MITM and trust

SSH resists machine-in-the-middle only because the client verifies the server's host key: on first connection the key is recorded in known_hosts (trust on first use), and later connections must match or the client warns. Certificate-based SSH replaces this with a CA that signs host keys. The attack surface is where that trust is weak: users conditioned to accept host-key-changed warnings, clients configured to accept any key (StrictHostKeyChecking no), fresh connections with no pinned key yet, and flaws in certificate validation. A positioned attacker exploits these to interpose, presenting their own host key, decrypting the session, capturing the password or key, and relaying to the real server.

bash
# position (ARP/DNS/route) + an SSH MITM proxy that presents a substitute host key
# the attack succeeds when the client does not reject the unknown/changed key

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more