【问题标题】:Secure way to use password in bash and expect在 bash 中使用密码的安全方法并期望
【发布时间】:2018-08-27 21:36:55
【问题描述】:

bash 如何使用密码安全地调用期望脚本?

我有两个脚本:一个由用户直接执行的 bash 脚本,以及一个由 bash 脚本调用并使用 bash 脚本中提供的密码登录到远程主机的期望脚本。

bash 脚本 (main.sh)

#!/bin/bash

read -p "User: " user
read -s -p "Password: " password

./login.expect "$user" "$password"

期望脚本(login.expect)

#!/usr/bin/expect --

set user [lindex $argv 0]
set password [lindex $argv 1]
set host 192.168.1.15

spawn ssh $user@$host
expect -re ".*ssword.*" { send "$password\n" }    # Send password
expect -re ":~\\\$" { send "ls\n" }               # Do stuff
expect -re ":~\\\$" { send "exit\n" }             # exit

此设置的至少一个问题是有人可以通过使用“ps -ef”查看进程来获知密码,因为密码是在命令行上提供的。

这些脚本与我的实际脚本相比大大简化了,因为我只是想了解这部分是否可以以某种方式安全地完成。我的实际用例非常复杂,需要将 bash 和 expect 脚本分开,所以我不能只将 expect 嵌入 bash 中,也不能从 expect 脚本中请求密码。同样不幸的是,ssh 密钥不是无密码登录的选项。我可以重组期望脚本以通过命令行选项以外的方式获取密码,但我不确定什么是好的选择。

我现在最好的选择是在 bash 中加密密码,将加密的密码作为参数传递给期望脚本,并期望解密密码(我没有为此制定出确切的机制)。

有没有更好的办法?

【问题讨论】:

标签: bash encryption passwords expect


【解决方案1】:

您可以在某种程度上安全地通过环境传递密码,因为它只能由同一用户和 root 读取。在 shell export password 和 expect 脚本中

set password $env(password)

【讨论】:

  • 谢谢你!如果可行,我将对此进行测试并接受作为答案。
【解决方案2】:

从文件中读取密码

set passfile [open "~/.sshpass" r]
gets $passfile userpass
close $passfile

还有chmod 700 ~/.sshpass

【讨论】:

    猜你喜欢
    • 2020-03-08
    • 1970-01-01
    • 1970-01-01
    • 2011-07-10
    • 2016-01-22
    • 1970-01-01
    • 1970-01-01
    • 2011-02-03
    • 1970-01-01
    相关资源
    最近更新 更多