检查SSH服务器列表,看是否允许密码认证,并验证已识别的服务器中是否存在SSH用户枚举漏洞(CVE-2018-15473)。
使用由@LeapSecurity提供的略微修改版https://www.exploit-db.com/exploits/45939来检查CVE-2018-15473。
screenshot
git clone https://github.com/securemode/enumpossible.git
接收一个服务器列表,格式为 ip:port:
# ./enumpossible.sh servers.txt