4 ms·
One of my favorites, from: http://www.phrack.org/issues.html?issue=64&id=4&page=2 http://www.phrack.org/issues.html?issue=64&id=4&page... See: An almost invis
by raffi 16y ago
One of my favorites, from:
http://www.phrack.org/issues.html?issue=64&id=4&page=2 http://www.phrack.org/issues.html?issue=64&id=4&page...
See: An almost invisible ssh connection
ssh -T user@host /bin/bash -i
This connects you to a box with no TTY allocation. If someone types 'w', they will not see your connection.
- alnayyir 16y agoOkay, you've done the trick, now what's the reveal? How do you readily detect someone who has started their shell without TTY allocation?
- daten 16y agoThe sshd process for your connection is still present on the server and looks like: "sshd: username@notty". You can find it easily with a grep of running processes. ps aux | grep sshd.*notty
- timtadh 16y agoif you are running sshd on port 22 this will show you all connections going into it sudo lsof -i :22 you can then reverse what people are doing based on the pids lsof gives you. [edit: using ps ax | grep sshd also works but you can't see where they are connecting from. [+1 daten]]
- astrim 16y agoThis is much better ssh -t user@host screen -ln since you get a full fledged shell with job control and everything