7 ms·
SSH Secret Menu
https://xcancel.com/rebane2001/status/2031037389347406054 https://xcancel.com/rebane2001/status/2031037389347406054
- blueflow 7mo agoAs secret as the ssh manual.
- bigstrat2003 7mo ago"secret" not in the sense that it's hidden, but that most people won't know about it. Because approximately nobody actually reads man pages in their entirety, they just get in to find out how a specific flag works and then get out.
- bell-cot 7mo agoUsing "secret" in that sense instantly reminds me of hyped-up headlines for time-waster news stories. Most people don't know what 2^8 is, either.
- rebane2001 7mo agothe difference is that knowing 2^8 is generally not useful to people who don't know it this here is something that's pretty useful to most ssh users, yet seldom spoken of a better analogy would be comparing it to calling a very good, but not well-known restaurant a secret place - using the word to mean a hidden gem rather than an intentionally hidden secret
- 0xbadcafebee 7mo agoFind the HIDDEN SECRETS that THEY DON'T WANT YOU TO KNOW! $ man ssh
- saguntum 7mo agoman ssh_config is even more interesting and hidden ProxyCommand is fun
- project2501a 7mo agoHonest question, why is ProxyCommand `fun`? What do I get out of ProxyCommand that i do not get out of setting the correct order for ProxyJump and doing an ssh finalhost -- domy --bidding?
- pmontra 7mo agoProxyJump is a newer functionality. There used to be only ProxyCommand. ProxyJump is a shortcut for the usual way to use ProxyCommand to connect through a bastion host but ProxyCommand is more flexible. For example with ProxyCommand you can run any command to connect to the remote host. ProxyJump only connects over ssh. I think I replaced all my ProxyCommand with ProxyJump because I don't need much else than the normal use case.
- pritambaral 7mo agoProxyCommand allows you to use any command to setup a connection. Not necessarily an ssh command, like ProxyJump. It can be any command, as long as it receives on stdin and produces on stdout, it can act like a TCP connection. ProxyJump is a special case of `ProxyCommand ssh -p <port> <user>@<host>`. Can't replace the `ssh` in there when using ProxyJump.
- brigandish 7mo agoI use ProxyCommand to run spipe tunnels for SSH.
- m132 7mo agoYou can get a lot more out of ProxyCommand. For example, you can run SSH over non-IP protocols, such as serial, Bluetooth RFCOMM for embedded boards, or vsock for virtual machines without networking set up at all. The latter is built into and setup up automatically by systemd: https://www.freedesktop.org/software/systemd/man/257/systemd-ssh-proxy.html https://www.freedesktop.org/software/systemd/man/257/systemd...
- pram 7mo agoYep the menu is handy for ssh tunneling. Maybe not a lot of people doing that these days though with stuff like dev tunnels and Tailscale.
- MayeulC 7mo agoI typically just create a "new" connection in a separate tab when I want to add tunneling. I put new in quotes because I use another little-known feature, "ControlMaster". Multiplexes multiple connections into one, it makes making " new" sessions instant (can also be configured to persist a bit after disconnecting). Also useful for tab-completing remote paths. It does not prompt for authentication again, though. And it's a bit annoying when the connection hands (can be solved with ssh -o close, IIRC).
- nyanchovy 7mo agoTIL; thanks, that's interesting (and somehow escaped my 20+ years of using ssh)! As usual the gold is in the comments :-)
- ghrl 7mo agoI'm using that as well but had issues with tunneling where it creates the tunnel in the background and terminates and so you might not know the random port it assigned or I couldn't figure out how to un-tunnel it and tunnel again to the same port. Just bypassed the control master then.
- NitpickLawyer 7mo ago> I use another little-known feature, "ControlMaster". Multiplexes multiple connections into one, it makes making " new" sessions instant Is this what secureCRT used as well? I remember this being all the rage back when I used windows, and it allowed this spawn new session by reusing the main one.
- qudat 7mo agoI use it all the time with https://tuns.sh https://tuns.sh that let's you expose localhost to the public.
- piccirello 7mo agoI've been using SSH for ~15 years and never knew about these escape sequences. I'm eagerly awaiting my next hung session so that I can test `~.`. It's much nicer than my current approach of having to close that terminal window.
- shmerl 7mo agoI've been using ~. on hung ssh connections for a while.
- wolvoleo 7mo agoI use that every day but it's the only one I know by heart lol
- lathiat 7mo agoHave been using that weekly since probably 20 years. Will change your life :) My other favourite is I very often SSH with -v to figure out why the connection is hanging, you rapidly figure out if DNS is failing, the TCP connection doesn't open, it does open but no traffic flows at all or it opens and SSH negotiation starts but never finishes. You can learn a lot just from this about what is wrong.
- Izkata 7mo agoAlso helps with auth failures, I've used it several times with co-workers who can't figure out why their ssh key isn't working. It lists the keys out and some extra information.
- syncsynchalt 7mo agoAnd of course, you can use the ~v / ~V commands (as listed in the ~? menu) to increase/decrease verbosity after the connection is established. That lets you `ssh -vvvv` to a host then once you've figured out the issue use ~V to decrease verbosity so that debug messages don't clutter your shell.
- sirfz 7mo agoYou can even chain them if you have deep ssh connections (i.e. ssh from one instance to another). I think it would be ~~. to terminate the 2nd hop. Edit: it's already explained in the OP
- _kst_ 7mo agoThat doesn't do much good if you set `EscapeChar` to `none` in `.ssh/config`. I find it convenient not to have to worry about accidentally entering escape characters. YMMV.
- MayeulC 7mo agoNote that it only works after pressing enter, so the odds are slim. In practice, I don't think I ever hit it by accident.
- greyface- 7mo agoI have noticed it while running ~/bin/some_command. The ~ doesn't echo until I also type the /. It doesn't cause any misbehavior because there is no binding for ~/ but can be slightly surprising.
- singlow 7mo agoI find it odd that you would have commands in ~/bin but not have it be the highest priority in your PATH. I use ~/.local/bin, but would never type it because i wouldn't have bins that overlap shell commands and no other path would have priority.
- greyface- 7mo agoUsually, it is. IIRC, this was when I was just setting up my environment on a new host, after I had populated ~/bin but before I restarted my shell to pick up PATH modifications.
- wolvoleo 7mo agoSSH does it pretty well though. Never once have I done it by mistake.
- jasomill 7mo agoI'd guess this is because it only works in ssh PTY sessions. So it would have no effect on tunneling or when piping arbitrary data through ssh to a non-interactive remote command (unless you use the -t switch to force PTY allocation even when stdin is not a TTY).
- juancn 7mo agoIt's like Ctrl + ] on telnet. The good old times!
- elric 7mo agoUnlike CTRL ], at least ~. doesn't require that I press two modifiers at the same time ... CTRL ALTGR $. Because people who define those kinds of shortcuts never consider how they might work on non-QWERTY layouts.
- Lasang 7mo agoHidden or undocumented features like this always have a strange appeal. Part of it is nostalgia for older software where small Easter eggs or experimental features would sometimes ship in production builds.
- alwillis 7mo agoIt's not hidden or undocumented; it's in the man page. Here's 15-year old HN link about it: http://grack.com/blog/2011/02/23/ssh-escape-sequences-or-dont-kill-9-that-process/ http://grack.com/blog/2011/02/23/ssh-escape-sequences-or-don...
- cestith 7mo agoHere’s a link to the man page for people who want to read man pages in a browser. https://linux.die.net/man/1/ssh https://linux.die.net/man/1/ssh https://die.net https://die.net and https://ss64.com https://ss64.com are sites I’ve been recommending for years.
- joecool1029 7mo agoFYI, you can kill forwarding tunnels with -KD portnum in that commandline too.
- vzaliva 7mo agoI've used ~. for a long time but did not know about others. I know, should have read man page. Anyway, if you try it from shell prompt it is likely will not work as pressing ENTER shows the next prompt. Try `cat` followed by ENTER and then ~?
- BenjiWiebe 7mo agoIt'll still work. OpenSSH doesn't care about output (for ~ stuff), only input, so if you type <enter>~. it will close the connection.
- vzaliva 7mo agoIt does not. open ssh linux to mac, typing ~ just types it on fish shell prompt. It works after`cat` followed by ENTER
- ploxiln 7mo agoJust type <enter> without cat, your shell will show you another prompt, and the ssh escape command will also work.
- gear54rus 7mo agoNo they are correct, fish seems to intercept this or something like that. Only works with cat.
- BenjiWiebe 7mo agoSo you're saying 'fish' intercepts it on the far end? The ssh server on the far end shouldn't be sending it to 'fish' until it knows what's coming next. Is this a current-ish version of OpenSSH or some other client/server? EDIT Interesting! I tested it with fish and it does indeed intercept it! Wonder how that works.
- dnet 7mo agoIn newer versions, it's disabled by default and you have to do something like this to enable in ~/.ssh/config: Host * EnableEscapeCommandline yes
- nirui 7mo agoSecret Menu -> Escape Characters I really hate it when people just rename terms. It made it harder to search properly for better answers.
- wrs 7mo agoThose aren’t “secret”, they’re obviously borrowed from rsh — oh that’s right, I’m old.
- aidenn0 7mo agoAnd these days you need to pass "-O" to scp to have it behave like rcp.
- aa-jv 7mo agoLaughs in uucp!bangpath.
- jervant 7mo agoI'm pretty sure the ~ command style came from cu(1) which had it in at least 4.1BSD. I don't think rsh (which came in 4.2BSD) ever had such commands.
- wrs 7mo agoWhoops -- I meant rlogin. That had ~. and ~^Z. But you're right, rlogin got them from cu! (I'm not that old. :) )
- olalonde 7mo agoWow, never knew this... That said I'm not sure if I'll remember using it as my muscle memory is already trained to kill hung processes via ctrl-b s, ctrl-k, ctrl-b x (in tmux).
- antisol 7mo agoYeah I discovered ~? a while back and had similar concerns, so I added: alias ssh="echo 'dont forget: ~? for SSH escapes!'; /usr/bin/ssh " into my .bashrc
- andrewflnr 7mo agoI've been using the ~. shortcut for a while, but somehow escaped learning about the help menu. Another neat thing I noticed while playing with it just now: there's an option to enter ~ twice to send a literal ~, but usually you don't have to do this when typing something like 'ls ~' in a regular session. Not only does the ~ have to be the first character on a line to start an escape sequence, but typing on a line, backspacing all the way to the start and then typing ~ also sends a literal tilde. It only triggers the escape sequence if the ~ is the chronologically first character after a newline (or first in the session), which is an unlikely thing to type into a shell in a normal session. Good choice of UI, both the character and the state machine.
- computerfriend 7mo agoThe drawback is that if you think your session is hanging and want to bail with ~., you have to press enter, which might actually make it to the server and execute something.
- bandie91 7mo agomany get used to Ctrl-U, Return, ~, period keystroke sequence for this.
- aragilar 7mo agoFor those of us in today's 10000, Ctrl-U is the default readline shortcut for unix-line-discard (see https://www.gnu.org/software/bash/manual/html_node/Commands-For-Killing.html#index-unix_002dline_002ddiscard-_0028C_002du_0029 https://www.gnu.org/software/bash/manual/html_node/Commands-... and https://susam.net/unix-line-discard.html https://susam.net/unix-line-discard.html).
- bandie91 7mo ago> typing on a line, backspacing all the way to the start and then typing ~ also sends a literal tilde for the younger readers, yes, because in terminal echo mode, "backspacing" does not clear your terminal line buffer, those characters backspaced are already sent on the line. if you ever seen a misconfigured terminal, it hints what's going on, like: user@host$ ls ~/^?^?^?^?^?~/a.out ^? is backspace's control char. that is ssh watches what you type, not what is on the screen (terminal).
- dennis-tra 7mo agohttps://xkcd.com/1053/ https://xkcd.com/1053/
- fay_ 7mo ago[dead]
- utopiah 7mo agoMy gosh... I've spent decades closing a connection by killing the terminal. ~.
- xnf 7mo agoSometimes things feel so simple that i dont even read the manual. cool
- codesnik 7mo agoit starts with a pretty common char, but almost never gets in the way to the point I forget it exists. Meanwhile docker -t uses ^P which I use all the time for history instead of arrow keys. It's possible to configure it, but it's not worth the hassle on servers. Really, really annoying.
- languagehacker 7mo agoBRB requesting access to my remote server "animal style"
- nticompass 7mo agoI've had to use [Enter] ~. in SSH sessions before. I've had SSH/network get stuck and using that was the only way to kill the session (and recover). I guess you could call it a "secret" or at least "not super-well known (to people who aren't Linux 'experts')."
- devnotes77 7mo ago[flagged]
- etrvic 7mo agoLlm generated comment? Am I going crazy?
- efilife 7mo agoYou are not crazy. This account's comments are all LLM generated. ALMOST believable
- devnotes77 7mo ago[flagged]
- spurgelaurels 7mo agoThis is a secret? I've had this baked into my muscle memory for decades when an SSH session hangs.
- antonyh 7mo agoWhat I thought I wanted: a way for Konsole to send SIGHUP What I now have: ~B What I really need: a way to stop long-running SSH connections from freezing
- billfor 7mo agoThis is not specific to ssh. Telnet and rlogin have similar things with ~ as the escape character. Back in the day it was common to send BREAK and other escape sequences when you were hardwired.
- fcloud 7mo agoI intended to post in defense of manpages. I love manpages. I think most open-source manpages are high-quality, and a few are really outstanding. "It's easier to ask an AI" can be true without implying that manpages are bad. However, "man" the tool does have issues, and one of them bit me just now. So, I didn't know about openssh client escapes like ~?. I thought, "surely that's in the manpage?" I opened the manpage (in less) and searched for "\~\?". No hits. Of course, escape characters are documented in the manpage, and the string "~?" does appear. Why didn't search find it? Because man, in its infinite wisdom, decided to render every instance of "~" as some bizarre unicode not-tilde, which is visually similar but totally impossible to grep for. This has also bitten me in the past with dash. DASH. A character that is critically important when documenting invocation options. man loves to convert it into something that looks like dash, prints like dash, but doesn't come up in search. I'm sure there is a way to turn this "feature" off, and I'm about to spend a bunch of time figuring out what it is. But this is documentation for command-line tools. Silently destroying our ability to grep it should NOT be the default.
- arccy 7mo agowith neovim as the pager for man, it does find ~? though you have to be aware of the escapes for regex, so \~?
- layer8 7mo agoWorks for me on Debian (with the default pager, less).
- b112 7mo agoThere was more, then less, but once upon a time there was 'most'. I miss most.
- whydoyoucare 7mo ago\~\? works on macOS, as well as CentOS.
- fcloud 7mo agoThanks for the suggestions. Invoking man with "-E ascii" fixed this for me. It sounds like some distributions do have this fixed in their default settings. I'm on Cygwin 3.6.6; maybe it's mostly a Cygwin thing.
- jeffrallen 7mo agoYou think that one is cool, go check out "~?" in IPMI "sol activate". From there you can deliver a serial break to the kernel, which then gets you to a third rarely seen menu from the kernel's console, which allows you to do kernel debugging of various sorts. I use it when I need to crash a kernel on purpose to test kdump over the network. You can also send commands to the simulated console of a VM under libvirt with "virsh connect". But I don't think you can send a break to the kernel with that.
- tyilo 7mo agoI have set up Ctrl+k to kill (SIGKILL) the front process in my terminal. I just use that for hanging connections and other hanging processes.
- spwa4 7mo agoDon't tell people this. In a minute you'll realize that this menu can only mean that ssh runs multiple channels, and so you can start up other things over an established ssh connection. Then the firewall guys will realize that they really can't allow ssh ... let's just not go there. Working at a bank is annoying enough already.
- antisol 7mo agoWhen your firewall guys "block" ssh (or anything else), all you need to do is run your ssh server on port 443 and then `ssh -p 443 user@host`. Running on 443 means it will blend in with https traffic, making it much more difficult for them to detect and block (I've never actually seen anywhere that can detect/block it - you'd need to be doing deep packet inspection on encrypted traffic) :)
- atannen 7mo agoThe ~ (tilde) escape character in UNIX cu (call UNIX) did the same thing in the 1970s, when the remote system was on the other side of a telephone modem or other serial port. I think it's safe to say that ssh is a descendant of cu. (I don't mean that cu printed a help menu, I mean it had the tilde escape.)
- Kim_Bruning 7mo agoconsider me one of the lucky 10000 . Used ssh for years, didn't know this! https://xkcd.com/1053/ https://xkcd.com/1053/
- 3abiton 7mo ago`ssh -D 1234` to open up SOCKS in the server. This is also flew over my head. I think the gzip one is the most surprising tbh.
- Kim_Bruning 7mo agoI use that one a lot! It is extremely useful for accessing web-interfaces on switches and firewalls and other devices on a remote network.
- wojciii 7mo agoThis might be a good place to mention: https://linux.die.net/man/1/autossh https://linux.die.net/man/1/autossh
- ThePowerOfFuet 7mo agohttps://infosec.exchange/@rebane2001/116200045748516097 https://infosec.exchange/@rebane2001/116200045748516097