ื˜ื™ืคื™ื ืžืขืฉื™ื™ื, ื“ื•ื’ืžืื•ืช ื•ืžื ื”ืจื•ืช SSH

ื˜ื™ืคื™ื ืžืขืฉื™ื™ื, ื“ื•ื’ืžืื•ืช ื•ืžื ื”ืจื•ืช SSH
ื“ื•ื’ืžืื•ืช ืžืขืฉื™ื•ืช SSH, ืฉื™ื™ืงื— ืืช ื”ื›ื™ืฉื•ืจื™ื ืฉืœืš ื›ืžื ื”ืœ ืžืขืจื›ืช ืžืจื—ื•ืง ืœืจืžื” ื—ื“ืฉื”. ืคืงื•ื“ื•ืช ื•ื˜ื™ืคื™ื ื™ืขื–ืจื• ืœื ืจืง ืœื”ืฉืชืžืฉ SSH, ืื‘ืœ ื’ื ืœื ื•ื•ื˜ ื‘ืจืฉืช ื‘ืฆื•ืจื” ืžื•ื›ืฉืจืช ื™ื•ืชืจ.

ืœื“ืขืช ื›ืžื” ื˜ืจื™ืงื™ื ssh ืฉื™ืžื•ืฉื™ ืœื›ืœ ืžื ื”ืœ ืžืขืจื›ืช, ืžื”ื ื“ืก ืจืฉืช ืื• ืžื•ืžื—ื” ืื‘ื˜ื—ื”.

ื“ื•ื’ืžืื•ืช SSH ืžืขืฉื™ื•ืช

  1. ืคืจื•ืงืกื™ ื’ืจื‘ื™ SSH
  2. ืžื ื”ืจืช SSH (ื”ืขื‘ืจืช ื ืžืœ)
  3. ืžื ื”ืจืช SSH ืœืžืืจื— ืฉืœื™ืฉื™
  4. ืžื ื”ืจืช SSH ื”ืคื•ื›ื”
  5. ืคืจื•ืงืกื™ ื”ืคื•ืš ืฉืœ SSH
  6. ื”ืชืงื ืช VPN ืขืœ SSH
  7. ื”ืขืชืงืช ืžืคืชื— SSH (ssh-copy-id)
  8. ื‘ื™ืฆื•ืข ืคืงื•ื“ื” ืžืจื—ื•ืง (ืœื ืื™ื ื˜ืจืืงื˜ื™ื‘ื™)
  9. ืœื›ื™ื“ืช ืžื ื•ืช ื•ืฆืคื™ื™ื” ืžืจื—ื•ืง ื‘-Wireshark
  10. ื”ืขืชืงืช ืชื™ืงื™ื” ืžืงื•ืžื™ืช ืœืฉืจืช ืžืจื•ื—ืง ื‘ืืžืฆืขื•ืช SSH
  11. ื™ื™ืฉื•ืžื™ GUI ืžืจื•ื—ืงื™ื ืขื SSH X11 Forwarding
  12. ื”ืขืชืงืช ืงื‘ืฆื™ื ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช rsync ื•-SSH
  13. SSH ื“ืจืš ืจืฉืช Tor
  14. ืžื•ืคืข SSH ืœ-EC2
  15. ืขืจื™ื›ืช ืงื‘ืฆื™ ื˜ืงืกื˜ ื‘ืืžืฆืขื•ืช VIM ื‘ืืžืฆืขื•ืช ssh/scp
  16. ื”ืชืงืŸ SSH ืžืจื•ื—ืง ื›ืชื™ืงื™ื” ืžืงื•ืžื™ืช ืขื SSHFS
  17. ืจื™ื‘ื•ื™ SSH ืขื ControlPath
  18. ื”ื–ืจื ื•ื™ื“ืื• ืขืœ SSH ื‘ืืžืฆืขื•ืช VLC ื•-SFTP
  19. ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™
  20. ืžืืจื—ื™ื ืงื•ืคืฆื™ื ืขื SSH ื•-J
  21. ื—ืกื™ืžืช ื ื™ืกื™ื•ื ื•ืช SSH brute force ื‘ืืžืฆืขื•ืช iptables
  22. SSH Escape ื›ื“ื™ ืœืฉื ื•ืช ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช

ืงื•ื“ื ื›ืœ ื”ื™ืกื•ื“ื•ืช

ื ื™ืชื•ื— ืฉื•ืจืช ื”ืคืงื•ื“ื” SSH

ื”ื“ื•ื’ืžื” ื”ื‘ืื” ืžืฉืชืžืฉืช ื‘ืคืจืžื˜ืจื™ื ื ืคื•ืฆื™ื ืฉื ืชืงืœื™ื ื‘ื”ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืฉืจืช ืžืจื•ื—ืง SSH.

localhost:~$ ssh -v -p 22 -C neo@remoteserver

  • -v: ืคืœื˜ ื ื™ืคื•ื™ ื‘ืื’ื™ื ืฉื™ืžื•ืฉื™ ื‘ืžื™ื•ื—ื“ ื‘ืขืช ื ื™ืชื•ื— ื‘ืขื™ื•ืช ืื™ืžื•ืช. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ืžืกืคืจ ืคืขืžื™ื ืœื”ืฆื’ืช ืžื™ื“ืข ื ื•ืกืฃ.
  • - p 22: ื™ืฆื™ืืช ื—ื™ื‘ื•ืจ ืœืฉืจืช SSH ืžืจื•ื—ืง. ืื™ืŸ ืฆื•ืจืš ืœืฆื™ื™ืŸ 22, ื›ื™ ื–ื”ื• ืขืจืš ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ืืš ืื ื”ืคืจื•ื˜ื•ืงื•ืœ ื ืžืฆื ื‘ื™ืฆื™ืื” ืื—ืจืช, ืื ื• ืžืฆื™ื™ื ื™ื ืื•ืชื• ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ -p. ื™ืฆื™ืืช ื”ื”ืื–ื ื” ืžืฆื•ื™ื ืช ื‘ืงื•ื‘ืฅ sshd_config ื‘ืคื•ืจืžื˜ Port 2222.
  • -C: ื“ื—ื™ืกื” ืœื—ื™ื‘ื•ืจ. ืื ื™ืฉ ืœืš ื—ื™ื‘ื•ืจ ืื™ื˜ื™ ืื• ืฆื•ืคื” ื”ืจื‘ื” ื˜ืงืกื˜, ื–ื” ื™ื›ื•ืœ ืœื”ืื™ืฅ ืืช ื”ื—ื™ื‘ื•ืจ.
  • neo@: ื”ืฉื•ืจื” ืœืคื ื™ ื”ืกืžืœ @ ืžืฆื™ื™ื ืช ืืช ืฉื ื”ืžืฉืชืžืฉ ืœืื™ืžื•ืช ื‘ืฉืจืช ื”ืžืจื•ื—ืง. ืื ืœื ืชืฆื™ื™ืŸ ื–ืืช, ื”ื•ื ื™ืงื‘ืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืืช ืฉื ื”ืžืฉืชืžืฉ ืฉืœ ื”ื—ืฉื‘ื•ืŸ ืืœื™ื• ืืชื” ืžื—ื•ื‘ืจ ื›ืขืช (~$whoami). ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืืช ื”ืžืฉืชืžืฉ ื’ื ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ -l.
  • remoteserver: ืฉื ื”ืžืืจื— ืฉืืœื™ื• ื™ืฉ ืœื”ืชื—ื‘ืจ ssh, ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื ื“ื•ืžื™ื™ืŸ ืžืœื, ื›ืชื•ื‘ืช IP ืื• ื›ืœ ืžืืจื— ื‘ืงื•ื‘ืฅ ื”ืžืืจื—ื™ื ื”ืžืงื•ืžื™. ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืœืžืืจื— ืฉืชื•ืžืš ื’ื ื‘-IPv4 ื•ื’ื ื‘-IPv6, ืืชื” ื™ื›ื•ืœ ืœื”ื•ืกื™ืฃ ืืช ื”ืคืจืžื˜ืจ ืœืฉื•ืจืช ื”ืคืงื•ื“ื” -4 ืื• -6 ืœืคืชืจื•ืŸ ื ื›ื•ืŸ.

ื›ืœ ื”ืคืจืžื˜ืจื™ื ืœืขื™ืœ ื”ื ืื•ืคืฆื™ื•ื ืœื™ื™ื ืœืžืขื˜ remoteserver.

ืฉื™ืžื•ืฉ ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื”

ืœืžืจื•ืช ืฉืจื‘ื™ื ืžื›ื™ืจื™ื ืืช ื”ืงื•ื‘ืฅ sshd_config, ื™ืฉ ื’ื ืงื•ื‘ืฅ ืชืฆื•ืจืช ืœืงื•ื— ืขื‘ื•ืจ ื”ืคืงื•ื“ื” ssh. ืขืจืš ื‘ืจื™ืจืช ืžื—ื“ืœ ~/.ssh/config, ืืš ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืื•ืชื• ื›ืคืจืžื˜ืจ ืœืื•ืคืฆื™ื” -F.

Host *
     Port 2222

Host remoteserver
     HostName remoteserver.thematrix.io
     User neo
     Port 2112
     IdentityFile /home/test/.ssh/remoteserver.private_key

ื™ืฉื ื ืฉื ื™ ืขืจื›ื™ ืžืืจื— ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืœื“ื•ื’ืžื” ืฉืœ ssh ืœืžืขืœื”. ื”ืจืืฉื•ืŸ ืื•ืžืจ ืืช ื›ืœ ื”ืžืืจื—ื™ื, ื›ื•ืœื ืžืฉืชืžืฉื™ื ื‘ืคืจืžื˜ืจ ื”ืชืฆื•ืจื” ืฉืœ Port 2222. ื”ืฉื ื™ ืื•ืžืจ ืฉืขื‘ื•ืจ ื”ืžืืจื— ืฉืจืช ืžืจื•ื—ืง ื™ืฉ ืœื”ืฉืชืžืฉ ื‘ืฉื ืžืฉืชืžืฉ, ื™ืฆื™ืื”, FQDN ื•-IdentityFile ืฉื•ื ื™ื.

ืงื•ื‘ืฅ ืชืฆื•ืจื” ื™ื›ื•ืœ ืœื—ืกื•ืš ื–ืžืŸ ื”ืงืœื“ื” ืจื‘ ื‘ื›ืš ืฉื”ื•ื ืžืืคืฉืจ ื™ื™ืฉื•ื ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืชืฆื•ืจื” ืžืชืงื“ืžืช ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืžืืจื—ื™ื ืกืคืฆื™ืคื™ื™ื.

ื”ืขืชืงืช ืงื‘ืฆื™ื ื“ืจืš SSH ื‘ืืžืฆืขื•ืช SCP

ืœืงื•ื— SSH ืžื’ื™ืข ืขื ืฉื ื™ ื›ืœื™ื ืฉื™ืžื•ืฉื™ื™ื ื ื•ืกืคื™ื ืœื”ืขืชืงืช ืงื‘ืฆื™ื ื—ื™ื‘ื•ืจ ssh ืžื•ืฆืคืŸ. ืจืื” ืœื”ืœืŸ ื“ื•ื’ืžื” ืœืฉื™ืžื•ืฉ ืกื˜ื ื“ืจื˜ื™ ื‘ืคืงื•ื“ื•ืช scp ื•-sftp. ืฉื™ืžื• ืœื‘ ืฉืจื‘ื•ืช ืžืืคืฉืจื•ื™ื•ืช ื”-ssh ื—ืœื•ืช ื’ื ืขืœ ืคืงื•ื“ื•ืช ืืœื•.

localhost:~$ scp mypic.png neo@remoteserver:/media/data/mypic_2.png

ื‘ื“ื•ื’ืžื” ื–ื• ื”ืงื•ื‘ืฅ mypic.png ื”ื•ืขืชืง ืœ ืฉืจืช ืžืจื•ื—ืง ืœืชื™ืงื™ื™ื” /media/data ื•ืฉื ืฉื•ื ื” ืœ mypic_2.png.

ืืœ ืชืฉื›ื— ืืช ื”ื”ื‘ื“ืœ ื‘ืคืจืžื˜ืจ ื”ื™ืฆื™ืื”. ื–ื” ื”ืžืงื•ื ืฉื‘ื• ืื ืฉื™ื ืจื‘ื™ื ื ืชืคืกื™ื ื›ืฉื”ื ืžืฉื’ืจื™ื scp ืžืฉื•ืจืช ื”ืคืงื•ื“ื”. ื”ื ื” ืคืจืžื˜ืจ ื”ื™ืฆื™ืื” -Pื•ืœื -p, ืžืžืฉ ื›ืžื• ื‘ืœืงื•ื— ssh! ืืชื” ืชืฉื›ื—, ืื‘ืœ ืืœ ืชื“ืื’, ื›ื•ืœื ืฉื•ื›ื—ื™ื.

ืœืžื™ ืฉืžื›ื™ืจ ืืช ื”ืงื•ื ืกื•ืœื” ftp, ื”ืจื‘ื” ืžื”ืคืงื•ื“ื•ืช ื“ื•ืžื•ืช ื‘ sftp... ืืชื” ื™ื›ื•ืœ ืœืขืฉื•ืช ืœื“ื—ื•ืฃ, ื’ื ะธ lsื›ืžื• ืฉื”ืœื‘ ื—ืคืฅ.

sftp neo@remoteserver

ื“ื•ื’ืžืื•ืช ืžืขืฉื™ื•ืช

ื‘ืจื‘ื•ืช ืžื”ื“ื•ื’ืžืื•ืช ื”ืœืœื• ื ื™ืชืŸ ืœื”ืฉื™ื’ ืืช ื”ืชื•ืฆืื•ืช ื‘ืฉื™ื˜ื•ืช ืฉื•ื ื•ืช. ื›ืžื• ืืฆืœ ื›ื•ืœื ื• ืกืคืจื™ ืœื™ืžื•ื“ ื•ื“ื•ื’ืžืื•ืช, ื ื™ืชื ืช ืขื“ื™ืคื•ืช ืœื“ื•ื’ืžืื•ืช ืžืขืฉื™ื•ืช ืฉืคืฉื•ื˜ ืขื•ืฉื•ืช ืืช ืขื‘ื•ื“ืชืŸ.

1. ืคืจื•ืงืกื™ ื’ืจื‘ื™ SSH

ืชื›ื•ื ืช SSH Proxy ื”ื™ื ืžืกืคืจ 1 ืžืกื™ื‘ื” ื˜ื•ื‘ื”. ื–ื” ื—ื–ืง ื™ื•ืชืจ ืžืžื” ืฉืจื‘ื™ื ืžื‘ื™ื ื™ื ื•ื ื•ืชืŸ ืœืš ื’ื™ืฉื” ืœื›ืœ ืžืขืจื›ืช ืฉื™ืฉ ืœืฉืจืช ื”ืžืจื•ื—ืง ื’ื™ืฉื” ืืœื™ื”, ื‘ืืžืฆืขื•ืช ื›ืžืขื˜ ื›ืœ ื™ื™ืฉื•ื. ืœืงื•ื— ssh ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืชืขื‘ื•ืจื” ื“ืจืš ืคืจื•ืงืกื™ SOCKS ื‘ืคืงื•ื“ื” ืคืฉื•ื˜ื” ืื—ืช. ื—ืฉื•ื‘ ืœื”ื‘ื™ืŸ ืฉืชืขื‘ื•ืจื” ืœืžืขืจื›ื•ืช ืžืจื•ื—ืงื•ืช ืชื’ื™ืข ืžืฉืจืช ืžืจื•ื—ืง, ื–ื” ื™ืฆื•ื™ืŸ ื‘ื™ื•ืžื ื™ ืฉืจืช ื”ืื™ื ื˜ืจื ื˜.

localhost:~$ ssh -D 8888 user@remoteserver

localhost:~$ netstat -pan | grep 8888
tcp        0      0 127.0.0.1:8888       0.0.0.0:*               LISTEN      23880/ssh

ื›ืืŸ ืื ื• ืžืจื™ืฆื™ื ืคืจื•ืงืกื™ socks ืขืœ ื™ืฆื™ืืช TCP 8888, ื”ืคืงื•ื“ื” ื”ืฉื ื™ื™ื” ื‘ื•ื“ืงืช ืฉื”ื™ืฆื™ืื” ืคืขื™ืœื” ื‘ืžืฆื‘ ื”ืื–ื ื”. 127.0.0.1 ืžืฆื™ื™ืŸ ืฉื”ืฉื™ืจื•ืช ืคื•ืขืœ ืจืง ืขืœ localhost. ืื ื—ื ื• ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ืงืฆืช ืฉื•ื ื” ื›ื“ื™ ืœื”ืื–ื™ืŸ ื‘ื›ืœ ื”ืžืžืฉืงื™ื, ื›ื•ืœืœ ethernet ืื• wifi, ื–ื” ื™ืืคืฉืจ ืœื™ื™ืฉื•ืžื™ื ืื—ืจื™ื (ื“ืคื“ืคื ื™ื ื•ื›ื•') ื‘ืจืฉืช ืฉืœื ื• ืœื”ืชื—ื‘ืจ ืœืฉื™ืจื•ืช ื”-proxy ื“ืจืš ืคืจื•ืงืกื™ ssh socks.

localhost:~$ ssh -D 0.0.0.0:8888 user@remoteserver

ื›ืขืช ืื ื• ื™ื›ื•ืœื™ื ืœื”ื’ื“ื™ืจ ืืช ื”ื“ืคื“ืคืŸ ืœื”ืชื—ื‘ืจ ืœ-proxy socks. ื‘ืคื™ื™ืจืคื•ืงืก, ื‘ื—ืจ ื”ื’ื“ืจื•ืช | ื‘ืกื™ืกื™ | ื”ื’ื“ืจื•ืช ืจืฉืช. ืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ื•ื”ื™ืฆื™ืื” ืœื—ื™ื‘ื•ืจ.

ื˜ื™ืคื™ื ืžืขืฉื™ื™ื, ื“ื•ื’ืžืื•ืช ื•ืžื ื”ืจื•ืช SSH

ืฉื™ืžื• ืœื‘ ืœืืคืฉืจื•ืช ืฉื‘ืชื—ืชื™ืช ื”ื˜ื•ืคืก ืฉื’ื ื‘ืงืฉื•ืช ื”-DNS ืฉืœ ื”ื“ืคื“ืคืŸ ืฉืœื›ื ื™ืขื‘ืจื• ื“ืจืš ืคืจื•ืงืกื™ SOCKS. ืื ืืชื” ืžืฉืชืžืฉ ื‘ืฉืจืช proxy ื›ื“ื™ ืœื”ืฆืคื™ืŸ ืชืขื‘ื•ืจืช ืื™ื ื˜ืจื ื˜ ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช ืฉืœืš, ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉืชืจืฆื” ืœื‘ื—ื•ืจ ื‘ืืคืฉืจื•ืช ื–ื• ื›ื“ื™ ืฉื‘ืงืฉื•ืช DNS ื™ื•ืขื‘ืจื• ื“ืจืš ื—ื™ื‘ื•ืจ ื”-SSH.

ื”ืคืขืœืช Proxy socks ื‘-Chrome

ื”ืคืขืœืช Chrome ืขื ืคืจืžื˜ืจื™ื ืžืกื•ื™ืžื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ืชืืคืฉืจ ืืช ืคืจื•ืงืกื™ socks, ื›ืžื• ื’ื ืžื ื”ื•ืจ ื‘ืงืฉื•ืช DNS ืžื”ื“ืคื“ืคืŸ. ืกืžื•ืš ืื‘ืœ ืชื‘ื“ื•ืง. ืœื”ืฉืชืžืฉ tcpdump ื›ื“ื™ ืœื‘ื“ื•ืง ืฉืื™ืœืชื•ืช DNS ืื™ื ืŸ ื’ืœื•ื™ื•ืช ืขื•ื“.

localhost:~$ google-chrome --proxy-server="socks5://192.168.1.10:8888"

ืฉื™ืžื•ืฉ ื‘ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื ืขื ืคืจื•ืงืกื™

ื–ื›ื•ืจ ืฉื™ื™ืฉื•ืžื™ื ืจื‘ื™ื ืื—ืจื™ื ืขืฉื•ื™ื™ื ืœื”ืฉืชืžืฉ ื’ื ื‘ืคืจื•ืงืกื™ ื’ืจื‘ื™ื™ื. ื“ืคื“ืคืŸ ื”ืื™ื ื˜ืจื ื˜ ื”ื•ื ืคืฉื•ื˜ ื”ืคื•ืคื•ืœืจื™ ืžื›ื•ืœื. ืœื—ืœืง ืžื”ื™ื™ืฉื•ืžื™ื ื™ืฉ ืืคืฉืจื•ื™ื•ืช ืชืฆื•ืจื” ืœื”ืคืขืœืช ืฉืจืช proxy. ืื—ืจื™ื ื–ืงื•ืงื™ื ืœืขื–ืจื” ืงื˜ื ื” ืขื ืชื•ื›ื ื™ืช ืขื•ื–ืจืช. ืœื“ื•ื’ืžื”, ืจืฉืชื•ืช ืคืจื•ืงืกื™ ืžืืคืฉืจ ืœืš ืœืจื•ืฅ ื“ืจืš socks proxy Microsoft RDP ื•ื›ื•'.

localhost:~$ proxychains rdesktop $RemoteWindowsServer

ืคืจืžื˜ืจื™ ืชืฆื•ืจืช Proxy ืฉืœ ื’ืจื‘ื™ื™ื ืžื•ื’ื“ืจื™ื ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืฉืœ Proxychains.

ืจืžื–: ืื ืืชื” ืžืฉืชืžืฉ ื‘ืฉื•ืœื—ืŸ ืขื‘ื•ื“ื” ืžืจื•ื—ืง ืž-Linux ื‘-Windows? ื ืกื” ืืช ื”ืœืงื•ื— FreeRDP. ื–ื”ื• ื™ื™ืฉื•ื ืžื•ื“ืจื ื™ ื™ื•ืชืจ ืžืืฉืจ rdesktop, ืขื ื—ื•ื•ื™ื” ื—ืœืงื” ื”ืจื‘ื” ื™ื•ืชืจ.

ืืคืฉืจื•ืช ืœื”ืฉืชืžืฉ ื‘-SSH ื“ืจืš socks proxy

ืืชื” ื™ื•ืฉื‘ ื‘ื‘ื™ืช ืงืคื” ืื• ื‘ืžืœื•ืŸ - ื•ื ืืœืฅ ืœื”ืฉืชืžืฉ ื‘-WiFi ืœื ืืžื™ืŸ ืœืžื“ื™. ืื ื• ืžืฉื™ืงื™ื ืคืจื•ืงืกื™ ssh ื‘ืื•ืคืŸ ืžืงื•ืžื™ ืžืžื—ืฉื‘ ื ื™ื™ื“ ื•ืžืชืงื™ื ื™ื ืžื ื”ืจืช ssh ืœืจืฉืช ื”ื‘ื™ืชื™ืช ื‘-Rasberry Pi ืžืงื•ืžื™. ื‘ืืžืฆืขื•ืช ื“ืคื“ืคืŸ ืื• ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื ื”ืžื•ื’ื“ืจื™ื ืขื‘ื•ืจ socks proxy, ืื ื• ื™ื›ื•ืœื™ื ืœื’ืฉืช ืœื›ืœ ืฉื™ืจื•ืชื™ ืจืฉืช ื‘ืจืฉืช ื”ื‘ื™ืชื™ืช ืฉืœื ื• ืื• ืœื’ืฉืช ืœืื™ื ื˜ืจื ื˜ ื“ืจืš ื”ื—ื™ื‘ื•ืจ ื”ื‘ื™ืชื™ ืฉืœื ื•. ื›ืœ ืžื” ืฉื‘ื™ืŸ ื”ืžื—ืฉื‘ ื”ื ื™ื™ื“ ืœืฉืจืช ื”ื‘ื™ืชื™ (ื‘ืืžืฆืขื•ืช Wi-Fi ื•ืื™ื ื˜ืจื ื˜ ืขื“ ื”ื‘ื™ืช) ืžื•ืฆืคืŸ ื‘ืžื ื”ืจืช SSH.

2. ืžื ื”ืจืช SSH (ื”ืขื‘ืจืช ื ืžืœื™ื)

ื‘ืฆื•ืจืชื” ื”ืคืฉื•ื˜ื” ื‘ื™ื•ืชืจ, ืžื ื”ืจืช SSH ืคืฉื•ื˜ ืคื•ืชื—ืช ื™ืฆื™ืื” ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช ืฉืœืš ืฉืžืชื—ื‘ืจืช ืœื™ืฆื™ืื” ืื—ืจืช ื‘ืงืฆื” ื”ืฉื ื™ ืฉืœ ื”ืžื ื”ืจื”.

localhost:~$ ssh  -L 9999:127.0.0.1:80 user@remoteserver

ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื”ืคืจืžื˜ืจ -L. ืืคืฉืจ ืœื—ืฉื•ื‘ ืขืœ ื–ื” ื›ืฆื“ ื”ืžืงื•ืžื™ ืฉืœ ื”ื”ืงืฉื‘ื”. ืื– ื‘ื“ื•ื’ืžื” ืฉืœืžืขืœื”, ื™ืฆื™ืื” 9999 ืžื•ืื–ื ืช ื‘ืฆื“ ืฉืœ ื”ืžืืจื— ื”ืžืงื•ืžื™ ื•ืžื•ืขื‘ืจืช ื“ืจืš ื™ืฆื™ืื” 80 ืœืฉืจืช ืžืจื•ื—ืง. ืฉื™ืžื• ืœื‘ ืฉ-127.0.0.1 ืžืชื™ื™ื—ืก ืœ-localhost ื‘ืฉืจืช ื”ืžืจื•ื—ืง!

ื‘ื•ืื• ื ืขืœื” ื‘ืžื“ืจื’ื”. ื”ื“ื•ื’ืžื” ื”ื‘ืื” ืžืชืงืฉืจืช ืขื ื™ืฆื™ืื•ืช ื”ืื–ื ื” ืขื ืžืืจื—ื™ื ืื—ืจื™ื ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช.

localhost:~$ ssh  -L 0.0.0.0:9999:127.0.0.1:80 user@remoteserver

ื‘ื“ื•ื’ืžืื•ืช ืืœื• ืื ื• ืžืชื—ื‘ืจื™ื ืœืคื•ืจื˜ ื‘ืฉืจืช ื”ืื™ื ื˜ืจื ื˜, ืืš ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉืจืช ืคืจื•ืงืกื™ ืื• ื›ืœ ืฉื™ืจื•ืช TCP ืื—ืจ.

3. ืžื ื”ืจืช SSH ืœืžืืจื— ืฆื“ ืฉืœื™ืฉื™

ืื ื• ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ืื•ืชื ืคืจืžื˜ืจื™ื ื›ื“ื™ ืœื—ื‘ืจ ืžื ื”ืจื” ืžืฉืจืช ืžืจื•ื—ืง ืœืฉื™ืจื•ืช ืื—ืจ ื”ืคื•ืขืœ ืขืœ ืžืขืจื›ืช ืฉืœื™ืฉื™ืช.

localhost:~$ ssh  -L 0.0.0.0:9999:10.10.10.10:80 user@remoteserver

ื‘ื“ื•ื’ืžื” ื–ื•, ืื ื• ืžืคื ื™ื ืžื ื”ืจื” ืžืฉืจืช ืžืจื•ื—ืง ืœืฉืจืช ืื™ื ื˜ืจื ื˜ ื”ืคื•ืขืœ ื‘ืชืืจื™ืš 10.10.10.10. ืชื ื•ืขื” ืžืฉืจืช ืžืจื•ื—ืง ืœืชืืจื™ืš 10.10.10.10 ื›ื‘ืจ ืœื ื‘ืžื ื”ืจืช SSH. ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืชืืจื™ืš 10.10.10.10 ื™ื—ืฉื•ื‘ ืขืœ ืฉืจืช ืžืจื•ื—ืง ื›ืžืงื•ืจ ืœื‘ืงืฉื•ืช ืื™ื ื˜ืจื ื˜.

4. ื”ืคื•ืš ืžื ื”ืจืช SSH

ื›ืืŸ ื ื’ื“ื™ืจ ื™ืฆื™ืืช ื”ืื–ื ื” ื‘ืฉืจืช ื”ืžืจื•ื—ืง ืฉืชืชื—ื‘ืจ ื—ื–ืจื” ืœื™ืฆื™ืื” ื”ืžืงื•ืžื™ืช ื‘-localhost ืฉืœื ื• (ืื• ืžืขืจื›ืช ืื—ืจืช).

localhost:~$ ssh -v -R 0.0.0.0:1999:127.0.0.1:902 192.168.1.100 user@remoteserver

ืกืฉืŸ SSH ื–ื” ื™ื•ืฆืจ ื—ื™ื‘ื•ืจ ืžื™ืฆื™ืื” 1999 ื‘ืฉืจืช ืžืจื•ื—ืง ืœื™ืฆื™ืื” 902 ื‘ืœืงื•ื— ื”ืžืงื•ืžื™ ืฉืœื ื•.

5. SSH Proxy ื”ืคื•ืš

ื‘ืžืงืจื” ื–ื”, ืื ื• ืžื’ื“ื™ืจื™ื ืคืจื•ืงืกื™ socks ื‘ื—ื™ื‘ื•ืจ ื”-ssh ืฉืœื ื•, ืืš ื”ืคืจื•ืงืกื™ ืžืื–ื™ืŸ ื‘ืงืฆื” ื”ืžืจื•ื—ืง ืฉืœ ื”ืฉืจืช. ื—ื™ื‘ื•ืจื™ื ืœ-proxy ืžืจื•ื—ืง ื–ื” ืžื•ืคื™ืขื™ื ื›ืขืช ืžื”ืžื ื”ืจื” ื›ืชื ื•ืขื” ืžื”ืžืืจื— ื”ืžืงื•ืžื™ ืฉืœื ื•.

localhost:~$ ssh -v -R 0.0.0.0:1999 192.168.1.100 user@remoteserver

ืคืชืจื•ืŸ ื‘ืขื™ื•ืช ืขื ืžื ื”ืจื•ืช SSH ืžืจื•ื—ืงื•ืช

ืื ื™ืฉ ืœืš ื‘ืขื™ื•ืช ื›ืฉืืคืฉืจื•ื™ื•ืช SSH ืžืจื•ื—ืงื•ืช ืคื•ืขืœื•ืช, ื‘ื“ื•ืง ืขื netstat, ืœืื™ืœื• ืžืžืฉืงื™ื ื ื•ืกืคื™ื ืžื—ื•ื‘ืจืช ื™ืฆื™ืืช ื”ื”ืื–ื ื”. ืืžื ื ืฆื™ื™ื ื• 0.0.0.0 ื‘ื“ื•ื’ืžืื•ืช, ืื‘ืœ ืื ื”ืขืจืš ื™ืฆื™ืื•ืช ืฉืขืจ ะฒ sshd_config ืžื›ื•ื•ืŸ ืœ ืœื, ืื– ื”ืžืื–ื™ืŸ ื™ื”ื™ื” ืงืฉื•ืจ ืจืง ืœ-localhost (127.0.0.1).

ืื–ื”ืจืช ื‘ื˜ื™ื—ื•ืช

ืฉื™ื ืœื‘ ืฉืขืœ ื™ื“ื™ ืคืชื™ื—ืช ืžื ื”ืจื•ืช ื•ืคืจื•ืงืกื™ ื’ืจื‘ื™ื™ื, ืžืฉืื‘ื™ ืจืฉืช ืคื ื™ืžื™ื™ื ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ื ื’ื™ืฉื™ื ืœืจืฉืชื•ืช ืœื ืžื”ื™ืžื ื•ืช (ื›ื’ื•ืŸ ื”ืื™ื ื˜ืจื ื˜!). ื–ื” ื™ื›ื•ืœ ืœื”ื•ื•ืช ืกื™ื›ื•ืŸ ืื‘ื˜ื—ื” ืจืฆื™ื ื™, ืื– ื•ื•ื“ื ืฉืืชื” ืžื‘ื™ืŸ ืžื”ื• ื”ืžืื–ื™ืŸ ื•ืœืžื” ื™ืฉ ืœื• ื’ื™ืฉื”.

6. ื”ืชืงื ืช VPN ื“ืจืš SSH

ื”ืžื•ื ื— ื”ื ืคื•ืฅ ื‘ืงืจื‘ ืžื•ืžื—ื™ื ื‘ืฉื™ื˜ื•ืช ืชืงื™ืคื” (ืคื ื˜ืกื˜ืจื™ื ื•ื›ื•') ื”ื•ื "ื ืงื•ื“ืช ืžืฉืขืŸ ื‘ืจืฉืช". ื‘ืจื’ืข ืฉื ื•ืฆืจ ื—ื™ื‘ื•ืจ ื‘ืžืขืจื›ืช ืื—ืช, ืžืขืจื›ืช ื–ื• ื”ื•ืคื›ืช ืœืฉืขืจ ืœื’ื™ืฉื” ื ื•ืกืคืช ืœืจืฉืช. ื ืงื•ื“ืช ืžืฉืขืŸ ื”ืžืืคืฉืจืช ืœื ื•ืข ืœืจื•ื—ื‘.

ืขื‘ื•ืจ ื“ืจื™ืกืช ืจื’ืœ ื›ื–ื• ื ื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ืคืจื•ืงืกื™ SSH ื• ืจืฉืชื•ืช ืคืจื•ืงืกื™, ืขื ื–ืืช ื™ืฉ ื›ืžื” ืžื’ื‘ืœื•ืช. ืœื“ื•ื’ืžื”, ืœื ื ื™ืชืŸ ื™ื”ื™ื” ืœืขื‘ื•ื“ ื™ืฉื™ืจื•ืช ืขื ืฉืงืขื™ื, ื•ืœื›ืŸ ืœื ื ื•ื›ืœ ืœืกืจื•ืง ืคื•ืจื˜ื™ื ื‘ืชื•ืš ื”ืจืฉืช ื‘ืืžืฆืขื•ืช Nmap SYN.

ื‘ืืžืฆืขื•ืช ืืคืฉืจื•ืช VPN ืžืชืงื“ืžืช ื™ื•ืชืจ ื–ื•, ื”ื—ื™ื‘ื•ืจ ืžืฆื˜ืžืฆื ืœ ืจืžื” 3. ืœืื—ืจ ืžื›ืŸ ื ื•ื›ืœ ืคืฉื•ื˜ ืœื ืชื‘ ืืช ื”ืชืขื‘ื•ืจื” ื“ืจืš ื”ืžื ื”ืจื” ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื‘ ืจืฉืช ืจื’ื™ืœ.

ื”ืฉื™ื˜ื” ืžืฉืชืžืฉืช ssh, iptables, tun interfaces ื•ื ื™ืชื•ื‘.

ืจืืฉื™ืช ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช ื”ืคืจืžื˜ืจื™ื ื”ืœืœื• sshd_config. ืžื›ื™ื•ื•ืŸ ืฉืื ื• ืžื‘ืฆืขื™ื ืฉื™ื ื•ื™ื™ื ื‘ืžืžืฉืงื™ื ื”ืŸ ืฉืœ ื”ืžืขืจื›ื•ืช ื”ืžืจื•ื—ืงื•ืช ื•ื”ืŸ ืฉืœ ืžืขืจื›ื•ืช ื”ืœืงื•ื—, ืื ื• ืฆืจื™ืš ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ืžืฉื ื™ ื”ืฆื“ื“ื™ื.

PermitRootLogin yes
PermitTunnel yes

ืœืื—ืจ ืžื›ืŸ ื ื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ssh ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจ ื”ืžื‘ืงืฉ ืืชื—ื•ืœ ืฉืœ ื”ืชืงื ื™ tun.

localhost:~# ssh -v -w any root@remoteserver

ื›ืขืช ืืžื•ืจ ืœื”ื™ื•ืช ืœื ื• ืžื›ืฉื™ืจ tun ื‘ืขืช ื”ืฆื’ืช ืžืžืฉืงื™ื (# ip a). ื”ืฉืœื‘ ื”ื‘ื ื™ื•ืกื™ืฃ ื›ืชื•ื‘ื•ืช IP ืœืžืžืฉืงื™ ื”ืžื ื”ืจื”.

ืฆื“ ืœืงื•ื— SSH:

localhost:~# ip addr add 10.10.10.2/32 peer 10.10.10.10 dev tun0
localhost:~# ip tun0 up

ืฆื“ ืฉืจืช SSH:

remoteserver:~# ip addr add 10.10.10.10/32 peer 10.10.10.2 dev tun0
remoteserver:~# ip tun0 up

ืขื›ืฉื™ื• ื™ืฉ ืœื ื• ืžืกืœื•ืœ ื™ืฉื™ืจ ืœืžืืจื— ืื—ืจ (route -n ะธ ping 10.10.10.10).

ืืชื” ื™ื›ื•ืœ ืœื ืชื‘ ื›ืœ ืชืช ืจืฉืช ื“ืจืš ืžืืจื— ื‘ืฆื“ ื”ืฉื ื™.

localhost:~# route add -net 10.10.10.0 netmask 255.255.255.0 dev tun0

ื‘ืฆื“ ื”ืžืจื•ื—ืง ืขืœื™ืš ืœื”ืคืขื™ืœ ip_forward ะธ iptables.

remoteserver:~# echo 1 > /proc/sys/net/ipv4/ip_forward
remoteserver:~# iptables -t nat -A POSTROUTING -s 10.10.10.2 -o enp7s0 -j MASQUERADE

ื‘ื•ื! VPN ืžืขืœ ืžื ื”ืจืช SSH ื‘ืฉื›ื‘ืช ืจืฉืช 3. ืขื›ืฉื™ื• ื–ื” ื ื™ืฆื—ื•ืŸ.

ืื ืžืชืจื—ืฉื•ืช ื‘ืขื™ื•ืช ื›ืœืฉื”ืŸ, ื”ืฉืชืžืฉ tcpdump ะธ pingื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืกื™ื‘ื”. ืžื›ื™ื•ื•ืŸ ืฉืื ื• ืžืฉื—ืงื™ื ื‘ืฉื›ื‘ื” 3, ืžื ื•ืช ื”-icmp ืฉืœื ื• ื™ืขื‘ืจื• ื“ืจืš ื”ืžื ื”ืจื” ื”ื–ื•.

7. ื”ืขืชืง ืืช ืžืคืชื— ื”-SSH (ssh-copy-id)

ื™ืฉื ืŸ ืžืกืคืจ ื“ืจื›ื™ื ืœืขืฉื•ืช ื–ืืช, ืืš ืคืงื•ื“ื” ื–ื• ื—ื•ืกื›ืช ื–ืžืŸ ืขืœ ื™ื“ื™ ืื™ ื”ืขืชืงืช ืงื‘ืฆื™ื ื™ื“ื ื™ืช. ื–ื” ืคืฉื•ื˜ ืžืขืชื™ืง ืืช ~/.ssh/id_rsa.pub (ืื• ืืช ืžืคืชื— ื‘ืจื™ืจืช ื”ืžื—ื“ืœ) ืžื”ืžืขืจื›ืช ืฉืœืš ืœ ~/.ssh/authorized_keys ื‘ืฉืจืช ืžืจื•ื—ืง.

localhost:~$ ssh-copy-id user@remoteserver

8. ื‘ื™ืฆื•ืข ืคืงื•ื“ื” ืžืจื—ื•ืง (ืœื ืื™ื ื˜ืจืืงื˜ื™ื‘ื™)

ืงึฐื‘ื•ึผืฆึธื” ssh ื ื™ืชืŸ ืœืงืฉืจ ืœืคืงื•ื“ื•ืช ืื—ืจื•ืช ืœืžืžืฉืง ืžืฉื•ืชืฃ ื•ื™ื“ื™ื“ื•ืชื™ ืœืžืฉืชืžืฉ. ืคืฉื•ื˜ ื”ื•ืกืฃ ืืช ื”ืคืงื•ื“ื” ืฉื‘ืจืฆื•ื ืš ืœื”ืคืขื™ืœ ืขืœ ื”ืžืืจื— ื”ืžืจื•ื—ืง ื›ืคืจืžื˜ืจ ื”ืื—ืจื•ืŸ ื‘ืžืจื›ืื•ืช.

localhost:~$ ssh remoteserver "cat /var/log/nginx/access.log" | grep badstuff.php

ื‘ื“ื•ื’ืžื” ื–ื• grep ื‘ื•ืฆืข ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช ืœืื—ืจ ื”ื•ืจื“ืช ื”ื™ื•ืžืŸ ื“ืจืš ืขืจื•ืฅ ssh. ืื ื”ืงื•ื‘ืฅ ื’ื“ื•ืœ, ื ื•ื— ื™ื•ืชืจ ืœื”ืคืขื™ืœ ืื•ืชื• grep ื‘ืฆื“ ื”ืžืจื•ื—ืง ืคืฉื•ื˜ ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืฉืชื™ ื”ืคืงื•ื“ื•ืช ื‘ืžื™ืจื›ืื•ืช ื›ืคื•ืœื•ืช.

ื“ื•ื’ืžื” ืื—ืจืช ืžื‘ืฆืขืช ืืช ืื•ืชื” ืคื•ื ืงืฆื™ื” ื›ืžื• ssh-copy-id ืžื“ื•ื’ืžื” 7.

localhost:~$ cat ~/.ssh/id_rsa.pub | ssh remoteserver 'cat >> .ssh/authorized_keys'

9. ืœื›ื™ื“ืช ืžื ื•ืช ื•ืฆืคื™ื™ื” ืžืจื—ื•ืง ื‘-Wireshark

ืœืงื—ืชื™ ืื—ื“ ืžืฉืœื ื• tcpdump ื“ื•ื’ืžืื•ืช. ื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืœื›ื•ื“ ืžื ื•ืช ืžืจื—ื•ืง ื•ืœื”ืฆื™ื’ ืืช ื”ืชื•ืฆืื•ืช ื™ืฉื™ืจื•ืช ื‘ืžืžืฉืง ื”ืžืฉืชืžืฉ ื”ืžืงื•ืžื™ ืฉืœ Wireshark.

:~$ ssh root@remoteserver 'tcpdump -c 1000 -nn -w - not port 22' | wireshark -k -i -

10. ื”ืขืชืงืช ืชื™ืงื™ื” ืžืงื•ืžื™ืช ืœืฉืจืช ืžืจื•ื—ืง ื‘ืืžืฆืขื•ืช SSH

ื˜ืจื™ืง ื ื—ืžื“ ืฉื“ื•ื—ืก ืชื™ืงื™ื” ื‘ืืžืฆืขื•ืช bzip2 (ื–ื•ื”ื™ ื”ืืคืฉืจื•ืช -j ื‘ืคืงื•ื“ื” tar), ื•ืœืื—ืจ ืžื›ืŸ ืžืื—ื–ืจ ืืช ื”ื–ืจื bzip2 ื‘ืฆื“ ื”ืฉื ื™, ื™ืฆื™ืจืช ืชื™ืงื™ื™ื” ื›ืคื•ืœื” ื‘ืฉืจืช ื”ืžืจื•ื—ืง.

localhost:~$ tar -cvj /datafolder | ssh remoteserver "tar -xj -C /datafolder"

11. ื™ื™ืฉื•ืžื™ GUI ืžืจื•ื—ืงื™ื ืขื ืฉื™ืœื•ื— SSH X11

ืื X ืžื•ืชืงืŸ ื‘ืœืงื•ื— ื•ื‘ืฉืจืช ื”ืžืจื•ื—ืง, ืื– ืืชื” ื™ื›ื•ืœ ืœื‘ืฆืข ืžืจื—ื•ืง ืคืงื•ื“ืช GUI ืขื ื—ืœื•ืŸ ื‘ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ื”ืžืงื•ืžื™ ืฉืœืš. ืชื›ื•ื ื” ื–ื• ืงื™ื™ืžืช ื›ื‘ืจ ื–ืžืŸ ืจื‘, ืืš ืขื“ื™ื™ืŸ ืฉื™ืžื•ืฉื™ืช ืžืื•ื“. ื”ืคืขืœ ื“ืคื“ืคืŸ ืื™ื ื˜ืจื ื˜ ืžืจื•ื—ืง ืื• ืืคื™ืœื• ืืช ืžืกื•ืฃ VMWawre Workstation ื›ืžื• ืฉืื ื™ ืขื•ืฉื” ื‘ื“ื•ื’ืžื” ื–ื•.

localhost:~$ ssh -X remoteserver vmware

ืžื—ืจื•ื–ืช ื ื“ืจืฉืช X11Forwarding yes ื‘ืงื•ื‘ืฅ sshd_config.

12. ื”ืขืชืงืช ืงื‘ืฆื™ื ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช rsync ื•-SSH

rsync ื”ืจื‘ื” ื™ื•ืชืจ ื ื•ื— scp, ืื ืืชื” ืฆืจื™ืš ื’ื™ื‘ื•ื™ื™ื ืชืงื•ืคืชื™ื™ื ืฉืœ ืกืคืจื™ื™ื”, ืžืกืคืจ ืจื‘ ืฉืœ ืงื‘ืฆื™ื ืื• ืงื‘ืฆื™ื ื’ื“ื•ืœื™ื ืžืื•ื“. ื™ืฉื ื” ืคื•ื ืงืฆื™ื” ืœืฉื—ื–ื•ืจ ืžื›ืฉืœ ื‘ื”ืขื‘ืจื” ื•ืœื”ืขืชืงืช ืจืง ืงื‘ืฆื™ื ืฉื”ืฉืชื ื•, ืžื” ืฉื—ื•ืกืš ืชืขื‘ื•ืจื” ื•ื–ืžืŸ.

ื“ื•ื’ืžื” ื–ื• ืžืฉืชืžืฉืช ื‘ื“ื—ื™ืกื” gzip (-z) ื•ืžืฆื‘ ืืจื›ื™ื•ืŸ (-a), ื”ืžืืคืฉืจ ื”ืขืชืงื” ืจืงื•ืจืกื™ื‘ื™ืช.

:~$ rsync -az /home/testuser/data remoteserver:backup/

13. SSH ื“ืจืš ืจืฉืช Tor

ืจืฉืช Tor ื”ืื ื•ื ื™ืžื™ืช ื™ื›ื•ืœื” ืœื ืชื‘ ืชืขื‘ื•ืจืช SSH ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” torsocks. ื”ืคืงื•ื“ื” ื”ื‘ืื” ืชืขื‘ื™ืจ ืืช ืคืจื•ืงืกื™ ssh ื“ืจืš Tor.

localhost:~$ torsocks ssh myuntracableuser@remoteserver

ื’ืจื‘ื™ื™ื ื™ืฉืชืžืฉ ื‘ื™ืฆื™ืื” 9050 ื‘-localhost ืขื‘ื•ืจ ืคืจื•ืงืกื™. ื›ืžื• ืชืžื™ื“, ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Tor ืืชื” ืฆืจื™ืš ืœื‘ื“ื•ืง ื‘ืจืฆื™ื ื•ืช ืื™ื–ื• ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ืžื ื”ื•ืจ ื•ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ืชืคืขื•ืœื™ื•ืช ืื—ืจื•ืช (opsec). ืœืืŸ ื”ื•ืœื›ื•ืช ืฉืื™ืœืชื•ืช ื”-DNS ืฉืœืš?

14. ืžื•ืคืข SSH ืœ-EC2

ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืœืžื•ืคืข EC2, ืืชื” ืฆืจื™ืš ืžืคืชื— ืคืจื˜ื™. ื”ื•ืจื“ ืื•ืชื• (ืกื™ื•ืžืช.pem) ืžืœื•ื— ื”ื‘ืงืจื” ืฉืœ Amazon EC2 ื•ืฉื ื” ืืช ื”ื”ืจืฉืื•ืช (chmod 400 my-ec2-ssh-key.pem). ืฉืžื•ืจ ืืช ื”ืžืคืชื— ื‘ืžืงื•ื ื‘ื˜ื•ื— ืื• ื”ื ื— ืื•ืชื• ื‘ืชื™ืงื™ื™ื” ืžืฉืœืš ~/.ssh/.

localhost:~$ ssh -i ~/.ssh/my-ec2-key.pem ubuntu@my-ec2-public

ืคืจืžื˜ืจ -i ืคืฉื•ื˜ ืื•ืžืจ ืœืœืงื•ื— ssh ืœื”ืฉืชืžืฉ ื‘ืžืคืชื— ื”ื–ื”. ืงื•ึนื‘ึถืฅ ~/.ssh/config ืื™ื“ื™ืืœื™ ืœื”ื’ื“ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืฉื™ืžื•ืฉ ื‘ืžืคืชื— ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืžืืจื— ec2.

Host my-ec2-public
   Hostname ec2???.compute-1.amazonaws.com
   User ubuntu
   IdentityFile ~/.ssh/my-ec2-key.pem

15. ืขืจื™ื›ืช ืงื‘ืฆื™ ื˜ืงืกื˜ ื‘ืืžืฆืขื•ืช VIM ื‘ืืžืฆืขื•ืช ssh/scp

ืœื›ืœ ื”ืื•ื”ื‘ื™ื vim ื˜ื™ืค ื–ื” ื™ื—ืกื•ืš ื–ืžืŸ. ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ vim ืงื‘ืฆื™ื ื ืขืจื›ื™ื ื‘ืืžืฆืขื•ืช scp ื‘ืคืงื•ื“ื” ืื—ืช. ืฉื™ื˜ื” ื–ื• ืคืฉื•ื˜ ื™ื•ืฆืจืช ืืช ื”ืงื•ื‘ืฅ ื‘ืื•ืคืŸ ืžืงื•ืžื™ ื‘ /tmpื•ืœืื—ืจ ืžื›ืŸ ืžืขืชื™ืง ืื•ืชื• ื‘ื—ื–ืจื” ื‘ืจื’ืข ืฉืฉืžืจื ื• ืื•ืชื• vim.

localhost:~$ vim scp://user@remoteserver//etc/hosts

ื”ืขืจื”: ื”ืคื•ืจืžื˜ ืฉื•ื ื” ื‘ืžืงืฆืช ืžื”ืจื’ื™ืœ scp. ืื—ืจื™ ื”ืžืืจื— ื™ืฉ ืœื ื• ื›ืคื•ืœ //. ื–ื•ื”ื™ ื”ืคื ื™ื” ืžื•ื—ืœื˜ืช ืœื ืชื™ื‘. ืงื• ื ื˜ื•ื™ ืื—ื“ ื™ืฆื™ื™ืŸ ื ืชื™ื‘ ื‘ื™ื—ืก ืœืชื™ืงื™ื™ืช ื”ื‘ื™ืช ืฉืœืš users.

**warning** (netrw) cannot determine method (format: protocol://[user@]hostname[:port]/[path])

ืื ืืชื” ืจื•ืื” ืฉื’ื™ืื” ื–ื•, ื‘ื“ื•ืง ืฉื•ื‘ ืืช ืคื•ืจืžื˜ ื”ืคืงื•ื“ื”. ื–ื” ื‘ื“ืจืš ื›ืœืœ ืื•ืžืจ ืฉื’ื™ืืช ืชื—ื‘ื™ืจ.

16. ื”ืจื›ื‘ื” ืฉืœ SSH ืžืจื•ื—ืง ื›ืชื™ืงื™ื” ืžืงื•ืžื™ืช ืขื SSHFS

ื‘ืืžืฆืขื•ืช sshfs - ืœืงื•ื— ืžืขืจื›ืช ืงื‘ืฆื™ื ssh - ืื ื• ื™ื›ื•ืœื™ื ืœื—ื‘ืจ ืกืคืจื™ื™ื” ืžืงื•ืžื™ืช ืœืžื™ืงื•ื ืžืจื•ื—ืง ืขื ื›ืœ ืื™ื ื˜ืจืืงืฆื™ื•ืช ื”ืงื‘ืฆื™ื ื‘ื”ืคืขืœื” ืžื•ืฆืคื ืช ssh.

localhost:~$ apt install sshfs

ื”ืชืงืŸ ืืช ื”ื—ื‘ื™ืœื” ื‘ืื•ื‘ื•ื ื˜ื• ื•ื‘ื“ื‘ื™ืืŸ sshfs, ื•ืœืื—ืจ ืžื›ืŸ ืคืฉื•ื˜ ื”ืจื›ื‘ ืืช ื”ืžื™ืงื•ื ื”ืžืจื•ื—ืง ืœืžืขืจื›ืช ืฉืœื ื•.

localhost:~$ sshfs user@remoteserver:/media/data ~/data/

17. ืจื™ื‘ื•ื™ SSH ืขื ControlPath

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืื ื™ืฉ ื—ื™ื‘ื•ืจ ืงื™ื™ื ืœืฉืจืช ืžืจื•ื—ืง ื‘ืืžืฆืขื•ืช ssh ื—ื™ื‘ื•ืจ ืฉื ื™ ื‘ืืžืฆืขื•ืช ssh ืื• scp ืžืงื™ื ื”ืคืขืœื” ื—ื“ืฉื” ืขื ืื™ืžื•ืช ื ื•ืกืฃ. ืื•ึนืคึผึฐืฆึดื™ึธื” ControlPath ืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื”ืคืขืœื” ื”ืงื™ื™ืžืช ืขื‘ื•ืจ ื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ื”ื‘ืื™ื. ื–ื” ื™ืื™ืฅ ืžืฉืžืขื•ืชื™ืช ืืช ื”ืชื”ืœื™ืš: ื”ื”ืฉืคืขื” ื ื™ื›ืจืช ืืคื™ืœื• ื‘ืจืฉืช ืžืงื•ืžื™ืช, ื•ืขื•ื“ ื™ื•ืชืจ ื‘ื—ื™ื‘ื•ืจ ืœืžืฉืื‘ื™ื ืžืจื•ื—ืงื™ื.

Host remoteserver
        HostName remoteserver.example.org
        ControlMaster auto
        ControlPath ~/.ssh/control/%r@%h:%p
        ControlPersist 10m

ControlPath ืžืฆื™ื™ืŸ ืืช ื”ืฉืงืข ืœื‘ื“ื™ืงืช ื—ื™ื‘ื•ืจื™ื ื—ื“ืฉื™ื ื›ื“ื™ ืœืจืื•ืช ืื ื™ืฉ ื”ืคืขืœื” ืคืขื™ืœื” ssh. ื”ืžืฉืžืขื•ืช ืฉืœ ื”ืืคืฉืจื•ืช ื”ืื—ืจื•ื ื” ื”ื™ื ืฉื’ื ืœืื—ืจ ืฉืชืฆืื• ืžื”ืงื•ื ืกื•ืœื”, ื”ื”ืคืขืœื” ื”ืงื™ื™ืžืช ืชื™ืฉืืจ ืคืชื•ื—ื” ืœืžืฉืš 10 ื“ืงื•ืช, ื›ืš ืฉื‘ื–ืžืŸ ื–ื” ืชื•ื›ืœื• ืœื”ืชื—ื‘ืจ ืžื—ื“ืฉ ืขืœ ื”ืฉืงืข ื”ืงื™ื™ื. ืœืžื™ื“ืข ื ื•ืกืฃ, ืขื™ื™ืŸ ื‘ืขื–ืจื”. ssh_config man.

18. ื”ื–ืจืžืช ื•ื™ื“ืื• ืขืœ SSH ื‘ืืžืฆืขื•ืช VLC ื•-SFTP

ืืคื™ืœื• ืžืฉืชืžืฉื™ื ื•ืชื™ืงื™ื ssh ะธ vlc (Video Lan Client) ืœื ืชืžื™ื“ ืžื•ื“ืขื™ื ืœืืคืฉืจื•ืช ื”ื ื•ื—ื” ื”ื–ื• ื›ืืฉืจ ืืชื” ื‘ืืžืช ืฆืจื™ืš ืœืฆืคื•ืช ื‘ืกืจื˜ื•ืŸ ื“ืจืš ื”ืจืฉืช. ื‘ื”ื’ื“ืจื•ืช ืงื•ื‘ืฅ | ืคืชื— ืืช ื–ืจื ื”ืจืฉืช ะฟั€ะพะณั€ะฐะผะผั‹ vlc ืืชื” ื™ื›ื•ืœ ืœื”ื–ื™ืŸ ืืช ื”ืžื™ืงื•ื ื‘ืชื•ืจ sftp://. ืื ื ื“ืจืฉืช ืกื™ืกืžื”, ืชื•ืคื™ืข ื”ื ื—ื™ื”.

sftp://remoteserver//media/uploads/myvideo.mkv

19. ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™

ืื•ืชื• ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ื›ืžื• ื—ืฉื‘ื•ืŸ ื”ื‘ื ืง ืื• ื—ืฉื‘ื•ืŸ Google ืฉืœืš โ€‹โ€‹ื—ืœ ืขืœ ืฉื™ืจื•ืช SSH.

ื›ืžื•ื‘ืŸ, ssh ื‘ืชื—ื™ืœื” ื™ืฉ ืคื•ื ืงืฆื™ื™ืช ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™, ื›ืœื•ืžืจ ืกื™ืกืžื” ื•ืžืคืชื— SSH. ื”ื™ืชืจื•ืŸ ืฉืœ ืืกื™ืžื•ืŸ ื—ื•ืžืจื” ืื• ืืคืœื™ืงืฆื™ื™ืช Google Authenticator ื”ื•ื ืฉื‘ื“ืจืš ื›ืœืœ ืžื“ื•ื‘ืจ ื‘ืžื›ืฉื™ืจ ืคื™ื–ื™ ืื—ืจ.

ืขื™ื™ืŸ ื‘ืžื“ืจื™ืš ืฉืœื ื• ื‘ืŸ 8 ื“ืงื•ืช ืœ ื‘ืืžืฆืขื•ืช Google Authenticator ื•-SSH.

20. ืžืืจื—ื™ื ืงื•ืคืฆื™ื ืขื ssh ื•-J

ืื ืคื™ืœื•ื— ืจืฉืช ืื•ืžืจ ืฉืืชื” ืฆืจื™ืš ืœืขื‘ื•ืจ ืžืกืคืจ ืžืืจื—ื™ ssh ื›ื“ื™ ืœื”ื’ื™ืข ืœืจืฉืช ื”ื™ืขื“ ื”ืกื•ืคื™ืช, ืงื™ืฆื•ืจ ื”ื“ืจืš -J ื™ื—ืกื•ืš ืœืš ื–ืžืŸ.

localhost:~$ ssh -J host1,host2,host3 [email protected]

ื”ืขื™ืงืจ ืœื”ื‘ื™ืŸ ื›ืืŸ ื–ื” ืฉื–ื” ืœื ื–ื”ื” ืœืคืงื•ื“ื” ssh host1ืื– user@host1:~$ ssh host2 ื•ื›ื•'. ื”ืืคืฉืจื•ืช -J ืžืฉืชืžืฉืช ื‘ื—ื•ื›ืžื” ื‘ื”ืขื‘ืจื” ื›ื“ื™ ืœืืœืฅ ืืช localhost ืœื™ืฆื•ืจ ื”ืคืขืœื” ืขื ื”ืžืืจื— ื”ื‘ื ื‘ืฉืจืฉืจืช. ืื– ื‘ื“ื•ื’ืžื” ืฉืœืžืขืœื”, ื”ืžืืจื— ื”ืžืงื•ืžื™ ืฉืœื ื• ืžืื•ืžืช ืœ-host4. ื›ืœื•ืžืจ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช ื”-localhost ืฉืœื ื•, ื•ื”ื”ืคืขืœื” ืž-localhost ืœ-host4 ืžื•ืฆืคื ืช ืœื—ืœื•ื˜ื™ืŸ.

ืœืืคืฉืจื•ืช ื›ื–ื• ื‘ ssh_config ืฆื™ื™ืŸ ืืคืฉืจื•ืช ืชืฆื•ืจื” ProxyJump. ืื ืืชื” ืฆืจื™ืš ืœืขื‘ื•ืจ ื“ืจืš ืžืกืคืจ ืžืืจื—ื™ื ื‘ืื•ืคืŸ ืงื‘ื•ืข, ืื•ื˜ื•ืžืฆื™ื” ื“ืจืš ื”ืชืฆื•ืจื” ืชื—ืกื•ืš ื”ืจื‘ื” ื–ืžืŸ.

21. ื—ืกื•ื ื ื™ืกื™ื•ื ื•ืช SSH brute force ื‘ืืžืฆืขื•ืช iptables

ื›ืœ ืžื™ ืฉื ื™ื”ืœ ืฉื™ืจื•ืช SSH ื•ื”ืกืชื›ืœ ื‘ื™ื•ืžื ื™ื ื™ื•ื“ืข ืขืœ ืžืกืคืจ ื ื™ืกื™ื•ื ื•ืช ื”ื›ื•ื— ื”ืื›ื–ืจื™ ื”ืžืชืจื—ืฉื™ื ื‘ื›ืœ ืฉืขื” ืฉืœ ื™ื•ื. ื“ืจืš ืžื”ื™ืจื” ืœื”ืคื—ื™ืช ืจืขืฉ ื‘ื™ื•ืžื ื™ื ื”ื™ื ืœื”ืขื‘ื™ืจ ืืช SSH ืœื™ืฆื™ืื” ืœื ืกื˜ื ื“ืจื˜ื™ืช. ื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืงื•ื‘ืฅ sshd_config ื‘ืืžืฆืขื•ืช ืคืจืžื˜ืจ ืชืฆื•ืจื” ื ืžืœ##.

ืขื iptables ื ื™ืชืŸ ื’ื ืœื—ืกื•ื ื‘ืงืœื•ืช ื ื™ืกื™ื•ื ื•ืช ืœื”ืชื—ื‘ืจ ืœื™ืฆื™ืื” ืขื ื”ื’ืขื” ืœืกืฃ ืžืกื•ื™ื. ื“ืจืš ืงืœื” ืœืขืฉื•ืช ื–ืืช ื”ื™ื ืœื”ืฉืชืžืฉ OSSEC, ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ืœื ืจืง ื—ื•ืกื SSH, ืืœื ื’ื ืขื•ืฉื” ื—ื‘ื•ืจื” ืฉืœ ืืžืฆืขื™ื ืื—ืจื™ื ืฉืœ ื–ื™ื”ื•ื™ ื—ื“ื™ืจื” ืžื‘ื•ืกืกื™ ืฉื ืžืืจื— (HIDS).

22. SSH Escape ื›ื“ื™ ืœืฉื ื•ืช ื”ืขื‘ืจืช ืคื•ืจื˜ื™ื

ื•ื”ื“ื•ื’ืžื” ื”ืื—ืจื•ื ื” ืฉืœื ื• ssh ื ื•ืขื“ ืœืฉื ื•ืช ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช ืชื•ืš ื›ื“ื™ ื”ืคืขืœื” ืงื™ื™ืžืช ssh. ื“ืžื™ื™ื ื• ืืช ื”ืชืจื—ื™ืฉ ื”ื–ื”. ืืชื” ืขืžื•ืง ื‘ืจืฉืช; ืื•ืœื™ ืงืคืฅ ืžืขืœ ื—ืฆื™ ืชืจื™ืกืจ ืžืืจื—ื™ื ื•ืฆืจื™ืš ื™ืฆื™ืื” ืžืงื•ืžื™ืช ื‘ืชื—ื ืช ื”ืขื‘ื•ื“ื” ืฉืžื•ืขื‘ืจืช ืœ-SMB ืฉืœ Microsoft ืฉืœ ืžืขืจื›ืช Windows 2003 ื™ืฉื ื” (ืžื™ืฉื”ื• ื–ื•ื›ืจ ืืช ms08-67?).

ืœื—ื™ืฆื” enter, ื ืกื” ืœื”ื–ื™ืŸ ื‘ืงื•ื ืกื•ืœื” ~C. ื–ื”ื• ืจืฆืฃ ื‘ืงืจืช ื”ืคืขืœื” ื”ืžืืคืฉืจ ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ื—ื™ื‘ื•ืจ ืงื™ื™ื.

localhost:~$ ~C
ssh> -h
Commands:
      -L[bind_address:]port:host:hostport    Request local forward
      -R[bind_address:]port:host:hostport    Request remote forward
      -D[bind_address:]port                  Request dynamic forward
      -KL[bind_address:]port                 Cancel local forward
      -KR[bind_address:]port                 Cancel remote forward
      -KD[bind_address:]port                 Cancel dynamic forward
ssh> -L 1445:remote-win2k3:445
Forwarding port.

ื›ืืŸ ืืชื” ื™ื›ื•ืœ ืœืจืื•ืช ืฉื”ืขื‘ืจื ื• ืืช ื”ื™ืฆื™ืื” ื”ืžืงื•ืžื™ืช 1445 ืฉืœื ื• ืœืžืืจื— ืฉืœ Windows 2003 ืฉืžืฆืื ื• ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช. ืขื›ืฉื™ื• ืจืง ืœืจื•ืฅ msfconsole, ื•ืืชื” ื™ื›ื•ืœ ืœื”ืžืฉื™ืš ื”ืœืื” (ื‘ื”ื ื—ื” ืฉืืชื” ืžืชื›ื ืŸ ืœื”ืฉืชืžืฉ ื‘ืžืืจื— ื–ื”).

ื”ืฉืœืžื”

ื”ื“ื•ื’ืžืื•ืช, ื”ื˜ื™ืคื™ื ื•ื”ืคืงื•ื“ื•ืช ื”ืœืœื• ssh ืฆืจื™ืš ืœืชืช ื ืงื•ื“ืช ืžื•ืฆื; ืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื›ืœ ืื—ืช ืžื”ืคืงื•ื“ื•ืช ื•ื”ื™ื›ื•ืœื•ืช ื–ืžื™ืŸ ื‘ื“ืคื™ ื”ืื“ื (man ssh, man ssh_config, man sshd_config).

ืชืžื™ื“ ื”ื•ืงืกืžืชื™ ืžื”ื™ื›ื•ืœืช ืœื’ืฉืช ืœืžืขืจื›ื•ืช ื•ืœื‘ืฆืข ืคืงื•ื“ื•ืช ื‘ื›ืœ ืžืงื•ื ื‘ืขื•ืœื. ืขืœ ื™ื“ื™ ืคื™ืชื•ื— ื”ื›ื™ืฉื•ืจื™ื ืฉืœืš ืขื ื›ืœื™ื ื›ืžื• ssh ืืชื” ืชื”ื™ื” ื™ืขื™ืœ ื™ื•ืชืจ ื‘ื›ืœ ืžืฉื—ืง ืฉืืชื” ืžืฉื—ืง.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”