blob: b005a08d368e99342e555cbbe7770850a574efa8 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
|
### SSH (Secure Shell Protocol)
- A method for secure remote login from one computer to another
> \# Add information about local and target to define which machines
* Find out your username
`$ whoami`
* Check ip address
> NOTE:
- lo usually stands for the loopback interface (localhost)
- wlan usually stands for a wireless networking interface
- rmnet interfaces are usually associated with cellular connections and usb tethering
* Linux
`$ ip addr show | grep "inet "`
`$ ifconfig`
`$ nmcli -p device show`
`$ ip route get 1.2.3.4 | awk '{print $7}'`
`$ curl ifconfig.me`
`$ ifconfig 2> /dev/null | grep -Eo 'inet (addr:)?([0-9]*\.){3}[0-9]*' | grep -Eo '[0-9.]*'`
* Windows
`$ ipconfig`
> NOTE: The IP Address we use will usually be the one not similar to 127.0.0.1 (localhost) but rather a different string of numbers, ignore any forward slash and the numbers after it
> Example:
> `$ ip addr show | grep "inet "`
```bash
inet 127.0.0.1/8 scope host lo
inet <u>10.1.1.5</u>/27 brd 10.1.1.31 [...]
```
> The `10.1.1.5` is what we want in this example
* See if any current ssh is running
`$ ps aux | grep sshd`
* Terminate sshd
- See all sshd connections, if non-zero number then there are ssh processes running
`$ pgrep -c sshd`
`$ pkill --signal HUP sshd`
- Check connections again to make sure, if still not 0 then use this
`$ pkill --signal KILL`
* Disconnect specific ssh clients off from server
1. First see who's logged into the the machine
`$ who` or `$ w`# if there is anything besides tty1, example `pts/3` then there is an active connection
> NOTE will not work for Termux since it does not support `utmp / wtmp / btmp` files
2. Look for specific process ID `PID`
`$ ps t`
3. (Optional) Laugh at their impending disconnection
`$ echo "HAHAHAHAHAHAHAHA" | write <user> pts/<n>`
4. Kill the process
`$ kill -9 30737`
* If `sshd` on remote server produces the following error message: `sshd re-exec requires execution with an absolute path` then use this `/usr/sbin/sshd`
* If `sshd` on remote server produces the following error message: `sshd: no hostkeys available -- exiting` then use this `ssh-keygen -A`
* For Termux users:
> NOTE: ip addr will not work unless phone is rooted, but `ifconfig` will from `net-tools` since the `proc_net` and `proc_net_tcp_udp` files are not accessible to `untrusted_app` domain but are allowed for `shell` (`adb`).
* Termux install openssh
`$ pkg in openssh`
* Termux make sure user/root password is set
`$ passwd <user> # root does not need to be specified`
* Generate your ssh key pair on remote host machine, not on server machine
`$ ssh-keygen`
* Accessing termux user environment from other consoles
`$ scp [email protected]:~/.ssh/id_rsa.pub ~/.ssh/authorized_keys`
* Second Option How do I add SSH Keys to authorized_keys file?
`$ cat ~/.ssh/id_rsa.pub | ssh [email protected] "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"`
* Start server in machine that will ssh into
`$ sshd`
* Android remote host into desktop server, assuming default port 8022
`$ ssh [email protected] -p 8022`
* Desktop remote host into android server, assuming default port 8022
`$ ssh [email protected]`
* To view the log output from the server process.
`$ logcat -s 'syslog:*'`
#### Copying files
##### (SCP Secure Copy Protocol)
- Syntax:
```bash
scp [OPTIONS] [[user@]src_host:]file1 [[user@]dest_host:]file2
```
```bash
scp file <remote_username>@<IPorHost>:<PathToFile> <LocalFileLocation>
```
How to SSH File Transfer from Remote to Local
1. Copy single file from local to remote using scp.
`$ scp myfile.txt remoteuser@remoteserver:/remote/folder/`
2. scp from remote to local on local using a single file.
`$ scp -P 22 remoteserver:/remote/folder/remotefile ~/localdir/localfile`
* Copy multiple files from remote to local on locall:
`$ scp [email protected]:/some/remote/directory/\{a,b,c\} ./`
* Copy multiple files from local to remote:
`$ scp foo.txt bar.txt [email protected]:~`
`$ scp {foo,bar}.txt [email protected]:~`
`$ scp *.txt [email protected]:~`
* Copy multiple files from remote to remote:
`$ scp [email protected]:/some/remote/directory/foobar.txt \`
3. Move 'r' using scp from remote to local on local using a single file.
`$ scp -r -P 22 remoteserver:/remote/folder/remotefile ~/localdir/localfile`
- - -
- (Optional) Install openssh
`$ apt install openssh`
- Make sure `passwd` is set for the server (root/non-root user)
- On server machine edit sshd_config
`$ vi /etc/ssh/sshd_config`
- Find and change the line `#Port 22` to `Port 8022`
- Find the line `#PermitRootLogin prohibit-password` or `#PermitRootLogin yes` and change it to `PermitRootLogin yes`. If it is already `PermitRootLogin yes` then don't change anything.
- Now do `ssh-keygen -A` and then `ssh-keygen`
or
`$ ssh-keygen -b 4096 -t rsa`
- OpenSSH has a utility to send the key remotely via either machine
`$ ssh-copy-id -p 8022 -i ~/.ssh/id_rsa.pub [email protected]`
- Ssh into the host server machine from the local machine
`$ ssh [email protected] -p 8022`
- - -
#### Trouble-shooting
- Check or disable firewall
`$ sudo ufw status`
`$ sudo ufw disable`
`$ sudo ufw reload`
`$ sudo ufw allow port/tcp` # if default port 22
`$ sudo ufw allow 8022/tcp` # if using specific port
|