
OpenSSH 7.7 - Username Enumeration
OpenSSH 7.7 - Username Enumeration
The attacker can try to authenticate a user with a malformed packet (for example, a truncated packet), and:
if the user is invalid (it does not exist), then userauth_pubkey() returns immediately, and the server sends an SSH2_MSG_USERAUTH_FAILURE to the attacker;
if the user is valid (it exists), then sshpkt_get_u8() fails, and the server calls fatal() and closes its connection to the attacker.
Usage of the Library is Very Simple and it can be used just in few lines
python <target> --port <port> --userlist <username_file>