RedShrew LogoREDSHREW

PhantomKey Demo

Your an attacker and found a key. Now what...

Found in /var/backups/id_rsa.bak — last modified 3 days ago

-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAADAQABAAABAQC7...
...R3UgZXZlbiByZWFkIHRoaXMuIEdvb2QgbG9jawogIAogICAK
-----END OPENSSH PRIVATE KEY-----
$ ssh -i /var/backups/id_rsa.bak root@decoy.dev.red
Permission denied (publickey).