SSH resists machine-in-the-middle only because the client verifies the server's host key: on first connection the key is recorded in known_hosts (trust on first use), and later connections must match or the client warns. Certificate-based SSH replaces this with a CA that signs host keys. The attack surface is where that trust is weak: users conditioned to accept host-key-changed warnings, clients configured to accept any key (StrictHostKeyChecking no), fresh connections with no pinned key yet, and flaws in certificate validation. A positioned attacker exploits these to interpose, presenting their own host key, decrypting the session, capturing the password or key, and relaying to the real server.
# position (ARP/DNS/route) + an SSH MITM proxy that presents a substitute host key
# the attack succeeds when the client does not reject the unknown/changed key
Subtopics#
- Known-hosts bypass: defeating trust-on-first-use and key pinning.
- SSH MITM: interposing to capture credentials and hijack the session.
- Certificate validation bypass: abusing certificate-based SSH trust.