Weak and stolen SSH keys

SFTP often authenticates with SSH keys rather than passwords. A private key recovered from a share, backup, home directory, or another compromised host authenticates as its owner wherever the matching public key is authorized, frequently without a passphrase. Historically, flawed key generation also produced guessable keys.

bash
# Use a recovered private key for SFTP
chmod 600 id_rsa && sftp -i id_rsa user@<target>
# Passphrase-protected keys: crack offline
ssh2john id_rsa > hash && john hash

Exploitation notes#

  • Private keys spread widely: developer home directories, CI configs, backups, and .ssh folders on shares; one key often works on many hosts.
  • Keys without a passphrase are immediate access; passphrase-protected keys are cracked offline with ssh2john and a wordlist.
  • Reuse is the theme: test a recovered key broadly, as teams share and copy keys across servers.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more