Acquiring Linux VPS via SSH
Scenario: compromised VPS instance (through a provider such as BinaryLane, Linode, Vultr, etc) which is no longer live, and requires remote acquisition for examination/analysis.



Last updated
Scenario: compromised VPS instance (through a provider such as BinaryLane, Linode, Vultr, etc) which is no longer live, and requires remote acquisition for examination/analysis.



Last updated
$ fdisk -l$ nano /etc/ssh/sshd_config
# PermitRootLogin yes$ /etc/init.d/ssh restart$ ssh root@remoteIP "dd if=/dev/vda" | dd of=filename.dd
OR with compression
$ ssh root@remoteIP "dd if=/dev/vda | gzip -1 -" | dd of=filename.gz