Hacker News new | ask | show | jobs
SSH caches keys of ongoing sessions in /tmp. Root can hijack, SSH to machine (twitter.com)
2 points by frogger8 1204 days ago
2 comments

Someone discovered either "ssh-agent" or ssh agent forwarding.

I bet the next tweet from that account is: "Red Teamers: Check out ~/.ssh for user ssh keys! root user can hijack them and SSH to any machine the user can access"

Um. Yeah. That's kinda how that whole root thing works.
lol fair response