-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathsshpass_proxy.go
More file actions
57 lines (54 loc) · 2.25 KB
/
sshpass_proxy.go
File metadata and controls
57 lines (54 loc) · 2.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
package sshpass_proxy
import (
"fmt"
"net"
"github.com/rectcircle/sshpass_proxy/crypto/ssh"
)
// SSHPassProxy 功能类似于 sshpass,但是原理完全不同。
//
// SSHPassProxy 通过一个 ssh 传输层协议 proxy,实现 openssh 的客户端,可以对使用密码鉴权的 ssh server 实现免密登录。
//
// SSHPassProxy
// +--------+ +------------------------------------------------------------------------------+ +--------+
// | client | ---> (clientConn) ssh transport server <--- Packet Copy ---> ssh transport client (serverConn) ---> | server |
// +--------+ +------------------------------------------------------------------------------+ +--------+
func SSHPassProxy(
clientConn, serverConn net.Conn,
proxyServerHostPrivateKey ssh.Signer,
serverAddr, serverPassword string,
) error {
// 1. 使用 ssh server 对接来 client 连接,完成握手和免密鉴权,并获取到 ssh 传输层协议对象。
proxyServerConfig := &ssh.ServerConfig{
NoClientAuth: true,
}
proxyServerConfig.AddHostKey(proxyServerHostPrivateKey)
proxyServerTransport, err := ssh.NewServerTrickTransport(clientConn, proxyServerConfig)
if err != nil {
return fmt.Errorf("failed handshake and authenticate with sshpass proxy server: %v", err)
}
serverUser := proxyServerTransport.User()
// 2. 使用 ssh client 对接 server 连接,完成握手和密码鉴权,并获取到 ssh 传输层协议对象。
proxyClientConfig := &ssh.ClientConfig{
User: serverUser,
Auth: []ssh.AuthMethod{
ssh.Password(serverPassword),
},
HostKeyCallback: func(hostname string, remote net.Addr, key ssh.PublicKey) error { return nil },
}
proxyClientTransport, err := ssh.NewClientTrickTransport(serverConn, serverAddr, proxyClientConfig)
if err != nil {
return fmt.Errorf("failed handshake and authenticate with target server: %v", err)
}
// 转发
errc := make(chan error, 1)
go func() {
errc <- ssh.TrickTransportPacketCopy(proxyServerTransport, proxyClientTransport)
}()
go func() {
errc <- ssh.TrickTransportPacketCopy(proxyClientTransport, proxyServerTransport)
}()
if err = <-errc; err != nil && !ssh.ErrIsDisconnectedByUser(err) {
return err
}
return nil
}