A piggy bank of commands, fixes, succinct reviews, some mini articles and technical opinions from a (mostly) Perl developer.

Jump to

Quick reference

Showing posts with label ssh. Show all posts
Showing posts with label ssh. Show all posts

Ubuntu Linux setup basics

For username "foo":

$ adduser foo

$ passwd foo

$ sudo usermod -aG sudo foo

$ mkdir -p /home/foo/.ssh

$ cat the_public_key.pem >> /home/foo/.ssh/authorized_keys

$ chown -R foo:foo /home/foo/.ssh

$ chmod 700 /home/foo/.ssh

$ chmod 600 /home/foo/.ssh/authorized_keys
Disable default account:
$ usermod -s /usr/sbin/nologin default_username

Notes:
  • Not useradd.
  • Even when logging in with just SSH key, user must have a password. It will only be used for sudo commands.

Using your bastion server as a socks proxy

How to access web services via a jump host:
​
ssh -v -N -C -D 9090 username@bastion.example.com
​
* `-v` verbose, see any issues as they arise
* `-N` don't execute a remote command
* `-C` turn on compression
* `-D #` open a SOCKS proxy on this local port
​
Browser setup: FoxyProxy (Configure to "Use Enabled Proxies By Patterns and Order")

screenshot of foxyproxy settings

NOTE: It's a bad idea to route all web traffic through your company's bastion server / jump host. Only route the hosts you absolutely need to.

Or for command line stuff:

ssh -v -N -C -D 9090 mad@bastard.example.com
hpts -s 127.0.0.1:9090 -p 8989 --level info
export http_proxy=http://127.0.0.1:8989/
export https_proxy=http://127.0.0.1:8989/

Docker basics

# Download an image and spin up a container, run it, connect to it

docker pull [name pf image] # download an image

docker run -d -p 80:80 --name pintail-whoami pintailai/pintail-whoami:0.0.1 # download + run

docker run --rm -v /path/on/machine:/app/out image-name:stable params to app

# List running containers

docker ps # show running containers

docker ps | cut -c-$(tput cols) # show running containers without wrapping to the next line

docker ps -q # show just the IDs of the running containers

docker ps -q | head -1 # show ID of most recently started container (how to sort)

# Run a shell on a container

docker run -i -t [Container ID] /bin/bash

# Connect to a shell on an already-runnning docker container.
# (Shell: Use /bin/bash for ubuntu or /bin/ash for alpine)

docker exec -it [Container ID] [shell]

docker exec -it `docker ps -q | head -1` /bin/bash # run shell on the most recently started container

# Copy a file off

docker cp <container>:<src-path> <local-dest-path>

# Delete all stopped containers and images

docker system prune -a

# List all images

docker image ls

SSH tunnel using a jump host

Access a service on a remote machine via an intermediary

ssh -v -L 4444:app.example.com:5000 $USER@jump.example.com -nNT

Now you can access the service running on app.example.com:5000 by going to localhost:4444 in your browser.

Explanation of the command

  • from the host machine (where you are running the command)
  • connect to jump.example.com as user $USER
  • once there, access service app.example.com on port 5000
  • then make that service available on the host machine on port 4444

Advanced usage - Two jumps

ssh -J user@jump.example.com user@app.example.com -L 1111:database.example.com:3306 -nNT -vvv

Notes:
-J jumps to another host
-L makes a tunnel to a service that's already running

Now you can do:

mysql --protocol=tcp --host=127.0.0.1 --port=1111

Notes:
- you must specify protocol because of the tunnel
- specifying 127.0.0.1 (instead of "localhost") prevents MySQL trying to use a local socket and failing

Use a proxy on a remote machine via an intermediary

If there's a proxy you need to use: proxy.example.com:8888 -- but you can only access it from jump.example.com -- then set up a tunnel like this:

ssh -A -L 4444:proxy.example.com:8888 $USER@jump.example.com -nNTv

Now you can use http://localhost:4444 as your proxy server, instead of http://proxy.example.com:8888


ssh debug3: Incorrect RSA1 identifier debug3: Could not load ".ssh/id_rsa" as a RSA1 public key

When testing ssh with -vvv, you see this in the log:

    debug3: Incorrect RSA1 identifier
    debug3: Could not load ".ssh/id_rsa" as a RSA1 public key

This is not an error.
This is not the problem you're looking for.
Your problem is something else.

(source)

See also another ssh non-error.

debug2: key_type_from_name: unknown key type '-----BEGIN'

SSH debug output can be quite misleading.
When you see the following output, it does NOT indicate a problem.

debug2: key_type_from_name: unknown key type '-----BEGIN'
debug3: key_read: missing keytype
debug3: key_read: missing whitespace
...
debug2: key_type_from_name: unknown key type '-----END'
debug3: key_read: missing keytype
debug1: identity file /home/foo/.ssh/id_rsa type 1

The final line tells you that the key was read successfully.

(source)

See also another ssh non-error.

SSH tunnel

ssh -N -R 5555:1.2.3.4:666 user@hostname
  • 5555 is a port you make up
  • 666 is the port to which you are forwarding
  • 1.2.3.4 is the IP of the target host to which you are fowarding
  • hostname is the host where port 5555 will be made available
  • you run this command on a third machine (e.g. your local host)

This results in  hostname:5555  getting forwarded to  1.2.3.4:666

SSH warning: authenticity of host can't be established

Problem

The authenticity of host 'example.com (1.2.3.4)' can't be established.
RSA key fingerprint is ab:cd:ef:12:34:56:78:90:ab:cd:ef:12:34:56:78:90
Are you sure you want to continue connecting (yes/no)?

Solution

ssh -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no

Make sure you understand the security implications of doing this (Hint: they're not good).

(source)

Cannot scp, but ssh works fine

Maybe your .bashrc or similar prints something to the console? This breaks scp.

e.g. if .bashrc or something it calls contains:
echo "Welcome to the server"

Then scp will just print "Welcome to the server" and not even attempt to copy the file.

How to forward your SSH key

Windows:

1. Run pageant, put it in startup, and pass it your key

2. Run putty or MobaXterm, configure them both to do "ssh -A" (i.e. forward your key)

3. On the server, check your SSH key is loaded:

ssh-add -l

4. ssh -A to other servers

Linux:

ssh -A to each server


sudo: no tty present and no askpass program specified

How to run sudo on a remote machine:

ssh user@domain.com 'sudo echo "foobar"'

Error:
    sudo: no tty present and no askpass program specified

Solution:

 ssh -t user@domain.com 'sudo echo "foobar"'

(source)

SSH port forwarding / tunnelling

Command for a tunnel:

ssh -D 9999 username@remote-host
  • -D means "dynamic application-level port forwarding"
  • 9999 is a port you make up
  • username@remote-host is the account you're relaying through
  • A prompt on the remote host will appear, ignore it (or use -N to avoid)
In your web browser, set the SOCKS5 proxy to localhost:9999

Can't push to github




The problem:

Git asks you for your password, when it should just accept your SSH key.

$ git push origin master
Password for 'https://github@github.com': 


The solution:

1) First, read the github documentation to ensure your SSH keys are set up correctly

2) Then add this to your ~/.ssh/config:

Host github github.com
Hostname github.com
User git
IdentityFile ~/.ssh/github/id_rsa


3) Finally, clone using ssh instead of https:

git clone https://github.com/username/project-name.git # wrong

git clone git@github.com:username/project-name.git # right

4) Push should now work as expected


Good FTP clients

  • WinSCP (Windows)
  • WS FTP LE (Windows)
  • FileZilla (Windows, Linux)
  • FireFTP (Windows, Linux)

Example ssh config

Host [alias]
    HostName [remote hostname]
    User [remote username]
    IdentityFile [file]

[alias] is what you type to select the connection, e.g. ssh [alias]
[file] is your DSA or RSA private key file

SSH on Blackberry

MidpSSH

I want to use SSH on my Blackberry, for example with the program MidpSSH.
I am using a Blackberry 8900 on the Orange UK network.

When I try to connect to a server using MidpSSH, I get the error: "Session error: Writer: Invalid parameter".
Apparently I need to set my APN to fix this. What is an APN? List of APNs

On my device in Options | Advanced Options | TCP/IP there's a tickbox for "APN Settings Enabled".
There I can set APN: orangeinternet But this doesn't help. Tried rebooting.

Perhaps it won't work because:
Orange would have had to setup the normal Orange GPRS APN on your account, ... which they don't do for blackberry users (understandably, we're all meant to use BIS).
(I can also see in Advanced Options | Host Routing Table, all the "Host Routing Information" entries have APN: blackberry.net)


Orange


UPDATE 10/09/10:
I called Orange and spoke to the "online services" team (439). A nice man called Ben (CMTS Darlington) found some instructions on their system for using SSH from a Blackberry. They recommended downloading the client from xk72.com. But then he spoke to the 2nd line support team for me and they said that SSH is "Not supported anymore".
Well, what does that mean? That I won't be able to get an SSH connection? Or that I will be able to get a connection, but they won't give me any help should a problem arise? How do I know if their system is working properly for me to try and make an SSH connection?

Here's an unrelated typical example of poor Orange customer service.

PaderSyncSSH

I tried connecting with PaderSyncSSH free trial from the Blackberry App Store.

When I set the Networking connection type in 'Misc. Settings' to "Direct TCP", and set my APN to orangeinternet, I get the error: Connect failed: Error opening socket. java.io.IOException: Peer refused the connection. (Note: This is the same message as I get when connecting to a server that does not offer SSH).
With Networking connection type 'BES/MD5' I got the error: Connect failed: Error opening socket. java.io.IOException: Invalid URL parameter (that's the same as MidpSSH!)
With Networking connection type 'BIS-B' I got the error: Connect failed: Connect failed. ab: Session.connect: java.io.IOException: BIS-B connection failed. (and a recommendation to try Direct-TCP, or have the server listen on a port above 1024 because some carriers block lower ports).

UPDATE 14/09/10:
After connecting once via wifi, I tried connecting to an SSH server via Orange's GRPS phone data network again, and it worked perfectly. Success! I discovered that sometimes I get the error "Connect failed: Error opening socket. java.io.IOException: Peer refused the connection", but other times it works just fine.




Telnet

I succeeded in making a telnet connection to bbc.co.uk:80 through GPRS and issuing a GET HTTP/1.1 command, which resulted in the HTML text of the BBC homepage.



Wifi

I succeeded in using PaderSyncSSH SSHing to shellmix.com:30 (newuser/newuser) when I connected my BlackBerry to a wifi network. It worked really well! MidpSSH gave the same error (but then it doesn't have a network type selection option like PaderSync does).


Remote file browsing

  • Mount a remote filesystem via SFTP
    • (Mac): http://pqrs.org/macosx/sshfs/
    • (Ubuntu): Use software centre
    • GUI
      • Try http://sshfs-gui.darwinports.com/
      • or Mac ports: sudo port install sshfs-gui
    • To start: sshfs hostname: mountpoint
    • To stop: fusermount -u mountpoint
  • Target Management (Remote file browsing in Eclipse via SSH): http://www.eclipse.org/dsdp/tm/

Eclipse plugins

Eclipse 3.5
      • Target Management (Remote file browsing, via SSH): http://www.eclipse.org/dsdp/tm/
        • works great (but sshfs is simpler)
        • Instead of that, see also http://wills-tech-notes.blogspot.com/2010/07/remote-file-browsing.html
      • XSLT: http://www.eclipse.org/webtools/
        • can't download through update manager, it's too slow
        • supposed to offer XML/XSL features, but I can't see any
      • Oxygen XML/XSLT: http://www.oxygenxml.com/download_oxygenxml_editor.html#Eclipse
        • Works. To use step-through debugging,you need to open the 'Debug Scenario' in the XML or XSL menu (it appears when you open an XML or XSL file)
      • vim -- why not use vim editor inside Eclipse? No good solution, apparently (none of these were tested):
        • http://www.viplugin.com/viplugin/ (2009 - costs a few pounds)
        • http://eclim.org/vim/ (recent)
        • http://vrapper.sourceforge.net/ (recent)
        • http://sourceforge.net/projects/vimplugin/ (2007, but states it supports syntax files)
      • Full Screen: http://code.google.com/p/eclipse-fullscreen/ (just works) 
      • P4WSAD: Perforce plugin: http://www.perforce.com/perforce/products/p4wsad.html (had to download zip file from FTP site and install manually, as automatic install URL was too slow)
        • Plugin can be slow to use if you browse the repository directly, but is faster if you check out, then do right-click | Import as project, and use the standard Eclipse Navigator or Project tab to work with the files.

          Log into a server using secure keys instead of typing a password

          On the client:
          1. ssh-keygen -t rsa
          2. accept the default filename
          3. press enter for a blank password
          4. a private (id_rsa) and public key (id_rsa.pub) will be created
          5. copy the public key to the server
          On the server
          1. cat id_rsa.pub >> ~/.ssh/authorized_keys
          2. chmod 700 ~/.ssh
          3. chmod 644 ~/.ssh/authorized_keys
          Now back up your keys.

          See also this and this.
          (Upon error "Agent admitted failure to sign using the key", log out of the client and log back in again to fix).