Before attacking SSH, enumerate it: the version banner names the implementation and build (mapping to known vulnerabilities), the offered key-exchange, cipher, and MAC algorithms reveal weak-crypto exposure, the host-key fingerprint identifies the server (and enables trust attacks), and valid usernames focus credential attacks. All of this is unauthenticated, and each result points at a specific follow-on: a vulnerable version to exploit, weak algorithms to target, or a user list to spray.
nmap -p22 -sV --script ssh2-enum-algos,ssh-hostkey,ssh-auth-methods <target>
nc <target> 22 # raw banner
Subtopics#
- Banner grabbing: version and implementation disclosure.
- Algorithm enumeration: offered crypto and weak-option detection.
- User enumeration: discovering valid usernames.