SFTP often authenticates with SSH keys rather than passwords. A private key recovered from a share, backup, home directory, or another compromised host authenticates as its owner wherever the matching public key is authorized, frequently without a passphrase. Historically, flawed key generation also produced guessable keys.
# Use a recovered private key for SFTP
chmod 600 id_rsa && sftp -i id_rsa user@<target>
# Passphrase-protected keys: crack offline
ssh2john id_rsa > hash && john hash
Exploitation notes#
- Private keys spread widely: developer home directories, CI configs, backups, and
.sshfolders on shares; one key often works on many hosts. - Keys without a passphrase are immediate access; passphrase-protected keys are cracked offline with ssh2john and a wordlist.
- Reuse is the theme: test a recovered key broadly, as teams share and copy keys across servers.