4 ms·
I wrote a similar tool[1] for a cybersecurity competition I was helping to red team for. It would try a dictionary of username and password combos against a li
by sdmike1 7y ago
I wrote a similar tool[1] for a cybersecurity competition I was helping to red team for. It would try a dictionary of username and password combos against a list of hosts generated from the results of a masscan[2], once it logged it it would run a bash script on the host to set up our persistence.
From there it would keep a session open on each host and allow you to run commands on a single host, a subset of hosts, or all hosts.
The advantage of this over hydra or some other SSH brute forcer is that it allows us to run our persistence tooling right away after finding a login and keep that SSH session alive so we can re-use it even if the password is changed.
The code is a tire fire, but it worked well for what we needed :)
[1] https://github.com/sdshlanta/ssher https://github.com/sdshlanta/ssher
[2] https://github.com/robertdavidgraham/masscan https://github.com/robertdavidgraham/masscan
- justinjlynn 7y agoIt'd be neat if it attempted to lateral as well.