2 ms·
Yes. https://thc.org/ssh-it/ https://thc.org/ssh-it/ being a more recent implementation of the same concept, using $PATH modification instead of LD_PRELOAD. It
by fullspectrumdev 2y ago
Yes. https://thc.org/ssh-it/ https://thc.org/ssh-it/ being a more recent implementation of the same concept, using $PATH modification instead of LD_PRELOAD.
It also has some other optional tricks such as searching for unprotected SSH keys and the likes.
This kind of thing can be deeply interesting to run in environments where developers share things like jump boxes, to determine the “blast radius” of a compromised account over time as part of a security exercise.