
User name enumeration against SSH daemons affected by CVE-2016-6210.
User name enumeration against SSH daemons affected by CVE-2016-6210.
Use against your own hosts only! Attacking stuff you are not permitted to may put you in big trouble!
git clone https://github.com/coolbabayaga/CVE-2016-6210.git
cd ssh-enum-cve-2016-6210
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
40136.py -h
example: 40136.py -U /usr/share/wordlists/metasploit/unix_users.txt -e -s 192.168.44.63:22
positional arguments: host Give SSH server address like ip:port or just by ip
options: -h, --help show this help message and exit -u, --user USER Give a single user name -U, --userlist USERLIST Give a file containing a list of users -e, --enumerated Only show enumerated users -s, --silent Silent mode --bytes BYTES Bytes to send as password --samples SAMPLES Samples for baseline timing --factor FACTOR Factor for timing boundary --trials TRIALS Trials per user