Stealing unencrypted SSH-agent keys from memory
Summary
SSH-agent holds decrypted keys in memory to spare users passphrases, but root attackers can dump that memory with gdb via ptrace and reconstruct private keys, for fast pivoting to other machines.
- Published
- Collected
Skip to content