List all SSH keys authorized on the server
list all authorized_keys on server | find unknown ssh keys | audit ssh access all users | find | ssh | auditfind / -xdev -path '*/.ssh/authorized_keys' -type f -exec awk 'NF && !/^#/ {print FILENAME ": " $NF}' {} + 2>/dev/nullSearches the root file system for all authorized_keys files and prints the file path and the last field of each key line, usually a comment like admin@laptop. This shows at a glance which keys are stored for which user. An unknown comment or a key without a comment deserves a closer look.
Note: If /var/www is on a separate partition, drop -xdev or specify the path directly. Also keep authorized_keys2 and custom AuthorizedKeysFile settings in mind.
Also searched as
- list all authorized_keys on server
- find unknown ssh keys
- audit ssh access all users