博文

目前显示的是标签为“SSH”的博文

Host Verification while SSHing

The first time you SSH to a remote host, you need to verify the fingerprint of the host. ``` The authenticity of host 'example.com (1.1.1.1)' can't be established. ECDSA key fingerprint is SHA256:suhfbwrunauibgsrbgeuygbsltnhubsiff. Are you sure you want to continue connecting (yes/no)? ``` MITM prevention ------ For MITM prevention, here's how: 1. Local machine cmd: ```bash ssh -o FingerprintHash=md5 example.com ``` 1. Remote host cmd:  Find a secure way to execute the below codes on your remote host and output host ssh fingerprint.     * Web console via https. Or     * Goto physical place of remote host. Or     * Ask your VPS hoster for the fingerprint. ```bash ssh-keygen -l -E md5 -f /etc/ssh/ssh_host_ecdsa_key.pub #  ssh-keygen -l            -f /etc/ssh/ssh_host_ecdsa_key.pub # if -E option not supported. ``` 1. Compare the two fingerprints.