SSH tricks
matt.might.net
matt.might.net
Unfortunately this guide does not mention ssh-agent to have usable passphrased keys. Tip: Mac OS X Keychain integrates fantastically with ssh-agent.
My favorite trick is transparently bouncing via ProxyCommand+netcat:
Host target.domain
Hostname target.local
ProxyCommand ssh -q bounce_host.domain nc -q0 %h 22
Also, authorizing by key but restricting the (passwordless) key to certain commands, allowing for remote action automation. [0]Ssh agent forwarding is also particularly awesome instead of naively scattering keys.
Ssh ControlMaster allowing to reuse connections can really improve responsiveness. Tip: start the master connection as a daemon (-f), so as not to mistakenly close the terminal which handles it, else you will close the channel for all other currently opened slave sessions. I wish ssh would fork and start the master on demand then close it when the last channel closes.
[0] http://www.cmdln.org/2008/02/11/restricting-ssh-commands/
It gives you most of the benefits of VPN, without requiring tun/tap and without needing root on the remote box -- all you need is the ability to run python. Very useful if you're on an insecure network and you want to tunnel everything over a secure connection, or if you have SSH access to a box inside your firewall and want to access other resources without having to specify each port individually.
Yes it does, but I've noticed when I do this, it breaks my rsnapshot backups. Is this something you've heard of or know a fix for?
Just FYI, that worked perfectly.
host *%*
proxycommand ssh $(echo %h | cut -d%% -f1) nc $(echo %h | cut -d%% -f2) %p
usage: ssh gateway%target Host *%*
Proxycommand ssh $(echo %h | rev | cut -d%% -f2- | rev) nc $(echo %h | rev | cut -d%% -f1 | rev) %p
usage: ssh gateway1%gateway2%target
(Not very clean, improvements welcome.) Host *%*
Proxycommand bash -c "h=%h; ssh \${h%%\\%%*} nc \${h##*%%} %p"
It would be shorter and cleaner if I knew a way to apply string operators on a constant string rather than defining the intermediate variable $h.Good news: as of OpenSSH 5.6p1, it can. Just set "ControlPersist 60" in ~/.ssh/config (in addition to setting ControlMaster auto and ControlPath), and ssh will automatically spawn an SSH master connection in the background, and close it 60 seconds after the last client exits. (You can obviously change the timeout to taste.)
here's what! it uses the intermediate hosts as a tunnel, which means no ssh agent is listening on the hosts (the regular way to do this is ssh -A hostx ssh -A hosty ssh finalhost)
This means no attacker can use your agent while connected.
Additionally, its less cumbersome when its setup.
What every CS major should know (http://matt.might.net/articles/what-cs-majors-should-know/)
12 resolutions for programmers (http://matt.might.net/articles/programmers-resolutions/)
These recent posts are part of the lecture notes for my "Scripting Language Design and Implementation" course.
There are slides that go along with some of them:
http://matt.might.net/teaching/scripting-languages/spring-20...
I prefer spartan slides, so I'm not sure how useful they are without me presenting them.
But, I'll throw them out there since there are a few nuggets in them that are not in the posts.
There are also slides for non-existent posts (e.g. bash), because I don't always have time to transcribe my notes into a blog post.
And article needs a date before any award is bestowed.
Re: iOS -- Panic (makers of Coda, etc.) developed a _really_ nice little iOS app for SSH called 'Prompt'. It got some coverage here when it was released, and I immediately replaced iSSH with it and haven't looked back once.
http://www.panic.com/blog/2011/04/introducing-prompt-ssh-for...
Here is an article with some less known features of ssh: http://www.jedi.be/blog/2010/08/27/ssh-tricks-the-usual-and-...
> $ cat .ssh/id_dsa.pub | ssh host 'cat >> ~/.ssh/authorized_keys'
Using ssh-copy-id is simpler: ssh-copy-id host
(Works On My Machine™)http://phildawson.tumblr.com/post/484798267/ssh-copy-id-in-m...
brew install ssh-copy-id $ tar czf - foo | ssh remote "cd /where/to/unpack && tar xzf -"
This is often significantly faster than rsync, e.g. when copying a directory with many files for the first (or only) time. $ scp -r remote foo /where/to/unpack $ tar cz foo | ssh remote "cd /where/to/unpack && tar xz"Or use ssh -C
IOW, specify "f -". :-)
The remote port forwarding feature can be very handy. I've used a combination of ssh and daemontools to set up remote access to a machine behind a particularly nasty firewall.
don't you have one of those?
The cryptostick does look cool. I've come across it before. I like the smart card because I can just pop it in my wallet like a credit card.
You can also get keyboards with built in smart card readers, where the numeric keypad has a mode to operate as a hardware pin pad (rather than sending the keypresses to the computer) I'm thinking of getting one of these at some point.
Another config option that has saved me a lot of time is the "ProxyCommand" option that lets you specify a command, whose stdin is used as a pipe to talk to a remote server. So, something like:
Host inside
ProxyCommand ssh gateway nc inside 22
Would allow you to just type "ssh inside" and ssh to a machine behind a gateway, without ssh-ing twice! ssh -[N]D 1080 [-p 33] user@server
A SOCKS5 proxy on the go...Another point is that most firewalls block most ports, but usually not 443 (https). So set up your SSH server on port 443. Since all traffic to 443 is encrypted anyway, you're less likely to raise suspicion.
SSH agents let you keep your key encrypted while only needing to enter your passphrase on first use (with the default ssh-agent, you must load the key manually with ssh-add; gpg-agent and seahorse both prompt you the first time it's needed). Add that to SSH agent forwarding (where multi-hop SSH connections authenticate using the agent on the originating machine, and your key is (A) only on the local machine and (B) encrypted when not in use.
ProxyCommand /usr/bin/corkscrew localhost 3128 %h %p
Finally, set up the socks proxy (most of these proxies only allow outgoing connections over ports 80 and 443):
ssh -ND2345 -p443 host
I use this technique constantly at school to browse the web unrestricted and with privacy.
While corporate IT couldn't tell exactly what was going on, they did ask him why he was ssh'd to an ISP-provided IP for X hours using Y bytes. So don't try to outclever your company this way; they can still nab you on suspicion of whatever, even if what you did was non-harmful in any way.
here are my 2 cents: http://txlab.wordpress.com/2012/01/25/call-home-ssh-scripts/