Well today super sucked. Here's one of my favorite techniques for lateral movement: SSH agent forwarding. Use a UNIX-domain socket to advance your presence on the network. No need for passwords or keys.
The socket info can also be pulled from environment info, e.g. /proc/<pid>/environ. Permissions on the temp directory are 0700 in my experience, so you'll likely need access as that account or root. Works great when I have a shell but no creds.
Peep game on the gist for extra hacks on SSH configs from @0xdade and Kerberos, ssh-add, and SSH tunnels from @wvuuuuuuuuuuuuu. Hack all the things!
You can follow @int0x80.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.