[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYY-XVrD22lt0MXLEYrmaZkJaVUPU8WpX4SIgz2S79gQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},840,"How can I implement an SSH password authentication program in Python for penetration testing?","You can use the third-party library paramiko to create an SSH password authentication program. The [Penetration Basics - Bypassing SSH Logs](\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs) article provides sample code that supports both password and certificate file login. This approach enables automated SSH login attempts during penetration testing, but remember that such tools should only be used on systems you own or have explicit permission to test.","\u003Cp>You can use the third-party library paramiko to create an SSH password authentication program. The [Penetration Basics - Bypassing SSH Logs](\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs) article provides sample code that supports both password and certificate file login. This approach enables automated SSH login attempts during penetration testing, but remember that such tools should only be used on systems you own or have explicit permission to test.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-implement-an-ssh-password-authentication-program-in-python-for-penetra-1777481576804","paramiko, SSH password authentication, penetration testing, Python",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},206,"Penetration Basics - Bypassing SSH Logs","penetration-basics-bypassing-ssh-logs","Learn SSH penetration basics: bypass logs, brute force techniques, and defensive detection methods for secure remote access testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SSH is a network protocol used for encrypted login between computers, commonly employed for remote access to Linux systems.\u003C\u002Fp>\u003Cp>In penetration testing, it is often necessary to consider SSH password brute-forcing and log deletion.\u003C\u002Fp>\u003Cp>This article will introduce some foundational aspects related to penetration testing, providing detection recommendations alongside exploitation methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Program Implementation of SSH Password Authentication\u003C\u002Fli>\u003Cli>Deletion of SSH Logs\u003C\u002Fli>\u003Cli>Bypassing SSH Logs\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Program Implementation of SSH Password Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Python Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library paramiko, the usage is very simple\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports password login and certificate file login\u003C\u002Fp>\u003Ch3>2. C# Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library SSH.NET, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u003C\u002Fp>\u003Cp>Download link for the compiled DLL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-bin.zip\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-help.chm\u003C\u002Fp>\u003Cp>After referencing Renci.SshNet.dll in the program, the usage is also very simple\u003C\u002Fp>\u003Cp>The following issues need to be noted when writing the program:\u003C\u002Fp>\u003Ch4>(1) Using certificate login\u003C\u002Fh4>\u003Cp>SSH.NET has specific requirements for certificate formats. The SSH.NET-2016.1.0-help.chm indicates it must be BEGIN RSA PRIVATE KEY, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017303901_0_5d59c6f7c9.jpeg\">\u003C\u002Fp>\u003Cp>When using the command ssh-keygen -t rsa, the default generated key file is in a new format: BEGIN OPENSSH PRIVATE KEY, requiring a conversion.\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use puttygen for conversion. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.chiark.greenend.org.uk\u002F~sgtatham\u002Fputty\u002Flatest.html\u003C\u002Fp>\u003Cp>Select Load to import the key.\u003C\u002Fp>\u003Cp>Export method:\u003C\u002Fp>\u003Cp>Conversions-&gt;Export OpenSSH key\u003C\u002Fp>\u003Cp>Therefore, in programming, it is necessary to first read the certificate file content and verify if the format is correct.\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code requires the Renci.SshNet.dll corresponding to the .NET version and can be compiled using csc.exe. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe SharpSSHCheck_SSH.NET.cs \u002Fr:Renci.SshNet.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code supports both password login and certificate file login.\u003C\u002Fp>\u003Ch2>0x03 SSH Log Deletion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Logs related to SSH login operations are located in the following positions:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp, records failed login attempts, query command: lastb\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauth.log, records successfully authenticated users\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fsecure, records security-related log information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, records user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records current and past users who logged into the system, query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records users currently logged into the system, query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning until the last login, query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Viewing log content\u003C\u002Fh3>\u003Cp>For logs that cannot be viewed directly, use the strings command\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Replacing IP addresses in logs\u003C\u002Fh3>\u003Cp>Using the sed command to replace a specified IP\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>utmpdump \u002Fvar\u002Flog\u002Fwtmp | sed \"s\u002F192.168.112.151\u002F1.1.1.1\u002Fg\" | utmpdump -r &gt; \u002Ftmp\u002Fwtmp11 &amp;&amp; mv \u002Ftmp\u002Fwtmp11 \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change 192.168.112.151 to 1.1.1.1\u003C\u002Fp>\u003Ch3>3. Delete specified lines from logs\u003C\u002Fh3>\u003Cp>Using the sed command to delete specified lines\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sed -i '\u002FMay 1 23:17:39\u002Fd' \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete lines starting with \"May 1 23:17:39\" in \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003Ch3>4. Evade administrator w command\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 1 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the \u002Fvar\u002Frun\u002Futmp file\u003C\u002Fp>\u003Ch3>5. Clear login logs for a specified IP\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 2 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003Ch3>6. Modify last login time and location\u003C\u002Fh3>\u003Cp>Requires the use of logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 3 -u re4lity -i 192.168.0.188 -t tty1 -d 2014:05:28:10:11:12\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Flastlog\u003C\u002Fp>\u003Ch3>7. Clear command history of the current session\u003C\u002Fh3>\u003Cp>Execute before exiting the session:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>history -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Bypassing SSH Logging\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If we use an SSH client (e.g., putty) for login, log cleanup needs to be considered, which is quite troublesome\u003C\u002Fp>\u003Cp>Here is a method to bypass various logging mechanisms: use protocols such as sftp, rsync, scp for login (notty)\u003C\u002Fp>\u003Cp>Here are two implementation methods:\u003C\u002Fp>\u003Cp>The two SSH password authentication programs (Python and C#) introduced in 0x02 precisely utilize notty\u003C\u002Fp>\u003Cp>I have added command execution functionality to the password authentication program, with the corresponding code addresses as follows:\u003C\u002Fp>\u003Cp>Python implementation: an open-source project\u003C\u002Fp>\u003Cp>C# implementation: an open-source project\u003C\u002Fp>\u003Cp>Both codes support executing single commands and interactive shells\u003C\u002Fp>\u003Cp>Select the interactive shell respectively and execute the following command to obtain the connection type:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps -aux|grep sshd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the connection type is notty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017330224_1_46d6513d2d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using putty for remote connection, the type at this point is pts\u002F2, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017380931_2_50eb3156b5.jpeg\">\u003C\u002Fp>\u003Cp>Testing shows that using notty can bypass the following logs:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, which records the user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records information about users who have logged in and previously logged into the system. Query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records information about users currently logged into the system. Query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning up to the previous login. Query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enhance SSH daemon, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.putorius.net\u002Fhow-to-secure-ssh-daemon.html\u003C\u002Fp>\u003Cp>Detection of notty connections:\u003C\u002Fp>\u003Col>\u003Cli>View failed login attempts, query command: lastb, file location: \u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>View authenticated users, file location: \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fli>\u003Cli>View TCP connections, query command: netstat -vatn\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of SSH in penetration testing (log deletion and log bypass), opensources 4 implementation codes (password verification and command execution), and provides detection recommendations based on exploitation methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SSH is a network protocol used for encrypted login between computers, commonly employed for remote access to Linux systems.\u003C\u002Fp>\u003Cp>In penetration testing, it is often necessary to consider SSH password brute-forcing and log deletion.\u003C\u002Fp>\u003Cp>This article will introduce some foundational aspects related to penetration testing, providing detection recommendations alongside exploitation methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Program Implementation of SSH Password Authentication\u003C\u002Fli>\u003Cli>Deletion of SSH Logs\u003C\u002Fli>\u003Cli>Bypassing SSH Logs\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Program Implementation of SSH Password Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Python Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library paramiko, the usage is very simple\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports password login and certificate file login\u003C\u002Fp>\u003Ch3>2. C# Implementation\u003C\u002Fh3>\u003Cp>Using the third-party library SSH.NET, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u003C\u002Fp>\u003Cp>Download link for the compiled DLL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-bin.zip\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsshnet\u002FSSH.NET\u002Freleases\u002Fdownload\u002F2016.1.0\u002FSSH.NET-2016.1.0-help.chm\u003C\u002Fp>\u003Cp>After referencing Renci.SshNet.dll in the program, the usage is also very simple\u003C\u002Fp>\u003Cp>The following issues need to be noted when writing the program:\u003C\u002Fp>\u003Ch4>(1) Using certificate login\u003C\u002Fh4>\u003Cp>SSH.NET has specific requirements for certificate formats. The SSH.NET-2016.1.0-help.chm indicates it must be BEGIN RSA PRIVATE KEY, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017303901_0_5d59c6f7c9-1.jpeg\">\u003C\u002Fp>\u003Cp>When using the command ssh-keygen -t rsa, the default generated key file is in a new format: BEGIN OPENSSH PRIVATE KEY, requiring a conversion.\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use puttygen for conversion. Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.chiark.greenend.org.uk\u002F~sgtatham\u002Fputty\u002Flatest.html\u003C\u002Fp>\u003Cp>Select Load to import the key.\u003C\u002Fp>\u003Cp>Export method:\u003C\u002Fp>\u003Cp>Conversions-&gt;Export OpenSSH key\u003C\u002Fp>\u003Cp>Therefore, in programming, it is necessary to first read the certificate file content and verify if the format is correct.\u003C\u002Fp>\u003Cp>My code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code requires the Renci.SshNet.dll corresponding to the .NET version and can be compiled using csc.exe. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe SharpSSHCheck_SSH.NET.cs \u002Fr:Renci.SshNet.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code supports both password login and certificate file login.\u003C\u002Fp>\u003Ch2>0x03 SSH Log Deletion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Logs related to SSH login operations are located in the following positions:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp, records failed login attempts, query command: lastb\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauth.log, records successfully authenticated users\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fsecure, records security-related log information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, records user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records current and past users who logged into the system, query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records users currently logged into the system, query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning until the last login, query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Viewing log content\u003C\u002Fh3>\u003Cp>For logs that cannot be viewed directly, use the strings command\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Replacing IP addresses in logs\u003C\u002Fh3>\u003Cp>Using the sed command to replace a specified IP\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>utmpdump \u002Fvar\u002Flog\u002Fwtmp | sed \"s\u002F192.168.112.151\u002F1.1.1.1\u002Fg\" | utmpdump -r &gt; \u002Ftmp\u002Fwtmp11 &amp;&amp; mv \u002Ftmp\u002Fwtmp11 \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change 192.168.112.151 to 1.1.1.1\u003C\u002Fp>\u003Ch3>3. Delete specified lines from logs\u003C\u002Fh3>\u003Cp>Using the sed command to delete specified lines\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sed -i '\u002FMay 1 23:17:39\u002Fd' \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete lines starting with \"May 1 23:17:39\" in \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fp>\u003Ch3>4. Evade administrator w command\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 1 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the \u002Fvar\u002Frun\u002Futmp file\u003C\u002Fp>\u003Ch3>5. Clear login logs for a specified IP\u003C\u002Fh3>\u003Cp>Requires logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 2 -u re4lity -i 192.168.0.188\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fp>\u003Ch3>6. Modify last login time and location\u003C\u002Fh3>\u003Cp>Requires the use of logtamper\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python logtamper.py -m 3 -u re4lity -i 192.168.0.188 -t tty1 -d 2014:05:28:10:11:12\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Achieved by modifying the file \u002Fvar\u002Flog\u002Flastlog\u003C\u002Fp>\u003Ch3>7. Clear command history of the current session\u003C\u002Fh3>\u003Cp>Execute before exiting the session:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>history -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Bypassing SSH Logging\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If we use an SSH client (e.g., putty) for login, log cleanup needs to be considered, which is quite troublesome\u003C\u002Fp>\u003Cp>Here is a method to bypass various logging mechanisms: use protocols such as sftp, rsync, scp for login (notty)\u003C\u002Fp>\u003Cp>Here are two implementation methods:\u003C\u002Fp>\u003Cp>The two SSH password authentication programs (Python and C#) introduced in 0x02 precisely utilize notty\u003C\u002Fp>\u003Cp>I have added command execution functionality to the password authentication program, with the corresponding code addresses as follows:\u003C\u002Fp>\u003Cp>Python implementation: an open-source project\u003C\u002Fp>\u003Cp>C# implementation: an open-source project\u003C\u002Fp>\u003Cp>Both codes support executing single commands and interactive shells\u003C\u002Fp>\u003Cp>Select the interactive shell respectively and execute the following command to obtain the connection type:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps -aux|grep sshd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the connection type is notty, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017330224_1_46d6513d2d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using putty for remote connection, the type at this point is pts\u002F2, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017380931_2_50eb3156b5-1.jpeg\">\u003C\u002Fp>\u003Cp>Testing shows that using notty can bypass the following logs:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Flastlog, which records the user's last login information\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp, records information about users who have logged in and previously logged into the system. Query command: last\u003C\u002Fli>\u003Cli>\u002Fvar\u002Frun\u002Futmp, records information about users currently logged into the system. Query command: w\u003C\u002Fli>\u003Cli>~\u002F.bash_history, records commands executed from the beginning up to the previous login. Query command: history\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Enhance SSH daemon, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.putorius.net\u002Fhow-to-secure-ssh-daemon.html\u003C\u002Fp>\u003Cp>Detection of notty connections:\u003C\u002Fp>\u003Col>\u003Cli>View failed login attempts, query command: lastb, file location: \u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>View authenticated users, file location: \u002Fvar\u002Flog\u002Fauth.log\u003C\u002Fli>\u003Cli>View TCP connections, query command: netstat -vatn\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of SSH in penetration testing (log deletion and log bypass), opensources 4 implementation codes (password verification and command execution), and provides detection recommendations based on exploitation methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",738,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"SSH Penetration Testing: Bypass Logs & Secure Detection Tips","SSH penetration testing, bypass SSH logs, SSH brute force, log deletion, cybersecurity detection",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],843,842,841,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.267Z","2026-07-23T16:02:11.154Z","draft","2026-07-23T16:15:03.522Z"]