Description
Installs a malicious PAM shared library (.so) on the target that silently accepts a configured master password for ANY local account, including root. Normal passwords continue to work, so the backdoor is transparent. Works with ssh, su, sudo, login, and any other service that routes through PAM.
On x86_64 targets the pre-compiled binary is patched in-memory and uploaded directly - no compiler needed on the target. On other architectures the module falls back to compiling the .c source on the target (requires gcc).
The module drops the .so into the system PAM module directory and inserts an "auth sufficient" line at the top of the selected PAM config so it is checked before the real authentication stack. Patching common-auth (Debian) or system-auth (RHEL) automatically covers sudo, because those configs are @include'd by /etc/pam.d/sudo.
Run with ACTION=Cleanup (and identical options) to remove all artifacts.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use post/linux/manage/pam/backdoormsf undefined(backdoor) > show actions ...actions...msf undefined(backdoor) > set ACTION < action-name >msf undefined(backdoor) > show options ...show and set options...msf undefined(backdoor) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub