Part of the SSH handshake, sent before authentication, is each side's list of supported algorithms for key exchange, host-key signature, encryption, and MAC. Reading the server's lists tells you exactly what it will accept, and grading them against modern baselines identifies weak or legacy options. This serves two purposes: it fingerprints the age and configuration of the server (old builds offer broad legacy sets), and it enumerates the specific weak-crypto attacks available, since you cannot force an algorithm the server does not offer.
# enumerate the four algorithm lists the server offers
nmap -p22 --script ssh2-enum-algos <target>
# interpret: look for weak entries in each list
# kex: diffie-hellman-group1-sha1, *-sha1, small GEX groups
# cipher: *-cbc, arcfour*, 3des, des
# mac: hmac-md5*, *-96 (truncated), non -etm
# hostkey: ssh-rsa (SHA-1) only, ssh-dss (DSA)
ssh -vv user@<target> 2>&1 | grep -iE 'kex:|cipher:|mac:' # what gets negotiated
Exploitation notes#
- Map each offered list to its weakness:
group1/SHA-1 KEX to key exchange downgrade,-cbc/arcfour/3desto weak ciphers,hmac-md5/-96to weak MAC algorithms. ssh-dss(DSA) host keys and SHA-1-onlyssh-rsaindicate an old server; DSA is disabled in modern OpenSSH, so its presence is a strong age signal.- You can only attack algorithms the server offers, so this enumeration is the prerequisite that turns the weak-crypto pages from theory into a concrete target list.
- A fully modern algorithm set (curve25519 KEX, ChaCha20/AES-GCM ciphers, ETM MACs) means the crypto surface is closed; pivot to authentication and implementation vulnerabilities instead.