https://github.com/citronneur/pamspy Skip to content Sign up * Product + Features + Mobile + Actions + Codespaces + Copilot + Packages + Security + Code review + Issues + Integrations + GitHub Sponsors + Customer stories * Team * Enterprise * Explore + Explore GitHub + Learn and contribute + Topics + Collections + Trending + Skills + GitHub Sponsors + Open source guides + Connect with others + The ReadME Project + Events + Community forum + GitHub Education + GitHub Stars program * Marketplace * Pricing + Plans + Compare plans + Contact Sales + Education [ ] * # In this repository All GitHub | Jump to | * No suggested jump to results * # In this repository All GitHub | Jump to | * # In this user All GitHub | Jump to | * # In this repository All GitHub | Jump to | Sign in Sign up {{ message }} citronneur / pamspy Public * Notifications * Fork 16 * Star 308 Credentials Dumper for Linux using eBPF License Apache-2.0 license 308 stars 16 forks Star Notifications * Code * Issues 0 * Pull requests 1 * Actions * Projects 0 * Wiki * Security * Insights More * Code * Issues * Pull requests * Actions * Projects * Wiki * Security * Insights citronneur/pamspy This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. main Switch branches/tags [ ] Branches Tags Could not load branches Nothing to show {{ refName }} default View all branches Could not load tags Nothing to show {{ refName }} default View all tags 1 branch 1 tag Code Latest commit @citronneur citronneur Update README.md ... e1ea136 Jul 5, 2022 Update README.md e1ea136 Git stats * 2 commits Files Permalink Failed to load latest commit information. Type Name Latest commit message Commit time .img Initial Commit Jul 4, 2022 libbpf @ 20f0330 Initial Commit Jul 4, 2022 src Initial Commit Jul 4, 2022 .gitignore Initial Commit Jul 4, 2022 .gitmodules Initial Commit Jul 4, 2022 LICENSE Initial Commit Jul 4, 2022 README.md Update README.md Jul 5, 2022 View code pamspy -- Credentials Dumper for Linux How to launch? How to build? How does It works? Credits and references README.md pamspy -- Credentials Dumper for Linux pamspy leverage eBPF technologies to achieve an equivalent work of 3snake. It will track a particular userland function inside the PAM (Pluggable Authentication Modules) library, used by many critical applications to handle authentication like: * sudo * sshd * passwd * gnome * x11 * and many other ... Demo How to launch? pamspy is built as a static binary without any dependencies, and available on the release page. Usage: pamspy [OPTION...] pamspy Uses eBPF to dump secrets use by PAM (Authentication) module By hooking the pam_get_authtok function in libpam.so USAGE: ./pamspy -p $(/usr/sbin/ldconfig -p | grep libpam.so | cut -d ' ' -f4) -d /var/log/trace.0 -d, --daemon=PATH TO OUTPUT CREDENTIALS Start pamspy in daemon mode and output in the file passed as argument -p, --path=PATH Path to the libpam.so file -r, --print-headers Print headers of the program -v, --verbose Verbose mode -?, --help Give this help list --usage Give a short usage message -V, --version Print program version Mandatory or optional arguments to long options are also mandatory or optional for any corresponding short options. Report bugs to . As pamspy rely on libpam, we have to set the path where libpam is installed on your distribution. To find where libpam is installed you can run the following command : > /usr/sbin/ldconfig -p | grep libpam.so | cut -d ' ' -f4 /lib/x86_64-linux-gnu/libpam.so.0 Once you get the path you can launch pamspy : > ./pamspy -p /lib/x86_64-linux-gnu/libpam.so.0 An easy way to launch pamspy is to use the following command : > ./pamspy -p $(/usr/sbin/ldconfig -p | grep libpam.so | cut -d ' ' -f4) pamspy can also be started as a daemon by providing an output file where credentials will be written: ./pamspy -p $(/usr/sbin/ldconfig -p | grep libpam.so | cut -d ' ' -f4) -d /tmp/credentials How to build? To build the static binary, we need third-party program. For eBPF we need clang to compile the C code into eBPF CO-RE code. We also rely on bpftool to create a skeleton from ebpf program to include it in our userland program. Then we need also libelf to find the correct symbol in libpam. sudo apt install make clang-11 gcc libelf-dev bpftool Then just build! git clone https://github.com/citronneur/pamspy --recursive cd pamspy/src make How does It works? pamspy will load a userland return probe eBPF program to hook the pam_get_authtok function from libpam.so. PAM stands for "Pluggable Authentication Modules", and have a flexible design to manage a different kind of authentication on Linux. Each time an authentication process tries to check a new user, It will call pam_get_authtok, and will be here to dump the content of the critical secrets! Easy! Enjoy! Credits and references Thanks to @blendin for 3snake tool !!! About Credentials Dumper for Linux using eBPF Resources Readme License Apache-2.0 license Stars 308 stars Watchers 5 watching Forks 16 forks Releases 1 Initial Release Latest Jul 4, 2022 Packages 0 No packages published Languages * C 99.9% * Makefile 0.1% Footer (c) 2022 GitHub, Inc. Footer navigation * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time. You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.