A vulnerability in OpenSSH before version 7.3 allows remote attackers to enumerate valid usernames on a target system. When SHA256 or SHA512 are used for user password hashing, and a non-existent username is supplied, sshd uses BLOWFISH hashing on a static password, resulting in a measurable timing difference in authentication responses. This enables attackers to distinguish between valid and invalid usernames by sending large passwords and observing response times.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository is a Python-based SSH user-enumeration research and detection project rather than a single weaponized exploit. Its offensive capability is network-based probing of SSH services to determine whether usernames can be distinguished through authentication behavior, timing differences, or tool-assisted enumeration. The main orchestrator is run_investigation.py, which executes a multi-stage pipeline: raw SSH banner grabbing and version parsing, repeated Paramiko authentication attempts against candidate usernames, statistical timing analysis for CVE-2016-6210-style leakage, and auth.log-based detection engineering. Repository structure is split cleanly into attack_tools and detection_tools. attack_tools/banner_fingerprinter.py opens a raw TCP socket to the SSH port, captures the pre-auth banner, extracts implementation/version/OS hints, and maps versions against a small local CVE registry including CVE-2016-6210, CVE-2023-38408, and CVE-2024-6387. attack_tools/manual_ssh.py is the core probing component: it uses Paramiko to attempt password authentication for each username, records elapsed time until AuthenticationException or connection failure, caches the remote SSH banner, and saves structured JSON results. attack_tools/hydra_automation.py and attack_tools/metasploit_scanner.py are wrappers around external tools; they automate Hydra and Metasploit auxiliary/scanner/ssh/ssh_enumuser respectively, parse outputs, and save findings. The detection side is substantial. detection_tools/log_parser.py parses SSH-related auth.log events such as failed password, invalid user, accepted login, and disconnects. detection_tools/pattern_detector.py identifies rapid username cycling from one IP, wordlist correlation, evenly spaced attempts suggesting automation, and distributed probing of the same username from multiple IPs. detection_tools/response_analyzer.py performs Welch’s t-test and Cohen’s d calculations to decide whether valid and invalid usernames are distinguishable by timing. alerting_system.py formats alerts. The repository also includes notebooks for exploratory analysis, wordlists of common usernames, saved JSON outputs from prior runs, and unit tests. Main exploit capabilities: (1) unauthenticated SSH banner fingerprinting over TCP/22; (2) repeated password-auth attempts against many usernames to test for enumeration leakage; (3) optional automation of Hydra and Metasploit enumeration workflows; (4) statistical determination of whether timing differences imply username existence; and (5) post-event detection/reporting from SSH logs. There is no custom RCE payload or shell delivery. The practical result is reconnaissance and validation of SSH username enumeration exposure, plus defender-focused detection artifacts. Based on the included results, the tested OpenSSH 8.9p1 target did not appear vulnerable to timing-based username enumeration, though its banner exposed version information and matched CVE ranges in the local triage registry.
This repository is a small standalone proof-of-concept for CVE-2016-6210, an OpenSSH username-enumeration vulnerability based on authentication timing differences. It contains two files: a short README describing the PoC and target context, and a single Python script, exploit.py, which is the functional entry point. The exploit uses Paramiko to make repeated SSH authentication attempts against a remote SSH daemon. Its core logic first retrieves the SSH banner by attempting a connection with invalid credentials, then establishes a timing baseline using multiple clearly nonexistent usernames. For each candidate username supplied either directly (-u) or via a file (-U), it sends an oversized password consisting of repeated 'B' characters (default 50,000 bytes), measures authentication duration with time.perf_counter(), and compares the mean timing against a computed threshold of baseline_mean + factor * standard_deviation. Usernames whose timing exceeds that threshold are treated as likely valid/enumerated accounts. Repository structure and purpose: - README.txt: brief description of the PoC, notes Python 3.8+ compatibility update, references exploit-db origin, and mentions testing context. - exploit.py: complete standalone enumeration tool with CLI parsing, SSH banner retrieval, timing baseline generation, repeated trials, and formatted output modes. Capabilities: - Remote SSH username enumeration over the network. - SSH banner collection from the target. - Baseline timing calibration using invalid usernames. - Batch testing from a supplied username list. - Adjustable probe size, sample count, threshold factor, and trial count. - Quiet/silent output modes for easier scripting. This is a real exploit PoC rather than malware or a destructive fake. It does not deliver code execution or a shell; instead, it exploits a side-channel to disclose valid usernames on vulnerable SSH servers.
This repository contains multiple Python scripts implementing a proof-of-concept (PoC) exploit for CVE-2016-6210, a timing side-channel vulnerability in OpenSSH that allows remote username enumeration. The main scripts are: - PoC.py: A script that takes a target IP address and a list of usernames, then performs SSH authentication attempts with very long passwords, measuring the response time for each username. If the response time is significantly different from a baseline (non-existent user), it infers that the username may exist on the target system. Results are logged to 'ssh_timing.log'. - cuangta.py: A more feature-rich script with command-line options for single or multiple users, baseline calculation, and colored output. It also uses timing analysis to enumerate valid SSH usernames. - test_poc.py: An enhanced version that logs results in JSONL format, simulates the bcrypt hash check used by OpenSSH for non-existent users, and provides more detailed statistics. - simu_hash.py: Simulates the bcrypt hash check for non-existent users to demonstrate the timing difference exploited by the attack. Supporting files include 'userlist.txt' (a list of usernames to test), 'log.jsonl' and 'ssh_timing.log' (output logs), and empty or auxiliary log files. The exploit requires network access to the target's SSH service and is effective against OpenSSH versions vulnerable to CVE-2016-6210. The overall purpose is to demonstrate and automate timing-based SSH username enumeration.
This repository contains a single Python script, 'sshuserenumeration.py', which is an exploit for CVE-2016-6210. The script targets SSH daemons (notably OpenSSH) vulnerable to a timing side-channel that allows remote attackers to enumerate valid usernames. It works by sending large password payloads to the SSH server and measuring the time taken for authentication responses. By comparing the timing for known invalid users to those for users of interest, the script can distinguish valid usernames based on statistically significant timing differences. The script requires network access to the target SSH server and can be run with either a single username or a list of usernames. The only fingerprintable endpoint is the SSH service (typically on TCP port 22) of the target host. The script is a proof-of-concept exploit and does not provide post-exploitation capabilities; its sole purpose is username enumeration via timing analysis.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.