ืคึผืจืึทืงื˜ื™ืฉ ืขืฆื•ืช, ื‘ื™ื™ืฉืคื™ืœืŸ ืื•ืŸ SSH ื˜ืึทื ืึทืœื–

ืคึผืจืึทืงื˜ื™ืฉ ืขืฆื•ืช, ื‘ื™ื™ืฉืคื™ืœืŸ ืื•ืŸ SSH ื˜ืึทื ืึทืœื–
ืคึผืจืึทืงื˜ื™ืฉ ื‘ื™ื™ืฉืคื™ืœืŸ ืกืฉ, ื•ื•ืึธืก ื•ื•ืขื˜ ื ืขืžืขืŸ ื“ื™ื™ืŸ ืกืงื™ืœื– ื•ื•ื™ ืึท ื•ื•ื™ื™ึทื˜ ืกื™ืกื˜ืขื ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืฆื• ืึท ื ื™ื™ึทืข ืžื“ืจื’ื”. ืงืึทืžืึทื ื“ื– ืื•ืŸ ืขืฆื•ืช ื•ื•ืขื˜ ื”ืขืœืคืŸ ื ื™ื˜ ื‘ืœื•ื™ื– ืฆื• ื ื•ืฆืŸ SSH, ืึธื‘ืขืจ ืื•ื™ืš ื ืึทื•ื•ื™ื’ื™ืจืŸ ื“ื™ ื ืขืฅ ืžืขืจ ืงืึทืžืคึผืึทื˜ื™ื ื˜ืœื™.

ื•ื•ื™ื™ืœ ืขื˜ืœืขื›ืข ื˜ืจื™ืงืก ssh ื ื•ืฆื™ืง ืคึฟืึทืจ ืงื™ื™ืŸ ืกื™ืกื˜ืขื ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ, ื ืขืฅ ื™ื ื–ืฉืขื ื™ืจ ืึธื“ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื•ืžื›ืข.

ืคึผืจืึทืงื˜ื™ืฉ ืกืฉ ื‘ื™ื™ืฉืคื™ืœืŸ

  1. SSH ืกืึทืงืก ืคึผืจืึทืงืกื™
  2. SSH ื˜ื•ื ืขืœ (ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’)
  3. SSH ื˜ื•ื ืขืœ ืฆื• ื“ืจื™ื˜ ื‘ืึทืœืขื‘ืึธืก
  4. ืคืึทืจืงืขืจื˜ ืกืฉ ื˜ื•ื ืขืœ
  5. SSH ืคืึทืจืงืขืจื˜ ืคืจืืงืกื™
  6. ื™ื ืกื˜ืึธืœื™ื ื’ VPN ืื™ื‘ืขืจ SSH
  7. ืงืึทืคึผื™ื™ื ื’ ืึท SSH ืฉืœื™ืกืœ (ssh-copy-id)
  8. ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ื‘ืึทืคึฟืขืœืŸ (ื ื™ื˜-ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื•)
  9. ืจื™ืžืึธื•ื˜ ืคึผืึทืงืึทื˜ ื›ืึทืคึผืŸ ืื•ืŸ ื•ื•ื™ื•ื™ื ื’ ืื™ืŸ Wireshark
  10. ืงืึทืคึผื™ื™ื ื’ ืึท ื”ื™ื’ืข ื˜ืขืงืข ืฆื• ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš SSH
  11. ื•ื•ื™ื™ึทื˜ GUI ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืžื™ื˜ SSH X11 ืคืึธืจื•ื•ืขืจื“ื™ื ื’
  12. ืจื™ืžืึธื•ื˜ ื˜ืขืงืข ืงืึทืคึผื™ื™ื ื’ ืžื™ื˜ rsync ืื•ืŸ SSH
  13. SSH ืื™ื‘ืขืจ Tor ื ืขืฅ
  14. SSH ืฆื• EC2 ื‘ื™ื™ึทืฉืคึผื™ืœ
  15. ืขื“ื™ื˜ื™ื ื’ ื˜ืขืงืกื˜ ื˜ืขืงืขืก ื ื™ืฆืŸ VIM ื“ื•ืจืš ssh / scp
  16. ื‘ืืจื’ ื•ื•ื™ื™ึทื˜ SSH ื•ื•ื™ ืึท ื”ื™ื’ืข ื˜ืขืงืข ืžื™ื˜ SSHFS
  17. ืžื•ืœื˜ื™ืคึผืœืขืงืกื™ื ื’ SSH ืžื™ื˜ ControlPath
  18. ืกื˜ืจื™ื ื•ื•ื™ื“ืขื ืื™ื‘ืขืจ SSH ื ื™ืฆืŸ VLC ืื•ืŸ SFTP
  19. ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ
  20. ื“ื–ืฉืึทืžืคึผื™ื ื’ ื”ืึธืกืฅ ืžื™ื˜ SSH ืื•ืŸ -J
  21. ื‘ืœืึทืงื™ื ื’ SSH ื‘ืจื•ื˜ ืงืจืึทืคื˜ ืคืจื•ื•ื•ืŸ ื ื™ืฆืŸ ื™ืคึผื˜ืึทื‘ืœืขืก
  22. SSH Escape ืฆื• ื˜ื•ื™ืฉืŸ ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’

ืขืจืฉื˜ืขืจ ื“ื™ ื‘ืึทืกื™ืงืก

ืคึผืึทืจืกื™ื ื’ ื“ื™ SSH ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”

ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ื™ื™ืฉืคึผื™ืœ ื ื™ืฆื˜ ืคึผืจืึธืกื˜ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืึธืคื˜ ื’ืขืคึผืœืึธื ื˜ืขืจื˜ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ SSH.

localhost:~$ ssh -v -p 22 -C neo@remoteserver

  • -v: ื“ื™ื‘ืึทื’ื™ื ื’ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ื– ืกืคึผืขืฆื™ืขืœ ื ื•ืฆื™ืง ื•ื•ืขืŸ ืึทื ืึทืœื™ื™ื–ื™ื ื’ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืจืึธื‘ืœืขืžืก. ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืขื˜ืœืขื›ืข ืžืึธืœ ืฆื• ื•ื•ื™ื™ึทื–ืŸ ื ืึธืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข.
  • - p 22: ืงืฉืจ ืคึผืึธืจื˜ ืฆื• ืึท ื•ื•ื™ื™ึทื˜ SSH ืกืขืจื•ื•ืขืจ. 22 ื“ืึทืจืฃ ื ื™ื˜ ื–ื™ื™ืŸ ืกืคึผืขืกื™ืคื™ืขื“ ื•ื•ื™ื™ึทืœ ื“ืึธืก ืื™ื– ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื•ื•ืขืจื˜, ืึธื‘ืขืจ ืื•ื™ื‘ ื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืื™ื– ืื•ื™ืฃ ืขื˜ืœืขื›ืข ืื ื“ืขืจืข ืคึผืึธืจื˜, ืžื™ืจ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืขืก ืžื™ื˜ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ -p. ื“ื™ ืฆื•ื’ืขื”ืขืจื˜ ืคึผืึธืจื˜ ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ืขืจ ื˜ืขืงืข sshd_config ืื™ืŸ ื“ืขื ืคึฟืึธืจืžืึทื˜ Port 2222.
  • -C: ืงืึทืžืคึผืจืขืฉืึทืŸ ืคึฟืึทืจ ืงืฉืจ. ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ ืึท ืคึผืึทืžืขืœืขืš ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืึธื“ืขืจ ื–ืขืŸ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ื˜ืขืงืกื˜, ื“ืึธืก ืงืขืŸ ืคืึทืจื’ื™ื›ืขืจืŸ ื“ื™ ืงืฉืจ.
  • neo@: ื“ื™ ืฉื•ืจื” ืื™ื™ื“ืขืจ ื“ื™ @ ืกื™ืžื‘ืึธืœ ื™ื ื“ื™ืงื™ื™ืฅ ื“ื™ ื ืืžืขืŸ ืคึฟืึทืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ. ืื•ื™ื‘ ืื™ืจ ื˜ืึธืŸ ื ื™ื˜ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืขืก, ืขืก ื•ื•ืขื˜ ืคืขืœื™ืงื™ื™ึทื˜ ืฆื• ื“ื™ ื ืืžืขืŸ ืคื•ืŸ ื“ื™ ื—ืฉื‘ื•ืŸ ืื™ืจ ื–ืขื ื˜ ืื™ืฆื˜ ืœืึธื’ื“ ืื™ืŸ (~$whoami). ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืงืขื ืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ืกืคึผืขืกื™ืคื™ืขื“ ืžื™ื˜ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ -l.
  • remoteserver: ื ืึธืžืขืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ssh, ื“ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืึท ื’ืึธืจ ืงื•ื•ืึทืœืึทืคื™ื™ื“ ืคืขืœื“ ื ืึธืžืขืŸ, ืึทืŸ IP ืึทื“ืจืขืก ืึธื“ืขืจ ืงื™ื™ืŸ ื‘ืึทืœืขื‘ืึธืก ืื™ืŸ ื“ื™ ื”ื™ื’ืข ืžื—ื ื•ืช ื˜ืขืงืข. ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึท ื‘ืึทืœืขื‘ืึธืก ื•ื•ืึธืก ืฉื˜ื™ืฆื˜ ื‘ื™ื™ื“ืข IPv4 ืื•ืŸ IPv6, ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ื’ืŸ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ ืฆื• ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” -4 ืึธื“ืขืจ -6 ืคึฟืึทืจ ื’ืขื”ืขืจื™ืง ื”ืึทื›ืœืึธื˜ืข.

ืึทืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืื•ื™ื‘ืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ืึทืคึผืฉืึทื ืึทืœ ืึทื—ื•ืฅ remoteserver.

ื ื™ืฆืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข

ื›ืึธื˜ืฉ ืคื™ืœืข ื–ืขื ืขืŸ ื‘ืึทืงืึทื ื˜ ืžื™ื˜ ื“ื™ ื˜ืขืงืข sshd_config, ืขืก ืื™ื– ืื•ื™ืš ืึท ืงืœื™ืขื ื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืคึฟืึทืจ ื“ื™ ื‘ืึทืคึฟืขืœ ssh. ืคืขืœื™ืงื™ื™ึทื˜ ื•ื•ืขืจื˜ ~/.ssh/config, ืึธื‘ืขืจ ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื™ืคื™ื™ื ื“ ื•ื•ื™ ืึท ืคึผืึทืจืึทืžืขื˜ืขืจ ืคึฟืึทืจ ืึทืŸ ืึธืคึผืฆื™ืข -F.

Host *
     Port 2222

Host remoteserver
     HostName remoteserver.thematrix.io
     User neo
     Port 2112
     IdentityFile /home/test/.ssh/remoteserver.private_key

ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื‘ืึทืœืขื‘ืึธืก ืื™ื™ื ืกืŸ ืื™ืŸ ื“ืขืจ ื‘ื™ื™ึทืฉืคึผื™ืœ ssh ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืื•ื™ื‘ืŸ. ื“ืขืจ ืขืจืฉื˜ืขืจ ืžื™ื˜ืœ ืึทืœืข ืžื—ื ื•ืช, ืึทืœืข ื ื™ืฆืŸ ื“ื™ ืคึผืึธืจื˜ 2222 ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคึผืึทืจืึทืžืขื˜ืขืจ. ื“ืขืจ ืฆื•ื•ื™ื™ื˜ืขืจ ื–ืื’ื˜ ืึทื– ืคึฟืึทืจ ื“ื™ ื‘ืึทืœืขื‘ืึธืก ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ืึท ืึทื ื“ืขืจืฉ ื ืืžืขืŸ, ืคึผืึธืจื˜, FQDN ืื•ืŸ IdentityFile ื–ืึธืœ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜.

ื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืงืขื ืขืŸ ืจืึทื˜ืขื•ื•ืขืŸ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ื˜ื™ื™ืคึผื™ื ื’ ืฆื™ื™ื˜ ื“ื•ืจืš ืึทืœืึทื•ื™ื ื’ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืฆื• ื–ื™ื™ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื’ืขื•ื•ืขื ื“ื˜ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืกืคึผืขืฆื™ืคื™ืฉ ืžื—ื ื•ืช.

ืงืึทืคึผื™ื™ื ื’ ื˜ืขืงืขืก ืื™ื‘ืขืจ SSH ื ื™ืฆืŸ SCP

ื“ืขืจ SSH ืงืœื™ืขื ื˜ ืงื•ืžื˜ ืžื™ื˜ ืฆื•ื•ื™ื™ ืื ื“ืขืจืข ื–ื™ื™ืขืจ ื”ืึทื ื˜ื™ืง ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ืงืึทืคึผื™ื™ื ื’ ื˜ืขืงืขืก ืขื ืงืจื™ืคึผื˜ื™ื“ ืกืฉ ืงืฉืจ. ื–ืขืŸ ืื•ื ื˜ืŸ ืคึฟืึทืจ ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ื ืึธืจืžืึทืœ ื ื•ืฆืŸ ืคื•ืŸ ื“ื™ scp ืื•ืŸ sftp ืงืึทืžืึทื ื“ื–. ื‘ืึทืžืขืจืงื•ื ื’ ืึทื– ืคื™ืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ssh ืึธืคึผืฆื™ืขืก ืึทืคึผืœื™ื™ื– ืฆื• ื“ื™ ืงืึทืžืึทื ื“ื– ืื•ื™ืš.

localhost:~$ scp mypic.png neo@remoteserver:/media/data/mypic_2.png

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ ื“ื™ ื˜ืขืงืข mypic.png ืงืึทืคึผื™ื“ ืฆื• ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ืฆื• ื˜ืขืงืข / ืžืขื“ื™ืข / ื“ืึทื˜ืŸ ืื•ืŸ ืจื™ื ื™ื™ืžื“ ืฆื• mypic_2.png.

ื“ื• ื–ืืœืกื˜ ื ื™ืฉื˜ ืคืึทืจื’ืขืกืŸ ื•ื•ืขื’ืŸ ื“ื™ ื—ื™ืœื•ืง ืื™ืŸ ื“ื™ ืคึผืึธืจื˜ ืคึผืึทืจืึทืžืขื˜ืขืจ. ื“ืึธืก ืื™ื– ื•ื•ื• ืคื™ืœืข ืžืขื ื˜ืฉืŸ ื‘ืึทืงื•ืžืขืŸ ื’ืขื›ืืคื˜ ื•ื•ืขืŸ ื–ื™ื™ ืงืึทื˜ืขืจ scp ืคื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”. ื“ืึธ ืก ื“ื™ ืคึผืึธืจื˜ ืคึผืึทืจืึทืžืขื˜ืขืจ -Pืื•ืŸ ื ื™ืฉื˜ -p, ืคึผื•ื ืงื˜ ื•ื•ื™ ืื™ืŸ ืึท ssh ืงืœื™ืขื ื˜! ืื™ืจ ื•ื•ืขื˜ ืคืึทืจื’ืขืกืŸ, ืึธื‘ืขืจ ื˜ืึธืŸ ื ื™ื˜ ื–ืึธืจื’, ืึทืœืขืžืขืŸ ืคืืจื’ืขืกืŸ.

ืคึฟืึทืจ ื“ื™ ื•ื•ืืก ื–ืขื ืขืŸ ื‘ืึทืงืึทื ื˜ ืžื™ื˜ ืงืึทื ืกืึธื•ืœ ftp, ืคื™ืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ืขื ืœืขืš ืื™ืŸ sftp. ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืฉื˜ื•ืคึผ, ืฉื˜ืขืœืŸ ะธ lsืฐื™ ื“ืึธืก ื”ืึทืจืฅ ื’ืœื•ืกื˜.

sftp neo@remoteserver

ืคึผืจืึทืงื˜ื™ืฉ ื‘ื™ื™ืฉืคื™ืœืŸ

ืื™ืŸ ืคื™ืœืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื‘ื™ื™ืฉืคื™ืœืŸ, ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึทื˜ืฉื™ื•ื•ื“ ืžื™ื˜ ืคืึทืจืฉื™ื“ืขื ืข ืžืขื˜ื”ืึธื“ืก. ื•ื•ื™ ืื™ืŸ ืื•ื ื“ื–ืขืจ ืึทืœืข ืœืขืจื ื‘ื™ื›ืขืจ ืื•ืŸ ื‘ื™ื™ืฉืคื™ืœืŸ, ื™ื™ื‘ืขืจื”ืึทื ื˜ ืื™ื– ื’ืขื’ืขื‘ืŸ ืฆื• ืคึผืจืึทืงื˜ื™ืฉ ื‘ื™ื™ืฉืคื™ืœืŸ ื•ื•ืึธืก ืคืฉื•ื˜ ื˜ืึธืŸ ื–ื™ื™ืขืจ ืึทืจื‘ืขื˜.

1. ืกืฉ ืกืึทืงืก ืคึผืจืึทืงืกื™

ื“ื™ SSH Proxy ืฉื˜ืจื™ืš ืื™ื– ื ื•ืžืขืจ 1 ืคึฟืึทืจ ืึท ื’ื•ื˜ ืกื™ื‘ื”. ืขืก ืื™ื– ืžืขืจ ืฉื˜ืึทืจืง ื•ื•ื™ ืคื™ืœืข ืคืึทืจืฉื˜ื™ื™ืŸ ืื•ืŸ ื’ื™ื˜ ืื™ืจ ืึทืงืกืขืก ืฆื• ืงื™ื™ืŸ ืกื™ืกื˜ืขื ื•ื•ืึธืก ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ื”ืื˜ ืฆื•ื˜ืจื™ื˜ ืฆื•, ื ื™ืฆืŸ ื›ืžืขื˜ ืงื™ื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ. ืึท ssh ืงืœื™ืขื ื˜ ืงืขื ืขืŸ ื˜ื•ื ืขืœ ืคืึทืจืงืขืจ ื“ื•ืจืš ืึท SOCKS ืคืจืืงืกื™ ืžื™ื˜ ืื™ื™ืŸ ืคึผืฉื•ื˜ ื‘ืึทืคึฟืขืœ. ืขืก ืื™ื– ื•ื•ื™ื›ื˜ื™ืง ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืึทื– ืคืึทืจืงืขืจ ืฆื• ื•ื•ื™ื™ึทื˜ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ืขื˜ ืงื•ืžืขืŸ ืคึฟื•ืŸ ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ, ื“ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืกืขืจื•ื•ืขืจ ืœืึธื’ืก.

localhost:~$ ssh -D 8888 user@remoteserver

localhost:~$ netstat -pan | grep 8888
tcp        0      0 127.0.0.1:8888       0.0.0.0:*               LISTEN      23880/ssh

ื“ืึธ ืžื™ืจ ืœื•ื™ืคืŸ ืึท ืกืึทืงืก ืคึผืจืึทืงืกื™ ืื•ื™ืฃ TCP ืคึผืึธืจื˜ 8888, ื“ื™ ืจื’ืข ื‘ืึทืคึฟืขืœ ื˜ืฉืขืง ืึทื– ื“ื™ ืคึผืึธืจื˜ ืื™ื– ืึทืงื˜ื™ื•ื• ืื™ืŸ ืฆื•ื’ืขื”ืขืจื˜ ืžืึธื“ืข. 127.0.0.1 ื™ื ื“ื™ืงื™ื™ืฅ ืึทื– ื“ื™ ืกืขืจื•ื•ื™ืก ืœื•ื™ืคื˜ ื‘ืœื•ื™ื– ืื•ื™ืฃ ืœืึธืงืึทืœื”ืึธืกื˜. ืžื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืึท ื‘ื™ืกืœ ืึทื ื“ืขืจืฉ ื‘ืึทืคึฟืขืœ ืฆื• ื”ืขืจืŸ ืื•ื™ืฃ ืึทืœืข ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืขื˜ื”ืขืจื ืขื˜ ืึธื“ืขืจ ื•ื•ื™ืคื™, ื“ืึธืก ื•ื•ืขื˜ ืœืึธื–ืŸ ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ( ื‘ืจืึทื•ื–ืขืจื–, ืืื–"ื• ื•) ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ื ืขืฅ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ื™ืก ื“ื•ืจืš ื“ื™ ssh ืกืึทืงืก ืคึผืจืึทืงืกื™.

localhost:~$ ssh -D 0.0.0.0:8888 user@remoteserver

ืื™ืฆื˜ ืžื™ืจ ืงืขื ืขืŸ ืงืึทื ืคื™ื’ื™ืขืจ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืกืึทืงืก ืคึผืจืึทืงืกื™. ืื™ืŸ Firefox, ืกืขืœืขืงื˜ื™ืจืŸ ืกืขื˜ื˜ื™ื ื’ืก | Basic | ื ืขืฅ ืกืขื˜ื˜ื™ื ื’ืก. ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ IP ืึทื“ืจืขืก ืื•ืŸ ืคึผืึธืจื˜ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ.

ืคึผืจืึทืงื˜ื™ืฉ ืขืฆื•ืช, ื‘ื™ื™ืฉืคื™ืœืŸ ืื•ืŸ SSH ื˜ืึทื ืึทืœื–

ื‘ื™ื˜ืข ื˜ืึธืŸ ื“ื™ ืึธืคึผืฆื™ืข ืื™ืŸ ื“ื™ ื“ื ืึธ ืคื•ืŸ ื“ื™ ืคืึธืจืขื ืฆื• ืื•ื™ืš ืœืึธื–ืŸ ื“ื™ื™ืŸ ื‘ืœืขื˜ืขืจืขืจ ืก ื“ื ืก ืจื™ืงื•ื•ืขืก ื’ื™ื™ืŸ ื“ื•ืจืš ืึท SOCKS ืคืจืืงืกื™. ืื•ื™ื‘ ืื™ืจ ื ื•ืฆืŸ ืึท ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ ืฆื• ืขื ืงืจื™ืคึผื˜ ื•ื•ืขื‘ ืคืึทืจืงืขืจ ืื•ื™ืฃ ื“ื™ื™ืŸ ื”ื™ื’ืข ื ืขืฅ, ืื™ืจ ื•ื•ืขื˜ ืžื™ืกื˜ืึธืžืข ื•ื•ื™ืœืŸ ืฆื• ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื ืึธืคึผืฆื™ืข ืึทื–ื•ื™ ืึทื– ื“ื ืก ืจื™ืงื•ื•ืขืก ื–ืขื ืขืŸ ื˜ืึทื ืึทืœื“ ื“ื•ืจืš ื“ื™ SSH ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’.

ืึทืงื˜ืึทื•ื•ื™ื™ื˜ื™ื ื’ ืกืึทืงืก ืคึผืจืึทืงืกื™ ืื™ืŸ ืงืจืึธื•ื

ืœืึธื ื˜ืฉื™ื ื’ ืงืจืึธื•ื ืžื™ื˜ ื–ื™ื›ืขืจ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคึผืึทืจืึทืžืขื˜ืขืจืก ื•ื•ืขื˜ ื’ืขื‘ืŸ ื“ื™ ืกืึทืงืก ืคึผืจืึทืงืกื™, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื˜ืึทื ืึทืœื™ื ื’ ื“ื ืก ืจื™ืงื•ื•ืขืก ืคึฟื•ืŸ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ. ืฆื•ื˜ืจื•ื™ ืึธื‘ืขืจ ื˜ืฉืขืง. ื ื™ืฆืŸ ื˜ืงืคึผื“ื•ืžืคึผ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืึทื– ื“ื ืก ืงื•ื•ื™ืจื™ื– ื–ืขื ืขืŸ ื ื™ื˜ ืžืขืจ ืงืขื ื˜ื™ืง.

localhost:~$ google-chrome --proxy-server="socks5://192.168.1.10:8888"

ื ื™ืฆืŸ ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืžื™ื˜ ืึท ืคึผืจืึทืงืกื™

ื”ืึทืœื˜ืŸ ืื™ืŸ ืžื™ื™ื ื•ื ื’ ืึทื– ืคื™ืœืข ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืงืขื ืขืŸ ืื•ื™ืš ื ื•ืฆืŸ ืกืึทืงืก ืคึผืจืึทืงืกื™ื–. ื“ืขืจ ื•ื•ืขื‘ ื‘ืœืขื˜ืขืจืขืจ ืื™ื– ืคืฉื•ื˜ ื“ื™ ืžืขืจืกื˜ ืคืึธืœืงืก ืคื•ืŸ ื–ื™ื™ ืึทืœืข. ืขื˜ืœืขื›ืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื”ืึธื‘ืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืคึผืฆื™ืขืก ืฆื• ื’ืขื‘ืŸ ืึท ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ. ืื ื“ืขืจืข ื“ืึทืจืคึฟืŸ ืึท ื‘ื™ืกืœ ื”ื™ืœืฃ ืžื™ื˜ ืึท ื”ืขืœืคึผืขืจ ืคึผืจืึธื’ืจืึทื. ืœืžืฉืœ, ืคืจืืงืกื™ื˜ืฉืึทื™ื ืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืœื•ื™ืคืŸ ื“ื•ืจืš ืึท ืกืึทืงืก ืคึผืจืึทืงืกื™ Microsoft RDP, ืขื˜ืง.

localhost:~$ proxychains rdesktop $RemoteWindowsServer

ืกืึทืงืก ืคึผืจืึทืงืกื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ื‘ืึทืฉื˜ื™ืžื˜ ืื™ืŸ ื“ื™ ืคึผืจืึทืงืกื™ื˜ืฉืึทื™ื ืก ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข.

ืึธื ืฆื•ื”ืขืจืขื ื™ืฉ: ืื•ื™ื‘ ืื™ืจ ื ื•ืฆืŸ ื•ื•ื™ื™ึทื˜ ื“ืขืกืงื˜ืึทืคึผ ืคึฟื•ืŸ ืœื™ื ื•ืงืก ืื•ื™ืฃ ื•ื•ื™ื ื“ืึธื•ื–? ืคึผืจื•ึผื•ื•ื˜ ื“ืขื ืงืœื™ืขื ื˜ FreeRDP. ื“ืึธืก ืื™ื– ืึท ืžืขืจ ืžืึธื“ืขืจืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื•ื•ื™ rdesktop, ืžื™ื˜ ืึท ืคื™ืœ ืกืžื•ื“ืขืจ ื“ืขืจืคืึทืจื•ื ื’.

ืึธืคึผืฆื™ืข ืฆื• ื ื•ืฆืŸ SSH ื“ื•ืจืš ืกืึทืงืก ืคึผืจืึทืงืกื™

ืื™ืจ ื–ื™ืฆื˜ ืื™ืŸ ืึท ืงืึทืคืข ืึธื“ืขืจ ื”ืึธื˜ืขืœ - ืื•ืŸ ืื™ืจ ื–ืขื ื˜ ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืฆื• ื ื•ืฆืŸ ื’ืึทื ืฅ ืึทื ืจื™ืœื™ื™ืึทื‘ืึทืœ WiFi. ืžื™ืจ ืงืึทื˜ืขืจ ืึท ssh ืคืจืืงืกื™ ืœืึธื•ืงืึทืœื™ ืคึฟื•ืŸ ืึท ืœืึทืคึผื˜ืึทืคึผ ืื•ืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืึท ssh ื˜ื•ื ืขืœ ืื™ืŸ ื“ื™ ื”ื™ื™ื ื ืขืฅ ืื•ื™ืฃ ืึท ื”ื™ื’ืข Rasberry Pi. ื ื™ืฆืŸ ืึท ื‘ืœืขื˜ืขืจืขืจ ืึธื“ืขืจ ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ืคึฟืึทืจ ืึท ืกืึทืงืก ืคืจืืงืกื™, ืžื™ืจ ืงืขื ืขืŸ ืึทืงืกืขืก ืงื™ื™ืŸ ื ืขืฅ ื‘ืึทื“ื™ื ื•ื ื’ืก ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ื”ื™ื™ื ื ืขืฅ ืึธื“ืขืจ ืึทืงืกืขืก ื“ื™ ืื™ื ื˜ืขืจื ืขื˜ ื“ื•ืจืš ืื•ื ื“ื–ืขืจ ื”ื™ื™ื ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’. ืึทืœืฅ ืฆื•ื•ื™ืฉืŸ ื“ื™ื™ืŸ ืœืึทืคึผื˜ืึทืคึผ ืื•ืŸ ื“ื™ื™ืŸ ื”ื™ื™ื ืกืขืจื•ื•ืขืจ (ื“ื•ืจืš Wi-Fi ืื•ืŸ ืื™ื ื˜ืขืจื ืขื˜ ืฆื• ื“ื™ื™ืŸ ื”ื™ื™ื) ืื™ื– ื™ื ืงืจื™ืคึผื˜ื™ื“ ืื™ืŸ ืึท SSH ื˜ื•ื ืขืœ.

2. SSH ื˜ื•ื ืขืœ (ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’)

ืื™ืŸ ื–ื™ื™ืŸ ืกื™ืžืคึผืœืึทืกื˜ ืคืึธืจืขื, ืึท SSH ื˜ื•ื ืขืœ ืคืฉื•ื˜ ืึธืคึผืขื ืก ืึท ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ื™ื™ืŸ ื”ื™ื’ืข ืกื™ืกื˜ืขื ื•ื•ืึธืก ืงืึทื ืขืงืฅ ืฆื• ืืŸ ืื ื“ืขืจ ืคึผืึธืจื˜ ืื™ืŸ ื“ื™ ืื ื“ืขืจืข ืกื•ืฃ ืคื•ืŸ ื“ืขื ื˜ื•ื ืขืœ.

localhost:~$ ssh  -L 9999:127.0.0.1:80 user@remoteserver

ื–ืืœ ืก ืงื•ืง ืื™ืŸ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจ -L. ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื“ืึทื ืง ืคื•ืŸ ื“ื™ ื”ื™ื’ืข ื–ื™ื™ึทื˜ ืคื•ืŸ ืฆื•ื’ืขื”ืขืจื˜. ืื™ืŸ ื“ืขื ื‘ื™ื™ืฉืคึผื™ืœ ืื•ื™ื‘ืŸ, ืคึผืึธืจื˜ 9999 ืื™ื– ืฆื•ื’ืขื”ืขืจื˜ ืื•ื™ืฃ ื“ื™ ืœืึธืงืึทืœื”ืึธืกื˜ ื–ื™ื™ึทื˜ ืื•ืŸ ืคืึธืจื•ื•ืขืจื“ื™ื“ ื“ื•ืจืš ืคึผืึธืจื˜ 80 ืฆื• ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ. ื‘ื™ื˜ืข ื˜ืึธืŸ ืึทื– 127.0.0.1 ืจืขืคืขืจืก ืฆื• ืœืึธืงืึทืœื”ืึธืกื˜ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ!

ืœืืžื™ืจ ื’ื™ื™ืŸ ืืจื•ื™ืฃ ื“ืขื ืฉืจื™ื˜. ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ื™ื™ืฉืคึผื™ืœ ืงืึทืžื™ื•ื ืึทืงื™ื™ืฅ ืฆื•ื’ืขื”ืขืจื˜ ืคึผืึธืจืฅ ืžื™ื˜ ืื ื“ืขืจืข ืžื—ื ื•ืช ืื•ื™ืฃ ื“ื™ ื”ื™ื’ืข ื ืขืฅ.

localhost:~$ ssh  -L 0.0.0.0:9999:127.0.0.1:80 user@remoteserver

ืื™ืŸ ื“ื™ ื‘ื™ื™ืฉืคื™ืœืŸ ืžื™ืจ ื–ืขื ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืึท ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ื™ ื•ื•ืขื‘ ืกืขืจื•ื•ืขืจ, ืึธื‘ืขืจ ื“ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืึท ืคืจืืงืกื™ ืกืขืจื•ื•ืขืจ ืึธื“ืขืจ ืงื™ื™ืŸ ืื ื“ืขืจืข ื˜ืงืคึผ ื“ื™ื ืกื˜.

3. SSH ื˜ื•ื ืขืœ ืฆื• ืึท ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ื‘ืึทืœืขื‘ืึธืก

ืžื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ ื–ืขืœื‘ืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืึท ื˜ื•ื ืขืœ ืคื•ืŸ ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ืฆื• ืืŸ ืื ื“ืขืจ ื“ื™ื ืกื˜ ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ ืึท ื“ืจื™ื˜ ืกื™ืกื˜ืขื.

localhost:~$ ssh  -L 0.0.0.0:9999:10.10.10.10:80 user@remoteserver

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ, ืžื™ืจ ืจื™ื“ืขืจืขืงื˜ื™ื ื’ ืึท ื˜ื•ื ืขืœ ืคื•ืŸ ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ืฆื• ืึท ื•ื•ืขื‘ ืกืขืจื•ื•ืขืจ ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ 10.10.10.10. ืคืึทืจืงืขืจ ืคื•ืŸ ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ืฆื• 10.10.10.10 ื ื™ื˜ ืžืขืจ ืื™ืŸ ื“ื™ ืกืฉ ื˜ื•ื ืขืœ. ื“ืขืจ ื•ื•ืขื‘ ืกืขืจื•ื•ืขืจ ืื•ื™ืฃ 10.10.10.10 ื•ื•ืขื˜ ื‘ืึทื˜ืจืึทื›ื˜ืŸ ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ื•ื•ื™ ื“ืขืจ ืžืงื•ืจ ืคื•ืŸ ื•ื•ืขื‘ ืจื™ืงื•ื•ืขืก.

4. ืคืึทืจืงืขืจื˜ ืกืฉ ื˜ื•ื ืขืœ

ื“ืึธ ืžื™ืจ ื•ื•ืขืœืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืึท ืฆื•ื’ืขื”ืขืจื˜ ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ื•ื•ืึธืก ื•ื•ืขื˜ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื•ืจื™ืง ืฆื• ื“ื™ ื”ื™ื’ืข ืคึผืึธืจื˜ ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ืœืึธืงืึทืœื”ืึธืกื˜ (ืึธื“ืขืจ ืื ื“ืขืจืข ืกื™ืกื˜ืขื).

localhost:~$ ssh -v -R 0.0.0.0:1999:127.0.0.1:902 192.168.1.100 user@remoteserver

ื“ืขืจ SSH ืกืขืกื™ืข ื™ืกื˜ืึทื‘ืœื™ืฉื™ื– ืึท ืงืฉืจ ืคื•ืŸ ืคึผืึธืจื˜ 1999 ืื•ื™ืฃ ืจื™ืžืึธื•ื˜ืกืขืจื•ื•ืขืจ ืฆื• ืคึผืึธืจื˜ 902 ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ื”ื™ื’ืข ืงืœื™ืขื ื˜.

5. SSH Reverse Proxy

ืื™ืŸ ื“ืขื ืคืึทืœ, ืžื™ืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึท ืกืึทืงืก ืคึผืจืึทืงืกื™ ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ssh ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’, ืึธื‘ืขืจ ื“ื™ ืคึผืจืึทืงืกื™ ืื™ื– ืฆื•ื’ืขื”ืขืจื˜ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกื•ืฃ ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ. ืงืึทื ืขืงืฉืึทื ื– ืฆื• ื“ืขื ื•ื•ื™ื™ึทื˜ ืคึผืจืึทืงืกื™ ืื™ืฆื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืคึฟื•ืŸ ื“ืขื ื˜ื•ื ืขืœ ื•ื•ื™ ืคืึทืจืงืขืจ ืคึฟื•ืŸ ืื•ื ื“ื–ืขืจ ืœืึธืงืึทืœื”ืึธืกื˜.

localhost:~$ ssh -v -R 0.0.0.0:1999 192.168.1.100 user@remoteserver

ื˜ืจืึธื•ื‘ืœืขืฉืึธืึธื˜ื™ื ื’ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื•ื•ื™ื™ึทื˜ SSH ื˜ืึทื ืึทืœื–

ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื•ื•ื™ื™ึทื˜ ืกืฉ ืึธืคึผืฆื™ืขืก ืืจื‘ืขื˜ืŸ, ื˜ืฉืขืง ืžื™ื˜ netstat, ื•ื•ืึธืก ืื ื“ืขืจืข ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื“ื™ ืฆื•ื’ืขื”ืขืจื˜ ืคึผืึธืจื˜ ืื™ื– ืงืึธื ื ืขืงื˜ืขื“ ืฆื•. ื›ืึธื˜ืฉ ืžื™ืจ ืื ื’ืขื•ื•ื™ื–ืŸ 0.0.0.0 ืื™ืŸ ื“ื™ ื‘ื™ื™ืฉืคื™ืœืŸ, ืึธื‘ืขืจ ืื•ื™ื‘ ื“ื™ ื•ื•ืขืจื˜ GatewayPorts ะฒ sshd_config ืฉื˜ืขืœืŸ ืฆื• ืงื™ื™ืŸ, ื“ืขืจ ืœื™ืกื ืขืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื‘ื•ื ื“ืŸ ื‘ืœื•ื™ื– ืฆื• ืœืึธืงืึทืœื”ืึธืกื˜ (127.0.0.1).

ื–ื™ื›ืขืจื”ื™ื™ึทื˜ ื•ื•ืืจืขื ื•ื ื’

ื‘ื™ื˜ืข ื˜ืึธืŸ ืึทื– ื“ื•ืจืš ืขืคืŸ ื˜ืึทื ืึทืœื– ืื•ืŸ ืกืึทืงืก ืคึผืจืึทืงืกื™ื–, ื™ื ืขืจืœืขืš ื ืขืฅ ืจืขืกื•ืจืกืŸ ืงืขืŸ ื–ื™ื™ืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ืฆื• ืึทื ื˜ืจืึทืกื˜ื™ื“ ื ืขื˜ื•ื•ืึธืจืงืก (ืึทื–ืึท ื•ื•ื™ ื“ื™ ืื™ื ื˜ืขืจื ืขื˜!). ื“ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืึท ืขืจื ืกื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืจื™ื–ื™ืงื™ืจืŸ, ืึทื–ื•ื™ ืžืึทื›ืŸ ื–ื™ื›ืขืจ ืื™ืจ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื•ื•ืึธืก ื“ื™ ืœื™ืกื ืขืจ ืื™ื– ืื•ืŸ ื•ื•ืึธืก ื–ื™ื™ ื”ืึธื‘ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื•.

6. ื™ื ืกื˜ืึธืœื™ื ื’ ื•ื•ืคึผืŸ ื“ื•ืจืš ืกืฉ

ื ืคึผืจืึธืกื˜ ื˜ืขืจืžื™ืŸ ืฆื•ื•ื™ืฉืŸ ืกืคึผืขืฉืึทืœืึทืกืฅ ืื™ืŸ ื‘ืึทืคืึทืœืŸ ืžืขื˜ื”ืึธื“ืก (ืคึผืขื ื˜ืขืกื˜ืขืจืก, ืืื–"ื• ื•) ืื™ื– "ืึท ืคื•ืœืงืจื•ื ืื™ืŸ ื“ืขืจ ื ืขืฅ." ืึทืžืึธืœ ืึท ืงืฉืจ ืื™ื– ื’ืขื’ืจื™ื ื“ืขื˜ ืื•ื™ืฃ ืื™ื™ืŸ ืกื™ืกื˜ืขื, ื“ื™ ืกื™ืกื˜ืขื ื•ื•ืขืจื˜ ื“ืขืจ ื’ื™ื™ื˜ื•ื•ื™ื™ ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืงืกืขืก ืฆื• ื“ื™ ื ืขืฅ. ื ืคื•ืœืงืจื•ื ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืžืึทืš ืื™ืŸ ื“ื™ ื‘ืจื™ื™ื˜.

ืคึฟืึทืจ ืึทื–ืึท ืึท ืคื•ื˜ื›ืึธื•ืœื“ ืžื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืึท SSH ืคืจืืงืกื™ ืื•ืŸ ืคืจืืงืกื™ื˜ืฉืึทื™ื ืกืึธื‘ืขืจ, ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ืœื™ืžื™ื˜ื™ื™ืฉืึทื ื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืขืก ื•ื•ืขื˜ ื ื™ืฉื˜ ื–ื™ื™ืŸ ืžืขื’ืœืขืš ืฆื• ืึทืจื‘ืขื˜ืŸ ื’ืœื™ื™ึทืš ืžื™ื˜ ืกืึทืงืึทืฅ, ืึทื–ื•ื™ ืžื™ืจ ืงืขื ืขืŸ ื ื™ืฉื˜ ื™ื‘ืขืจืงื•ืงืŸ ืคึผืึธืจืฅ ืื™ืŸ ื“ื™ ื ืขืฅ ื“ื•ืจืš ื ืžืึทืคึผ SYN.

ืžื™ื˜ ื“ืขื ืžืขืจ ืึทื•ื•ืึทื ืกื™ืจื˜ืข VPN ืึธืคึผืฆื™ืข, ื“ื™ ืงืฉืจ ืื™ื– ืจื™ื“ื•ืกื˜ ืฆื• ืžื“ืจื’ื” 3. ืžื™ืจ ืงืขื ืขืŸ ื“ืขืจื™ื‘ืขืจ ืคืฉื•ื˜ ืžืึทืจืฉืจื•ื˜ ืคืึทืจืงืขืจ ื“ื•ืจืš ื“ืขื ื˜ื•ื ืขืœ ื ื™ืฆืŸ ื ืึธืจืžืึทืœ ื ืขืฅ ืจื•ื˜ื™ื ื’.

ื“ืขืจ ืื•ืคึฟืŸ ื ื™ืฆื˜ ssh, iptables, tun interfaces ืื•ืŸ ืจื•ื˜ื™ื ื’.

ืขืจืฉื˜ืขืจ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ sshd_config. ื–ื™ื ื˜ ืžื™ืจ ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืคื•ืŸ ื‘ื™ื™ื“ืข ื“ื™ ื•ื•ื™ื™ึทื˜ ืื•ืŸ ืงืœื™ืขื ื˜ ืกื™ืกื˜ืขืžืขืŸ, ืžื™ืจ ื“ืึทืจืคึฟืŸ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜ ืื•ื™ืฃ ื‘ื™ื™ื“ืข ื–ื™ื™ื˜ืŸ.

PermitRootLogin yes
PermitTunnel yes

ื“ืขืจื ืึธืš, ืžื™ืจ ื•ื•ืขืœืŸ ืคืึทืจืœื™ื™ื’ืŸ ืึท ssh ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืžื™ื˜ ื“ืขื ืคึผืึทืจืึทืžืขื˜ืขืจ ื•ื•ืึธืก ืจื™ืงื•ื•ืขืก ื“ื™ ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื™ืฉืึทืŸ ืคื•ืŸ ื˜ื•ื ืก ื“ืขื•ื•ื™ืกืขืก.

localhost:~# ssh -v -w any root@remoteserver

ืžื™ืจ ื–ืึธืœ ืื™ืฆื˜ ื”ืึธื‘ืŸ ืึท ื˜ื•ืŸ ืžื™ื˜ืœ ื•ื•ืขืŸ ืื™ืจ ื•ื•ื™ื™ึทื–ืŸ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– (# ip a). ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืฉืจื™ื˜ ื•ื•ืขื˜ ืœื™ื™ื’ืŸ IP ืึทื“ืจืขืกืขืก ืฆื• ื“ื™ ื˜ื•ื ืขืœ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–.

SSH ืงืœื™ืขื ื˜ ื–ื™ื™ึทื˜:

localhost:~# ip addr add 10.10.10.2/32 peer 10.10.10.10 dev tun0
localhost:~# ip tun0 up

SSH ืกืขืจื•ื•ื™ืจืขืจ ื–ื™ื™ึทื˜:

remoteserver:~# ip addr add 10.10.10.10/32 peer 10.10.10.2 dev tun0
remoteserver:~# ip tun0 up

ืื™ืฆื˜ ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื“ื™ืจืขืงื˜ ืžืึทืจืฉืจื•ื˜ ืฆื• ืืŸ ืื ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก (route -n ะธ ping 10.10.10.10).

ืื™ืจ ืงืขื ืขืŸ ืžืึทืจืฉืจื•ื˜ ืงื™ื™ืŸ ืกื•ื‘ื ืขื˜ ื“ื•ืจืš ืึท ื‘ืึทืœืขื‘ืึธืก ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื–ื™ื™ึทื˜.

localhost:~# route add -net 10.10.10.0 netmask 255.255.255.0 dev tun0

ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ื–ื™ื™ึทื˜ ืื™ืจ ืžื•ื–ืŸ ื’ืขื‘ืŸ ip_forward ะธ iptables.

remoteserver:~# echo 1 > /proc/sys/net/ipv4/ip_forward
remoteserver:~# iptables -t nat -A POSTROUTING -s 10.10.10.2 -o enp7s0 -j MASQUERADE

ื‘ื•ื! VPN ืื™ื‘ืขืจ SSH ื˜ื•ื ืขืœ ืื™ืŸ ื ืขืฅ ืฉื™ื›ื˜ืข 3. ืื™ืฆื˜ ืื™ื– ื“ืึธืก ืึท ื ืฆื—ื•ืŸ.

ืื•ื™ื‘ ืงื™ื™ืŸ ืคืจืื‘ืœืขืžืขืŸ ืคืึทืœืŸ, ื ื•ืฆืŸ ื˜ืงืคึผื“ื•ืžืคึผ ะธ pingืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ืกื™ื‘ื”. ื–ื™ื ื˜ ืžื™ืจ ืฉืคึผื™ืœืŸ ืื™ืŸ ืฉื™ื›ื˜ืข 3, ืื•ื ื“ื–ืขืจ ื™ืงืžืคึผ ืคึผืึทืงื™ืฅ ื•ื•ืขื˜ ื’ื™ื™ืŸ ื“ื•ืจืš ื“ืขื ื˜ื•ื ืขืœ.

7. ื ืึธื›ืžืึทื›ืŸ ื“ื™ SSH ืฉืœื™ืกืœ (ssh-copy-id)

ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ื•ื•ืขื’ืŸ ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืึธื‘ืขืจ ื“ืขื ื‘ืึทืคึฟืขืœ ืกืึทื•ื•ืขืก ืฆื™ื™ื˜ ื“ื•ืจืš ื ื™ืฉื˜ ืงืึทืคึผื™ื™ื ื’ ื˜ืขืงืขืก ืžืึทื ื™ื•ืึทืœื™. ืขืก ืคืฉื•ื˜ ืงืึทืคึผื™ื– ~/.ssh/id_rsa.pub (ืึธื“ืขืจ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืฉืœื™ืกืœ) ืคื•ืŸ ื“ื™ื™ืŸ ืกื™ืกื˜ืขื ืฆื• ~/.ssh/authorized_keys ืื•ื™ืฃ ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ.

localhost:~$ ssh-copy-id user@remoteserver

8. ืจื™ืžืึธื•ื˜ ื‘ืึทืคึฟืขืœ ื“ื•ืจื›ืคื™ืจื•ื ื’ (ื ื™ื˜-ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื•)

ื“ื™ ืžืึทื ืฉืึทืคึฟื˜ ssh ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœื™ื ื’ืงื˜ ืฆื• ืื ื“ืขืจืข ืงืึทืžืึทื ื“ื– ืคึฟืึทืจ ืึท ืคึผืจืึธืกื˜, ื‘ืึทื ื™ืฆืขืจ-ืคืจื™ื™ึทื ื“ืœืขืš ืฆื•ื‘ื™ื ื“. ื ืึธืจ ืœื™ื™ื’ืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืœื•ื™ืคืŸ ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ื‘ืึทืœืขื‘ืึธืก ื•ื•ื™ ื“ื™ ืœืขืฆื˜ืข ืคึผืึทืจืึทืžืขื˜ืขืจ ืื™ืŸ ืฆื™ื˜ื™ืจื˜.

localhost:~$ ssh remoteserver "cat /var/log/nginx/access.log" | grep badstuff.php

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ grep ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื•ื™ืฃ ื“ื™ ื”ื™ื’ืข ืกื™ืกื˜ืขื ื ืึธืš ื“ื™ ืงืœืึธืฅ ืื™ื– ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ื“ื•ืจืš ssh ืงืึทื ืึทืœ. ืื•ื™ื‘ ื“ื™ ื˜ืขืงืข ืื™ื– ื’ืจื•ื™ืก, ืขืก ืื™ื– ืžืขืจ ื‘ืึทืงื•ื•ืขื ืฆื• ืœื•ื™ืคืŸ grep ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ื–ื™ื™ึทื˜ ื“ื•ืจืš ืคืฉื•ื˜ ืขื ืงืœืึธื•ื–ื™ื ื’ ื‘ื™ื™ื“ืข ืงืึทืžืึทื ื“ื– ืื™ืŸ ื˜ืึธืคึผืœ ืงื•ื•ืึธื˜ืขืก.

ืืŸ ืื ื“ืขืจ ื‘ื™ื™ึทืฉืคึผื™ืœ ืคึผืขืจืคืึธืจืžื– ื“ื™ ื–ืขืœื‘ืข ืคึฟื•ื ืงืฆื™ืข ื•ื•ื™ ssh-copy-id ืคึฟื•ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ 7.

localhost:~$ cat ~/.ssh/id_rsa.pub | ssh remoteserver 'cat >> .ssh/authorized_keys'

9. ืจื™ืžืึธื•ื˜ ืคึผืึทืงืึทื˜ ื›ืึทืคึผืŸ ืื•ืŸ ื•ื•ื™ื•ื™ื ื’ ืื™ืŸ Wireshark

ืื™ืš ื’ืขื ื•ืžืขืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ืื•ื ื“ื–ืขืจ tcpdump ื‘ื™ื™ืฉืคื™ืœืŸ. ื ื™ืฆืŸ ืขืก ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื›ืึทืคึผืŸ ืคึผืึทืงื™ืฅ ืื•ืŸ ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ื’ืœื™ื™ืš ืื™ืŸ ื“ื™ ื”ื™ื’ืข Wireshark GUI.

:~$ ssh root@remoteserver 'tcpdump -c 1000 -nn -w - not port 22' | wireshark -k -i -

10. ืงืึทืคึผื™ื™ื ื’ ืึท ื”ื™ื’ืข ื˜ืขืงืข ืฆื• ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ืกืฉ

ื ืคื™ื™ึทืŸ ื˜ืจื™ืง ืึทื– ืงืึทืžืคึผืจืขืกื™ื– ืึท ื˜ืขืงืข ื ื™ืฆืŸ bzip2 (ื“ืึธืก ืื™ื– ื“ื™ -j ืึธืคึผืฆื™ืข ืื™ืŸ ื“ื™ ื‘ืึทืคึฟืขืœ tar), ืื•ืŸ ื“ืขืจื ืึธืš ืจื™ื˜ืจื™ื•ื•ื– ื“ื™ ื˜ื™ื™ึทืš bzip2 ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื–ื™ื™ึทื˜, ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ื“ื•ืคึผืœื™ืงืึทื˜ ื˜ืขืงืข ืื•ื™ืฃ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ.

localhost:~$ tar -cvj /datafolder | ssh remoteserver "tar -xj -C /datafolder"

11. ื•ื•ื™ื™ึทื˜ ื’ื•ื™ ืึทืคึผืคึผืœื™ืงืึทื˜ื™ืึธื ืก ืžื™ื˜ ืกืฉ ืงืก 11 ืคืึธืจื•ื•ืขืจื“ื™ื ื’

ืื•ื™ื‘ X ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ืฃ ื“ืขื ืงืœื™ืขื ื˜ ืื•ืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ, ืื™ืจ ืงืขื ืขืŸ ืจื™ืžืึธื•ื˜ืœื™ ื•ื™ืกืคื™ืจืŸ ืึท GUI ื‘ืึทืคึฟืขืœ ืžื™ื˜ ืึท ืคึฟืขื ืฆื˜ืขืจ ืื•ื™ืฃ ื“ื™ื™ืŸ ื”ื™ื’ืข ื“ืขืกืงื˜ืึทืคึผ. ื“ืขืจ ืฉื˜ืจื™ืš ืื™ื– ื’ืขื•ื•ืขืŸ ืึทืจื•ื ืคึฟืึทืจ ืึท ืœืึทื ื’ ืฆื™ื™ึทื˜, ืึธื‘ืขืจ ืื™ื– ื ืึธืš ื–ื™ื™ืขืจ ื ื•ืฆื™ืง. ืงืึทื˜ืขืจ ืึท ื•ื•ื™ื™ึทื˜ ื•ื•ืขื‘ ื‘ืœืขื˜ืขืจืขืจ ืึธื“ืขืจ ืืคื™ืœื• ื“ื™ VMWawre ื•ื•ืขืจืงืกื˜ื™ื™ืฉืึทืŸ ืงืึทื ืกืึธื•ืœ ื•ื•ื™ ืื™ืš ื˜ืึธืŸ ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ.

localhost:~$ ssh -X remoteserver vmware

ืคืืจืœืื ื’ื˜ ืฉื˜ืจื™ืงืœ X11Forwarding yes ืื™ืŸ ื˜ืขืงืข sshd_config.

12. ืจื™ืžืึธื•ื˜ ื˜ืขืงืข ืงืึทืคึผื™ื™ื ื’ ื ื™ืฆืŸ ืจืกื™ื ืง ืื•ืŸ ืกืฉ

rsync ืคื™ืœ ืžืขืจ ื‘ืึทืงื•ื•ืขื scp, ืื•ื™ื‘ ืื™ืจ ื“ืึทืจืคึฟืŸ ืคึผืขืจื™ืึธื“ื™ืฉ ื‘ืึทืงืึทืคึผืก ืคื•ืŸ ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื˜ืขืงืขืก ืึธื“ืขืจ ื–ื™ื™ืขืจ ื’ืจื•ื™ืก ื˜ืขืงืขืก. ืขืก ืื™ื– ืึท ืคึฟื•ื ืงืฆื™ืข ืคึฟืึทืจ ืจื™ืงืึทื•ื•ืขืจื“ ืคื•ืŸ ืึท ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื•ืจื›ืคืึทืœ ืื•ืŸ ืงืึทืคึผื™ื™ื ื’ ื‘ืœื•ื™ื– ื˜ืฉื™ื™ื ื“ื–ืฉื“ ื˜ืขืงืขืก, ื•ื•ืึธืก ืกืึทื•ื•ืขืก ืคืึทืจืงืขืจ ืื•ืŸ ืฆื™ื™ื˜.

ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ ื ื™ืฆื˜ ืงืึทืžืคึผืจืขืฉืึทืŸ gzip (-ื–) ืื•ืŸ ืึทืจื˜ืฉื™ื•ื•ื™ื ื’ ืžืึธื“ืข (-ืึท), ื•ื•ืึธืก ื™ื ื™ื™ื‘ืึทืœื– ืจืขืงื•ืจืกื™ื•ื•ืข ืงืึทืคึผื™ื™ื ื’.

:~$ rsync -az /home/testuser/data remoteserver:backup/

13. ืกืฉ ืื™ื‘ืขืจ ื“ื™ ื˜ืึธืจ ื ืขืฅ

ื“ื™ ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก ื˜ืึธืจ ื ืขืฅ ืงืขื ืขืŸ ื˜ื•ื ืขืœ SSH ืคืึทืจืงืขืจ ื ื™ืฆืŸ ื“ืขื ื‘ืึทืคึฟืขืœ torsocks. ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืึทืคึฟืขืœ ื•ื•ืขื˜ ืคืึธืจืŸ ื“ื™ ssh ืคืจืืงืกื™ ื“ื•ืจืš Tor.

localhost:~$ torsocks ssh myuntracableuser@remoteserver

ื˜ืึธืจืกืึธืงืงืก ื•ื•ืขื˜ ื ื•ืฆืŸ ืคึผืึธืจื˜ 9050 ืื•ื™ืฃ ืœืึธืงืึทืœื”ืึธืกื˜ ืคึฟืึทืจ ืคึผืจืึทืงืกื™. ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง, ื•ื•ืขืŸ ืื™ืจ ื ื•ืฆืŸ Tor, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืขืžืขืก ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื•ื•ืึธืก ืคืึทืจืงืขืจ ืื™ื– ื˜ืึทื ืึทืœื“ ืื•ืŸ ืื ื“ืขืจืข ืึทืคึผืขืจื™ื™ืฉืึทื ืึทืœ ื–ื™ื›ืขืจื”ื™ื™ื˜ (ืึธืคึผืกืขืง) ื™ืฉื•ื–. ื•ื•ืื• ื’ื™ื™ืŸ ื“ื™ื™ืŸ DNS ืคึฟืจืื’ืŸ?

14. ืกืฉ ืฆื• ืขืง2 ื‘ื™ื™ึทืฉืคึผื™ืœ

ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึทืŸ EC2 ื‘ื™ื™ึทืฉืคึผื™ืœ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืึท ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ. ืืจืืคืงืืคื™ืข ืขืก (.ืคึผืขื ื’ืขืฉืคึผืจื™ื™ื˜) ืคึฟื•ืŸ Amazon EC2 ืงืึธื ื˜ืจืึธืœ ื˜ืึทืคืœื™ืข ืื•ืŸ ื˜ื•ื™ืฉืŸ ื“ื™ ืคึผืขืจืžื™ืฉืึทื ื– (chmod 400 my-ec2-ssh-key.pem). ื”ืึทืœื˜ืŸ ื“ื™ ืฉืœื™ืกืœ ืื™ืŸ ืึท ื–ื™ื›ืขืจ ืึธืจื˜ ืึธื“ืขืจ ืฉื˜ืขืœืŸ ืขืก ืื™ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื˜ืขืงืข ~/.ssh/.

localhost:~$ ssh -i ~/.ssh/my-ec2-key.pem ubuntu@my-ec2-public

ืคึผืึทืจืึทืžืขื˜ืขืจ -i ืคืฉื•ื˜ ื“ืขืจืฆื™ื™ืœื˜ ื“ื™ ssh ืงืœื™ืขื ื˜ ืฆื• ื ื•ืฆืŸ ื“ืขื ืฉืœื™ืกืœ. ื˜ืขืงืข ~/.ssh/config ื™ื“ืขืึทืœ ืคึฟืึทืจ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืงืึทื ืคื™ื’ื™ืขืจื™ื ื’ ืฉืœื™ืกืœ ื‘ืึทื ื™ืฅ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ืึทืŸ ec2 ื‘ืึทืœืขื‘ืึธืก.

Host my-ec2-public
   Hostname ec2???.compute-1.amazonaws.com
   User ubuntu
   IdentityFile ~/.ssh/my-ec2-key.pem

15. ืขื“ื™ื˜ื™ื ื’ ื˜ืขืงืกื˜ ื˜ืขืงืขืก ื ื™ืฆืŸ VIM ื“ื•ืจืš ssh / scp

ืคึฟืึทืจ ืึทืœืข ืœื™ื‘ื”ืื‘ืขืจืก vim ื“ืขื ืฉืคึผื™ืฅ ื•ื•ืขื˜ ืฉืคึผืึธืจืŸ ืขื˜ืœืขื›ืข ืžืึธืœ. ื“ื•ืจืš ื ื•ืฆืŸ vim ื˜ืขืงืขืก ื–ืขื ืขืŸ ืขื“ื™ื˜ื™ื“ ื“ื•ืจืš ืกืงืคึผ ืžื™ื˜ ืื™ื™ืŸ ื‘ืึทืคึฟืขืœ. ื“ืขืจ ืื•ืคึฟืŸ ืคืฉื•ื˜ ืงืจื™ื™ื™ืฅ ื“ื™ ื˜ืขืงืข ืœืึธื•ืงืึทืœื™ ืื™ืŸ /tmpืื•ืŸ ื“ืึทืŸ ืงืืคื™ืขืก ืขืก ืฆื•ืจื™ืง ืึทืžืึธืœ ืžื™ืจ ื’ืขืจืื˜ืขื•ื•ืขื˜ ืขืก ืคื•ืŸ vim.

localhost:~$ vim scp://user@remoteserver//etc/hosts

ื‘ืึทืžืขืจืงื•ื ื’: ื“ืขืจ ืคึฟืึธืจืžืึทื˜ ืื™ื– ืึท ื‘ื™ืกืœ ืึทื ื“ืขืจืฉ ืคื•ืŸ ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ืœืขืš scp. ื ืึธืš ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ื˜ืึธืคึผืœ //. ื“ืึธืก ืื™ื– ืึทืŸ ืึทื‘ืกืึธืœื•ื˜ ื•ื•ืขื’ ืจืขืคึฟืขืจืขื ืฅ. ืื™ื™ืŸ ืฆืขื”ืึทืงืŸ ื•ื•ืขื˜ ืึธื ื•ื•ื™ื™ึทื–ืŸ ืึท ื“ืจืš ืงืึธืจืขื•ื• ืฆื• ื“ื™ื™ืŸ ื”ื™ื™ื ื˜ืขืงืข users.

**warning** (netrw) cannot determine method (format: protocol://[user@]hostname[:port]/[path])

ืื•ื™ื‘ ืื™ืจ ื–ืขืŸ ื“ืขื ื˜ืขื•ืช, ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ืคึฟืึธืจืžืึทื˜. ื“ืขื ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืžื™ื˜ืœ ืึท ืกื™ื ื˜ืึทืงืก ื˜ืขื•ืช.

16. ืžืึธื•ื ื˜ื™ื ื’ ืึท ื•ื•ื™ื™ึทื˜ SSH ื•ื•ื™ ืึท ื”ื™ื’ืข ื˜ืขืงืข ืžื™ื˜ SSHFS

ื“ื•ืจืš ืžื™ื˜ืœ ืคื•ืŸ sshfs - ื˜ืขืงืข ืกื™ืกื˜ืขื ืงืœื™ืขื ื˜ ssh - ืžื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืึท ื”ื™ื’ืข ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืฆื• ืึท ื•ื•ื™ื™ึทื˜ ืึธืจื˜ ืžื™ื˜ ืึทืœืข ื˜ืขืงืข ื™ื ื˜ืขืจืึทืงืฉืึทื ื– ืื™ืŸ ืึท ื™ื ืงืจื™ืคึผื˜ื™ื“ ืกืขืกื™ืข ssh.

localhost:~$ apt install sshfs

ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ืขื ืคึผืขืงืœ ืื•ื™ืฃ ื•ื‘ื•ื ื˜ื• ืื•ืŸ ื“ืขื‘ื™ืึทืŸ sshfs, ืื•ืŸ ื“ืขืžืึธืœื˜ ืคืฉื•ื˜ ืึธื ืงืœืึทืคึผืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ ืึธืจื˜ ืฆื• ืื•ื ื“ื–ืขืจ ืกื™ืกื˜ืขื.

localhost:~$ sshfs user@remoteserver:/media/data ~/data/

17. ืกืฉ ืžื•ืœื˜ื™ืคึผืœืขืงืกื™ื ื’ ืžื™ื˜ ืงืึธื ื˜ืจืึธืœืคึผืึทื˜ื”

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืื•ื™ื‘ ืขืก ืื™ื– ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ืงืฉืจ ืฆื• ืึท ื•ื•ื™ื™ึทื˜ ืกืขืจื•ื•ืขืจ ื ื™ืฆืŸ ssh ืจื’ืข ืงืฉืจ ื ื™ืฆืŸ ssh ืึธื“ืขืจ scp ื™ืกื˜ืึทื‘ืœื™ืฉื™ื– ืึท ื ื™ื™ึทืข ืกืขืกื™ืข ืžื™ื˜ ื ืึธืš ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ืึธืคึผืฆื™ืข ControlPath ืึทืœืึทื•ื– ื“ื™ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืกืขืกื™ืข ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ ืึทืœืข ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ืงืึทื ืขืงืฉืึทื ื–. ื“ืึธืก ื•ื•ืขื˜ ืคืึทืจื’ื™ื›ืขืจืŸ ื“ืขื ืคึผืจืึธืฆืขืก ื‘ืื˜ื™ื™ื˜ื™ืง: ื“ื™ ื•ื•ื™ืจืงื•ื ื’ ืื™ื– ื‘ืืžืขืจืงื˜ ืืคื™ืœื• ืื•ื™ืฃ ืึท ื”ื™ื’ืข ื ืขืฅ, ืื•ืŸ ืืคื™ืœื• ืžืขืจ ืึทื–ื•ื™ ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ื•ื•ื™ื™ึทื˜ ืจืขืกื•ืจืกืŸ.

Host remoteserver
        HostName remoteserver.example.org
        ControlMaster auto
        ControlPath ~/.ssh/control/%r@%h:%p
        ControlPersist 10m

ControlPath ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ื“ื™ ื›ืึธืœืขืœ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคึฟืึทืจ ื ื™ื™ึทืข ืงืึทื ืขืงืฉืึทื ื– ืฆื• ื–ืขืŸ ืื•ื™ื‘ ืขืก ืื™ื– ืึทืŸ ืึทืงื˜ื™ื•ื• ืกืขืกื™ืข ssh. ื“ื™ ืœืขืฆื˜ืข ืึธืคึผืฆื™ืข ืžื™ื˜ืœ ืึทื– ืืคื™ืœื• ื ืึธืš ืื™ืจ ืึทืจื•ื™ืกื’ืึทื ื’ ื“ื™ ืงืึทื ืกืึธื•ืœ, ื“ื™ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืกืขืกื™ืข ื•ื•ืขื˜ ื‘ืœื™ื™ื‘ืŸ ืึธืคืŸ ืคึฟืึทืจ 10 ืžื™ื ื•ื˜, ืึทื–ื•ื™ ืื™ืจ ืงืขื ืขืŸ ืจื™ืงืึทื ืขืงื˜ ืื•ื™ืฃ ื“ื™ ื™ื’ื–ื™ืกื˜ื™ื ื’ ื›ืึธืœืขืœ ืื™ืŸ ื“ืขื ืฆื™ื™ื˜. ืคึฟืึทืจ ืžืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื–ืขืŸ ื“ื™ ื”ื™ืœืฃ. ssh_config man.

18. ืกื˜ืจื™ื ื•ื•ื™ื“ืขื ืื™ื‘ืขืจ ืกืฉ ื ื™ืฆืŸ ื•ื•ืœืง ืื•ืŸ ืกืคื˜ืคึผ

ืืคื™ืœื• ืœืึทื ื’-ืฆื™ื™ึทื˜ ื ื™ืฆืขืจืก ssh ะธ vlc (Video Lan Client) ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฉื˜ืขื ื“ื™ืง ืึทื•ื•ืขืจ ืคื•ืŸ ื“ืขื ื‘ืึทืงื•ื•ืขื ืึธืคึผืฆื™ืข ื•ื•ืขืŸ ืื™ืจ ื˜ืึทืงืข ื“ืึทืจืคึฟืŸ ืฆื• ื–ืขืŸ ืึท ื•ื•ื™ื“ืขื ืื™ื‘ืขืจ ื“ื™ ื ืขืฅ. ืื™ืŸ ืกืขื˜ื˜ื™ื ื’ืก ื˜ืขืงืข | ืขืคึฟืŸ ื ืขื˜ื•ื•ืึธืจืง ืกื˜ืจื™ื ื“ื™ ืคึผืจืึธื’ืจืึทื vlc ืื™ืจ ืงืขื ืขืŸ ืึทืจื™ื™ึทืŸ ื“ื™ ืึธืจื˜ ื•ื•ื™ sftp://. ืื•ื™ื‘ ืึท ืคึผืึทืจืึธืœ ืื™ื– ืคืืจืœืื ื’ื˜, ืึท ืคึผื™ื ื˜ืœืขืš ื•ื•ืขื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ.

sftp://remoteserver//media/uploads/myvideo.mkv

19. ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ

ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื•ื•ื™ ื“ื™ื™ืŸ ื‘ืึทื ืง ืืงืื•ื ื˜ ืึธื“ืขืจ Google ื—ืฉื‘ื•ืŸ ืึทืคึผืœื™ื™ื– ืฆื• ื“ื™ SSH ื“ื™ื ืกื˜.

ืคื•ืŸ ืงื•ืจืก, ssh ื˜ื›ื™ืœืขืก ื”ืื˜ ืึท ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ืžื™ื˜ืœ ืึท ืคึผืึทืจืึธืœ ืื•ืŸ ืึท SSH ืฉืœื™ืกืœ. ื“ื™ ืžื™ื™ึทืœืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืึท ื™ื™ึทื–ื ื•ื•ืึทืจื’ ืกื™ืžืขืŸ ืึธื“ืขืจ Google Authenticator ืึทืคึผ ืื™ื– ืึทื– ืขืก ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ืึท ืึทื ื“ืขืจืฉ ื’ืฉืžื™ื•ืช ืžื™ื˜ืœ.

ื–ืขืŸ ืื•ื ื“ื–ืขืจ 8-ืžื™ื ื•ื˜ ืคื™ืจืขืจ ืฆื• ื ื™ืฆืŸ Google Authenticator ืื•ืŸ SSH.

20. ืฉืคึผืจื™ื ื’ืขืŸ ืžื—ื ื•ืช ืžื™ื˜ ืฉืฉ ืื•ืŸ -ื“ื–ืฉ

ืื•ื™ื‘ ื ืขืฅ ืกืขื’ืžืขื ื˜ืึทื˜ื™ืึธืŸ ืžื™ื˜ืœ ืื™ืจ ื”ืึธื‘ืŸ ืฆื• ืฉืคึผืจื™ื ื’ืขืŸ ื“ื•ืจืš ืงื™ื™ืคืœ ssh ืžื—ื ื•ืช ืฆื• ื‘ืึทืงื•ืžืขืŸ ืฆื• ื“ื™ ืœืขืฆื˜ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ื ืขืฅ, ื“ื™ -J ื“ื•ืจื›ื•ื•ืขื’ ื•ื•ืขื˜ ืจืึทื˜ืขื•ื•ืขืŸ ืื™ืจ ืฆื™ื™ื˜.

localhost:~$ ssh -J host1,host2,host3 [email protected]

ื“ื™ ื”ื•ื™ืคึผื˜ ื–ืึทืš ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ืึธ ืื™ื– ืึทื– ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ ื“ื™ ื‘ืึทืคึฟืขืœ ssh host1ื“ืขืžืึธืœื˜ user@host1:~$ ssh host2 ืืื–"ื• ื• ื“ื™ -J ืึธืคึผืฆื™ืข ืงืœืขื•ื•ืขืจืœื™ ื ื™ืฆื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืฆื• ืฆื•ื•ื™ื ื’ืขืŸ ืœืึธืงืึทืœื”ืึธืกื˜ ืฆื• ืคืึทืจืœื™ื™ื’ืŸ ืึท ืกืขืกื™ืข ืžื™ื˜ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ื‘ืึทืœืขื‘ืึธืก ืื™ืŸ ื“ื™ ืงื™ื™ื˜. ืึทื–ื•ื™ ืื™ืŸ ื“ืขื ืื•ื™ื‘ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืื•ื ื“ื–ืขืจ ืœืึธืงืึทืœื”ืึธืกื˜ ืื™ื– ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืฆื• ื”ืึธืกื˜4. ื“ืึธืก ืื™ื–, ืื•ื ื“ื–ืขืจ ืœืึธืงืึทืœื”ืึธืกื˜ ืฉืœื™ืกืœืขืŸ ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜, ืื•ืŸ ื“ื™ ืกืขืกื™ืข ืคึฟื•ืŸ ืœืึธืงืึทืœื”ืึธืกื˜ ืฆื• ื”ืึธืกื˜4 ืื™ื– ื’ืึธืจ ื™ื ืงืจื™ืคึผื˜ื™ื“.

ืคึฟืึทืจ ืึทื–ืึท ืึท ืžืขื’ืœืขื›ืงื™ื™ื˜ ืื™ืŸ ssh_config ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืคึผืฆื™ืข ProxyJump. ืื•ื™ื‘ ืื™ืจ ืงืขืกื™ื™ื“ืขืจ ื”ืึธื‘ืŸ ืฆื• ื’ื™ื™ืŸ ื“ื•ืจืš ืขื˜ืœืขื›ืข ืžื—ื ื•ืช, ืึธื˜ืึทืžื™ื™ืฉืึทืŸ ื“ื•ืจืš ื“ื™ ืงืึธื ืคื™ื’ ื•ื•ืขื˜ ืฉืคึผืึธืจืŸ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ืฆื™ื™ื˜.

21. ืคืึทืจืฉืคึผืึทืจืŸ ืกืฉ ื‘ืจื•ื˜ ืงืจืึทืคื˜ ืคืจื•ื•ื•ืŸ ื ื™ืฆืŸ ื™ืคึผื˜ืึทื‘ืœืขืก

ื•ื•ืขืจ ืขืก ื™ื– ื•ื•ืืก ื”ืื˜ ื’ืขืจืื˜ืŸ ืึท SSH ื“ื™ื ืกื˜ ืื•ืŸ ื’ืขืงื•ืงื˜ ืื•ื™ืฃ ื“ื™ ืœืึธื’ืก ื•ื•ื™ื™ืกื˜ ื•ื•ืขื’ืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื‘ืจื•ื˜ ืงืจืึทืคื˜ ืคืจื•ื•ื•ืŸ ื•ื•ืึธืก ืคึผืึทืกื™ืจืŸ ื™ืขื“ืขืจ ืฉืขื” ืคื•ืŸ ื™ืขื“ืขืจ ื˜ืึธื’. ื ืฉื ืขืœ ื•ื•ืขื’ ืฆื• ืจืขื“ื•ืฆื™ืจืŸ ืจืึทืฉ ืื™ืŸ ื“ื™ ืœืึธื’ืก ืื™ื– ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ SSH ืฆื• ืึท ื ื™ื˜-ื ืึธืจืžืึทืœ ืคึผืึธืจื˜. ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ืขืจ ื˜ืขืงืข sshd_config ื“ื•ืจืš ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคึผืึทืจืึทืžืขื˜ืขืจ ืคึผืึธืจื˜##.

ื ื™ืฆืŸ iptables ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืš ืœื™ื™ื›ื˜ ืคืึทืจืฉืคึผืึทืจืŸ ืคืจื•ื•ื•ืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืึท ืคึผืึธืจื˜ ื•ื•ืขืŸ ืื™ืจ ื“ืขืจื’ืจื™ื™ื›ืŸ ืึท ื–ื™ื›ืขืจ ืฉื•ื•ืขืœ. ืึทืŸ ื’ืจื™ื ื’ ื•ื•ืขื’ ืฆื• ื˜ืึธืŸ ื“ืึธืก ืื™ื– ืฆื• ื ื•ืฆืŸ OSSEC, ื•ื•ื™ื™ึทืœ ืขืก ื ื™ื˜ ื‘ืœื•ื™ื– ื‘ืœืึทืงืก SSH, ืึธื‘ืขืจ ืื•ื™ืš ืึท ื‘ื™ื ื˜ืœ ืคื•ืŸ ืื ื“ืขืจืข ื”ืึธืกื˜ื ืึทืžืข-ื‘ืื–ื™ืจื˜ ื™ื ื˜ืจื•ื–ืฉืึทืŸ ื“ื™ื˜ืขืงืฉืึทืŸ (HIDS) ืžื™ื˜ืœืขืŸ.

22. SSH Escape ืฆื• ื˜ื•ื™ืฉืŸ ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’

ืื•ืŸ ืื•ื ื“ื–ืขืจ ืœืขืฆื˜ืข ื‘ื™ื™ึทืฉืคึผื™ืœ ssh ื“ื™ื–ื™ื™ื ื“ ืฆื• ื˜ื•ื™ืฉืŸ ืคึผืึธืจื˜ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ืคืœื™ืขืŸ ืื™ืŸ ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ืกืขืกื™ืข ssh. ื™ืžืึทื“ื–ืฉืึทืŸ ื“ืขื ืกืฆืขื ืึทืจ. ืื™ืจ ื–ืขื ื˜ ื˜ื™ืฃ ืื™ืŸ ื“ื™ ื ืขืฅ; ืืคึฟืฉืจ ื›ืึทืคึผื˜ ืื™ื‘ืขืจ ืึท ื”ืึทืœื‘ ื˜ื•ืฅ ืžื—ื ื•ืช ืื•ืŸ ื“ืึทืจืคึฟืŸ ืึท ื”ื™ื’ืข ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ื™ ื•ื•ืขืจืงืกื˜ื™ื™ืฉืึทืŸ ื•ื•ืึธืก ืื™ื– ืคืึธืจื•ื•ืขืจื“ื™ื“ ืฆื• ื“ื™ Microsoft SMB ืคื•ืŸ ืึทืŸ ืึทืœื˜ Windows 2003 ืกื™ืกื˜ืขื (ื•ื•ืขืจ ืขืก ื™ื– ื’ืขื“ืขื ืงื˜ ืžืก08-67?).

ืงืœื™ืงื™ื ื’ enter, ืคึผืจื•ึผื•ื•ื˜ ืึทืจื™ื™ึทืŸ ื“ื™ ืงืึทื ืกืึธื•ืœ ~C. ื“ืึธืก ืื™ื– ืึท ืกืขืกื™ืข ืงืึธื ื˜ืจืึธืœ ืกื™ืงื•ื•ืึทื ืก ื•ื•ืึธืก ืึทืœืึทื•ื– ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ืงืฉืจ.

localhost:~$ ~C
ssh> -h
Commands:
      -L[bind_address:]port:host:hostport    Request local forward
      -R[bind_address:]port:host:hostport    Request remote forward
      -D[bind_address:]port                  Request dynamic forward
      -KL[bind_address:]port                 Cancel local forward
      -KR[bind_address:]port                 Cancel remote forward
      -KD[bind_address:]port                 Cancel dynamic forward
ssh> -L 1445:remote-win2k3:445
Forwarding port.

ื“ืึธ ืื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ืึทื– ืžื™ืจ ื”ืึธื‘ืŸ ืคืึธืจื•ื•ืขืจื“ื™ื“ ืื•ื ื“ื–ืขืจ ื”ื™ื’ืข ืคึผืึธืจื˜ 1445 ืฆื• ืึท Windows 2003 ื‘ืึทืœืขื‘ืึธืก ื•ื•ืึธืก ืžื™ืจ ื’ืขืคึฟื•ื ืขืŸ ืื•ื™ืฃ ื“ื™ ื™ื ืขืจืœืขืš ื ืขืฅ. ืื™ืฆื˜ ื ืึธืจ ืœื•ื™ืคืŸ msfconsole, ืื•ืŸ ืื™ืจ ืงืขื ืขืŸ ืžืึทืš ืื•ื™ืฃ (ืึทืกื•ืžื™ื ื’ ืื™ืจ ืคึผืœืึทืŸ ืฆื• ื ื•ืฆืŸ ื“ืขื ื‘ืึทืœืขื‘ืึธืก).

ืงืึทืžืคึผืœื™ืฉืึทืŸ

ื“ื™ ื‘ื™ื™ืฉืคื™ืœืŸ, ืขืฆื•ืช ืื•ืŸ ืงืึทืžืึทื ื“ื– ssh ื–ืึธืœ ื’ืขื‘ืŸ ืึท ืกื˜ืึทืจื˜ื™ื ื’ ืคื•ื ื˜; ืžืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื™ืขื“ืขืจ ืคื•ืŸ ื“ื™ ืงืึทืžืึทื ื“ื– ืื•ืŸ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืื™ื– ื‘ื ื™ืžืฆื ืื•ื™ืฃ ื“ื™ ืžืขื ื˜ืฉ ื‘ืœืขื˜ืขืจ (man ssh, man ssh_config, man sshd_config).

ืื™ืš ื•ื•ืข ืฉื˜ืขื ื“ื™ืง ื’ืขื•ื•ืขืŸ ืคืึทืกืึทื ื™ื™ื˜ื™ื“ ื“ื•ืจืš ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืึทืงืกืขืก ืกื™ืกื˜ืขืžืขืŸ ืื•ืŸ ื•ื™ืกืคื™ืจืŸ ืงืึทืžืึทื ื“ื– ืขืจื’ืขืฅ ืื™ืŸ ื“ืขืจ ื•ื•ืขืœื˜. ื“ื•ืจืš ื“ืขื•ื•ืขืœืึธืคึผื™ื ื’ ื“ื™ื™ืŸ ืกืงื™ืœื– ืžื™ื˜ ืžื›ืฉื™ืจื™ื ื•ื•ื™ ssh ืื™ืจ ื•ื•ืขื˜ ื•ื•ืขืจืŸ ืžืขืจ ืขืคืขืงื˜ื™ื•ื• ืื™ืŸ ืงื™ื™ืŸ ืฉืคึผื™ืœ ืื™ืจ ืฉืคึผื™ืœ.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’