Unix / Linux - 通信
Unix / Linux - 网络通信工具
Section titled “Unix / Linux - 网络通信工具”在本章中,我们将探讨类 Unix 系统中必不可少的网络通信工具。在分布式环境中工作时,需要安全高效地与远程用户通信并访问远程系统。
现代的类 Unix 系统提供了一套用于网络交互的工具。我们将介绍用于诊断、远程访问和文件传输的基本工具,重点关注当前的最佳实践。
ping 工具
Section titled “ping 工具”ping 命令是一个基本工具,用于测试网络连通性。它向目标主机发送 ICMP ECHO_REQUEST 包,并等待 ECHO_RESPONSE 回复。这有助于验证远程主机是否可达并响应。
ping 的用途包括:
- 诊断基本的网络连通性问题。
- 确定远程主机是否在线。
- 粗略估计网络延迟(往返时间)。
- 识别丢包率。
ping 的基本语法是:
$ ping [options] hostname_or_ip-address默认情况下,ping 会持续发送数据包直到被中断。您可以通过按 Ctrl + C 来停止它。您通常可以使用 -c count 这样的选项来限制 ping 的次数(例如,ping -c 4 google.com)。
注意:某些网络防火墙可能会阻止 ICMP 请求,因此没有响应并不总是意味着主机已宕机,只是说明它没有响应 ping 请求。
检查 google.com 的可用性:
$ ping -c 4 google.comPING google.com (142.250.190.78) 56(84) bytes of data.64 bytes from lhr48s15-in-f14.1e100.net (142.250.190.78): icmp_seq=1 ttl=118 time=15.4 ms64 bytes from lhr48s15-in-f14.1e100.net (142.250.190.78): icmp_seq=2 ttl=118 time=15.9 ms64 bytes from lhr48s15-in-f14.1e100.net (142.250.190.78): icmp_seq=3 ttl=118 time=15.5 ms64 bytes from lhr48s15-in-f14.1e100.net (142.250.190.78): icmp_seq=4 ttl=118 time=15.2 ms
--- google.com ping statistics ---4 packets transmitted, 4 received, 0% packet loss, time 3005msrtt min/avg/max/mdev = 15.198/15.508/15.889/0.242 ms$如果主机无法解析或无法访问(且未阻止 ping 请求):
$ ping nonexistanthostname12345.comping: nonexistanthostname12345.com: Name or service not known$安全文件传输:scp 和 sftp
Section titled “安全文件传输:scp 和 sftp”在系统之间传输文件是一项常见任务。虽然存在较旧的 ftp(文件传输协议)工具,但强烈建议不要将其用于一般用途,因为它会以明文形式传输数据,包括用户名和密码,这非常不安全。
现代的最佳实践是使用利用 SSH(安全外壳协议)的安全替代方案:
scp(Secure Copy): 简单命令行工具,用于通过 SSH 在主机之间复制文件/目录。非常适合非交互式传输。sftp(SSH File Transfer Protocol): 一个交互式文件传输程序,用法类似于ftp,但通过安全的 SSH 连接进行操作。允许浏览远程目录、上传、下载等。
scp 和 sftp 都会加密整个会话,保护您的凭据和数据。
使用 scp
Section titled “使用 scp”基本语法类似于 cp 命令:
将本地文件复制到远程主机:
$ scp local_file.txt username@remotehost:/path/to/destination/从远程主机复制文件到本地机器:
$ scp username@remotehost:/path/to/remote_file.txt /local/destination/path/递归复制目录(使用 -r 选项):
$ scp -r local_directory username@remotehost:/path/to/destination/除非您配置了 SSH 密钥认证(建议频繁使用时采用),否则通常会提示您输入远程用户的密码。
使用 sftp
Section titled “使用 sftp”要启动交互式 sftp 会话:
$ sftp username@remotehost连接成功后,您会看到 sftp> 提示符。常用的命令包括:
ls: 列出远程系统上的文件。lls: 列出本地系统上的文件。cd path: 改变远程目录。lcd path: 改变本地目录。pwd: 显示当前远程目录。lpwd: 显示当前本地目录。get remote_file [local_file]: 下载文件。put local_file [remote_file]: 上传文件。mkdir directory: 创建远程目录。rm file: 删除远程文件。helpor?: 显示可用命令。quitorexit: 关闭会话。
sftp 会话示例片段:
$ sftp user@example.comConnected to example.com.sftp> pwdRemote working directory: /home/usersftp> lsDocuments Downloads myfile.txtsftp> get myfile.txtFetching /home/user/myfile.txt to myfile.txt/home/user/myfile.txt 100% 12KB 3.1MB/s 00:00sftp> lcd /tmpLocal working directory: /tmpsftp> put important_report.pdfUploading important_report.pdf to /home/user/important_report.pdfimportant_report.pdf 100% 512KB 10.2MB/s 00:00sftp> quit$对于更高级的文件同步任务,可以考虑使用 rsync 工具,它在传输文件差异时非常高效。
安全远程登录:ssh
Section titled “安全远程登录:ssh”要连接到远程 Unix/Linux 机器并使用其命令行,标准且安全的方法是使用 ssh(安全外壳协议)。它取代了较旧、不安全的协议,如 telnet 和 rlogin。
telnet 非常不安全,因为它以明文形式传输所有数据,包括密码。在不受信任的网络上绝不应该使用 telnet。
ssh 提供了一个安全的加密通道,用于远程登录会话和命令执行。
$ ssh [options] username@hostname_or_ip-address如果您的本地用户名与远程用户名相同,可以省略 username@:
$ ssh hostname_or_ip-address以用户 admin 连接到远程服务器 server.example.com:
$ ssh admin@server.example.comThe authenticity of host 'server.example.com (192.0.2.10)' can't be established.ECDSA key fingerprint is SHA256:AbCdEfGhIjKlMnOpQrStUvWxYzabcdefghijklmnop.Are you sure you want to continue connecting (yes/no/[fingerprint])? yesWarning: Permanently added 'server.example.com' (ECDSA) to the list of known hosts.admin@server.example.com's password:Last login: Mon Jul 25 10:00:00 2023 from client.example.org[admin@server ~]$ # You are now logged into the remote server[admin@server ~]$ pwd/home/admin[admin@server ~]$ lsDocuments Public Templates[admin@server ~]$ logoutConnection to server.example.com closed.$首次连接主机时,ssh 会要求您验证其主机密钥。后续连接将使用存储的密钥来防止中间人攻击。与 scp/sftp 一样,建议使用 SSH 密钥进行无密码登录,以获得更好的安全性和便利性。
已废弃的工具:finger
Section titled “已废弃的工具:finger”finger 命令过去常用于显示本地或远程系统上用户的信息(登录名、真实姓名、终端、登录时间等)。
然而,出于隐私和安全考虑(可能泄露敏感的用户信息),现代系统几乎普遍禁用了 finger 服务(fingerd)。虽然客户端命令可能仍然存在,但它不太可能对远程主机起作用,并且在实际使用中已被视为过时。