3 ms·
Nice :) In practice I have used metasploit's `auxiliary/scanner/ssh/ssh_login_pubkey` to do this: https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_l
by justsomeadvice0 4y ago
Nice :)
In practice I have used metasploit's `auxiliary/scanner/ssh/ssh_login_pubkey` to do this: https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_login_pubkey/ https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_...
But standalone tools are always handy!
(Edited to add a better URL)
(Second edit: I linked the wrong module here see my comment below for the correct one.)
- pimlottc 4y agoThe exploit title says “public key” but the details say “private key”, which is it?
- jeroenhd 4y agoThe exploit actually performs a login, so you need a private key for that. It's a way for a hacker to track what machines (still) accept the key they've obtained. Key-based authentication for SSH is often referred to as "pubkey authentication" (because you share your public key with the server) so that's probably where the title comes from. I don't think it exploits the same problem.
- justsomeadvice0 4y agoYou're totally right, this is not the module I am thinking of. We used to do this exact step (yank all admins pubkeys from somewhere, and test logins with it to make an access map) in our pentests but now I am having trouble remembering what we used. Even better that there is a standalone tool then :) Edit: here is the right module: `auxiliary/scanner/ssh/ssh_identify_pubkeys`, it is sort of nice in that you can give it a range of usernames, pubkeys, and hosts and it will try all combinations, and can be routed through your meterpreter pivots: https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_identify_pubkeys/ https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_...