
SSH를 통한 HTTP/HTTPS 프록시
SSH를 통한 HTTP/HTTPS 프록시.
go install github.com/justmao945/mallory/cmd/mallory@latest기본 경로는 $HOME/.config/mallory.json이며, 프로그램 시작 시 설정할 수 있습니다
mallory -config path/to/config.json
내용:
id_rsa는 개인 키 파일의 경로이며, ssh-keygen으로 생성할 수 있습니다.local_smart는 대상 호스트를 스마트하게 감지하여 HTTP 프록시를 제공하는 로컬 주소입니다.local_normal은 local_smart와 유사하지만 대상 호스트 감지 없이 모든 트래픽을 원격 SSH 서버를 통해 전송합니다.remote는 SSH 서버의 원격 주소입니다.blocked는 프록시를 사용해야 하는 도메인 목록이며, 다른 모든 도메인은 직접 서버에 연결됩니다.{
"id_rsa": "$HOME/.ssh/id_rsa",
"local_smart": ":1315",
"local_normal": ":1316",
"remote": "ssh://[email protected]:22",
"blocked": [
"angularjs.org",
"golang.org",
"google.com",
"google.co.jp",
"googleapis.com",
"googleusercontent.com",
"google-analytics.com",
"gstatic.com",
"twitter.com",
"youtube.com"
]
}
설정 파일의 차단 목록은 업데이트될 때 자동으로 다시 로드되며, 수동으로도 할 수 있습니다:
# 시그널을 보내 다시 로드
kill -USR2 <pid of mallory>
# 또는 http 요청으로 reload 명령 사용
mallory -reload
localhost의 포트 1315로 설정하여 차단 목록과 함께 사용http_proxy와 https_proxy를 localhost:1316으로 설정mallory -suffix www.google.com
# 설치: go get github.com/justmao945/mallory/cmd/forward
# 포트 20022를 통한 모든 트래픽이 destination.com:22로 전달됩니다.
forward -network tcp -listen :20022 -forward destination.com:22
# 로컬호스트:20022를 통해 destination:22로 ssh 가능
ssh root@localhost -p 20022
다음 설정 파일을 고려하세요:
$ cat mallory.json
{
"id_rsa": "/tmp/id_rsa",
"local_smart": ":1315",
"local_normal": ":1316",
"remote": "ssh://[email protected]:22"
}
다음과 같이 컨테이너를 실행할 수 있습니다:
$ docker run -v $PWD/mallory.json:/root/.config/mallory.json -p 1316:1316 -p 1315:1315 -v $PWD/.ssh/id_rsa:/tmp/id_rsa zoobab/mallory
mallory: 2020/03/30 16:51:10 main.go:22: Starting...
mallory: 2020/03/30 16:51:10 main.go:23: PID: 1
mallory: 2020/03/30 16:51:10 config.go:103: Loading: /root/.config/mallory.json
mallory: 2020/03/30 16:51:10 main.go:30: Connecting remote SSH server: ssh://[email protected]:22
mallory: 2020/03/30 16:51:10 main.go:38: Local normal HTTP proxy: :1316
mallory: 2020/03/30 16:51:10 main.go:48: Local smart HTTP proxy: :1315
제 사용 사례는 SSH 배스천 뒤에 설치된 Kubernetes 클러스터(Openshift)에 연결하는 것이었습니다:
$ export http_proxy=http://localhost:1316
$ export https_proxy=https://localhost:1316
$ oc login https://master.mycluster.zoobab.com:8443
Authentication required for https://master.mycluster.zoobab.com:8443 (openshift)
Username: bhenrion
Password:
Login successful.