Key exchange downgrade

The SSH key exchange (KEX) derives the symmetric session keys and authenticates the server's host key. Its strength depends on the method negotiated: modern curve-based exchanges are strong, but servers that still offer diffie-hellman-group1-sha1 (a fixed 1024-bit group) or other legacy KEX present a weaker target. Because both sides pick from offered lists, a server advertising weak groups can end up using them, and a positioned attacker who influences the negotiated algorithm set, or who simply records a handshake that used a weak group, attacks the key agreement to recover or weaken the session keys.

bash
# which KEX methods does the server offer?
nmap -p22 --script ssh2-enum-algos <target> | grep -A15 kex_algorithms
# force a weak KEX to confirm the server accepts it
ssh -o KexAlgorithms=diffie-hellman-group1-sha1 user@<target>
ssh -o KexAlgorithms=diffie-hellman-group-exchange-sha1 user@<target>

Exploitation notes#

  • The signal is the server's offered kex_algorithms: presence of group1 (1024-bit), SHA-1-based exchanges, or the GEX with small group sizes marks a weak negotiation that can be forced.
  • A 1024-bit fixed group is within reach of well-resourced precomputation attacks against the shared parameters; the practical impact is enabling decryption of a captured session that used it.
  • This pairs with a capture or on-path position: forcing or observing a weak KEX is the groundwork for attacking the session, rather than a standalone break.
  • The broader weakness set (ciphers, MACs) compounds this; a server offering weak KEX usually offers weak ciphers and MACs too.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more