daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ssh-forward-agent-exploitation.md (3099B)


      1 ---
      2 title: "SSH Agent Forwarding Exploitation"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/user-information/ssh-forward-agent-exploitation.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/user-information/ssh-forward-agent-exploitation.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SSH Agent Forwarding Exploitation
     14 
     15 ## Summary
     16 
     17 What can you do if the system-wide SSH client configuration (commonly `/etc/ssh/ssh_config`) or `$HOME/.ssh/config` contains the following directive?<sup>[[3]](#references)</sup>
     18 
     19 ```text
     20 ForwardAgent yes
     21 ```
     22 
     23 `ForwardAgent yes` forwards the authentication agent to the remote host for matching connections. If you have root on an intermediate host where another user's agent was forwarded, you can access the forwarded Unix-domain socket and ask that agent to authenticate with its loaded identities; this can let you access hosts where those identities are authorized.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup>
     24 
     25 Useful socket hunting commands on Linux systems include (the exact socket directory depends on the client and forwarding setup):<sup>[[1]](#references)[[2]](#references)</sup>
     26 
     27 ```bash
     28 ls -la /run/user/*/ssh-* /tmp/ssh-* 2>/dev/null
     29 find /run/user /tmp -type s -name 'agent.*' 2>/dev/null
     30 ```
     31 
     32 If you have access to Bob's forwarded socket, use it for an SSH connection:<sup>[[1]](#references)[[2]](#references)</sup>
     33 
     34 ```bash
     35 SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh bob@boston
     36 ```
     37 
     38 ### Why does this work?
     39 
     40 Setting `SSH_AUTH_SOCK` points the SSH client at a Unix-domain socket for the agent; it does not load Bob's private-key file. The agent performs private-key operations itself and returns the result, rather than sending private-key material to the client or over the network.<sup>[[1]](#references)[[2]](#references)</sup>
     41 
     42 If Bob has already loaded a key into the agent and that key is authorized on another host, anyone who can use the socket can ask the agent to authenticate there as Bob without knowing the key's passphrase at request time; confirmation and destination constraints may still limit the request.<sup>[[1]](#references)[[2]](#references)[[4]](#references)</sup>
     43 
     44 Access to the socket is normally enough; extracting key material from the agent process is unnecessary and is not part of the agent protocol. The owning user or root may be able to bypass socket permissions, so protect hosts receiving forwarded agents accordingly.<sup>[[2]](#references)[[3]](#references)</sup>
     45 
     46 ## Long explanation and exploitation
     47 
     48 **Read [Clockwork's original research](https://www.clockwork.com/insights/ssh-agent-hijacking/)**.<sup>[[1]](#references)</sup>
     49 
     50 ## References
     51 
     52 - [1] [SSH Agent Hijacking](https://www.clockwork.com/insights/ssh-agent-hijacking/)
     53 - [2] [ssh-agent(1)](https://man.openbsd.org/ssh-agent.1)
     54 - [3] [ssh_config(5)](https://man.openbsd.org/ssh_config.5)
     55 - [4] [ssh-add(1)](https://man.openbsd.org/ssh-add.1)