SSH begins each session by negotiating algorithms for key exchange, encryption, and message authentication from the lists both sides offer. If a server still advertises weak options, the negotiation (or a positioned attacker forcing it) can land on a breakable combination: legacy or broken ciphers, weak or truncated MACs, and small or flawed key-exchange groups. These do not matter against a passive observer of a strong session, but they enable decryption, tampering, or downgrade for an attacker who can capture or sit on the connection, and they are the enabling weakness behind some SSH machine-in-the-middle and traffic attacks.
# enumerate offered algorithms and grade them
nmap -p22 --script ssh2-enum-algos <target>
ssh -Q cipher; ssh -Q mac; ssh -Q kex # what your client supports (for comparison)
# connect forcing a weak algorithm to test acceptance
ssh -c aes128-cbc -o MACs=hmac-md5 user@<target>
Subtopics#
- Key exchange downgrade: forcing weak or small key-exchange groups.
- Weak ciphers: legacy and CBC-mode cipher weaknesses.
- Weak MAC algorithms: broken or truncated integrity protection.