Skip to content

Latest commit

 

History

History
5 lines (4 loc) · 471 Bytes

README.md

File metadata and controls

5 lines (4 loc) · 471 Bytes

Since OpenSSH servers don't restrict the login password length, you can cause these servers to crash by sending very long passwords which use massive amounts of a the server's CPU to hash. This vulnerability is known as CVE-2016-6515.

My POC can be downloaded here (you will need to unzip)

Usage:

openssh_dos [target IP] [target port]