Show HN: Mole – an open source tool to easily create ssh tunnels
davrodpin.github.io
davrodpin.github.io
It's the same with mosh. Normally i use tmux on the destination host, and i simply cannot see any reason to use mosh over ssh/tmux.
How about automatic session resumption and predictive character insertion to improve typing when under latency?
tmux a
As for predictive character insertion, when i'm working in a shell, especially with high latency, i prefer my commands to be as i type them, not something some algorithm "guessed" i was going to type.In other words, imagine typing ssh somebox.typo.com and waiting 1 second before the text renders and discovering the typo, then pressing backspace, waiting a while for the backspaces to render, then going through all of this again. With mosh you'll be able to instantly see what you typed and fix it. On high latency connections it makes a huge difference in quality of life.
Basically for those with experience of text terminals genrally: local echo.
Everything there connected via serial ports, remote offices got multiplexed over a 9600 baud connection. Back then we had local echo for the sometimes slow link, i.e. printing a spreadsheet converted to 3Mb PostScript, and still only 9600 baud in total.
So i know what local echo is. It has nothing to do with prediction :)
I'm still not convinced about mosh, but it sounds like it really does help a lot of people, so who am i to judge. I guess i'm privileged since i don't usually experience latency. We have about 95% 4G coverage in this country, coupled with fiber connections.
The last time i experienced any noticeable latency was when editing files on a clients SCO OpenServer across The Atlantic Ocean over a 1200 baud connection.
Not precisely, because you're sometimes predicting whether a keypress should be rendered as a letter on the screen or not (e.g. if you click 'j' in vim command mode it doesn't actually print j). mosh, at least from my experimentation, seems smart enough to do that reliably.
We also never have enough players for the latest FPS games that require low latency :(
As well as that and protecting unencrypted traffic on public WiFi, I get my ad blocker & other protection and credit card payments are smoother as the payment processors think I am at home not coming from some random address so doesn't ask for extra security details as often as they otherwise would.
It works well WITH tmux, not instead of tmux.
Which means your solution would be something like:
while true; do
ssh -t ${HOST} tmux a
done
But that lacks the other benefits, especially having to wait for the session to timeout.. Take a look at:
https://en.wikipedia.org/wiki/Mosh_(software)#Performancehttps://www.everythingcli.org/ssh-tunnelling-for-fun-and-pro...
Someone else opened an issue requesting that: https://github.com/davrodpin/mole/issues/22
It also has aliases to store configuration that user usually use, but that is comparable to the ssh config file.
autossh detects and restarts broken tunnels and uses aliases and tidy config files: https://www.everythingcli.org/ssh-tunnelling-for-fun-and-pro...
$ mole -local 127.0.0.1:3306 -remote 127.0.0.1:3306 -server example@172.12.0.100
$ ssh -L3306:127.0.0.1:3306 example@172.12.0.100
$ mole -v -local 127.0.0.1:8080 -remote 172.17.0.100:80 -server user@example.com:22 -key ~/.ssh/id_rsa
$ ssh -v -L8080:172.17.0.100:80 -p 22 -I ~/.ssh/id_rsa user@example.com
$ mole -v -local 127.0.0.1:8080 -remote 172.17.0.100:80 -server example1
$ ssh -v -L8080:172.17.0.100:80 example1
$ mole -remote 172.17.0.100:80 -server example1
$ ssh -L2937:172.17.0.100:80 example1
NB Random port is predefined to be 2937, see https://xkcd.com/221/. Or use $RANDOM.
$ mole -v -local :8080 -remote 172.17.0.100:80 -server example1
$ ssh -L8080:172.17.0.100:80 example1
NB difference with SSH, -L:8080... would bind the local port to 0.0.0.0:8080.
$ mole -v -local 127.0.0.1:8080 -remote :80 -server example1
$ ssh -L8080:127.0.0.1:80 example1
$ mole -alias example1 -v -local :8443 -remote :443 -server user@example.com
Add to SSH config: "LocalForward 8443 localhost:443"
I don't know if Mole supports it, but SSH also has the option to forward a remote port through the local machine. home $ ssh -R8888:example.net:80 work.example.com
...
work $ curl -H "Host: example.net" localhost:8888
But the most useful of all is perhaps: work $ ssh -D3128 personal-vm-or-raspberry-pi-whatever.example.net
Then configure Firefox to use a SOCKS proxy on localhost:3128. You now bypass any corporate HTTP proxy. ssh -D *:1080 work
Combined with a .pac file that proxies my work domain(s) through the tunnel, it's all the forwarding I ever need.ETA: largely redundant comment now the parent now also mentions this option. :)
NB including
*:
does mean anyone on your local network (assuming a firewall at the gateway) can use your computer to proxy to work. That's great if you're on a private LAN and want to look at a work site on your phone, but not great at a coffee shop.Assuming that said corporation isn’t blocking random ssh connections with their fancy NGFW. ;)
This is 2018, anyone who can bypass their corporate proxy with that example, should find employment elsewhere or atleast prepare to do so since your company's internals will surface on twitter any time now.
$ mole -v -remote :80 -server example1
The missing "-local" flag will make mole to listen on a random local port.
ZeroTier solves all your networking needs and much more, the thing is pure power.
ssh -L 21234:localhost:1234 bob@server.com
I will confess that I googled it numerous times until one day I realized how silly and obvious it was and now it's burned into my brain...
curl -L https://... | tar xz -C /usr/local/bin
curl -L https://github.com/davrodpin/mole/releases/download/v0.2.0/m... | tar xz -C /usr/local/bin
And there are plans to implement a script to improve this process: https://github.com/davrodpin/mole/issues/19
I find it easy to remember, it's just one flag (-L) with local_port:remote_ip:remote_port
to forward local port 3306 to mysqlhost:3306:
ssh -L 3306:mysqlhost:3306
The strength of using ssh is that you can forward multiple ports with the same connection.
i.e. ssh -L 3306:mysqlhost:3306 -L 8080:webhost:80In the same topic, do you remember the syntax of tar? I don't. https://www.xkcd.com/1168/
copy files from a to b:
(cd /src && tar cf - .) | (cd /dest && tar xf -)
operations are easy :(c)reate, e(x)tract, (t)est
options the same: (f)ile, (v)erbose, g(z)ip compression.
the only illogical ones is bzip2 compression and xz compression with -j and -JI think i can remember cpio syntax as well, though i haven't used that i a decade, but did use it quite often in my old sysadm job.
copy files from a to b by piping :
find /somewhere -print | cpio -o | (cd /destination && cpio -i)
or simply for all you kids: find /somewhere -print | cpio -p /destinationMy brain chooses to store other things in life.
mole -local 127.0.0.1:3306 -remote 127.0.0.1:3306 -server example@172.12.0.100
vs ssh -L 3306:127.0.0.1:3306 example@172.12.0.100
With the extra installation of mole on top.