3 ms·
Where is it storing the keys? The amount of clients I have tested that store keys in plaintext locally on the hard drive. It is mostly trivial to hoover these u
by bikeshack 11y ago
Where is it storing the keys? The amount of clients I have tested that store keys in plaintext locally on the hard drive. It is mostly trivial to hoover these up if you are so inclined. Most malware checks for the default paths to keys on your system. Of course, if the value you enter is checked against a hash we are fine, but most people do not take that step of entering the pass each time. In other words, if I can fire up the application and suddenly I'm in an SSH session, so can anybody else. A common technique I have seen in some clients is using the machine GUID as a salt to login, but even that can be hoovered up by malware and replayed on another system.