Skip to content

Releases: dreamcatchered/swagssh

swagSSH 1.2.0

Choose a tag to compare

@dreamcatchered dreamcatchered released this 03 Sep 05:18

Admin panel

  • Live dashboard at /admin/ (password-protected, nginx-fronted): sessions with connected operators, traffic, TTL
  • Session history: ended sessions with who shared, who attached as operator and when
  • IP management: per-IP stats (connections, sessions, handshake failures, ID enumeration), block for 1h / 24h / 7d / 30d / forever
  • Persistent bans: all blocks are stored in a JSON file and survive restarts
  • Enumeration guard: 10 failed session lookups in 10 min from one IP → auto-block (24h → 7d → permanent on repeat)
  • Full event log: sessions, operators, transfers, bans, rejected connections
  • Login brute-force protection: 5 wrong passwords → 1h IP ban

Server flags: -admin 127.0.0.1:8022 -admin-password-file <path> -admin-prefix /admin -ban-file <path>

🤖 Generated with Claude Code

swagSSH 1.1.0 — file transfers, exec, custom IDs, resilience

Choose a tag to compare

@dreamcatchered dreamcatchered released this 03 Sep 03:04

What's new

📦 File transfers (scp-like)

  • swagssh send <id> <file-or-dir> — push files and whole directories (streamed tar) to the machine behind NAT
  • swagssh recv <id> <path> — pull files and directories back
  • Progress display, delivery confirmation, path-traversal protection on the receiving side

⚡ exec

  • swagssh exec <id> <command> — run a one-shot command on the remote machine, stream output, mirror the exit code

🏷 Custom session IDs with TTL

  • swagssh share --id my-laptop --ttl 30m — a memorable ID with a bounded lifetime (1m..24h)
  • TTL is enforced across reconnects (not renewed)

🛡 Security

  • TOFU host key verification: the relay's host key is pinned on first use; any change aborts the connection with a MITM warning
  • Handshake timeout, per-IP connection limits, session caps, session ID validation
  • Panic recovery per connection, graceful shutdown on SIGTERM

🔁 Resilience

  • Auto-reconnect: the share side re-establishes the relay connection with the same session ID; the local shell survives network drops
  • Keepalives on both ends, dial retries with exponential backoff
  • Half-close relay semantics so transfer confirmations survive a finished upload

🐛 Fixes

  • Terminal resize (window-change) was sent as a global request and silently dropped — now a proper channel request

Install

iwr -useb https://ssh.swag.best/install.ps1 | iex
curl -fsSL https://ssh.swag.best/install.sh | bash

Binaries for Linux/macOS/Windows (amd64, arm64, 386) are attached below. The relay server binary is swagssh-server-linux-amd64.

🤖 Generated with Claude Code