4

Pentester Tools : SSHScan

Posted by zuhaircmr
    SSHScan is a testing tool that enumerates SSH Ciphers. We Can easily detect weak ciphers by using this .


Lets tryout SSHScan in BrokenWeb (A Vulnerable machine) hosted locally .

Brokenweb IP : 192.168.3.107


codebreaker@zbox:~$ ./SSHScan/sshscan.py -t 192.168.3.107:22



 In Network Pentesting, Once you detect an SSH port , then try for SSHScan to detect the ciphers. If KEX algoritham is weak then an attacker can easily create a Denial of Service attack on SSH port and hence the target wont be accessible by the anyone at the moment.

GITHUB Link:
https://github.com/evict/SSHScan

Installation :
git clone https://github.com/evict/SSHScan 

4 Comments


The article provides a useful practical introduction to SSHScan and shows how security testing can reveal weaknesses in SSH configurations. I particularly like the hands-on approach of demonstrating the tool against a deliberately vulnerable BrokenWeb environment. Enumerating supported SSH ciphers is an important assessment step because outdated or weak cryptographic options can increase the risk of insecure remote access and should be identified during security audits.

The focus on penetration testing makes this a relevant example of Cyber Security Projects for Final Year Students. Using a controlled vulnerable machine to examine SSH services provides a practical way to understand how security testers discover configuration weaknesses before they can be exploited in real environments.

Post a Comment

Copyright © 2009 Topfom Cybersecurity Blog: Navigating Tech Trends & Digital Security Since 2007 All rights reserved. Theme by zuhaircmr. | Bloggerized by topform.

free hit counters