Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
sshtunnel — Tunnel SSH verso server remoto. | Kitploit
Strumenti/GitHubGitHub/pahaz/sshtunnel
Utilità GenericheSicurezza di ReteUtilità e Framework
GitHubpahaz/sshtunnel

sshtunnel

Tunnel SSH verso server remoto.

Vedi Repository
1.3k20241 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

|CircleCI| |AppVeyor| |readthedocs| |coveralls| |version|

|pyversions| |license|

Autore: Pahaz_

Repository: https://github.com/pahaz/sshtunnel/

Ispirato da https://github.com/jmagnusson/bgtunnel, che non funziona su Windows.

Vedi anche: https://github.com/paramiko/paramiko/blob/master/demos/forward.py

Requisiti

  • paramiko_

Installazione

sshtunnel_ è su PyPI, quindi esegui semplicemente:

::

root@kitploit:~
pip install sshtunnel

oppure ::

root@kitploit:~
easy_install sshtunnel

oppure ::

root@kitploit:~
conda install -c conda-forge sshtunnel

per installarlo nel tuo ambiente.

Per installare dal sorgente, clona il repository <https://github.com/pahaz/sshtunnel>_ ed esegui::

root@kitploit:~
python setup.py install

Test del pacchetto

Per eseguire i test devi prima installare tox <https://testrun.org/tox/latest/>_ e poi eseguire::

root@kitploit:~
python setup.py test

Scenari di utilizzo

Uno degli scenari tipici in cui sshtunnel è utile è rappresentato nella figura sottostante. L'utente potrebbe dover connettere una porta di un server remoto (es. 8080) dove solo la porta SSH (di solito porta 22) è raggiungibile. ::

root@kitploit:~
----------------------------------------------------------------------

                            |
-------------+              |    +----------+
    LOCALE   |              |    | REMOTO   | :22 SSH
    CLIENT   | <== SSH ========> | SERVER   | :8080 servizio web
-------------+              |    +----------+
                            |
                         FIREWALL (solo porta 22 aperta)

----------------------------------------------------------------------

Fig1: Come connettersi a un servizio bloccato da un firewall tramite tunnel SSH.

Se consentito dal server SSH, è anche possibile raggiungere un server privato (dalla prospettiva del SERVER REMOTO) non direttamente visibile dall'esterno (prospettiva del CLIENT LOCALE). ::

root@kitploit:~
----------------------------------------------------------------------

                            |
-------------+              |    +----------+               +---------
    LOCALE   |              |    | REMOTO   |               | PRIVATO
    CLIENT   | <== SSH ========> | SERVER   | <== locale ==>| SERVER
-------------+              |    +----------+               +---------
                            |
                         FIREWALL (solo porta 443 aperta)

----------------------------------------------------------------------

Fig2: Come connettersi al SERVER PRIVATO tramite tunnel SSH.

Esempi di utilizzo

L'API consente sia di inizializzare il tunnel e avviarlo, sia di usare un contesto with, che si occuperà di avviare e fermare il tunnel:

Esempio 1

Codice corrispondente alla Fig1 sopra, dato l'indirizzo del server remoto pahaz.urfuclub.ru, autenticazione tramite password e porta locale di bind assegnata casualmente.

.. code-block:: python

root@kitploit:~
from sshtunnel import SSHTunnelForwarder

server = SSHTunnelForwarder(
    'alfa.8iq.dev',
    ssh_username="pahaz",
    ssh_password="secret",
    remote_bind_address=('127.0.0.1', 8080)
)

server.start()

print(server.local_bind_port)  # show assigned local port
# work with `SECRET SERVICE` through `server.local_bind_port`.

server.stop()

Esempio 2

Esempio di port forwarding verso un server privato non direttamente raggiungibile, supponendo autenticazione tramite pkey protetta da password, il servizio SSH del server remoto ascolta sulla porta 443 e tale porta è aperta nel firewall (Fig2):

.. code-block:: python

root@kitploit:~
import paramiko
import sshtunnel

with sshtunnel.open_tunnel(
    (REMOTE_SERVER_IP, 443),
    ssh_username="",
    ssh_pkey="/var/ssh/rsa_key",
    ssh_private_key_password="secret",
    remote_bind_address=(PRIVATE_SERVER_IP, 22),
    local_bind_address=('0.0.0.0', 10022)
) as tunnel:
    client = paramiko.SSHClient()
    client.load_system_host_keys()
    client.set_missing_host_key_policy(paramiko.AutoAddPolicy())
    client.connect('127.0.0.1', 10022)
    # do some operations with client session
    client.close()

print('FINISH!')

Esempio 3

Esempio di port forwarding per la porta MySQL locale di Vagrant:

.. code-block:: python

root@kitploit:~
from sshtunnel import open_tunnel
from time import sleep

with open_tunnel(
    ('localhost', 2222),
    ssh_username="vagrant",
    ssh_password="vagrant",
    remote_bind_address=('127.0.0.1', 3306)
) as server:

    print(server.local_bind_port)
    while True:
        # press Ctrl-C for stopping
        sleep(1)

print('FINISH!')

O semplicemente tramite CLI:

.. code-block:: console

root@kitploit:~
(bash)$ python -m sshtunnel -U vagrant -P vagrant -L :3306 -R 127.0.0.1:3306 -p 2222 localhost

Esempio 4

Aprire una sessione SSH saltando due tunnel. Il trasporto SSH e i tunnel saranno demoneizzati, quindi non aspetteranno la chiusura delle connessioni al momento della terminazione.

.. code-block:: python

root@kitploit:~
import sshtunnel
from paramiko import SSHClient


with sshtunnel.open_tunnel(
    ssh_address_or_host=('GW1_ip', 20022),
    remote_bind_address=('GW2_ip', 22),
) as tunnel1:
    print('Connection to tunnel1 (GW1_ip:GW1_port) OK...')
    with sshtunnel.open_tunnel(
        ssh_address_or_host=('localhost', tunnel1.local_bind_port),
        remote_bind_address=('target_ip', 22),
        ssh_username='GW2_user',
        ssh_password='GW2_pwd',
    ) as tunnel2:
        print('Connection to tunnel2 (GW2_ip:GW2_port) OK...')
        with SSHClient() as ssh:
            ssh.connect('localhost',
                port=tunnel2.local_bind_port,
                username='target_user',
                password='target_pwd',
            )
            ssh.exec_command(...)

Utilizzo da riga di comando

::

root@kitploit:~
$ sshtunnel --help
usage: sshtunnel [-h] [-U SSH_USERNAME] [-p SSH_PORT] [-P SSH_PASSWORD] -R
                 IP:PORT [IP:PORT ...] [-L [IP:PORT ...]] [-k SSH_HOST_KEY]
                 [-K KEY_FILE] [-S KEY_PASSWORD] [-t] [-v] [-V] [-x IP:PORT]
                 [-c SSH_CONFIG_FILE] [-z] [-n] [-d [FOLDER ...]]
                 ssh_address

Pure python ssh tunnel utils
Version 0.4.0

positional arguments:
  ssh_address           SSH server IP address (GW for SSH tunnels)
                        set with "-- ssh_address" if immediately after -R or -L

options:
  -h, --help            show this help message and exit
  -U SSH_USERNAME, --username SSH_USERNAME
                        SSH server account username
  -p SSH_PORT, --server_port SSH_PORT
                        SSH server TCP port (default: 22)
  -P SSH_PASSWORD, --password SSH_PASSWORD
                        SSH server account password
  -R IP:PORT [IP:PORT ...], --remote_bind_address IP:PORT [IP:PORT ...]
                        Remote bind address sequence: ip_1:port_1 ip_2:port_2 ... ip_n:port_n
                        Equivalent to ssh -Lxxxx:IP_ADDRESS:PORT
                        If port is omitted, defaults to 22.
                        Example: -R 10.10.10.10: 10.10.10.10:5900
  -L [IP:PORT ...], --local_bind_address [IP:PORT ...]
                        Local bind address sequence: ip_1:port_1 ip_2:port_2 ... ip_n:port_n
                        Elements may also be valid UNIX socket domains:
                        /tmp/foo.sock /tmp/bar.sock ... /tmp/baz.sock
                        Equivalent to ssh -LPORT:xxxxxxxxx:xxxx, being the local IP address optional.
                        By default it will listen in all interfaces (0.0.0.0) and choose a random port.
                        Example: -L :40000
  -k SSH_HOST_KEY, --ssh_host_key SSH_HOST_KEY
                        Gateway's host key
  -K KEY_FILE, --private_key_file KEY_FILE
                        RSA/DSS/ECDSA private key file
  -S KEY_PASSWORD, --private_key_password KEY_PASSWORD
                        RSA/DSS/ECDSA private key password
  -t, --threaded        Allow concurrent connections to each tunnel
  -v, --verbose         Increase output verbosity (default: ERROR)
  -V, --version         Show version number and quit
  -x IP:PORT, --proxy IP:PORT
                        IP and port of SSH proxy to destination
  -c SSH_CONFIG_FILE, --config SSH_CONFIG_FILE
                        SSH configuration file, defaults to ~/.ssh/config
  -z, --compress        Request server for compression over SSH transport
  -n, --noagent         Disable looking for keys from an SSH agent
  -d [FOLDER ...], --host_pkey_directories [FOLDER ...]
                        List of directories where SSH pkeys (in the format `id_*`) may be found

.. _Pahaz: https://github.com/pahaz .. _sshtunnel: https://pypi.python.org/pypi/sshtunnel .. paramiko: http://www.paramiko.org/ .. |CircleCI| image:: https://circleci.com/gh/pahaz/sshtunnel.svg?style=svg :target: https://circleci.com/gh/pahaz/sshtunnel .. |AppVeyor| image:: https://ci.appveyor.com/api/projects/status/oxg1vx2ycmnw3xr9?svg=true&passingText=Windows%20-%20OK&failingText=Windows%20-%20Fail :target: https://ci.appveyor.com/project/pahaz/sshtunnel .. |readthedocs| image:: https://readthedocs.org/projects/sshtunnel/badge/?version=latest :target: http://sshtunnel.readthedocs.io/en/latest/?badge=latest :alt: Stato della documentazione .. |coveralls| image:: https://coveralls.io/repos/github/pahaz/sshtunnel/badge.svg?branch=master :target: https://coveralls.io/github/pahaz/sshtunnel?branch=master .. |pyversions| image:: https://img.shields.io/pypi/pyversions/sshtunnel.svg .. |version| image:: https://img.shields.io/pypi/v/sshtunnel.svg :target: sshtunnel .. |license| image:: https://img.shields.io/pypi/l/sshtunnel.svg :target: https://github.com/pahaz/sshtunnel/blob/master/LICENSE

Scarica lo strumento