ãªã¢ã¼ãã®éããããç°å¢ã®ãµã¼ãã«ã¢ã¯ã»ã¹ããã
web applicationãªã©ãä½æãã¦ããã¨ããå
¬éåã®æ®µéã§ããã«ããããããwebãã©ã¦ã¶ãªã©ã§ã¢ã¯ã»ã¹ãã¦
å®éã®åä½ããã§ãã¯ãããã¨ãããã¨ãããããããªæã«ãã³ãã«ãæã£ã¦ä½æ¥ããã
ã¡ãã£ã¨èª¿ã¹ãããã¦æéãããã£ãããã¦ãã¾ã£ãã®ã§ã¡ã¢ã
ã ãããã²ã¤ãããªä½æ¥
大ä½å¿ è¦ãªä½æ¥ã¯ä»¥ä¸ã®ã¨ãã
- sshã§login(éµã®è¨å®)
- ã¢ã¯ã»ã¹ã§ããã確èªã³ãã³ãã©ã¤ã³
- ãã©ã¦ã¶ã®è¨å®
sshã§login
sshã§loginããããåãéµãæã¡åãæssh-agentã使ã£ã¦ãè¯ãã
ã¾ãã以ä¸ã®ãããªè¨å®ãã¡ã¤ã«ããããã³ãã«ãæã£ã¦ãè¯ãã
対象ã¨ãããããã¯ã¼ã¯
[local] --> [humidai] ---> [target.app]
humidaiã¯å¤é¨ã¸å
¬éããã¦ãã¦ãlocal(èªå)ããsshã§ã¢ã¯ã»ã¹ãããã¨ã¯å¯è½ã
ããã§ãsshã§ãã³ãã«ãæã£ã¦ç´æ¥target.appã«ã¤ãªããããããã«ãã¦ã¿ãã*1
HOST target.app.net user podhmo HostName ap2 ProxyCommand ssh [email protected] -W %h:%p IdentityFile ~/.ssh/id_rsa_your_key HOST humidai.net User podhmo IdentityFile ~/.ssh/id_rsa_your_key
ProxyCommandã¯ãsshã§ãã°ã¤ã³ãããã¨ããéã«éã§å®è¡ãããã³ãã³ãã%h,%pã«ã¯ãã¹ãåã¨ãã¼ãçªå·ãå ¥ãã
Dynamic forwarding
sshã«ã¯dynamic forwardingã®æ©è½ããããããã使ãã¨ç°¡åã«socksãµã¼ãã¨ãã¦åä½ããããã«ãªãã
ããã使ã£ã¦ãä¸å³ã®target.appã®ãããªå¤é¨ããéããç°å¢ã¸ãã©ã¦ã¶ã§ã¢ã¯ã»ã¹ããã¨ãã£ããã¨ãã§ããããã«ãªãã
ã¢ã¯ã»ã¹ã§ããã確èªã³ãã³ãã©ã¤ã³
å®éã«ãã°ã¤ã³ã§ãããã©ãããã sshã§ã¢ã¯ã»ã¹ãã¦ã¿ãã
ssh [email protected]
ããã§ãã°ã¤ã³ã§ããªãã£ããè¨å®ãè¦ç´ãã(-v)ã¨ãã¤ãã¦å®è¡ãã¦ã¿ãã¨ã¨ã©ã¼ã®åå ãåãããããããªãã
sshã§ãã°ã¤ã³ãã§ããããã«ãªã£ãããåè¿°ããsocksãµã¼ããç«ã¦ãã
ssh -D 1080 -N [email protected]
Dã«æ¸¡ãããã¼ãçªå·(çç¥ããã¨1080)ã§socksãµã¼ããç«ã¡ä¸ããã(Nã¤ãã¦è¯ãã¨æãã-fã¯ããã®ã¿ã§)
ãããå®éã«åãã¦ãããã©ãã確ãããããGUIãã¼ã¹ã®ãã©ã¦ã¶ã¯ç¢ºèªãé¢åãªã®ã§ã³ãã³ãã©ã¤ã³ã§èª¿ã¹ããcurlã使ãã
## ã¡ãªã¿ã«ãã®ãªãã·ã§ã³ã®æå®æ¹æ³ã¯å¤ãããã¨socks4ã§ã¯ãªããsocks5ãããããªãã curl --socks4 localhost:1080 localhost:8000 curl --socks4a localhost:1080 localhost:8000
200ã£ã½ãã¡ãã»ã¼ã¸ãè¿ã£ã¦ããã調ã¹ã¦ã¿ãã
socks4aã¯ãã¹ãåã®è§£æ±ºããªã¢ã¼ãå
ã®ãã¹ãã§è¡ãããããaãªãã®sock4ã¯ãã¹ãåã®è§£æ±ºãã¢ã¯ã»ã¹å
(local)ã®ãã¹ãã§è¡ããã
(ã¨ããããã§ãä¸ã®socks4ã®ä¾ã¯ãã¾ãæå³ããªãã)
curlãåãããã¨ã確èªããããã©ã¦ã¶ã§ç¢ºèªãã
ãã©ã¦ã¶ã§ã®ç¢ºèªä½æ¥
firefoxãchromeã§proxyè¨å®(socks)ãé¸ã³ãsocksé¢ä¿ã®é¸æã追å ããã
firefoxã¯ã
- network.proxy.socks_remote_dns
- network.proxy.socks_version
ãªã©ã確èªãã¦ã¿ããremote_dnsãtrueãªãã°ãcurlã®socks4aã¨åæ§ã®åããããã¯ã*2