Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure
SSHatter 0.6
 

Index | Next | Previous | View Flat


timb at nth-dimension

Oct 6, 2007, 8:53 AM


Views: 724
Permalink
SSHatter 0.6

All,

SSHatter, the SSH brute forcer is now up to release 0.6. New since the last
announcement include:

* Changes allowing rudimentary username enumeration via timing attacks (as
described in
http://www.securityfocus.com/archive/1/archive/1/448025/100/0/threaded) have
been implemented. These changes has been validated against OpenSSH 3.5p1.

* Targets and usernames are now specified in a file and targets can now be
specified one per line in the format <hostname>[:<portnumber>].

* Reconnection can optionally be enabled where support on connection failures
have occurred.

* A default passwords list (taken from
http://www.nth-dimension.org.uk/downloads.php?id=30) has also been added.

* Fixes for systems configured with AllowUsers have added as these systems do
not return "Permission denied" on Net::SSH::Perl->login().

This latest version can be downloaded from
http://www.nth-dimension.org.uk/downloads.php?id=34.

Remember, auditing systems without permission may be a crime, always read the
label.

Tim
--
Tim Brown
<mailto:timb[at]nth-dimension.org.uk>
<http://www.nth-dimension.org.uk/>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Subject User Time
SSHatter 0.6 timb at nth-dimension Oct 6, 2007, 8:53 AM
    Re: SSHatter 0.6 full-disclosure at hushmail Oct 7, 2007, 7:39 AM
    Re: SSHatter 0.6 phioust at gmail Oct 7, 2007, 12:23 PM
    Re: SSHatter 0.6 ghosts at gmail Oct 7, 2007, 3:44 PM
    Re: SSHatter 0.6 hdw at kallisti Oct 7, 2007, 3:50 PM

  Index | Next | Previous | View Flat
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.