Weak MAC algorithms

SSH appends a message authentication code (MAC) to every packet so tampering is detected. The strength of that guarantee depends on the negotiated MAC, and old servers offer weak ones: MD5-based MACs (hmac-md5), 96-bit truncated MACs (hmac-*-96), and MACs used in the weaker encrypt-and-MAC (rather than encrypt-then-MAC, *-etm) construction. Weak or truncated MACs reduce the work to forge or tamper with packets, so a positioned attacker uses them to manipulate the session, undermining the integrity protection that otherwise blocks injection and modification attacks.

bash
# which MACs are offered?
nmap -p22 --script ssh2-enum-algos <target> | grep -A20 mac_algorithms
# force a weak MAC to confirm acceptance
ssh -o MACs=hmac-md5 user@<target>
ssh -o MACs=hmac-sha1-96 user@<target>        # 96-bit truncated

Exploitation notes#

  • The offered mac_algorithms list flags the weakness: hmac-md5*, any *-96 truncation, and the absence of -etm (encrypt-then-MAC) variants indicate weaker integrity.
  • Truncated and MD5 MACs lower the effort to forge a valid tag for tampered ciphertext; combined with a weak CBC cipher and an on-path position, this enables session manipulation rather than only passive observation.
  • Like the cipher and KEX weaknesses, weak MACs mainly matter to an attacker who can capture or relay the traffic; they also fingerprint an outdated SSH build.
  • These three weak-crypto pages compound: a server offering weak MACs, CBC ciphers, and small KEX groups is a candidate for cryptographic session attacks and for SSH machine-in-the-middle, see SSH MITM.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more