Skip to main content

Service Detection


Brute-Force


Login with Credentials

Login with Key

Specify Algorithm (Old Servers)


User Enumeration

CVE-2018-15473 (OpenSSH < 7.7)

Nmap


SSH Tunneling

Local Port Forward

Access internal service through SSH:

Remote Port Forward

Expose attacker service to target network:

Dynamic SOCKS Proxy


SSH Key Theft

Crack Key Passphrase


Authorized Keys Persistence


NSE Scripts


Quick Reference