-
Notifications
You must be signed in to change notification settings - Fork 0
Enumeration of usernames on ssh servers
License
AndreLMe/ssh_enum
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
Script based on the CVE 2018-15473 How this script works ? A: First it estabilishes an encrypted connection with the OpenSSH Server then sends a malformed packeage(SSH2_MSG_USERAUTH_REQUEST), the script analyze the anwser, discovering if the username exists or not by the messeage receved by the server, if there's no anwser, then the user exists. Otherwise, it will send a messeage of invalid user. Why this happens? A: You can read about it on this article: https://blog.nviso.be/2018/08/21/openssh-user-enumeration-vulnerability-a-close-look/ where you'll find a detailed explanation about the case.
About
Enumeration of usernames on ssh servers
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published