Extend logging of openssh-server - e.g. plaintext password

Stephen Harris lists at spuddy.org
Sun Dec 18 11:48:23 AEDT 2016


On Sun, Dec 18, 2016 at 01:37:59AM +0100, Philipp Vlassakakis wrote:
> I want to extend the logging of the openssh-server, so it also logs the entered passwords in plaintext, and yes I know that this is a security issue, but relax, Password Authentication is disabled. ;)
> 
> The logging is only used for collecting data on my honeypots.
...
> Is there any way to implement this?

I explored this a few months back in a blog entry:
  https://www.sweharris.org/post/2016-09-18-ssh-password-exposure/

-- 

rgds
Stephen


More information about the openssh-unix-dev mailing list