9 ms·
SSH for Fun and Profit
- dexterdog 10y agoI really like stories like this where somebody was overly curious about something and instead of just reading about it, he takes it apart and puts it back together to gain the kind of knowledge you will never find in a book/blog post.
- vog 10y ago> takes it apart and puts it back together to gain the kind of knowledge you will never find in a book/blog post. Interestingly, the author still worked a lot with the docs (RFCs), not just with the software itself. I believe this is important for any hands-on activity. Even though the documentation isn't your starting point, and may be too cumbersome and badly structured, sooner or later you should go back to them, now with more specific questions, picking out what you need.
- pavel_lishin 10y agoI thought it was fairly discouraging that the docs weren't sufficient to get the author up and running with ssh; a lot of seemingly undocumented gotchas popped up.
- dexterdog 10y agoYeah, I would hope with a tool as critical as ssh the docs would be pretty good. Hopefully the author will contribute and it will get accepted.
- aaachilless 10y agoauthor is a woman. edit: I guess, depending on how one reads your post, you didn't actually say author is a "he". Too quick on the trigger on my part.
- zer0defex 10y agopssst... your gender bias is showing, put that shit away.
- RapLyricsFTW 10y agoHe clearly missed typing a s only. Take away your bias please.
- woodman 10y agoDoes HN not have a an explicit list of all actions that are unacceptable?! We need to get the TODO Group in on this. Also, so that everybody knows that my opinion is more valid, I am a 1/32 Cherokee left handed 87 year old black woman. On a related note, I demand that you implement trigger warning flag function.
- tomlock 10y agoIts so weird that there aren't more women in tech. Amirite? What could possibly be driving them away?!?!
- woodman 10y agoThere aren't enough white knights rushing in to save us, and we aren't being treated as equals. Another problem is the cultural racism of future time orientation and emphasizing individualism as opposed to a more collective ideology.
- ams6110 10y agoAuthor never did say whether the Logjam vulnerability was present.
- spydum 10y agoInfoSec folks dont make vulnerability data public usually..
- nxzero 10y agoDid you read the link she provided? https://weakdh.org https://weakdh.org
- ams6110 10y agoNo. I assumed since it was prominently mentioned in the opening of the piece, it would be addressed before the conclusion. Sort of the Chekov's Gun principle. https://en.wikipedia.org/wiki/Chekhov's_gun https://en.wikipedia.org/wiki/Chekhov's_gun
- lucb1e 10y agoMeta: the grey text thing which seems to be really popular right now? That's just unreadable. Third time today I inspect-elemented a blog post to turn the text coloring off. Edit: Finished reading, what a great project! I've looked for something like this before, but ssh documentation never quite contained what I was looking for, let alone providing a simple client to hack with. Many code snippets look a lot easier than I would expect it to be (e.g. DH KEX looks very simple there), though of course finding out what the correct code is, even if it's brief, takes a lot of effort. Great writeup and thanks for sharing!
- nxzero 10y agoYou know about "reader mode", right? http://www.howtogeek.com/228104/how-to-make-the-mobile-web-more-readable-and-the-desktop-web-too/ http://www.howtogeek.com/228104/how-to-make-the-mobile-web-m...
- cyphar 10y agoIt's very odd to have to depend on a browser feature that is basically for accessibility in order to read a website because the colour choices are bad.
- nxzero 10y agoIt's weird to me that people want millions of random people controlling how content is visually presented; aka, wish the web would die already.
- cyphar 10y agoYou can cry creative freedom all you want, the colour choices make it hard for certain people (with visual difficulties) to read the site. Not accepting that and improving the design is basically saying "my creative freedom is more important than people actually reading the website".
- nitrogen 10y ago
- kpcyrd 10y agoI really enjoyed reading this, you should add an rss feed to your blog, I couldn't find anything to subscribe to.
- tetrakai 10y agoThanks! I'll try to add one later this week, I've been meaning to :)
- vog 10y agoThat would be really great! It's always a pity when this happens: - I read a great article. - I have a look at the rest of the blog, seeing more interesting articles. - I see that the posting frequency is low. [1] - I want to add it to my QuiteRSS reader, but there is no Atom/RSS feed. [1] Which is actually a very good sign! Daily posters are inevitably posting mostly crap, and I'm too tired of such blogs to pick out the cherries. I prefer authors who publish only their cherries in the first place, or at least provide a "cherry-only" feed.
- atdt 10y agoThere are several services out there that will create an RSS feed out of any web page. They do this by periodically scraping the page's contents for you. https://feedity.com/ https://feedity.com/ is pretty good; there are others.
- autotune 10y ago>“none” as my compression algorithm. Next blog post idea: taking apart how zlib works (https://tools.ietf.org/html/rfc1950 https://tools.ietf.org/html/rfc1950) and using that as a built-in compression algorithm. Seriously though great article.
- idiot900 10y agoAnother way to help discover how SSH works is to compile your own openssh server, instrumenting it with your own printfs, and see exactly what it's doing. I did this at one point, and it helped immensely to write a (horrifyingly insecure) homegrown SSH client. It was at least a good learning experience.
- vog 10y agoThe actual code on GitHub: https://github.com/tetrakai/miscellaneous/tree/master/ssh_client https://github.com/tetrakai/miscellaneous/tree/master/ssh_cl... Unfortunately, that was somewhat hidden in a small "here" link near the end of the article. By the way, I believe to would be preferable to have a separate Git repository for that, rather than putting all mini projects ("miscellaneous code snippets") into a single repository.
- michaelvillar 10y agoIt'd be nice to be gender neutral :)
- rdslw 10y agoReally? While talking in a context of a specific post, written by a male?
- x3ro 10y agoYes, because the comment refers to "stories like these", and not only the specific story in question. Also, what makes you think the author is male?
- Mndrain 10y agoNot to presume which gender OP identifies with, but if you take a look at their GitHub profile, you'd probably come to the conclusion the the writer is not male. Since the specific context matters to you, would you now suggest the parent of this thread then change the pronoun to "she" instead?
- rdslw 10y agoI've misread (english is not my native language) post with ", he takes it apart..." as a fact about author gender and reacted to subsequent comment which I find wrong. Answering your question: would he, or me, or other poster know the gender of author while writting about author -> we should use proper form. If no prior knowledge is present: it does not matter to me, and I consider it not worth mentioning or correcting.
- beardog 10y agowho cares?
- x3ro 10y agoMany do. The author probably does, because it doesn't seem like they'd choose "he" as their pronoun.
- opk 10y agoIt's interesting that "The transport protocol doesn’t cover who sends their banner first". It'd be good if I could configure my server to keep quiet until the client identifies itself as an SSH client. I run it on an unusual port and it gets scanned frequently. sshguard helps but I'd prefer it wasn't announcing to any client that it is an ssh server.
- DDub 10y agoSslh would give you this ability, if you're prepared to shim an extra program infront of your daemon; http://www.rutschle.net/tech/sslh.shtml http://www.rutschle.net/tech/sslh.shtml
- tokenizerrr 10y agoHow does sshguard compare to fail2ban?
- opk 10y agoI never used fail2ban: sshguard was simply what I came across first and it was easy to setup and worked as advertised. The Arch wiki states: "sshguard is different from the other two in that it is written in C, is lighter and simpler to use with fewer features while performing its core function equally well."
- rsync 10y ago"It'd be good if I could configure my server to keep quiet until the client identifies itself as an SSH client. I run it on an unusual port and it gets scanned frequently." This is unpopular, but you could implement port knocking. Now the rest of the world doesn't even see your sshd - on any port. I love the idea and have implemented it everywhere that it's practical.
- bartvk 10y agosshguard is amazing, I routinely install it on any new servers. It comes with the standard Debian and derivatives' repositories. After installation, simply type: $ sudo apt-get -y install sshguard And then edit the whitelist to include your local IP if you want; $ sudo vim /etc/sshguard/whitelist $ sudo service sshguard restart
- m0d3m 10y ago"This was a problem, because my initial packets to the server were met with immediate disconnects, and I’d now lost my main means of debugging. I banged my head against the wall for a while, then at the suggestion of a friend, decided to turn the server’s OpenSSH log verbosity way up. I bumped the LogLevel in /etc/ssh/sshd_config to DEBUG3, and suddenly I was getting helpful error messages!" ssh server can be run with -d option for monitoring. It redirects debug messages to stdout. /usr/sbin/sshd -d
- jbaviat 10y agoNice. What first revealed me the hidden complexity of SSH was typing this during a live SSH session: ~? Which show you the SSH supported escape sequences.
- jjnoakes 10y agoNote that the actual sequence is 3 characters (newline, tilde, question mark). If you try ~? after anything except a newline, ssh won't intercept it (this is true for all ssh tilde escapes). Telnet had something similar.
- arantius 10y agoThis is of course specifically how to reveal these features in the OpenSSH client. If you're using another client (e.g. PuTTY) there's a different way to get to these features (click the menu).
- jwilk 10y agoBut where's the "profit" part?
- AlexCoventry 10y agoHireability
- curiousgal 10y agoWell what are the odds of this young lady not being one of them "oh the Tech industry/culture is not welcoming towards women" women? See the difference?
- alexellisuk 10y agoI liked reading the code for this - added a Star too. * Picking some RFCs and then writing a client/server is fun as a coding exercise. * I had a go at implementing POP3 and HTTP years ago in a MUD / LPC, but HTTP has been done to death now. * Documentation is also really really good and I like the self-describing code, but have you thought about adding any unit tests i.e. for the algorithms?