
OpenSSH 9.1漏洞大规模扫描和利用
CVE-2023-25136
OpenSSH 9.1 Vulnerability Mass Scanning and Exploitation
*Vulnerability Details
OpenSSH is software that implements the SSH protocol, commonly used to securely connect to Linux (or Windows) machines for remote administration.
The CVE-2023-25136 security vulnerability introduced in OpenSSH 9.1 affects the SSH pre-authentication process. By exploiting it, an attacker can corrupt memory and execute arbitrary code on the machine without authenticating to the target server.
#Usage
Run the script to select "IP Address List Scan" or "Directly Exploit Vulnerable IP"
#requirements
•Paramiko: To install, simply type
pip install paramiko
•Pyfiglet: To install, simply type
pip install pyfiglet
•TermColor: To install, simply type
pip install termcolor
#Dork
Use https://www.criminalip.io/asset/search?query=IP
DORK:ssh-2.0-openssh-9.1