Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Stealing unencrypted SSH-agent keys from memory

Summary

SSH-agent holds decrypted keys in memory to spare users passphrases, but root attackers can dump that memory with gdb via ptrace and reconstruct private keys, for fast pivoting to other machines.
Published
Collected

original ↗