|
|
|
|
|
by LinuxBender
1542 days ago
|
|
I would not. I would phish you running a script that adds my public key to your authorized_keys and would ssh from your client in the background creating a gateway port back to you. At that point I can get your ssh keys and just about anything else. If systems in your org allow ssh multiplexing default is enabled then I can also piggy-back your sessions bypassing MFA/2FA. I say you but I mean most people. I'm certain that you specifically would not fall for it but about 10% [1] of technical people will. [1] - stats based on past career and testing of a large technical population. |
|