Enumeration

Before attacking SSH, enumerate it: the version banner names the implementation and build (mapping to known vulnerabilities), the offered key-exchange, cipher, and MAC algorithms reveal weak-crypto exposure, the host-key fingerprint identifies the server (and enables trust attacks), and valid usernames focus credential attacks. All of this is unauthenticated, and each result points at a specific follow-on: a vulnerable version to exploit, weak algorithms to target, or a user list to spray.

bash
nmap -p22 -sV --script ssh2-enum-algos,ssh-hostkey,ssh-auth-methods <target>
nc <target> 22                                 # raw banner

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more