18 ms·
SSH Check – public SSH server testing tool
- snvzz 9y agoNo IPv6 support.
- dhbx9 9y agoIs there a similar tool that tests HTTPS enabled web servers on their choice of ciphers etc?
- Maakuth 9y agohttps://www.ssllabs.com/ https://www.ssllabs.com/ is just that.
- l-p 9y agoOr https://testssl.sh/ https://testssl.sh/ if you don't want to rely on a third-party.
- deleted 9y ago[deleted]
- AdamGibbins 9y agohttps://observatory.mozilla.org/ https://observatory.mozilla.org/ is a great all-in-one tool that does SSL, headers, and a bunch of other stuff - calls out to ssllabs among others.
- weddpros 9y agohttps://sslping.com https://sslping.com even monitors your configuration every day for free
- scrollaway 9y agoWhat a wonderful little site. Thanks for the link!
- weddpros 9y agoThank you! (my site)... SSLPing didn't get as much attention on HN as SSHCheck does...
- scrollaway 9y agoWell then let me thank you again :) Very slick UI, signed up in seconds, set myself up in under a minute. What are your plans with it? Just leaving a free service running or do you want to add paid plans as well? (and if not, I would recommend setting up at least a "Support" plan of some kind; it sends a strong signal)
- andriussev 9y agoIf it included info on what to do with the WEAK ones, it would be much better. Sort of like the Google Pagespeed style.
- akerro 9y agohttps://stribika.github.io/2015/01/04/secure-secure-shell.html https://stribika.github.io/2015/01/04/secure-secure-shell.ht...
- deleted 9y ago[deleted]
- sleavey 9y agoGreat tool - I found some weaknesses in my SSH server. After fixing them, I wanted to test it again but I can't find a refresh button... EDIT: turns out you need to wait 10 minutes.
- devdoomari 9y agohope someone makes a local-executable version...
- TimNN 9y agoThere already is: https://github.com/evict/SSHScan https://github.com/evict/SSHScan
- bechampion 9y agoand returns almost the same details , there is also a nmap script https://nmap.org/nsedoc/scripts/ssh2-enum-algos.html https://nmap.org/nsedoc/scripts/ssh2-enum-algos.html I've always found these kind of webapps attractive in a way ... the fact that it may be doing a os.popen("nmap -vv bla bla bla") makes me uncomfortable ,
- ipostonthisacc 9y agoAnother one https://github.com/arthepsy/ssh-audit https://github.com/arthepsy/ssh-audit
- andreaso 9y agoIt appear to have problems with newer chiphers. sshd[28670]: fatal: Unable to negotiate with 40.112.150.31 port 47286: no matching cipher found. Their offer: aes256-ctr,aes192-ctr,aes128-ctr,aes256-cbc,aes192-cbc,aes128-cbc,3des-ctr,3des-cbc,twofish256-ctr,twofish192-ctr,twofish128-ctr,twofish256-cbc,twofish192-cbc,twofish128-cbc,twofish-cbc [preauth]
- sajagi 9y agoHi andreaso, do you happen to have a list of encryption algs on your side? We don't support chacha20-poly1305 (yet) and afaik aes in gcm mode, but e.g. aes ctr are reliable so I find it strange these are not supported on your side.
- andreaso 9y agoThat sshd only supports the chacha20-poly1305 cipher. Perfectly fine with that, since I'm the only one logging into that server.
- sandrina 9y agoCan you share what went into building this?
- sajagi 9y ago(disclaimer: I work for Rebex) SSH libraries written by Rebex. With the exception of ECC it's all closed-source.
- hannob 9y agoThere are a couple of strange things here. It lists oakley group 14 as insecure with no justification. That's a 2048 bit diffie hellman group and it should be totally fine. It also lists hmac-sha1 as problematic, although in hmac the weaknesses of sha1 are irrelevant. I'm not sure about the umac 64 bit block size. That should at least have some more info why it's considered problematic. Usually OpenSSH is pretty good at deprecating problematic algorithm choices, so I tend to stick with upstream defaults.
- starquake 9y agoIt shows this as justification right now: Oakley Group 14 is no longer considered secure enough. SHA-1 is no longer considered secure enough (see shattered.io).
- pawadu 9y agoHere is my problem with this statement: SHA-1 can be used in different configurations for different applications. Some are secure, some are not. People making these blanket statement very clearly demonstrate that they don't understand security and cryptography. Do you really want to use a security tool written by such people? https://plus.google.com/+LinusTorvalds/posts/7tp2gYWQugL https://plus.google.com/+LinusTorvalds/posts/7tp2gYWQugL
- CJefferson 9y agoI disagree with Linus here -- there are hashes which are secure in all ways, and hashes which are broken, like SHA1. Why try to figure out where SHA1 is safe? Also, git's use of SHA1 is completely broken, it's just that no-one (that we know of) has chosen to spend the money required to make evil git repositories (you can't just take existing collisions and use them in git, you would have to go find git-specific ones).
- breser 9y agoYou'd have to find collisions that are of an identical length and still be useful (i.e. able to do something evil rather than just being a bunch of random data). The current techniques for creating collisions in SHA1 don't make it possible to find identical length collisions. So your statement that nobody has bothered to spend the money to create the collisions is not correct. Now if you want to say that nobody has spent the time to find a technique to produce identically sized collisions, that would be correct. But that's far from trivial and we don't know that such a technique is guaranteed to exist.
- rythie 9y agoIt'd be useful to know what this is likely to break, AFAIK I sshd doesn't log what ciphers people used, like Apache can do. A caniuse.com for SSH would be useful.
- jlgaddis 9y agoIt can log that stuff -- increase "LogLevel" in sshd_config.
- crispyambulance 9y agoOK, I am not embarrassed to ask... If I see some "weak" or "insecure" tags, what can I do about it? I have no idea how to disable MAC, key-exchange, and encryption algorithms used by the server I control. I had thought that just using SSH was "enough" More importantly, if I do disable the insecure stuff, what will it break ?
- bimmer44 9y agoThis article is very detailed and includes examples of setting sshd to only use more secure options: https://stribika.github.io/2015/01/04/secure-secure-shell.html https://stribika.github.io/2015/01/04/secure-secure-shell.ht... There was also a lot of HN discussion about it: https://news.ycombinator.com/item?id=8843994 https://news.ycombinator.com/item?id=8843994
- problems 9y ago> If I see some "weak" or "insecure" tags, what can I do about it? I have no idea how to disable MAC, key-exchange, and encryption algorithms used by the server I control. I had thought that just using SSH was "enough" For the most part it is, many of the things they're labeling as "weak" is not stuff that's likely to get you exploited today, but stuff that might at some point in the future - attacks only get better. Not necessarily things that are completely broken, just weak by today's standards. > More importantly, if I do disable the insecure stuff, what will it break ? Older clients mostly. Many phone apps for example don't have recent SSH implementations that support newer cryptography.
- formula_ninguna 9y agoOk, that's a very, very elementary stuff, how come do you don't that yet? Oh, Gosh, are you a programmer? For long how? :)))))
- sp0ck 9y agoKind of useless. I've checked, change settings and can't check again. I'm getting results from some cache.
- sajagi 9y agoyou have to wait 10 minutes ... I am adding a refresh button as we speak.
- Spare_account 9y agoShould this have "Show HN:" in the title? The author of the site appears to be the OP. https://news.ycombinator.com/showhn.html https://news.ycombinator.com/showhn.html
- jacquesm 9y agoIs there a good reason to open up access to your ssh port for some service by a novelty account which could easily collect information on what version ssl sub-protocols you do and do not support? Consider me paranoid but I don't like services like this unless they come from reputable sources and even then I'd much rather run something local. Remember to close your port in your firewall after running the test.
- sajagi 9y agoI think it's more the other way round. You already have a public SSH server for whatever reason (e.g. hosting, tunelling, ...) and you might use this tool to check its capabilities. The reputability of such service or even existence thereof does not have anything to do with how much your server is or is not secured.
- simias 9y agoI'm not sure I get you, I find this service most useful for public-facing SSH services (where the risk of attack in the greatest). I wouldn't bother forwarding my laptop's port 22 just to test it, that's for sure. If an attacker wants to gather a list of vulnerable SSH servers in the wild they just have to map a bunch of random addresses (and that seems to be extremely common judging by the number of failed auths on my public server). Although it could be useful if you wanted to get a list of ssh servers not running on port 22.
- jacquesm 9y agoYes, if it is public then I agree. But if it is private you're going to have to unlock a port, let the service do its thing and then re-lock afterwards. If you forget the last step you are now more at risk than before. Also, since the service does not advertise what IP it will be connecting from beforehand (presumably the host you complete that form on, but that's not a certainty, it's IP is 40.112.150.31, in an MS Azure block) you would open up access to the world in order to do this.
- sajagi 9y ago
- dobin 9y agoIs this based on ssh-audit? https://github.com/arthepsy/ssh-audit https://github.com/arthepsy/ssh-audit
- sajagi 9y agoIt is not, but thanks for sharing that link, looks very useful!
- theandrewbailey 9y agoI followed the Mozilla SSH guidelines[0] modern configuration, and turned out pretty good on this tool. [0] https://wiki.mozilla.org/Security/Guidelines/OpenSSH https://wiki.mozilla.org/Security/Guidelines/OpenSSH
- GordonS 9y agoIt would be super-useful if it could give you something actionable for each issue if finds.
- meritt 9y agohttps://wiki.mozilla.org/Security/Guidelines/OpenSSH https://wiki.mozilla.org/Security/Guidelines/OpenSSH While not exactly the solution you're looking for the Mozilla OpenSSH guidelines are quite better than the default sshd_config
- GordonS 9y agoThat is useful, thanks!
- problems 9y agoSeems fairly good - I would consider going 25519-only if you have compatible clients for kex and auth. Some of their concerns with SSH agent forwarding are good too - but make me wonder if writing some little GUI that would have you allow or deny authentication requests would solve the problem.
- Aaargh20318 9y agoAfter updating my SSH config, the tool won't let me re-check, it just gives me the previous results.
- el_duderino 9y agoYou have to wait 10 minutes, but he is adding a refresh button. https://news.ycombinator.com/item?id=14559709 https://news.ycombinator.com/item?id=14559709
- MrRadar 9y agoA suggestion: add simulated handshakes for various versions of OpenSSH and PuTTY to indicate which cipher/auth/kex algorithm they would negotiate with their default settings (ala the SSL Labs scanner).
- usuallybaffled 9y agoOn one hand, nice way to collect a database of SSH servers without triggering alarms. On the other, people using this tool are more likely to take steps to secure their servers.
- vel0city 9y agoshodan.io already has a pretty good database of SSH servers. Want to find servers running an old version of OpenSSH? Easily queriable. https://www.shodan.io/search?query=OpenSSH_5.2+country%3A%22US%22 https://www.shodan.io/search?query=OpenSSH_5.2+country%3A%22... There's a decent chance your SSH server is already in this database and many others.
- usuallybaffled 9y agoVery good point!
- jokr004 9y agoIs it just me or am I the only one who is a bit hesitant to submit the public IP/hostname to some random service on the web. I'm not trying to say that the creator of this has any ill intent, but I also don't know that they aren't cataloging addresses of potentially vulnerable ssh daemons. Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
- ZoFreX 9y agoIf they wanted to find vulnerable ssh daemons it would be much faster and easier to scan the web than wait for people to enter their details here. Or to put it another way: if you're worried that your SSH is vulnerable, fix it. Don't rely on not typing it into a website, because people will find it regardless.
- JorgeGT 9y ago> because people will find it regardless In my experience, if you have an SSH port accessible from the internet, it has been probed today by a few Chinese/Russian IPs. Unless my raspberry pi home server is somehow a high value intelligence target...
- avian 9y agoIn my experience a SSH service on a random, non-standard port gets surprisingly few probes. I look after several machines and I see less than one attempt per year (versus hundreds per day for port 22). I have yet to see somebody probe a SSH that listens on IPv6-only.
- pmoriarty 9y agoYou might want to consider using port knocking[1] to make your ssh server even less susceptible to attack. [1] - https://en.wikipedia.org/wiki/Port_knocking https://en.wikipedia.org/wiki/Port_knocking
- 9y ago
- duxet 9y agoIs there any possibility to do check again, eg. after updating sshd config? After entering same data again i get previous result.
- deleted 9y ago[deleted]
- r1ch 9y agoJust shows the following for me: An error occurred This happenned when we were trying to connect to io.r1ch.net:22. https://sshcheck.com/server/io.r1ch.net/ https://sshcheck.com/server/io.r1ch.net/
- sajagi 9y agoI'll take a look - it will take some time as I am currently swamped. Can you please check again in few days? Thanks!
- thinkMOAR 9y agoCall me critical AND paranoid.. but this kind of thing should be a tool people can run locally. Not via some public service, which is probably gonna be blacklisted on plenty of RBLs. However first and above all, SSH SHOULD NEVER LISTEN AND/OR RESPOND to non whitelisted ip addresses. NEVER, no exceptions. Also i think it is more a promotion for the rebex site and software, not so much the ssh scan utility... based on the selected sample site, simplicity of the utility and site, Server Identification: SSH-2.0-RebexSSH_1.0.0.0
- theandrewbailey 9y agoThere are many cases when you don't know the IP you will be connecting from. The only way around that I know of would be a VPN, but SSH's auth and crypto strength is at least as good.
- thinkMOAR 9y agoAs long as people keep doing this, i will have a job cleaning up fuck ups. :)
- rnhmjoj 9y agoI think it suffice to disable root login, password authentication and maybe use a non-standard port to clear the logs from scanners. What do you do if your address changes or something? I wouldn't risk locking myself out.
- jlgaddis 9y agoMeh, I've got two hosts running SSH that are accessible from anywhere. They run OpenSSH on OpenBSD and are pretty locked down (only specific ciphers, key exchange algorithms, and MACs are permitted), root login is disabled, and password authentication is disabled, among other non-default configuration options. These two hosts allow access (via SSH) to another 40 or so boxes running various flavors and versions of Linux that can't be locked down as much. I do not worry one bit about those two hosts getting compromised as I took the time to minimize the chances of that happening.
- edmanet 9y agonetcat -z -w 2 $ipaddress 22;echo $? How hard is that?
- matt_wulfeck 9y agoGreat tool! Though I think it much safer to control these things client side, that way no matter what you're connecting to you know you're getting safe ciphers.
- woodrowbarlow 9y agosafer for you, not safer for the server.
- pmoriarty 9y agoWhy is this a service and not a standalone tool that I can use from my own machine? Do I really want to be giving out the locations of my ssh servers to some random website? Also, a standalone tool could be used behind corporate firewalls, where this service is useless.
- blacksmith_tb 9y agoWell, yes and no - I can see the argument that it might be nice to test them locally before you expose them to the world (and I suppose you might also have them on a private LAN permanently), but otherwise, they will be tested, by someone, and soon...
- pmoriarty 9y agoBut the fewer people "test" it, apart from me, the better. This is akin to putting your email address all over the internet. If you do that, you're going to get lots of spam. If you are more careful about who you give it to, you'll get less. It's clearly a win to keep both email addresses and ssh server addresses as private as possible.
- semi-extrinsic 9y agoThe difference between IP and email adresses is that one is trivially enumerated, the other is not. Any internet-facing server that responds on port 22 will get several (up to hundreds) of failed login attempts per day. Just install something like fail2ban and watch your logs.
- dicknuckle 9y agoWhen was the last time you looked at your SSH logs for public machines? Your public IP is just that, public. Anyone can scan it, and it most certainly gets hit by many scanners a day.
- cmurf 9y agoYeah I'd like a local tool. Maybe I want to do a test before I put it on the internet.
- atmosx 9y agoOk, say I am on vacations and my laptop turned brick. The SQL crashed and I need to perform a restore. What do I do if only SSH keys are allowed? So I keep my key on a USB key? How is that safe to plug in into a computer? Do I go around with a USB-Linux-distro with my key on it? What if in the border an official decides to keep the USB device I was holding on to. How do you manage this situation?
- blfr 9y agoYou have other people on call to care for critical infrastructure.
- dicknuckle 9y agoI know many people keep an encrypted copy in various cloud or email accounts. Then all you would need is the encryption password and internet access to download the application to decrypt.
- bradfa 9y agoA USB smart card like a Yubikey NEO or 4 might be useful. Keys are securly stored in the card and never leave it. Alternatively, a USB smart card reader and a normal smart card, but this is physically larger.
- carroccio 9y agohttps://github.com/isgroup-srl/secure-ssh-server https://github.com/isgroup-srl/secure-ssh-server
- goblin89 9y agoUbuntu 16.04 launched from an AMI on AWS EC2 has weak points in its SSH setup out of the box—supporting SHA-1 and 64-bit UMAC.
- sajagi 9y agoIt's quite probably because of compatibility with the older clients. Unfortunately you can't simply use only the safest algorithms out there because the clients wouldn't be able to connect :/
- nemoniac 9y agoOut of curiosity I tried github.com and one of my servers. To my surprise it judges my server to be far more secure than github.