How can I remotely unlock a Windows workstation using SSH?

Viewed 1318

I'm running an OpenSSH server on a Windows 10 workstation, which I'm connecting to from Linux and using to run PowerShell scripts on the host machine, querying information about things like running processes and administrating the system.

I know that some actions such as remotely launching a gui application visible to users on the host machine are limited as a result of OpenSSH's sshd service existing in session 0 isolation. I've been able to work around this freely by scheduling anything I want to execute as a task with schtasks.exe and immediately running the task.

  • I can lock the workstation with rundll32.exe user32.dll,LockWorkStation
  • I can query whether the workstation is locked with Get-Process logonui
  • How would I unlock the system? I need something that could be automated at the click of a button on the client machine.

I've tried this third-party utility called Logon.exe, to no avail. I don't believe it is compatible with Windows 10.

I've even tried using SendKeys() with PowerShell to send the password's keystrokes while on the lockscreen and then press enter, as well as an AutoHotKey script to do the same. While the keystrokes cause the lockscreen to wake up, neither methods seem to be capable of creating any input in the password input field.

1 Answers

Here is the Microsoft Doc for Ref: https://docs.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse

Download


Get-WindowsCapability -Online | ? Name -like 'OpenSSH*'


Install. Ensure you install SSH server as that is what allows others to connect to you.


Install the OpenSSH Client

Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0


Install the OpenSSH Server

Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0


Configuration. Notice the inbound traffic rule. Super necessary.


Start the sshd service

Start-Service sshd


OPTIONAL but recommended:

Set-Service -Name sshd -StartupType 'Automatic'


Confirm the firewall rule is configured. It should be created automatically by setup.

Get-NetFirewallRule -Name ssh


There should be a firewall rule named "OpenSSH-Server-In-TCP", which should be enabled

If the firewall does not exist, create one

New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22


And finally, here is how you connect


ssh username@servername


Enjoy

PS. I tried with the formatting. I didn't want bold, it just kept happening captain. The internet decided it wanted to be bold today...

Related