Home >Backend Development >Golang >SSH agent, wrong packet length

SSH agent, wrong packet length

WBOY
WBOYforward
2024-02-09 14:00:36911browse

SSH 代理,数据包长度错误

#php editor Shinichi will introduce to you a common network error today - "SSH agent, packet length error". When using the SSH agent tool, you sometimes encounter this error message, causing the network connection to fail. This error is usually caused by the packet length being set incorrectly. In this article, we will explain the cause of this error in detail and provide some solutions to fix the problem and ensure that your network connection is smooth.

Question content

Implementing ssh proxy in go, errors occur due to incorrect packet length. These are ssh errors in debug mode:

debug1: ssh2_msg_kexinit sent
bad packet length 1231976033.
ssh_dispatch_run_fatal: connection to ::1 port 8080: message authentication code incorrect

Code:

func handleSSH(conn net.Conn, r *bufio.Reader, protocol string) {

    target, err := url.Parse("ssh://localhost:3333")
    if err != nil {
        fmt.Println("Error parsing target", err)
        conn.Close()
        return
    }

    targetConn, err := net.Dial("tcp", target.Host)
    if err != nil {
        fmt.Println("error dialing SSH target:", err)
        conn.Close()
        return
    }

    defer targetConn.Close()

    var wg sync.WaitGroup
    wg.Add(2)
    go func() {
        _, err := io.Copy(targetConn, conn)
        if err != nil {
            fmt.Println("error copying data to target:", err)
        }
        wg.Done()
    }()

    go func() {
        _, err := io.Copy(conn, targetConn)
        if err != nil {
            fmt.Println("error copying data from target:", err)
        }
        wg.Done()
    }()

    wg.Wait()
    conn.Close()
}

// EDIT

func connection(conn net.Conn) {

    r := bufio.NewReader(conn)
    protocol, err := r.ReadString('\n')
    if err != nil {
        fmt.Println("Error reading first line", err)
        conn.Close()
        return
    }

if protocol[0:3] == "SSH" {
        handleSSH(conn, r, protocol)
    }
}

func main() {
   ln, err := net.Listen("tcp", ":8080")
    if err != nil {
        panic(err)
    }
    defer ln.Close()

    for {
        conn, err := ln.Accept()
        if err != nil {
            panic(err)
        }
        go connection(conn)
    }
}

EDIT: Added code with relevant information on how to initiate the connection and reproduce the error.

My best guess is that the ssh negotiation process was interrupted and things got out of sync.

Workaround

The code reads the first line from the client and checks the protocol type so the appropriate handler can be called:

protocol, err := r.ReadString('\n')
...
if protocol[0:3] == "SSH" {
        handleSSH(conn, r, protocol)
    }
}

But the code cannot forward the read bytes to the connected server. These bytes are located in protocol and provided to handlessh. But once the connection is established, it cannot send these bytes to the connected server. Instead, it only copies new data between the client and server.

This means that the server did not get the first row from the client. Therefore, it may complain about protocol errors like invalid ssh id string. which is forwarded to the client and misinterpreted as valid data from the ssh connection.

The above is the detailed content of SSH agent, wrong packet length. For more information, please follow other related articles on the PHP Chinese website!

Statement:
This article is reproduced at:stackoverflow.com. If there is any infringement, please contact admin@php.cn delete