Showing posts with label SSH. Show all posts
Showing posts with label SSH. Show all posts

Tuesday, May 24, 2016

越来越慢的网速





The Internet  is slow more!  I don't know why? just someone say: I will change the internet to be better! So many man start to build a great fire wall to block human to freedom. I don't understand why?If they have time, You can make the internet to more fast. Do you know the internet how so slow, Just like the snails moving in the land! I hate this. 

The internet speed is more slow than before! I don't know  how they do ?  I think Good job for you. but for many people I think it is not good!

How could to be better?
How to be faster?
How to be Freedom?



ssh: connect to host IP port 22: Connection refused

一般我们自己买的VPS, 会把端口22 给禁掉,因为他特别容易受到攻击!

但是,我们在用git clone 代码的时候,会出现这种问题

╰─$ git clone hades@IP:/home/hades/kernelCode.git        128 ↵
Cloning into 'kernelCode'...
ssh: connect to host IP port 22: Connection refused
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.


ssh  默认访问 22 端口

所以我们git  clone  set port 

you can do it like this:

git clone ssh://git@IP:port/home/hades/kernelCode.git


Thanks To:







Friday, March 18, 2016

CentOS 6.0 VPS 安全问题

http://www.osyunwei.com/archives/672.html

实现目的:把ssh默认远程连接端口修改为2222
方法如下:

1、编辑防火墙配置:vi /etc/sysconfig/iptables
防火墙增加新端口2222
-A INPUT -m state --state NEW -m tcp -p tcp --dport 2222 -j ACCEPT
======================================================================
# Firewall configuration written by system-config-firewall
# Manual customization of this file is not recommended.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 2222 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
重启防火墙,使配置生效:
/etc/init.d/iptables restart
 service iptables restart
=======================================================================
2、备份ssh端口配置文件
cp /etc/ssh/ssh_config   /etc/ssh/ssh_configbak
cp /etc/ssh/sshd_config  /etc/ssh/sshd_configbak
修改ssh端口为:2222
vi /etc/ssh/sshd_config
在端口#Port 22下面增加Port 2222
vi /etc/ssh/ssh_config
在端口#Port 22下面增加Port 2222
重启:/etc/init.d/sshd restart
          service sshd restart
用2222端口可以正常连接之后,再返回去重复上面的步骤。把22端口禁用了,以后ssh就只能用2222端口连接了!增强了系统的安全性。系统运维  www.osyunwei.com  温馨提醒:qihang01原创内容©版权所有,转载请注明出处及原文链接
=======================================================================
3、禁止root通过ssh远程登录
vi /etc/ssh/sshd_config
找到PermitRootLogin,将后面的yes改为no,把前面的注释#取消,这样root就不能远程登录了!
可以用普通账号登录进去,要用到root的时候使用命令su root 切换到root账户
=======================================================================
4、限制用户的SSH访问
假设我们只要root,user1和user2用户能通过SSH使用系统,向sshd_config配置文件中添加
vi /etc/ssh/sshd_config
AllowUsers root user1  user2
=======================================================================
5、配置空闲超时退出时间间隔
用户可以通过ssh登录到服务器,你可以设置一个空闲超时时间间隔。
打开sshd_config配置文件,设置为如下。
vi /etc/ssh/sshd_config
ClientAliveInterval 600
ClientAliveCountMax 0
上面的例子设置的空闲超时时间间隔是600秒,即10分钟,
过了这个时间后,空闲用户将被自动踢出出去(可以理解为退出登录/注销)。
系统运维  www.osyunwei.com  温馨提醒:qihang01原创内容©版权所有,转载请注明出处及原文链接
=======================================================================
6、限制只有某一个IP才能远程登录服务器
vi /etc/hosts.deny     #在其中加入sshd:ALL
vi /etc/hosts.allow    #在其中进行如下设置:sshd:192.168.1.1     #(只允许192.168.1.1这个IP远程登录服务器)
最后重启ssh服务:/etc/init.d/sshd restart

Thursday, March 3, 2016

Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic


问题终于解决了,感谢  邵思嘉 大神!




问题的根源是权限的问题!
The question is that is user competence too strong!

I use this command:

ssh git@ip

because my git user:
you can see the competence is 777 



How to resolve it ?

chmod 755 git


How to add git to VPS and  avoid  always input password?

1  you should login vps
you can see the link:http://geekhades.blogspot.com/2016/01/how-to-make-up-yourself-git-repo-in.html

ssh root@ip

useradd git

passwd git

git init --bare test.git

cd /home

chmod 777 git  
this lay to the question!


git clone git@IP:/home/git/test.git


2  create ssh key

In your pc

https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys--2


ssh-keygen -t rsa

There is no need input password!

cat ~/.ssh/id_rsa.pub

you should remeber the key in the sublime or file.


After you can login the VPS use git

ssh git@ip          input the password

First:
   mkdir .ssh
   chmod 700 .shh



   cd .ssh
   vi  authorized_keys
   chmod 644  authorized_keys
 


click  i 
input  the  id_rsa.pub key 

click  :wq      
enter  you save authorized_keys


3  Now you ssh login like this:

ssh  -vvv  git@ip

you can see this detail error info in the last  this file  !

debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
debug2: we did not send a packet, disable method
debug3: authmethod_lookup password
debug3: remaining preferred: ,password
debug3: authmethod_is_enabled password

debug1: Next authentication method: password

How to resolve this question?

you find this answer in the start of blog:

you use root login VPS

cd /home
chmod 755 git

---------------------------------------------------------------------------------------

The same Question:
http://stackoverflow.com/questions/25885880/permission-denied-publickey-gssapi-keyex-gssapi-with-mic-in-openshift


Thanks To:
http://superuser.com/questions/814363/ssh-under-os-x-10-6-8-outgoing-permission-denied

https://discussions.apple.com/thread/1759465?start=0&tstart=0

https://www.digitalocean.com/community/questions/i-can-t-ssh-with-root-or-setup-keys-properly

https://bbs.archlinux.org/viewtopic.php?id=182688


======================================================

error info:


$ ssh -vvv git@45.78.17.86

OpenSSH_6.2p2, OSSLShim 0.9.8r 8 Dec 2011
debug1: Reading configuration data /Users/Hades/.ssh/config
debug1: /Users/Hades/.ssh/config line 1: Applying options for 45.78.17.86
debug1: Reading configuration data /etc/ssh_config
debug1: /etc/ssh_config line 20: Applying options for *
debug1: /etc/ssh_config line 102: Applying options for *
debug2: ssh_connect: needpriv 0
debug1: Connecting to 45.78.17.86 [45.78.17.86] port 27417.
debug1: Connection established.
debug3: Incorrect RSA1 identifier
debug3: Could not load "/Users/Hades/.ssh/id_rsa" as a RSA1 public key
debug1: identity file /Users/Hades/.ssh/id_rsa type 1
debug1: identity file /Users/Hades/.ssh/id_rsa-cert type -1
debug3: Incorrect RSA1 identifier
debug3: Could not load "/Users/Hades/.ssh/id_dsa" as a RSA1 public key
debug1: identity file /Users/Hades/.ssh/id_dsa type 2
debug1: identity file /Users/Hades/.ssh/id_dsa-cert type -1
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_6.2
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.3
debug1: match: OpenSSH_5.3 pat OpenSSH_5*
debug2: fd 3 setting O_NONBLOCK
debug3: put_host_port: [45.78.17.86]:27417
debug3: load_hostkeys: loading entries for host "[45.78.17.86]:27417" from file "/Users/Hades/.ssh/known_hosts"
debug3: load_hostkeys: found key type RSA in file /Users/Hades/.ssh/known_hosts:2
debug3: load_hostkeys: loaded 1 keys
debug3: order_hostkeyalgs: prefer hostkeyalgs: ssh-rsa-cert-v01@openssh.com,ssh-rsa-cert-v00@openssh.com,ssh-rsa
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
debug2: kex_parse_kexinit: ssh-rsa-cert-v01@openssh.com,ssh-rsa-cert-v00@openssh.com,ssh-rsa,ssh-dss-cert-v01@openssh.com,ssh-dss-cert-v00@openssh.com,ssh-dss
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se
debug2: kex_parse_kexinit: hmac-md5-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-md5,hmac-sha1,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: hmac-md5-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-md5,hmac-sha1,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib
debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit: first_kex_follows 0
debug2: kex_parse_kexinit: reserved 0
debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se
debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: none,zlib@openssh.com
debug2: kex_parse_kexinit: none,zlib@openssh.com
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit: first_kex_follows 0
debug2: kex_parse_kexinit: reserved 0
debug2: mac_setup: found hmac-md5
debug1: kex: server->client aes128-ctr hmac-md5 none
debug2: mac_setup: found hmac-md5
debug1: kex: client->server aes128-ctr hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug2: dh_gen_key: priv key bits set: 127/256
debug2: bits set: 528/1024
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Server host key: RSA b0:c0:08:49:21:7a:f3:99:a4:96:94:7c:1f:4b:05:89
debug3: put_host_port: [45.78.17.86]:27417
debug3: put_host_port: [45.78.17.86]:27417
debug3: load_hostkeys: loading entries for host "[45.78.17.86]:27417" from file "/Users/Hades/.ssh/known_hosts"
debug3: load_hostkeys: found key type RSA in file /Users/Hades/.ssh/known_hosts:2
debug3: load_hostkeys: loaded 1 keys
debug3: load_hostkeys: loading entries for host "[45.78.17.86]:27417" from file "/Users/Hades/.ssh/known_hosts"
debug3: load_hostkeys: found key type RSA in file /Users/Hades/.ssh/known_hosts:2
debug3: load_hostkeys: loaded 1 keys
debug1: Host '[45.78.17.86]:27417' is known and matches the RSA host key.
debug1: Found key in /Users/Hades/.ssh/known_hosts:2
debug2: bits set: 522/1024
debug1: ssh_rsa_verify: signature correct
debug2: kex_derive_keys
debug2: set_newkeys: mode 1
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug2: set_newkeys: mode 0
debug1: SSH2_MSG_NEWKEYS received
debug1: Roaming not allowed by server
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug2: key: /Users/Hades/.ssh/id_rsa (0x7ff7a3415a20),
debug2: key: /Users/Hades/.ssh/id_dsa (0x7ff7a3500160),
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
debug3: start over, passed a different list publickey,gssapi-keyex,gssapi-with-mic,password
debug3: preferred publickey,keyboard-interactive,password
debug3: authmethod_lookup publickey
debug3: remaining preferred: keyboard-interactive,password
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug1: Offering RSA public key: /Users/Hades/.ssh/id_rsa
debug3: send_pubkey_test
debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
debug1: Offering DSA public key: /Users/Hades/.ssh/id_dsa
debug3: send_pubkey_test
debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password
debug2: we did not send a packet, disable method
debug3: authmethod_lookup password
debug3: remaining preferred: ,password
debug3: authmethod_is_enabled password

debug1: Next authentication method: password




Tuesday, December 15, 2015

Mac SSH 快速登录VPS?

如何使用SSH快速的登录你的 远程的服务器呢?

下面我们一一解答:
Mac  下有一个好用的工具 Iterm2

我们来配置一下如何快速的登录VPS:

1  shell 脚本
#!/usr/bin/expect -f
set username YourUserName    // 设置用户名
set host ***.***.***.***     // 设置主机IP
set password YourPassword    // 设置密码
set time -1                  // 设置永不超时

spawn ssh $username@$host    // 启动一个新进程
expect "*assword:*"          // 进程返回带有assword:字符时
send "$password\r"           // 向进程输入前面设置的密码
interact                     // 允许用户交互

expect eof                   // 结束


注意,你在复制的时候需要将注释全部删掉 如下:
#!/usr/bin/expect -f
set username YourUserName    
set host ***.***.***.***     
set password YourPassword    
set time -1                  

spawn ssh $username@$host    
expect "*assword:*"          
send "$password\r"           
interact                     
expect eof                   


我们定义一个名字 login

然后你随便制定一个目录:


2  配置Iterm2

command + o  (不是0) 出现快捷方式



点击框住的按钮Edit Profiles...,会出现下面的图,点击左下角的加号新建一个Profile,设置快捷键执行刚写好的脚本:





注意: Shortcurt Key 可以设置自己的快捷键, 我设置的是  Control + Command + B  



让我们一起来看看 我们配置是否成功了吗?

打开iterm  按下快捷键



Ok  success!

================================================
如果不成功的话:
1  请看一下 自己的文件中的单词拼写是不是出错了!

2  看一下在iterm中 指定的路径和文件名是不是 拼写错误





参考链接:
1  http://xuquan.me/blog/Mac-iTerm-configuration.html




Sunday, December 13, 2015

Mac how to use Iterm to connect the VPS ?

mac 通过 终端 ssh 远程连接 centos 服务器
在终端下输入
ssh -l root 204.74.*.*      就可以连接了,这是端口没变的情况,还是原来的22


ssh -p 448(你改变的端口) -l root(连接用户名) 204.74.*.*      这个是端口改变后的连接


======================================
Mac-4a0002833f10:~ Hades$ ssh -p 27417 -l root  45.78.17.86
root@45.78.17.86's password: