[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBiaNULEytDr5Y93ND9vSCQXFgE7V6zuw3lAmndvgZZ0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},843,"How can defenders detect 'notty' SSH connections and other stealthy SSH activity?","Defenders can detect notty connections by reviewing `\u002Fvar\u002Flog\u002Fauth.log` for authentication records and using `netstat -vatn` to check TCP connections. Failed login attempts are still logged in `\u002Fvar\u002Flog\u002Fbtmp` (accessible via `lastb`). Additionally, enhancing the SSH daemon configuration (following guides like the one from putorius.net) and monitoring for unusual connection patterns helps. For Windows-specific log evasion, refer to [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance).","\u003Cp>Defenders can detect notty connections by reviewing `\u002Fvar\u002Flog\u002Fauth.log` for authentication records and using `netstat -vatn` to check TCP connections. Failed login attempts are still logged in `\u002Fvar\u002Flog\u002Fbtmp` (accessible via `lastb`). Additionally, enhancing the SSH daemon configuration (following guides like the one from putorius.net) and monitoring for unusual connection patterns helps. For Windows-specific log evasion, refer to [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-defenders-detect-notty-ssh-connections-and-other-stealthy-ssh-activity-1777481576995","notty detection, SSH security, netstat, lastb, auth.log",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},206,"Penetration Basics - Bypassing SSH Logs","penetration-basics-bypassing-ssh-logs","Learn SSH penetration basics: bypass logs, brute force techniques, and defensive detection methods for secure remote access testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SSH is a network protocol used for encrypted login between computers, commonly employed for remote access to Linux systems.\u003C\u002Fp>\u003Cp>In penetration testing, it is often necessary to consider SSH password brute-forcing and log deletion.\u003C\u002Fp>\u003Cp>This article will introduce some foundational aspects related to penetration testing, providing detection recommendations alongside exploitation methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Program Implementation of SSH Password Authentication\u003C\u002Fli>\u003Cli>Deletion of SSH Logs\u003C\u002Fli>\u003Cli>Bypassing SSH Logs\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Program Implementation of SSH Password Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Python Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library paramiko, the usage is very simple\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports password login and certificate file login\u003C\u002Fp>\u003Ch3>2. C# Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library SSH.NET, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u003C\u002Fp>\u003Cp>Download link for the compiled DLL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-bin.zip\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-help.chm\u003C\u002Fp>\u003Cp>After referencing Renci.SshNet.dll in the program, the usage is also very simple\u003C\u002Fp>\u003Cp>The following issues need to be noted when writing the program:\u003C\u002Fp>\u003Ch4>(1) Using certificate login\u003C\u002Fh4>\u003Cp>SSH.NET has specific requirements for certificate formats. The SSH.NET-2016.1.0-help.chm indicates it must be BEGIN RSA PRIVATE KEY, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017303901_0_5d59c6f7c9.jpeg\">\u003C\u002Fp>\u003Cp>When using the command ssh-keygen -t rsa, the default generated key file is in a new format: BEGIN OPENSSH PRIVATE KEY, requiring a conversion.\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use puttygen for conversion. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.chiark.greenend.org.uk\u002F~sgtatham\u002Fputty\u002Flatest.html\u003C\u002Fp>\u003Cp>Select Load to import the key.\u003C\u002Fp>\u003Cp>Export method:\u003C\u002Fp>\u003Cp>Conversions-&gt;Export OpenSSH key\u003C\u002Fp>\u003Cp>Therefore, in programming, it is necessary to first read the certificate file content and verify if the format is correct.\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code requires the Renci.SshNet.dll corresponding to the .NET version and can be compiled using csc.exe. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe SharpSSHCheck_SSH.NET.cs \u002Fr:Renci.SshNet.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code supports both password login and certificate file login.\u003C\u002Fp>\u003Ch2>0x03 SSH Log Deletion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Logs related to SSH login operations are located in the following positions:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp, records failed login attempts, query command: lastb\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauth.log, records successfully authenticated users\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fsecure, records security-related log information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, records user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records current and past users who logged into the system, query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records users currently logged into the system, query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning until the last login, query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Viewing log content\u003C\u002Fh3>\u003Cp>For logs that cannot be viewed directly, use the strings command\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Replacing IP addresses in logs\u003C\u002Fh3>\u003Cp>Using the sed command to replace a specified IP\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>utmpdump \u002Fvar\u002Flog\u002Fwtmp | sed \"s\u002F192.168.112.151\u002F1.1.1.1\u002Fg\" | utmpdump -r &gt; \u002Ftmp\u002Fwtmp11 &amp;&amp; mv \u002Ftmp\u002Fwtmp11 \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change 192.168.112.151 to 1.1.1.1\u003C\u002Fp>\u003Ch3>3. Delete specified lines from logs\u003C\u002Fh3>\u003Cp>Using the sed command to delete specified lines\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sed -i '\u002FMay 1 23:17:39\u002Fd' \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete lines starting with \"May 1 23:17:39\" in \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003Ch3>4. Evade administrator w command\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 1 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the \u002Fvar\u002Frun\u002Futmp file\u003C\u002Fp>\u003Ch3>5. Clear login logs for a specified IP\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 2 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003Ch3>6. Modify last login time and location\u003C\u002Fh3>\u003Cp>Requires the use of logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 3 -u re4lity -i 192.168.0.188 -t tty1 -d 2014:05:28:10:11:12\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Flastlog\u003C\u002Fp>\u003Ch3>7. Clear command history of the current session\u003C\u002Fh3>\u003Cp>Execute before exiting the session:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>history -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Bypassing SSH Logging\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If we use an SSH client (e.g., putty) for login, log cleanup needs to be considered, which is quite troublesome\u003C\u002Fp>\u003Cp>Here is a method to bypass various logging mechanisms: use protocols such as sftp, rsync, scp for login (notty)\u003C\u002Fp>\u003Cp>Here are two implementation methods:\u003C\u002Fp>\u003Cp>The two SSH password authentication programs (Python and C#) introduced in 0x02 precisely utilize notty\u003C\u002Fp>\u003Cp>I have added command execution functionality to the password authentication program, with the corresponding code addresses as follows:\u003C\u002Fp>\u003Cp>Python implementation: an open-source project\u003C\u002Fp>\u003Cp>C# implementation: an open-source project\u003C\u002Fp>\u003Cp>Both codes support executing single commands and interactive shells\u003C\u002Fp>\u003Cp>Select the interactive shell respectively and execute the following command to obtain the connection type:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps -aux|grep sshd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the connection type is notty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017330224_1_46d6513d2d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using putty for remote connection, the type at this point is pts\u002F2, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017380931_2_50eb3156b5.jpeg\">\u003C\u002Fp>\u003Cp>Testing shows that using notty can bypass the following logs:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, which records the user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records information about users who have logged in and previously logged into the system. Query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records information about users currently logged into the system. Query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning up to the previous login. Query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enhance SSH daemon, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.putorius.net\u002Fhow-to-secure-ssh-daemon.html\u003C\u002Fp>\u003Cp>Detection of notty connections:\u003C\u002Fp>\u003Col>\u003Cli>View failed login attempts, query command: lastb, file location: \u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>View authenticated users, file location: \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fli>\u003Cli>View TCP connections, query command: netstat -vatn\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of SSH in penetration testing (log deletion and log bypass), opensources 4 implementation codes (password verification and command execution), and provides detection recommendations based on exploitation methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SSH is a network protocol used for encrypted login between computers, commonly employed for remote access to Linux systems.\u003C\u002Fp>\u003Cp>In penetration testing, it is often necessary to consider SSH password brute-forcing and log deletion.\u003C\u002Fp>\u003Cp>This article will introduce some foundational aspects related to penetration testing, providing detection recommendations alongside exploitation methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Program Implementation of SSH Password Authentication\u003C\u002Fli>\u003Cli>Deletion of SSH Logs\u003C\u002Fli>\u003Cli>Bypassing SSH Logs\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Program Implementation of SSH Password Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Python Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library paramiko, the usage is very simple\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports password login and certificate file login\u003C\u002Fp>\u003Ch3>2. C# Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library SSH.NET, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u003C\u002Fp>\u003Cp>Download link for the compiled DLL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-bin.zip\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-help.chm\u003C\u002Fp>\u003Cp>After referencing Renci.SshNet.dll in the program, the usage is also very simple\u003C\u002Fp>\u003Cp>The following issues need to be noted when writing the program:\u003C\u002Fp>\u003Ch4>(1) Using certificate login\u003C\u002Fh4>\u003Cp>SSH.NET has specific requirements for certificate formats. The SSH.NET-2016.1.0-help.chm indicates it must be BEGIN RSA PRIVATE KEY, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017303901_0_5d59c6f7c9-1.jpeg\">\u003C\u002Fp>\u003Cp>When using the command ssh-keygen -t rsa, the default generated key file is in a new format: BEGIN OPENSSH PRIVATE KEY, requiring a conversion.\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use puttygen for conversion. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.chiark.greenend.org.uk\u002F~sgtatham\u002Fputty\u002Flatest.html\u003C\u002Fp>\u003Cp>Select Load to import the key.\u003C\u002Fp>\u003Cp>Export method:\u003C\u002Fp>\u003Cp>Conversions-&gt;Export OpenSSH key\u003C\u002Fp>\u003Cp>Therefore, in programming, it is necessary to first read the certificate file content and verify if the format is correct.\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code requires the Renci.SshNet.dll corresponding to the .NET version and can be compiled using csc.exe. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe SharpSSHCheck_SSH.NET.cs \u002Fr:Renci.SshNet.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code supports both password login and certificate file login.\u003C\u002Fp>\u003Ch2>0x03 SSH Log Deletion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Logs related to SSH login operations are located in the following positions:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp, records failed login attempts, query command: lastb\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauth.log, records successfully authenticated users\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fsecure, records security-related log information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, records user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records current and past users who logged into the system, query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records users currently logged into the system, query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning until the last login, query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Viewing log content\u003C\u002Fh3>\u003Cp>For logs that cannot be viewed directly, use the strings command\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Replacing IP addresses in logs\u003C\u002Fh3>\u003Cp>Using the sed command to replace a specified IP\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>utmpdump \u002Fvar\u002Flog\u002Fwtmp | sed \"s\u002F192.168.112.151\u002F1.1.1.1\u002Fg\" | utmpdump -r &gt; \u002Ftmp\u002Fwtmp11 &amp;&amp; mv \u002Ftmp\u002Fwtmp11 \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change 192.168.112.151 to 1.1.1.1\u003C\u002Fp>\u003Ch3>3. Delete specified lines from logs\u003C\u002Fh3>\u003Cp>Using the sed command to delete specified lines\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sed -i '\u002FMay 1 23:17:39\u002Fd' \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete lines starting with \"May 1 23:17:39\" in \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003Ch3>4. Evade administrator w command\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 1 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the \u002Fvar\u002Frun\u002Futmp file\u003C\u002Fp>\u003Ch3>5. Clear login logs for a specified IP\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 2 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003Ch3>6. Modify last login time and location\u003C\u002Fh3>\u003Cp>Requires the use of logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 3 -u re4lity -i 192.168.0.188 -t tty1 -d 2014:05:28:10:11:12\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Flastlog\u003C\u002Fp>\u003Ch3>7. Clear command history of the current session\u003C\u002Fh3>\u003Cp>Execute before exiting the session:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>history -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Bypassing SSH Logging\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If we use an SSH client (e.g., putty) for login, log cleanup needs to be considered, which is quite troublesome\u003C\u002Fp>\u003Cp>Here is a method to bypass various logging mechanisms: use protocols such as sftp, rsync, scp for login (notty)\u003C\u002Fp>\u003Cp>Here are two implementation methods:\u003C\u002Fp>\u003Cp>The two SSH password authentication programs (Python and C#) introduced in 0x02 precisely utilize notty\u003C\u002Fp>\u003Cp>I have added command execution functionality to the password authentication program, with the corresponding code addresses as follows:\u003C\u002Fp>\u003Cp>Python implementation: an open-source project\u003C\u002Fp>\u003Cp>C# implementation: an open-source project\u003C\u002Fp>\u003Cp>Both codes support executing single commands and interactive shells\u003C\u002Fp>\u003Cp>Select the interactive shell respectively and execute the following command to obtain the connection type:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps -aux|grep sshd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the connection type is notty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017330224_1_46d6513d2d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using putty for remote connection, the type at this point is pts\u002F2, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017380931_2_50eb3156b5-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing shows that using notty can bypass the following logs:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, which records the user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records information about users who have logged in and previously logged into the system. Query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records information about users currently logged into the system. Query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning up to the previous login. Query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enhance SSH daemon, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.putorius.net\u002Fhow-to-secure-ssh-daemon.html\u003C\u002Fp>\u003Cp>Detection of notty connections:\u003C\u002Fp>\u003Col>\u003Cli>View failed login attempts, query command: lastb, file location: \u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>View authenticated users, file location: \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fli>\u003Cli>View TCP connections, query command: netstat -vatn\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of SSH in penetration testing (log deletion and log bypass), opensources 4 implementation codes (password verification and command execution), and provides detection recommendations based on exploitation methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",738,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"SSH Penetration Testing: Bypass Logs & Secure Detection Tips","SSH penetration testing, bypass SSH logs, SSH brute force, log deletion, cybersecurity detection",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],842,841,840,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.267Z","2026-07-23T16:02:11.154Z","draft","2026-07-23T16:15:04.280Z"]