Pam-ussh may be tricked into using another logged in user's ssh-agent
hackerone.com
hackerone.com
It seems to me another zero on the end would be appropriate.
High level consulting basically.
I don't think Solar Designer even expected a bounty.
He'd solved the same problem before:
https://github.com/jbeverly/pam_ssh_agent_auth/blob/master/a...
Also, was this written because pam_ssh_agent_auth does not support certificates specifically? If so, why wouldn't they just modify the existing module? Another example of "Hey let's re-engineer the wheel for fun" ?
The HTML hidden in that mountain of div tags is remarkably well formed for the standard I see around on the "modern web".
If we stop pointing this out, then we lose.