Bootleg bot
Networking
π£ = a device (server/laptop/phone/...) π‘ = a network
We will go through the following commands from π£ sergio.
So the first step is to log into π£ sergio:
ssh sergio
To which networks is π£ sergio connected right now?
ip a
To which networks is π£ the bootleg library connected right now?
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether dc:a6:32:54:34:1c brd ff:ff:ff:ff:ff:ff
inet 145.24.153.55/23 brd 145.24.153.255 scope global dynamic noprefixroute eth0
valid_lft 207029sec preferred_lft 174629sec
inet6 fe80::9e59:5f86:ee6:e86d/64 scope link
valid_lft forever preferred_lft forever
3: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether dc:a6:32:54:34:1e brd ff:ff:ff:ff:ff:ff
inet 10.9.8.1/24 brd 10.9.8.255 scope global noprefixroute wlan0
valid_lft forever preferred_lft forever
inet6 fe80::9724:36ee:d995:558e/64 scope link
valid_lft forever preferred_lft forever
4: hub: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 500
link/none
inet 10.0.0.103/24 scope global hub
valid_lft forever preferred_lft forever
inet6 fe80::6fce:6106:9b56:33db/64 scope link stable-privacy
valid_lft forever preferred_lft forever
Is π£ sergio part of the same network as π£ the bootleg library is?
...
How can we check if we can communicate with π£ the bootleg library through this network?
ping ip-address
Let's first check π‘ the XPUB HUB (see all HUB servers listed here)
ping 10.0.0.103
Who else is on π‘ the HUB network right now?
nmap 10.0.0.*
And who else is on π‘ eduroam right now? (in the same subnet)
nmap 145.24.152.*
Can we reach π£ the bootleg library through π‘ eduroam?
ping 145.24.153.55
We can make such a mapping because we are part of the same LAN network.
LAN = local area network
Let's take a short side step.
We want to make a zulip bot. Which network do we use everyday to connect to π£ the XPUB zulip server?
ping zulip.xpub.nl <check your ip address from your device>
How does such a zulip connection travel?
traceroute zulip.xpub.nl
We can trace this route because all the "hops" are done on π‘ the public internet (the WAN).
WAN = wider area network, aka the internet
So to summarize, these devices are part of the following networks:
π£ bootleg library: π‘ 10.0.0.103 + π‘ 145.24.153.55 π£ sergio: π£ your laptop: π£ XPUB zulip server:
With an important footnote: we're not sure if it was intentional to have π£ the bootleg library on π‘ eduroam. So let's keep in mind that we will most likely loose this connection.
Which π£ device can we use to run a bot that connects the π£ XPUB zulip server to π£ the bootleg library (on π‘ the HUB), keeping in mind that the whole goal of this is to connect to π£ the bootleg library from π‘ the WAN?
...
How can we connect π£ our device (on π‘ WAN) to π£ sergio (on π‘ eduroam + π‘ HUB) to connect to π£ the bootleg library (on π‘ eduroam + π‘ HUB)?
in many ways...
But which option will we focus on today?
SSH tunnelling!
SSH tunnelling
https://ittavern.com/visual-guide-to-ssh-tunneling-and-port-forwarding/
(I think we need to simplify this step and only use the xpub user on sergio...)
From sergio...
ssh sergio
ssh into the bootleg library using a SSH tunnel:
ssh -J sergio pi@10.0.0.103
From $ man ssh:
-J destination Connect to the target host by first making a ssh connection to the jump host described by destination and then establishing a TCP forwarding to the ultimate destination from there. Multiple jump hops may be specified separated by comma characters. This is a shortcut to specify a ProxyJump configuration directive.
If you get a "publickey denied" error, you need to install a SSH key of your user on sergio to the bootleg library.
First generate a SSH key.
ssh-keygen -t ed25519
Find the public key:
cd .ssh cat id_ed25519.pub
Copy the output.
Log in to the bootleg library with the xpub user on sergio:
ssh sergio sudo su - xpub sudo pi@10.0.0.103
This works, and without password, because the SSH keys of xpub@sergio are already installed at pi@bootleglibrary.
Move to the .ssh folder:
cd .ssh
Open the authorized keys file:
nano authorized_keys
Paste your public key!
Now try the tunnel again.