SSH Password Harvesting with eBPF

TL;DR
Six years ago I wrote SSHD Injection and Password Harvesting. The idea was simple: ptrace into sshd, scan its code for a byte pattern, overwrite the next instruction with INT3, wait for the breakpoint, read the password out of a register, restore the byte, detach.
This is the …
more ...