Home > Backend Development > Golang > SSH agent, wrong packet length

SSH agent, wrong packet length

WBOY
Release: 2024-02-09 14:00:36
forward
963 people have browsed it

SSH 代理,数据包长度错误

#php editor Shinichi will introduce to you a common network error today - "SSH agent, packet length error". When using the SSH agent tool, you sometimes encounter this error message, causing the network connection to fail. This error is usually caused by the packet length being set incorrectly. In this article, we will explain the cause of this error in detail and provide some solutions to fix the problem and ensure that your network connection is smooth.

Question content

Implementing ssh proxy in go, errors occur due to incorrect packet length. These are ssh errors in debug mode:

debug1: ssh2_msg_kexinit sent
bad packet length 1231976033.
ssh_dispatch_run_fatal: connection to ::1 port 8080: message authentication code incorrect
Copy after login

Code:

func handleSSH(conn net.Conn, r *bufio.Reader, protocol string) {

    target, err := url.Parse("ssh://localhost:3333")
    if err != nil {
        fmt.Println("Error parsing target", err)
        conn.Close()
        return
    }

    targetConn, err := net.Dial("tcp", target.Host)
    if err != nil {
        fmt.Println("error dialing SSH target:", err)
        conn.Close()
        return
    }

    defer targetConn.Close()

    var wg sync.WaitGroup
    wg.Add(2)
    go func() {
        _, err := io.Copy(targetConn, conn)
        if err != nil {
            fmt.Println("error copying data to target:", err)
        }
        wg.Done()
    }()

    go func() {
        _, err := io.Copy(conn, targetConn)
        if err != nil {
            fmt.Println("error copying data from target:", err)
        }
        wg.Done()
    }()

    wg.Wait()
    conn.Close()
}

// EDIT

func connection(conn net.Conn) {

    r := bufio.NewReader(conn)
    protocol, err := r.ReadString('\n')
    if err != nil {
        fmt.Println("Error reading first line", err)
        conn.Close()
        return
    }

if protocol[0:3] == "SSH" {
        handleSSH(conn, r, protocol)
    }
}

func main() {
   ln, err := net.Listen("tcp", ":8080")
    if err != nil {
        panic(err)
    }
    defer ln.Close()

    for {
        conn, err := ln.Accept()
        if err != nil {
            panic(err)
        }
        go connection(conn)
    }
}
Copy after login

EDIT: Added code with relevant information on how to initiate the connection and reproduce the error.

My best guess is that the ssh negotiation process was interrupted and things got out of sync.

Workaround

The code reads the first line from the client and checks the protocol type so the appropriate handler can be called:

protocol, err := r.ReadString('\n')
...
if protocol[0:3] == "SSH" {
        handleSSH(conn, r, protocol)
    }
}
Copy after login

But the code cannot forward the read bytes to the connected server. These bytes are located in protocol and provided to handlessh. But once the connection is established, it cannot send these bytes to the connected server. Instead, it only copies new data between the client and server.

This means that the server did not get the first row from the client. Therefore, it may complain about protocol errors like invalid ssh id string. which is forwarded to the client and misinterpreted as valid data from the ssh connection.

The above is the detailed content of SSH agent, wrong packet length. For more information, please follow other related articles on the PHP Chinese website!

source:stackoverflow.com
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template