Default User SSH Authorized Key Risks on Linux
Videos Education Linux ForensicsDateDecember 09, 2024AuthorThe Sandfly Security TeamDefault Linux us 2024-12-10 05:59:7 Author: sandflysecurity.com(查看原文) 阅读量:25 收藏

Videos Education Linux Forensics

Date
December 09, 2024
Author
The Sandfly Security Team

Default Linux users with SSH authorized keys are a way for attackers to hide backdoor accounts that can avoid detection for some time. In this video we discuss and demonstrate the threat, why it's used, and how to find it with command line tools and automatic discovery with Sandfly, the agentless Linux EDR platform.

Sandfly is able to find this and many other types of Linux attacks without deploying any endpoint agents. Get your free license today or contact us for more information.


文章来源: https://sandflysecurity.com/blog/default-user-ssh-authorized-key-risks-on-linux/
如有侵权请联系:admin#unsafe.sh