Advanced SSH Techniques
stearns.org
stearns.org
That said, fanout can still be a useful utility.
I should make a blog post detailing my setup, but for now, I'll share the critical pieces:
In my local .ssh/config:
==========
Host vpn
ForwardAgent=yes
ProxyCommand none
ControlMaster auto
ControlPath=~/.ssh/%r@%h:%p
HostName myvpn.domain.com
Host dest??
ProxyCommand ssh vpn 'nc -w 60 %h.internal.domain.com %p'
==========Then, if I ssh to any dest machine like dest01 or dest05, the first one will create the connection to the vpn jumphost, and all the subsequent ones will reuse that connection.
sudo /bin/dd if=/path/to/anything of=/sbin/route
sudo /sbin/route # pwned!
So I can now run ANY program without a password. If you like, throw in a few more dd commands to backup/restore the abused command (route).He also has /sbin/insmod in NOPASSWD, which is another "get out of jail free" card. If I can load a kernel module, I can do anything.
It can be run in both interactive and non-interactive modes. The interactive mode is curses based and lets you easily control how many of your ssh tasks run in parallel, lets you pause and resume, and nicely separates out the stdout and stderr output. The non-interactive modes let you define what success means in terms out output and return code, and splits out output and return codes into separate files for further processing.
ssh martha -> ssh waldo -> do stuff -> exit ssh othermachine -> do stuff -> exit exit
Port-forwarding surely works but did he explain the origins of this problem somewhere?
You only need some place where you can do for loops and spawn subsequent ssh connections -- 'martha' sounds like a good candidate for that.