Some SSH versions and configurations reveal whether a username exists, through timing differences in password processing or through which authentication methods the server offers for a given user. Enumerating valid accounts narrows a password spray to real targets and avoids noise against non-existent users.
# Timing/behaviour-based enumeration against vulnerable OpenSSH versions
nmap -p 22 --script ssh-auth-methods --script-args="ssh.user=<user>" <target>
# Public enumeration tooling probes auth responses per username
Exploitation notes#
- Enumeration relies on a server that leaks a distinguishable response or timing for valid versus invalid users; patched OpenSSH largely closes timing leaks.
- A confirmed user list makes spraying efficient and quieter.
- Combine with names harvested elsewhere (shares, web, OSINT) rather than pure guessing.