When PasswordAuthentication is enabled, SSH logins can be guessed online. The practical attack is shaped by SSH's defenses: MaxAuthTries limits attempts per connection, MaxStartups throttles concurrent handshakes, and fail2ban-style tools block offending IPs, so a fast, broad brute force is noisy and self-defeating. A slow spray, one or a few likely passwords across a validated user list, is the effective approach, and any valid credential is prime reuse material because SSH accounts are real system accounts.
# confirm password auth is offered before spraying
ssh -o PreferredAuthentications=password -o PubkeyAuthentication=no user@<target> 2>&1 | head -1
# spray one password across users (quiet), stop on success, few threads
hydra -L users.txt -p 'Autumn2025!' ssh://<target> -t 4 -f
nxc ssh <target> -u users.txt -p 'Autumn2025!' # marks shell vs no-shell on hit
# brute one high-value account with a short, targeted list
hydra -l admin -P top-passwords.txt ssh://<target> -t 4 -f
Exploitation notes#
- Check
PasswordAuthenticationfirst; many servers are key-only (password auth disabled), in which case pivot to the key routes rather than guessing. - Keep threads low and the password list short and contextual: SSH logs every failure,
MaxAuthTriescloses the connection after a few tries, and IP-blocking tools react to bursts. - Validate usernames first (User enumeration) so attempts land on real accounts; derive passwords from the organisation (season/year, company name, breached creds) rather than a generic giant wordlist.
- Any working SSH credential is likely reused; test it against other hosts and services immediately. NetExec marks whether the account gets a shell or is confined.