SSH
BASIC CONNECTIONS#
ssh user@host # Basic connection ssh -p 2222 user@host # Custom port ssh user@host command # Run command and exit ssh -v user@host # Verbose output ssh -vv user@host # More verbose ssh -vvv user@host # Debug level
KEY MANAGEMENT#
# Generate keys ssh-keygen # Default (RSA) ssh-keygen -t ed25519 # Ed25519 (recommended) ssh-keygen -t rsa -b 4096 # RSA 4096-bit ssh-keygen -t ecdsa -b 521 # ECDSA 521-bit ssh-keygen -f ~/.ssh/mykey # Custom filename ssh-keygen -C "comment" # Add comment ssh-keygen -p -f ~/.ssh/id_rsa # Change passphrase # Key locations ~/.ssh/id_rsa # Private key (RSA) ~/.ssh/id_rsa.pub # Public key (RSA) ~/.ssh/id_ed25519 # Private key (Ed25519) ~/.ssh/id_ed25519.pub # Public key (Ed25519) ~/.ssh/authorized_keys # Authorized public keys ~/.ssh/known_hosts # Known hosts # Copy public key to server ssh-copy-id user@host ssh-copy-id -i ~/.ssh/mykey.pub user@host cat ~/.ssh/id_rsa.pub | ssh user@host "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys" # SSH Agent eval $(ssh-agent) # Start agent ssh-add # Add default key ssh-add ~/.ssh/mykey # Add specific key ssh-add -l # List keys ssh-add -d ~/.ssh/mykey # Remove key ssh-add -D # Remove all keys
SSH CONFIG FILE (~/.ssh/config)#
Host myserver
HostName 192.168.1.100
User admin
Port 22
IdentityFile ~/.ssh/mykey
Host *
ServerAliveInterval 60
ServerAliveCountMax 3
AddKeysToAgent yes
IdentitiesOnly yes
Host jump
HostName jump.example.com
User jumpuser
Host internal
HostName 10.0.0.5
User admin
ProxyJump jump
PORT FORWARDING#
# Local port forwarding (access remote service locally) ssh -L 8080:localhost:80 user@host ssh -L 8080:remotehost:80 user@jumphost ssh -L 127.0.0.1:8080:localhost:80 user@host # Bind to localhost only # Remote port forwarding (expose local service to remote) ssh -R 8080:localhost:80 user@host ssh -R 0.0.0.0:8080:localhost:80 user@host # Bind to all interfaces # Dynamic port forwarding (SOCKS proxy) ssh -D 1080 user@host ssh -D 127.0.0.1:1080 user@host # Background forwarding ssh -fN -L 8080:localhost:80 user@host # Fork to background
TUNNELING OPTIONS#
-L [bind_addr:]port:host:hostport # Local forward -R [bind_addr:]port:host:hostport # Remote forward -D [bind_addr:]port # Dynamic forward -N # No remote command -f # Fork to background -g # Allow remote hosts to connect
PROXY & JUMP HOSTS#
# Jump host (ProxyJump) ssh -J jumphost user@target ssh -J user1@jump1,user2@jump2 user@target # ProxyCommand ssh -o ProxyCommand="ssh -W %h:%p jumphost" user@target # SOCKS proxy ssh -o ProxyCommand="nc -x 127.0.0.1:1080 %h %p" user@host
FILE TRANSFER#
# SCP (Secure Copy) scp file user@host:/path/ # Upload file scp user@host:/path/file . # Download file scp -r dir user@host:/path/ # Upload directory scp -P 2222 file user@host:/path/ # Custom port scp -i ~/.ssh/key file user@host:/path/ # Specific key # SFTP sftp user@host sftp -P 2222 user@host # SFTP commands: ls, cd, get, put, mkdir, rm, exit
X11 FORWARDING#
ssh -X user@host # Enable X11 forwarding ssh -Y user@host # Trusted X11 forwarding
SECURITY OPTIONS#
ssh -o StrictHostKeyChecking=no user@host # Skip host check (insecure) ssh -o UserKnownHostsFile=/dev/null user@host # Don't save known hosts ssh -o PasswordAuthentication=no user@host # Key auth only ssh -o PubkeyAuthentication=no user@host # Password auth only ssh -o ConnectTimeout=10 user@host # Connection timeout
ESCAPE SEQUENCES#
~. # Disconnect ~^Z # Suspend ssh ~# # List forwarded connections ~& # Background ssh ~? # Help ~~ # Send ~
TROUBLESHOOTING#
# Debug connection ssh -vvv user@host # Check permissions ls -la ~/.ssh/ # Should be: # ~/.ssh/ drwx------ (700) # ~/.ssh/id_rsa -rw------- (600) # ~/.ssh/id_rsa.pub -rw-r--r-- (644) # ~/.ssh/authorized_keys -rw------- (600) # Fix permissions chmod 700 ~/.ssh chmod 600 ~/.ssh/id_rsa chmod 644 ~/.ssh/id_rsa.pub chmod 600 ~/.ssh/authorized_keys # Remove old host key ssh-keygen -R hostname ssh-keygen -R ip_address # Test key authentication ssh -o PreferredAuthentications=publickey -v user@host
SSHD CONFIG (/etc/ssh/sshd_config)#
# Security hardening Port 22 PermitRootLogin no PasswordAuthentication no PubkeyAuthentication yes MaxAuthTries 3 AllowUsers user1 user2 AllowGroups sshusers X11Forwarding no PermitEmptyPasswords no ClientAliveInterval 300 ClientAliveCountMax 2 # Restart sshd after changes sudo systemctl restart sshd
USEFUL ALIASES#
# In ~/.bashrc or ~/.zshrc alias ssht='ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null' alias sshv='ssh -v'
SSH CHEATSHEET
==============
Source: https://cheatsheet.johlem.net
BASIC CONNECTIONS
-----------------
ssh user@host # Basic connection
ssh -p 2222 user@host # Custom port
ssh user@host command # Run command and exit
ssh -v user@host # Verbose output
ssh -vv user@host # More verbose
ssh -vvv user@host # Debug level
KEY MANAGEMENT
--------------
# Generate keys
ssh-keygen # Default (RSA)
ssh-keygen -t ed25519 # Ed25519 (recommended)
ssh-keygen -t rsa -b 4096 # RSA 4096-bit
ssh-keygen -t ecdsa -b 521 # ECDSA 521-bit
ssh-keygen -f ~/.ssh/mykey # Custom filename
ssh-keygen -C "comment" # Add comment
ssh-keygen -p -f ~/.ssh/id_rsa # Change passphrase
# Key locations
~/.ssh/id_rsa # Private key (RSA)
~/.ssh/id_rsa.pub # Public key (RSA)
~/.ssh/id_ed25519 # Private key (Ed25519)
~/.ssh/id_ed25519.pub # Public key (Ed25519)
~/.ssh/authorized_keys # Authorized public keys
~/.ssh/known_hosts # Known hosts
# Copy public key to server
ssh-copy-id user@host
ssh-copy-id -i ~/.ssh/mykey.pub user@host
cat ~/.ssh/id_rsa.pub | ssh user@host "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
# SSH Agent
eval $(ssh-agent) # Start agent
ssh-add # Add default key
ssh-add ~/.ssh/mykey # Add specific key
ssh-add -l # List keys
ssh-add -d ~/.ssh/mykey # Remove key
ssh-add -D # Remove all keys
SSH CONFIG FILE (~/.ssh/config)
-------------------------------
Host myserver
HostName 192.168.1.100
User admin
Port 22
IdentityFile ~/.ssh/mykey
Host *
ServerAliveInterval 60
ServerAliveCountMax 3
AddKeysToAgent yes
IdentitiesOnly yes
Host jump
HostName jump.example.com
User jumpuser
Host internal
HostName 10.0.0.5
User admin
ProxyJump jump
PORT FORWARDING
---------------
# Local port forwarding (access remote service locally)
ssh -L 8080:localhost:80 user@host
ssh -L 8080:remotehost:80 user@jumphost
ssh -L 127.0.0.1:8080:localhost:80 user@host # Bind to localhost only
# Remote port forwarding (expose local service to remote)
ssh -R 8080:localhost:80 user@host
ssh -R 0.0.0.0:8080:localhost:80 user@host # Bind to all interfaces
# Dynamic port forwarding (SOCKS proxy)
ssh -D 1080 user@host
ssh -D 127.0.0.1:1080 user@host
# Background forwarding
ssh -fN -L 8080:localhost:80 user@host # Fork to background
TUNNELING OPTIONS
-----------------
-L [bind_addr:]port:host:hostport # Local forward
-R [bind_addr:]port:host:hostport # Remote forward
-D [bind_addr:]port # Dynamic forward
-N # No remote command
-f # Fork to background
-g # Allow remote hosts to connect
PROXY & JUMP HOSTS
------------------
# Jump host (ProxyJump)
ssh -J jumphost user@target
ssh -J user1@jump1,user2@jump2 user@target
# ProxyCommand
ssh -o ProxyCommand="ssh -W %h:%p jumphost" user@target
# SOCKS proxy
ssh -o ProxyCommand="nc -x 127.0.0.1:1080 %h %p" user@host
FILE TRANSFER
-------------
# SCP (Secure Copy)
scp file user@host:/path/ # Upload file
scp user@host:/path/file . # Download file
scp -r dir user@host:/path/ # Upload directory
scp -P 2222 file user@host:/path/ # Custom port
scp -i ~/.ssh/key file user@host:/path/ # Specific key
# SFTP
sftp user@host
sftp -P 2222 user@host
# SFTP commands: ls, cd, get, put, mkdir, rm, exit
X11 FORWARDING
--------------
ssh -X user@host # Enable X11 forwarding
ssh -Y user@host # Trusted X11 forwarding
SECURITY OPTIONS
----------------
ssh -o StrictHostKeyChecking=no user@host # Skip host check (insecure)
ssh -o UserKnownHostsFile=/dev/null user@host # Don't save known hosts
ssh -o PasswordAuthentication=no user@host # Key auth only
ssh -o PubkeyAuthentication=no user@host # Password auth only
ssh -o ConnectTimeout=10 user@host # Connection timeout
ESCAPE SEQUENCES
----------------
~. # Disconnect
~^Z # Suspend ssh
~# # List forwarded connections
~& # Background ssh
~? # Help
~~ # Send ~
TROUBLESHOOTING
---------------
# Debug connection
ssh -vvv user@host
# Check permissions
ls -la ~/.ssh/
# Should be:
# ~/.ssh/ drwx------ (700)
# ~/.ssh/id_rsa -rw------- (600)
# ~/.ssh/id_rsa.pub -rw-r--r-- (644)
# ~/.ssh/authorized_keys -rw------- (600)
# Fix permissions
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
chmod 600 ~/.ssh/authorized_keys
# Remove old host key
ssh-keygen -R hostname
ssh-keygen -R ip_address
# Test key authentication
ssh -o PreferredAuthentications=publickey -v user@host
SSHD CONFIG (/etc/ssh/sshd_config)
----------------------------------
# Security hardening
Port 22
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
AllowUsers user1 user2
AllowGroups sshusers
X11Forwarding no
PermitEmptyPasswords no
ClientAliveInterval 300
ClientAliveCountMax 2
# Restart sshd after changes
sudo systemctl restart sshd
USEFUL ALIASES
--------------
# In ~/.bashrc or ~/.zshrc
alias ssht='ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null'
alias sshv='ssh -v'
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.