side or to open or forward any ports.

There's no installation required. After downloading and unpacking a compressed file, you just launch the executable ‘ButConnect.exe’.

Moreover, no registration is requested. You just log on with the credentials that are generated on-the-fly and then passed on to you.

This way you both can easily build up an ad-hoc team and start working together.

Do you need an alternative remote access software?

As an IT professional, you are expected to just fix this or help with that quite often — even when you're off site.
If you have VPN access to that location, there's no problem. But if it's, for instance, a new customer you are not yet really associated with and thus have no control over their infrastructure or if it's a friend, a relative or other private person or in any other unprepared situation, you don't have any remote access to their computers, usually.
Fortunately, most of them are behind a firewall but also have no clue how to let you in from the Internet.

Remote support without connection could be a challenge ...
This is where ButConnect comes into play — with ButConnect you connect anyway!

In fact, you can do remote access with other tools, too. Some of them are free for non-commercial use, but if you want to use them lawfully as an IT professional, it can be quite expensive.
Some even stop you from helping others by claiming ‘Commercial use suspected’ or ‘Commercial use detected’, even when you are using it non-commercially.

By contrast, ButConnect is free for both private and business use. It could be a substitute for all those well-established remote access and support solutions but also offers some extra features.

How does remote access with ButConnect work?

Both you and your communication partner simply need to launch ‘ButConnect.exe’.

The “client” uses ButConnect in client mode by just pressing the [Return] key. He gets the credentials for a specific channel back and communicates them to his agent by phone or text message.

The “agent” for his part switches over to agent mode by typing [A] (or ‘agent’) and then pressing the [Return] key. He is now for a short period of time able to join that particular channel by logging on using those credentials.

After that time and when a session is finished, the channel will be destroyed and can no longer be used.

As soon (and as long) as the connection is established, the agent is able to access the client's host. The agent pretends to direct the requests to his own computer — it looks like he's talking to the local host, but in fact the communication is redirected and forwarded to the remote host.

ButConnect is powered by the secure shell (SSH) protocol. This means your communication is encrypted and even if the public and private keys are available, it is not possible to decrypt the transferred data and your privacy is still protected.
(In fact, the SSH keys of the default client and agent user are included in the ButConnect executable, but these are used for authentication against the ButConnect servers only — and ... well ... anyone is welcome to use our service and thus is also authenticated to do so. For the encryption within the channel, a Diffie-Hellman Key Exchange is used and those keys are not available.)

Furthermore, nothing is stored on the “broker” (the ButConnect server), not even when transferring files. The broker only manages the connection between two communication partners by providing a “channel”.

Remote Support and Other Possibilities

Once you got that channel, you can use it for the type of communication you need to satisfy your or your customer's requirements.
A few basic use cases are integrated already:

(File transfer and chat can coexist with a running remote support session without conflict. Alternatively, you can use the file transfer or chat capabilities of UltraVNC or other tools over the ButConnect link.)

What else? What makes ButConnect unique?

For advanced users, there are some more possibilities than this.
But also and above all, there's actually more than provided by other remote connectivity tools:

This way, ButConnect provides a “link” from one network into the other. Without the need to install and configure a gateway but only by exchanging credentials (username, password and a code), you get a VPN-like functionality when a real VPN is not available.
(But unlike a VPN, ButConnect restricts access to the intended host and port. It does not additionally give access to the entire network and therefore makes it easier to adhere to the ‘zero trust’ principle. However, if access is granted to a remote desktop or to a command line, this restriction can be overcome.)

For all those facilities, no administrative privileges are required on both the client and the agent host.

So ... as the “client”, be careful not to break your company's security policy by accident! Only give access to those agents you know and trust!
And as the “agent”, act in a responsible manner!

All Linked Together

Apart from the default mode that works either on invitation or unattended, there is also a direct mode for connecting to the remote network via your own or your customer's SSH server.
Connections in both modes can be combined and cascaded to build on each other and thus bring even more devices within reach.
Once it has been set up with keys from our shop, a small ButConnect Appliance can provide access to any device on your network without further configuration and without exposing it to the Internet.
That appliance running ButConnect just needs to be connected to your network and have basic Internet access. No port forwarding and no firewall or router configuration is required.

Unlike others, it's not expensive.

The use of ButConnect is basically free of charge for both personal and commercial use.

If you want to automate things (for instance for unattended operation on the client side or even on both sides) or if you want stronger security, it's possible to get your own dedicated SSH keys and thus your own username, password and code. In that case, there would also be no need to visit the ButConnect website and get a new code for every single connection.
Don't hesitate to contact us (info@butconnect.com) or visit our shop to get those keys online.

It's secure!

Okay — let's assume the SSH protocol is quite secure and well tested.
We rely on SSH and didn't change anything regarding the use of its protocol.
(BTW: We use SSH.NET and OpenSSH for the SSH part.)

When generating the credentials, we use 8 randomly chosen lower case letters for usernames and randomly chosen numbers between 16384 and 49151 for passwords. Together, that's more than 6.8x1015 different combinations. Additionally, we use a randomly chosen combination of one lower case letter and one digit for the code.
After several unsuccessful attempts to log on or to get a code, the IP address of a possible attacker will be blocked for longer than the created account exists at all.

If you got your own dedicated SSH keys, your username, password and code will no longer be generated randomly for every new session, but are fixed now. Also, your account is available permanently.
On the other hand, your account is additionally secured with that SSH key (which is much stronger than the username/password/code combination and which for its part can — and should — be secured with a passphrase).