Bootleg bot: Difference between revisions

From XPUB & Lens-Based wiki
Line 1: Line 1:
==Networks==
==Networks==


(we will go through the following commands from '''sergio''')
🟣 = a device (server/laptop/phone/...)
🟡 = a network


To which networks is sergio connected right now?
We will go through the following commands from 🟣 '''sergio'''.
 
So the first step is to log into 🟣 sergio:
 
ssh sergio
 
To which networks is 🟣 sergio connected right now?


  ip a
  ip a


To which networks is the bootleg library connected right now?
To which networks is 🟣 the bootleg library connected right now?


<pre>
<pre>
Line 36: Line 43:
</pre>
</pre>


Are we sharing a network with the bootleg library?  
Is 🟣 sergio part of the same network as 🟣 the bootleg library is?  


  yes! the HUB
  ...


Can we check if we can communicate with the bootleg library through this network? (see all HUB ip address [[HUB|here]])
How can we check if we can communicate with 🟣 the bootleg library through this network?  
 
ping ip-address
 
Let's first check 🟡 the XPUB HUB (see all servers listed [[HUB|here]])


  ping 10.0.0.103
  ping 10.0.0.103


Who else is on the network right now?
Who else is on 🟡 the HUB network right now?


  nmap 10.0.0.*
  nmap 10.0.0.*


And who else is on the eduroam right now? (in the same subnet)
And who else is on 🟡 eduroam right now? (in the same subnet)


  nmap 145.24.152.*
  nmap 145.24.152.*
Can we reach 🟣 the bootleg library through 🟡 eduroam?
ping 145.24.153.55


We can make such a mapping because we are part of the same LAN network.
We can make such a mapping because we are part of the same LAN network.


(LAN = local area network)
LAN = local area network
 
Let's take a short side step.
 
We want to make a zulip bot. Which network do we use everyday to connect to 🟣 the XPUB zulip server?


But how do you travel from one network to another within the WAN?
ping zulip.xpub.nl
<check your ip address from your device>


(WAN = wider area network, aka the internet)
How does such a zulip connection travel?


  traceroute zulip.xpub.nl
  traceroute zulip.xpub.nl


But how do we reach the hidden LAN/VPN 10.0.0.* network from the WAN?
We can trace this route because all the "hops" are done on 🟡 the public internet (the WAN).
 
WAN = wider area network, aka the internet
 
So to summarize, these devices are part of the following networks:
 
🟣 bootleg library: 🟡 10.0.0.103 + 🟡 145.24.153.55
🟣 sergio:
🟣 your laptop:
🟣 XPUB zulip server:
 
With an important footnote: we're not sure if it was intentional to have 🟣 the bootleg library on 🟡 eduroam. So let's keep in mind that we will most likely loose this connection.
 
Which 🟣 device can we use to run a bot that connects the 🟣 XPUB zulip server to 🟣 the bootleg library (on 🟡 the HUB), keeping in mind that the whole goal of this is to connect to 🟣 the bootleg library from 🟡 the WAN?
 
...
 
How can we connect 🟣 our device (on 🟡 WAN) to 🟣 sergio (on 🟡 eduroam + 🟡 HUB) to connect to 🟣 the bootleg library (on 🟡 eduroam + 🟡 HUB)?
 
in many ways...
 
But which option will we focus on today?


  ssh tunnelling!
  SSH tunnelling!


==SSH tunnels==
==SSH tunnels==


https://ittavern.com/visual-guide-to-ssh-tunneling-and-port-forwarding/
https://ittavern.com/visual-guide-to-ssh-tunneling-and-port-forwarding/

Revision as of 21:38, 1 March 2026

Networks

🟣 = a device (server/laptop/phone/...)
🟡 = a network

We will go through the following commands from 🟣 sergio.

So the first step is to log into 🟣 sergio:

ssh sergio

To which networks is 🟣 sergio connected right now?

ip a

To which networks is 🟣 the bootleg library connected right now?

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether dc:a6:32:54:34:1c brd ff:ff:ff:ff:ff:ff
    inet 145.24.153.55/23 brd 145.24.153.255 scope global dynamic noprefixroute eth0
       valid_lft 207029sec preferred_lft 174629sec
    inet6 fe80::9e59:5f86:ee6:e86d/64 scope link 
       valid_lft forever preferred_lft forever
3: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
    link/ether dc:a6:32:54:34:1e brd ff:ff:ff:ff:ff:ff
    inet 10.9.8.1/24 brd 10.9.8.255 scope global noprefixroute wlan0
       valid_lft forever preferred_lft forever
    inet6 fe80::9724:36ee:d995:558e/64 scope link 
       valid_lft forever preferred_lft forever
4: hub: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 500
    link/none 
    inet 10.0.0.103/24 scope global hub
       valid_lft forever preferred_lft forever
    inet6 fe80::6fce:6106:9b56:33db/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever

Is 🟣 sergio part of the same network as 🟣 the bootleg library is?

...

How can we check if we can communicate with 🟣 the bootleg library through this network?

ping ip-address 

Let's first check 🟡 the XPUB HUB (see all servers listed here)

ping 10.0.0.103

Who else is on 🟡 the HUB network right now?

nmap 10.0.0.*

And who else is on 🟡 eduroam right now? (in the same subnet)

nmap 145.24.152.*

Can we reach 🟣 the bootleg library through 🟡 eduroam?

ping 145.24.153.55

We can make such a mapping because we are part of the same LAN network.

LAN = local area network

Let's take a short side step.

We want to make a zulip bot. Which network do we use everyday to connect to 🟣 the XPUB zulip server?

ping zulip.xpub.nl
<check your ip address from your device>

How does such a zulip connection travel?

traceroute zulip.xpub.nl

We can trace this route because all the "hops" are done on 🟡 the public internet (the WAN).

WAN = wider area network, aka the internet

So to summarize, these devices are part of the following networks:

🟣 bootleg library: 🟡 10.0.0.103 + 🟡 145.24.153.55
🟣 sergio: 
🟣 your laptop: 
🟣 XPUB zulip server: 

With an important footnote: we're not sure if it was intentional to have 🟣 the bootleg library on 🟡 eduroam. So let's keep in mind that we will most likely loose this connection.

Which 🟣 device can we use to run a bot that connects the 🟣 XPUB zulip server to 🟣 the bootleg library (on 🟡 the HUB), keeping in mind that the whole goal of this is to connect to 🟣 the bootleg library from 🟡 the WAN?

...

How can we connect 🟣 our device (on 🟡 WAN) to 🟣 sergio (on 🟡 eduroam + 🟡 HUB) to connect to 🟣 the bootleg library (on 🟡 eduroam + 🟡 HUB)?

in many ways... 

But which option will we focus on today?

SSH tunnelling!

SSH tunnels

https://ittavern.com/visual-guide-to-ssh-tunneling-and-port-forwarding/