|
发表于 2018-12-13 01:57:32
|
显示全部楼层
请教楼主:
C$ E$ D+ U1 g, J+ w- d, ?8 KR017版hs8145v,已改华为界面补全shell,按一楼方法手动操作到安装dropbear,提示成功,但重启后ssh无法连接。2 |& g& k4 B K2 \9 L
相关信息如下: P; e, n$ S' k
- Welcome Visiting Huawei Home Gateway
4 P0 g) ^$ q) E; B3 N3 l - Copyright by Huawei Technologies Co., Ltd.+ X+ ?4 P6 y: Q' D6 C1 t/ F
- ! O# ^9 o8 c; F$ d* i. [+ N
- Login:root; \9 ?! D' Q, J3 ?: }
- Password:% Q( q; @1 `4 S7 E
- WAP>su6 e' I B$ h9 d+ `
- success! O7 C" h4 l( m" z& F
- SU_WAP>
2 D3 `3 S2 S5 v q- R7 u - SU_WAP>shell5 s, b5 L7 N0 ^. R0 a/ e
4 B& i, _5 C, c( U! ]+ u3 Z: q- BusyBox v1.18.4 (2017-08-16 10:43:34 CST) built-in shell (ash)3 s+ [0 J1 K) w
- Enter 'help' for a list of built-in commands.# H3 O; h& N% u2 J3 @
6 l3 m- n5 [$ C7 n1 t1 \1 B- profile close core dump
- b U; _* {" f - WAP(Dopra Linux) # ps -w|grep dropbear$ _- D a6 I/ g( g3 z: h& e2 z
- 1932 srv_ssmp 1132 S dropbear -r /etc/dropbear/dropbear_rsa_host_key -p 22 -j -k <font color="Red">(系统dropbear没被禁用)</font>
- M6 w, c, V! ]! y6 r$ g* n, v - 3165 root 1000 S /usr/sbin/dropbear -F -P /var/run/dropbear.1.pid -p 22 -K 300 <font color="Red">( openwrt 的 ssh 已启动)</font>
. Y. y& X4 D: c2 T4 s - 3595 srv_ssmp 1344 S grep dropbear: P/ [8 C7 n P. s# T5 D
- WAP(Dopra Linux) #
* M. b4 t; r* v/ g! ^; P - 5 d5 n! ^' N- V7 t/ i o; p+ h
- WAP(Dopra Linux) # cp /mnt/jffs2/hw_ctree.xml .
1 E$ F0 Z5 Q& {+ k% W3 K - WAP(Dopra Linux) # mv hw_ctree.xml hw_ctree.xml.gz
" G* n" p6 s7 d. c! q - WAP(Dopra Linux) # aescrypt2 1 hw_ctree.xml.gz tmp
, j& A2 L! F8 @7 c! V Z - WAP(Dopra Linux) # gunzip hw_ctree.xml.gz
& h2 }# K5 r1 S& }! @1 h - WAP(Dopra Linux) # grep -i ssh hw_ctree.xml
* Y6 ]0 l, b! x) q - <AclServices HTTPLanEnable="1" HTTPWanEnable="0" FTPLanEnable="1" FTPWanEnable="0" TELNETLanEnable="1" TELNETWanEnable="0" SSHLanEnable="1" SSHWanEnable="0" HTTPPORT="80" FTPPORT="21" TELNETPORT="23" SSHPORT="22" HTTPWifiEnable="1" TELNETWifiEnable="1" WebPermanentCloseControl="1" SamBaLanEnable="1" SamBaWanEnable="0" WebAccessControl="1" TrustHost=""> ( c1 W( E6 ^% e$ _" z3 w
- <X_HW_CLISSHControl Enable="1" port="22" Mode="1" AluSSHAbility="0"/> <font color="Red">(hw_ctree.xml中这句已添加,但在上一句后面,是否跟位置有关?)</font>
2 I8 h0 m2 I- L) Y. H9 v - WAP(Dopra Linux) # 1 h1 ]% f# j: e/ |! z- N
- WAP(Dopra Linux) # netstat -na
( P( ^' E3 `; w- ^/ H% y$ V7 D - Active Internet connections (servers and established); z5 i4 t% T) R* G- U( ~
- Proto Recv-Q Send-Q Local Address Foreign Address State
9 o' b+ l9 l, f" `3 k - tcp 0 0 192.168.1.1:17998 0.0.0.0:* LISTEN
9 C8 I% Q+ ~ m4 ?) B) { - tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
" R$ |( L2 D8 T7 U: L, X& o7 O2 k - tcp 0 0 192.168.1.1:49652 0.0.0.0:* LISTEN $ ]4 g- m9 k5 o4 v7 x3 v$ L6 }
- tcp 0 0 192.168.1.1:53 0.0.0.0:* LISTEN
5 m" ? G5 C* ~9 x - tcp 0 0 113.245.189.230:53 0.0.0.0:* LISTEN & k. u, e, e1 P' h' A {: v' N
- tcp 0 0 192.168.1.1:49653 0.0.0.0:* LISTEN ' \( k0 _3 ?; D! c& O7 X7 x
- tcp 0 0 169.254.151.36:53 0.0.0.0:* LISTEN
0 U+ B. j* r$ T) g2 X% b# n - tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN <font color="Red">(22端口已监听)</font>: G N, y+ J& J4 } p5 I: |; S7 v# I2 I
- tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN 0 W6 ~8 J6 K4 B
- tcp 0 0 127.0.0.1:60000 0.0.0.0:* LISTEN
. h- j K k/ E) b* C - tcp 0 0 0.0.0.0:32768 0.0.0.0:* LISTEN 3 x% |8 s D* h% \* `$ e
- tcp 0 0 192.168.1.1:37443 0.0.0.0:* LISTEN & u e6 c6 W; p T$ \2 C) I
- tcp 0 0 192.168.1.1:37444 0.0.0.0:* LISTEN
9 S6 b' I/ Y, |/ e8 T* | - tcp 0 139 192.168.1.1:23 192.168.1.24:2423 ESTABLISHED
" c5 Y! M; q8 x: N3 T( }# v - tcp 0 0 :::80 :::* LISTEN 1 x# }' l3 ~4 T6 w5 m$ |+ R
- tcp 0 0 :::8080 :::* LISTEN ! R2 R# ~6 F, T# y1 Z
- tcp 0 0 :::22 :::* LISTEN 8 V" k7 z3 N P* F% i' g' n% \5 h
- ..." v$ M6 V. L ^" }% [% s
- WAP(Dopra Linux) # cat /opt/upt/apps/apps/etc/config/dropbear
5 f1 S1 {- h9 }" K - config dropbear* O. I" _( D0 R. E& A7 p
- option PasswordAuth 'on'9 O" b# {3 M/ G
- option RootPasswordAuth 'on'
& |1 R% e' E% m" X0 G: d% b& f- s - option Port '22'6 M% \) j/ ^, E; P
- # option BannerFile '/etc/banner' T- K6 K+ L; C! [4 q
- WAP(Dopra Linux) # 3 I" D2 @/ A% \, g v! b ]
复制代码 此时ssh无法连接22端口。使用iptables开22端口:
7 G$ R' s9 _* d0 D8 Siptables -A INPUT_ACL -p tcp -mtcp --dport 22 -j ACCEPT
! A# J! [# u+ V! l: pssh连接被拒绝,提示:
$ s: \/ P+ b1 K2 dPublic-key authentication with the server for user root failed. Please verify username and public/private key pair.
# g X; h! h- U& K7 J3 E) I6 [" R: g" d2 h9 R- }' a
直接kill 华为dropbear:
9 j( v3 P e$ u X z# z6 L- WAP(Dopra Linux) # kill 1932/ |* |7 E2 ~! q$ X/ @1 X5 B; S
- WAP(Dopra Linux) # ps -w|grep dropbear4 Y) [' i) l. L
- 3165 root 1000 S /usr/sbin/dropbear -F -P /var/run/dropbear.1.pid -p 22 -K 300
$ f% n7 g/ G2 E# @ - 5194 srv_ssmp 1344 S grep dropbear3 ]" I1 ?5 Q/ p9 A: ^
% A( e8 V* L8 y& i# l- WAP(Dopra Linux) # netstat -na
( r$ d; f' ?4 v5 V5 s - Active Internet connections (servers and established)1 d# P" W% v6 q/ J3 ~7 v
- Proto Recv-Q Send-Q Local Address Foreign Address State 8 B; u% C( c! E" Q! B
- tcp 0 0 192.168.1.1:17998 0.0.0.0:* LISTEN . @+ A% r- Y8 G: \
- tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
4 K0 y9 B Q- V6 Y - tcp 0 0 192.168.1.1:49652 0.0.0.0:* LISTEN
& O- S' x( S% Q8 G - tcp 0 0 192.168.1.1:53 0.0.0.0:* LISTEN 2 w3 {& @9 u; E& |7 }* U
- tcp 0 0 113.245.189.230:53 0.0.0.0:* LISTEN 4 x# I E" y4 }/ f
- tcp 0 0 192.168.1.1:49653 0.0.0.0:* LISTEN 8 I& P) n# \9 G: Q
- tcp 0 0 169.254.151.36:53 0.0.0.0:* LISTEN
. P6 g' A* C) r4 l+ M( f! G9 m5 Z# ~ - tcp 0 0 0.0.0.0:23 0.0.0.0:* LISTEN : [5 D; k. o0 a* _$ z/ O
- tcp 0 0 127.0.0.1:60000 0.0.0.0:* LISTEN
: o8 [+ z `7 V! ^8 \, O( W - tcp 0 0 0.0.0.0:32768 0.0.0.0:* LISTEN
: K/ n+ X$ r8 @; ^/ ^( }% ]0 ] - tcp 0 0 192.168.1.1:37443 0.0.0.0:* LISTEN * A8 }+ x; Z# R2 a) |- P/ w9 C
- tcp 0 0 192.168.1.1:37444 0.0.0.0:* LISTEN / F9 d* `. p _7 ]+ w
- tcp 0 139 192.168.1.1:23 192.168.1.24:2502 ESTABLISHED
2 G: H0 u# n: J- c+ { - tcp 0 0 :::80 :::* LISTEN
3 l- \# h3 N1 o6 N( d4 Z% o3 J' O - tcp 0 0 :::8080 :::* LISTEN
8 I+ S i" g, z! l! k q' O, U" | F - tcp 0 0 fe80::1:49652 :::* LISTEN
' \( j/ N1 e* `$ l1 |# S) j1 e - tcp 0 0 fe80::1:53 :::* LISTEN
7 d: ]' B9 h, f& F1 u% [' g1 G) X4 y - tcp 0 0 fe80::3dc3:5a08:2b80:67f6:53 :::* LISTEN ! z' A" e6 N# X# D; `7 n
- tcp 0 0 fe80::1:49653 :::* LISTEN
: U! d# [0 S9 I8 M0 L6 a" ^6 |! \' O+ G - tcp 0 0 :::22 :::* LISTEN , F6 C8 ?( T+ D3 m. c$ J
复制代码 ssh连接还是不成功,提示:远程系统拒绝连接!
- m3 \0 _1 V, m6 O# p6 W: y
; z- {( d5 o1 H9 G+ z) G I6 c5 ~. ~, Q# e2 B8 A; ]3 G
. S( f9 X. B1 G" b: d- z
a% I; c; g# q7 ?, y
|
|