SSH grants access by password or by public-key authentication, and the server's configuration decides which is offered. Both are attacked. Passwords fall to default-credential checks, brute force, and spraying, bounded by any rate limiting. Public-key authentication, the more common real mechanism, is attacked not by breaking the key but by finding the private key, exposed in shares, backups, and repositories, or reused across hosts, and by exploiting keys generated weakly enough to be predictable. Enumerating which method the server accepts per user directs the effort.
# which authentication methods does the server offer for a user?
ssh -o PreferredAuthentications=none -o PubkeyAuthentication=no user@<target> 2>&1 | grep -i 'authentications that can continue'
Subtopics#
- Default credentials: vendor and factory SSH logins.
- Password brute force: online password attacks and spraying.
- Public key exposure: finding and reusing private keys.
- Weak key generation: predictable keys from broken generators.