Closed clem9669 closed 2 years ago
As far as I can see in the code, linpeas is looking for files called "agent*" in /tmp and printing the word ForwardAgent in red from the SSH config. Is there anything you would add/change to check for this privesc?
My bad, I missed it 😄
Hey folks,
To my knowledge, linPEAS do not check for SSH_AUTH_SOCK as described here: https://book.hacktricks.xyz/linux-unix/privilege-escalation/ssh-forward-agent-exploitation
Thanks 😄