SSH

SSH (Secure Shell) is the standard encrypted remote-administration protocol, listening on TCP 22, and because the session is encrypted and integrity-protected the attack surface is active rather than passive. Five aspects matter. Enumeration fingerprints the version, supported algorithms, and valid users. Authentication is attacked through passwords, default credentials, and the keys that really grant access. Weak cryptography lets a positioned attacker negotiate or downgrade to breakable ciphers, MACs, or key exchange. Host-key and certificate trust, built on trust-on-first-use, is abused for machine-in-the-middle. And SSH's tunnelling features turn one reachable host into a pivot across the network.

bash
# fingerprint the service
nmap -p22 -sV --script ssh2-enum-algos,ssh-hostkey,ssh-auth-methods <target>
nc <target> 22                                 # banner (SSH-2.0-OpenSSH_x.y)

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more