Auditing Ssh Trust And Agent Forwarding

Audit secure-shell trust hygiene, not cipher hardening: a forwarded authentication agent a remote host can abuse to log in as you elsewhere, client configuration or a proxy-command directive influenced by an untrusted source, host-key verification disabled or blind-accepted so a machine-in-the-middle succeeds, and authorized-key entries whose forced command can be escaped or whose source and forwarding are unrestricted. Covers agent-socket exposure on multi-user or untrusted hosts, config and proxy-command injection from attacker-controlled data, trust-on-first-use gaps, and permissive key options. Use when auditing how hosts and users establish secure-shell trust and what a compromised endpoint can reach. The forwarded socket, injected directive, or unverified key is the source, authentication or command execution as an unintended identity is the sink.

UnboundCompute 18439f7 9.5 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-ssh-trust-and-agent-forwarding commit 18439f7577

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-ssh-trust-and-agent-forwarding