CVE-2018-15473 is a username enumeration vulnerability in OpenSSH through 7.7. The issue arises because OpenSSH does not delay bailout for an invalid authenticating user until after the authentication request packet has been fully parsed. This behavioral difference allows an attacker to distinguish invalid usernames from valid ones by observing server responses during authentication attempts. The issue is related to authentication handling in auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
24 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (9 hidden).
This repository is a small standalone Python proof-of-concept for CVE-2018-15473, an OpenSSH username enumeration issue. The repository contains three files: a README describing the vulnerability and usage, the main exploit script enum_ssh.py, and a sample username wordlist usernames.txt. The exploit logic is entirely in enum_ssh.py. The script uses Python sockets plus Paramiko to connect to a remote SSH server and manually craft an SSH USERAUTH_REQUEST packet. For each candidate username from the supplied wordlist, it opens a TCP connection to the target, starts an SSH client transport, and sends a malformed publickey authentication request using the username under test. It then infers whether the username exists based on how the transport behaves: inactive transport raises the custom InvalidUsername path and returns false, while other exception paths are treated as indicating a valid username. This makes the tool an active enumeration exploit rather than mere passive detection. Operationally, the script is simple and somewhat rigid: the target IP is hardcoded to 10.10.10.100 and the port to 22, while only the wordlist path is taken from the command line. It prints per-username results and a final summary of discovered accounts. There is no post-exploitation capability, shell payload, credential brute force, or lateral movement logic. The included usernames.txt is a generic candidate list of common administrative, service, and personal account names. Overall, this is a lightweight network-based SSH enumeration PoC targeting vulnerable OpenSSH behavior on Linux systems.
Noregressh is a standalone Python penetration-testing toolkit centered on OpenSSH vulnerability discovery and exploitation workflows, especially CVE-2024-6387 (regreSSHion), with additional checks for CVE-2020-14145, CVE-2021-28041, CVE-2019-16905, and CVE-2018-15473. The repository contains 10 files, primarily Python modules: a launcher, menu/UI, core framework, scanner, exploit manager, listener manager, system checker, setup script, plus README and requirements. Repository structure and purpose: - no_regresh_launcher.py: simple startup wrapper that imports the menu system and launches the framework. - no_regresh_menu.py: interactive CLI front-end exposing scanner, exploitation, listener, system status, and log viewing workflows. - no_regresh_main.py: core framework utilities including logging, signal handling, banner display, SSH banner grabbing, and version-to-CVE matching logic. - no_regresh_scanner.py: multithreaded network scanner for IP ranges or single hosts, focused on SSH service discovery and banner-based vulnerability assessment, with export/report support. - no_regresh_exploit.py: exploit/payload module. It defines payload configuration/result structures and generates multiple shell payload variants (bash, Python, PowerShell, Perl, bind shell, shellcode stubs). It also includes post-exploitation helper routines for persistence, exfiltration prep, lateral movement prep, and cleanup steps. - no_regresh_listener.py: local listener subsystem implementing a Python TCP listener and management for active listeners, intended to receive reverse-shell connections and provide an interactive shell-like session. - no_regresh_system.py: environment validation and reporting, checking Python version, modules, tools, permissions, connectivity, firewall/AV status, and generating JSON system reports. - setup.py: installer/bootstrap script that installs Python dependencies, checks for external tools, optionally installs packages via apt/yum, creates directories, and prepares the environment. Main exploit capabilities: 1. Network reconnaissance: scans IP ranges with threading, probes SSH banners, and identifies likely vulnerable OpenSSH versions. 2. Vulnerability targeting: maps observed OpenSSH banners to supported CVEs and drives targeted workflows. 3. Payload generation: creates reverse-shell payloads for multiple interpreters and a Python bind-shell payload; includes base64-encoded bash and simple shellcode placeholders. 4. Listener operations: starts local listeners on configurable ports, defaulting to 0.0.0.0 and commonly 4444, to catch reverse connections. 5. Post-exploitation support: includes helper logic and operator guidance for file transfer, screenshots, keylogging, persistence, exfiltration, lateral movement, and cleanup. The code appears to be an operational offensive toolkit rather than a pure detector. However, based on the visible content, the vulnerability identification is largely banner/version based, and the actual exploit reliability for CVE-2024-6387 is not fully verifiable from the truncated excerpts. Still, the repository clearly contains exploit-oriented payload and listener functionality beyond simple detection.
This repository is a small standalone Python proof-of-concept/operational enumeration tool for CVE-2018-15473 affecting OpenSSH versions earlier than 7.7. It contains two files: a README describing usage and compatibility notes, and a single executable script, exploit.py. The script uses Paramiko and monkey-patches internal authentication handlers to trigger and detect the username enumeration condition. Specifically, it overrides Paramiko message handling so that an invalid username causes a custom BadUsername exception, while a valid username proceeds far enough to raise a normal AuthenticationException during public-key auth. The exploit connects to a target over SSH, sets a spoofed client banner string (SSH-2.0-OpenSSH_7.6p1), starts the SSH client handshake, and attempts auth_publickey() with a freshly generated RSA key for each tested username. A calibration phase first tests a random username to determine whether the target reliably distinguishes nonexistent users; if the random username appears valid, the script aborts as unreliable. For bulk enumeration, it reads usernames from a local wordlist and uses multiprocessing with imap_unordered to test them concurrently and print valid/invalid results in real time. There is no post-exploitation payload, persistence, or command execution capability; the repository’s sole purpose is remote SSH username enumeration against vulnerable OpenSSH servers.
This repository is a small, self-contained penetration-test artifact set for the VulnHub SecOS:1 VM rather than a polished standalone exploit framework. It contains 4 files: a README documenting the full attack chain, a CSRF HTML payload, a bash script with the end-to-end command history used during reconnaissance/exploitation/post-exploitation, and a helper script for creating an attacker user on Kali. The primary exploit capability implemented directly in code is the CSRF attack in csrf-exploit.html. That file auto-submits a POST request to http://127.0.0.1:8081/change-password with username=spiderman and password=abc123, relying on a victim browser session on the target host to reset the account password. The exploit-commands.sh file then documents operational follow-on steps: host the lure via Apache as holidays.html, monitor access logs, SSH into 192.168.122.202 as spiderman, enumerate the host with LinPEAS, download and compile the OverlayFS local privilege-escalation exploit (37292.c / CVE-2015-1328), obtain root, read /root/flag.txt, dump sensitive files, inspect MongoDB data, crack hashes, clear logs, create a UID 0 backdoor user, and install a cron-based reverse shell to 192.168.122.186:4444. Repository structure and purpose: - README.md: narrative report of the black-box assessment, target environment, discovered services, vulnerabilities, attack chain, and recommendations. - csrf-exploit.html: actual exploit payload for the CSRF password reset. - exploit-commands.sh: documentation-style shell script containing all commands used across discovery, exploitation, privilege escalation, and persistence. - user-creation.sh: local attacker workstation preparation script. Attack vectors are mixed: web (CSRF against the password-change endpoint), network (SSH access and web enumeration), and local (kernel privilege escalation via OverlayFS). The repository is a real exploit/pentest artifact, not merely a detector. However, it is not highly modular or reusable; most actions are hardcoded to the lab IPs and target account, so OPERATIONAL is the best maturity fit rather than WEAPONIZED.
This repository is a small standalone Python proof-of-concept/operational exploit for CVE-2018-15473, containing one executable script and a README. The main file, CVE-2018-15473.py, implements SSH username enumeration against vulnerable OpenSSH servers by opening a TCP socket to the target SSH service, initializing a Paramiko Transport session, and attempting public-key authentication with a freshly generated RSA key for each candidate username. The script interprets differences in authentication/protocol handling to decide whether a username likely exists. It supports both single-user checks and bulk enumeration from a wordlist, uses a ThreadPoolExecutor for concurrent testing, prints progress and per-user results, and can write discovered usernames to an output file. The exploit does not deliver code execution or a shell; its capability is reconnaissance/account discovery against network-exposed SSH services. The README documents the vulnerability, affected OpenSSH versions, and dependency requirements.
This repository is a small standalone Python proof-of-concept for CVE-2018-15473, an OpenSSH username enumeration issue affecting versions earlier than 7.7. The repository contains only two files: a README with usage notes and one executable script, exploit.py, which is the main entry point. The exploit works by monkey-patching Paramiko internals to alter SSH authentication packet handling. It overrides AuthHandler parsing functions so that malformed authentication behavior triggers a custom BadUsername exception for nonexistent users, while valid users produce a normal AuthenticationException. The script then uses this behavioral difference to infer whether a tested username exists on the remote SSH service. Operationally, exploit.py accepts a target host, optional port, thread count, and a username wordlist. Before bulk enumeration, it performs a calibration step using a random username to determine whether the target reliably distinguishes nonexistent users; if the random username appears valid, the script aborts and warns that the target may be patched or otherwise unsuitable. For enumeration, it opens raw TCP sockets to the SSH service, creates a Paramiko Transport object, sets the local SSH banner to "SSH-2.0-OpenSSH_7.6p1", starts the SSH client handshake, and attempts public-key authentication with a generated 1024-bit RSA key. It then reports usernames as valid or invalid in real time using a multiprocessing pool. There are no hardcoded remote URLs, IPs, or domains in the code. The primary fingerprintable targets are the user-supplied SSH host and port 22 by default, plus local wordlist file paths. Overall, this is a focused network-based enumeration exploit rather than a post-exploitation tool: it does not provide shell access or code execution, only discovery of valid SSH usernames.
This repository is a small standalone Python proof-of-concept exploit for CVE-2018-15473, an OpenSSH username-enumeration vulnerability affecting OpenSSH 2.3 through 7.7. The repository contains 5 files total: a single code file (exploit.py), README documentation, requirements.txt, license, and .gitignore. The only executable entry point is exploit.py. The exploit's purpose is to remotely determine whether usernames exist on a target SSH server without valid credentials. It does this by monkey-patching Paramiko's AuthHandler methods so that when the client sends an SSH public-key authentication request, the generated SSH_MSG_USERAUTH_REQUEST is malformed by omitting a boolean field. The script then interprets the target's behavior: a normal AuthenticationException indicates the server fully parsed the request and rejected the key, implying the username is valid; a custom InvalidUsername path indicates the server bailed out early, implying the username is invalid. Core structure of exploit.py: - Defines InvalidUsername exception for signaling invalid-account behavior. - Saves the original Paramiko AuthHandler._parse_service_accept method. - Implements _patched_parse_service_accept to temporarily replace Message.add_boolean with a no-op, causing malformed packet generation. - Implements _patched_parse_userauth_failure to raise InvalidUsername. - apply_patches() installs both monkey patches. - check_username() opens a TCP connection to the target SSH service, starts a Paramiko transport, attempts public-key authentication with a generated RSA key, and classifies the username based on exception behavior. It retries on connection errors. - main() parses CLI arguments, performs a banner-grab connectivity test, loads either a single username or a wordlist, and uses a ThreadPoolExecutor to test multiple usernames concurrently. Capabilities: - Remote unauthenticated username enumeration over SSH. - Single-username testing or bulk enumeration from a wordlist. - Concurrent scanning with configurable thread count. - SSH banner retrieval before enumeration. - Basic retry handling for transient connection failures. There is no post-exploitation payload, shell, command execution, persistence, or lateral movement logic. The script is focused strictly on information disclosure via protocol-level behavior differences, making it a true exploit/POC rather than a benign detector, but its end result is limited to identifying valid usernames.
This repository is a standalone Python proof-of-concept/operational exploit tool for CVE-2018-15473, an OpenSSH username enumeration vulnerability. The repository is small and focused: main.py contains the full exploit logic, README.md documents the vulnerability and usage, requirements.txt lists dependencies (paramiko and python-nmap), and users.txt provides a sample username wordlist. The exploit works by monkey-patching Paramiko’s SSH client behavior. Specifically, patch_paramiko_global() replaces the handler for MSG_SERVICE_ACCEPT so that during processing it temporarily swaps paramiko.message.Message.add_boolean with a no-op, causing the subsequent public-key authentication packet to be malformed/truncated. It also patches MSG_USERAUTH_FAILURE handling to raise a custom InvalidUsername exception. The code then attempts auth_publickey() with a generated RSA key for each candidate username. Based on the server response, it distinguishes invalid usernames (mapped to InvalidUsername) from valid usernames (AuthenticationException after the server proceeds further into auth processing). Capabilities include: automatic target vulnerability detection using nmap service/version scanning; single-username validation; multithreaded wordlist enumeration; deduplication of usernames; and summary reporting of valid, invalid, and errored usernames. The implementation includes a thread-safety improvement over older PoCs by protecting the temporary Paramiko patch with a threading lock, reducing race conditions during concurrent scans. Network targeting is straightforward: the user supplies a target host/IP and optional SSH port, defaulting to TCP/22. The code first fingerprints the service with nmap -sV and checks whether the reported product contains OpenSSH and whether the parsed version falls between 2.3 and 7.7. If the target does not appear vulnerable, the tool aborts unless used in check-only mode. Overall, this is a real exploit tool rather than a mere detector, because it actively performs malformed SSH authentication attempts to enumerate valid accounts. However, it does not provide code execution or shell access; its purpose is information disclosure/user enumeration against vulnerable OpenSSH servers.
This repository provides an operational exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions prior to 7.7. The exploit is implemented in Python and leverages the Paramiko library to interact with SSH servers. There are two main scripts: 'sshUsernameEnumExploit.py' (the original, more complex version) and 'sshUsernameEnumExploit_simple.py' (a simplified, modernized version recommended for use). Both scripts allow the user to test single or multiple usernames against a target SSH server, using either direct command-line input or a file of usernames. The exploit works by exploiting differences in SSH authentication responses (timing or protocol behavior) to determine if a username is valid. The repository includes a Dockerfile for easy containerized execution and a sample username list ('test_users.txt'). Output can be saved in various formats. The exploit is not a detection script but a true enumeration tool, and is not part of a larger framework. It is intended for authorized penetration testing and research on systems running vulnerable OpenSSH versions.
This repository is a professional-grade network reconnaissance and SSH penetration testing toolkit written in Python. The main code is in 'scanner.py', which implements a multi-functional network scanner and SSH security assessment tool. The toolkit provides advanced network discovery (ping sweeps), multi-protocol port scanning, service fingerprinting, and banner grabbing. Its SSH exploitation engine includes username enumeration using CVE-2018-15473 (timing-based attack), brute-force credential attacks with custom wordlists, and vulnerability analysis based on SSH banner versions. The configuration is managed via 'config.py', which defines default ports, service mappings, common credentials, and output paths. The tool is designed for authorized penetration testing and educational use, as emphasized in the README and LICENSE. It supports stealth and evasion features (randomized delays, connection pacing) to bypass detection mechanisms. The toolkit does not target a single product but is capable of scanning and attacking any accessible network hosts, with a focus on SSH services, especially those running vulnerable OpenSSH versions. No hardcoded IPs or domains are present; all targets are user-supplied at runtime. The repository is operational, providing real exploitation capabilities (not just detection), but is not part of a larger exploit framework.
This repository contains a Python proof-of-concept exploit for CVE-2018-15473, a user enumeration vulnerability in OpenSSH (prior to version 7.7). The main file, CVE-2018-15473.py, uses the paramiko library to connect to a target SSH server and attempts to authenticate with supplied usernames (either a single username or a list from a wordlist file). By exploiting differences in SSH protocol responses, the script can determine which usernames are valid on the target system. The script accepts command-line arguments for the target IP, port, single username, or a wordlist of usernames. The README provides usage instructions and example commands. The exploit is network-based, targeting the SSH service (default port 22, but customizable). No hardcoded IPs or domains are present; the target is specified at runtime. The repository is structured simply, with the main exploit script, a requirements file for dependencies, a README, and a license. The exploit does not provide post-exploitation capabilities; its sole function is to enumerate valid SSH usernames on a vulnerable server.
This repository provides two exploit scripts (Python and Bash) for CVE-2018-15473, a username enumeration vulnerability in OpenSSH (<=7.7). The exploit works by sending invalid SSH public key authentication requests and analyzing the server's response to distinguish between valid and invalid usernames. The Python script (exploit.py) uses the Paramiko library and multiprocessing for fast, parallelized checks, and can operate in both single-username and wordlist modes. The Bash script (exploit.sh) uses the OpenSSH client and netcat to perform similar checks, also supporting parallel execution. Both scripts output valid usernames to the console and save them to valid_usernames.txt. The repository is structured with a README.md (usage and description), exploit.py (main Python exploit), and exploit.sh (Bash exploit). The exploit targets network-accessible OpenSSH servers and requires only basic command-line tools or Python dependencies.
This repository contains a proof-of-concept (PoC) exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH. The repository consists of a README.md explaining the vulnerability, usage, and mitigation, and a Python script (cve-2018-15473-poc.py) that implements the exploit. The script uses the Paramiko library to connect to a target SSH server (default port 22) and attempts authentication with a list of usernames and an invalid password. By analyzing the server's response, it determines which usernames are valid on the target system. The exploit is a network-based PoC and does not provide post-exploitation capabilities; its sole purpose is to enumerate valid usernames on vulnerable OpenSSH servers.
This repository contains a Python proof-of-concept exploit for CVE-2018-15473, a user enumeration vulnerability in OpenSSH (prior to version 7.7). The main script, 'SSHEnum.py', uses the Paramiko library to connect to a target SSH server and attempts authentication with usernames from a provided wordlist ('diccionario.txt') or a single username. By analyzing the server's response, the script determines which usernames are valid on the target system. The repository also includes setup instructions ('Instrucciones.txt'), a requirements file for dependencies, and a sample wordlist. The exploit is network-based and targets SSH services, making it useful for penetration testers to identify valid usernames on vulnerable OpenSSH instances.
This repository provides a Python-based proof-of-concept exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions 7.7 and earlier. The main script, 'ssh-username-enum.py', uses the paramiko library (with a monkey-patch) to send specially crafted SSH authentication requests to a target host. By analyzing the server's responses, the script can determine which usernames are valid on the remote system. The exploit supports both single username checks and bulk enumeration using a wordlist, with multithreading for efficiency. It can target both IPv4 and IPv6 addresses and allows the user to specify the SSH port. The repository includes a README with usage instructions and examples, a requirements.txt for dependencies, and standard project files. The exploit is operational and effective for fingerprinting valid usernames on vulnerable OpenSSH servers, making it a valuable tool for penetration testers and security researchers.
This repository contains a Python script (SSHUsernameBrute.py) that exploits CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions prior to 7.7. The script uses the paramiko library to interact with SSH servers and manipulates the authentication process to distinguish between valid and invalid usernames. It supports multi-threaded operation and can use supplied username lists (provided as 'small' and 'medium' files in the repository) or custom lists. The script can also attempt to authenticate using username/username pairs if desired. The README provides a brief description of the tool and its purpose. The main entry point is SSHUsernameBrute.py, which is a standalone exploit script, not part of a larger framework. The attack vector is network-based, targeting SSH services (typically on TCP port 22). The repository is structured with the main exploit script and two username wordlists, making it easy to use for penetration testers or security researchers.
This repository contains a Python script (ssh_enum_usr.py) that exploits CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions 2.3 to 7.7. The script allows an attacker to determine valid SSH usernames on a target system by sending crafted authentication requests and analyzing the server's responses. It supports checking a single username or a list of usernames from a file. The script uses the 'paramiko' library to interact with the SSH protocol and 'colorama' for colored console output. The README.md provides detailed usage instructions, requirements, and credits. The exploit is a proof-of-concept and does not provide post-exploitation capabilities beyond username enumeration. The main attack vector is network-based, targeting the SSH service (typically on TCP port 22).
This repository contains 'opensshenum', a C++ tool for exploiting the OpenSSH user enumeration vulnerability (CVE-2018-15473). The tool allows an attacker to verify which usernames exist on a remote OpenSSH server by sending crafted authentication requests and analyzing the server's responses. It supports scanning a range of TCP ports to find SSH daemons (not just the default port 22), and can perform fingerprinting to guess the target OS or service based on user lists and a database of known user/service combinations. The main entry point is 'src/Main.cpp', which implements command-line parsing and orchestrates the attack logic. The repository also includes a Bash script ('src/parallenum.sh') for parallelizing port scans and user enumeration, and a utility ('utils/createdb.cpp') for building fingerprint databases from user lists. The exploit is operational and requires a vulnerable OpenSSH server (pre-July 2018 patch), a list of usernames, and a valid SSH key (can be a dummy key). The tool is intended for Unix-like systems and depends on OpenSSL. No fake or destructive payloads are present; the tool is focused on information gathering (user enumeration and fingerprinting) and port scanning.
This repository provides a Python-based exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions prior to 7.7. The main exploit script, 'sshUsernameEnumExploit.py', uses the Paramiko library to send specially crafted SSH authentication packets to a target host. By analyzing the server's responses, the script can determine whether a given username is valid or invalid. The exploit supports both single and multiple username checks, multithreading, and outputs results in list, JSON, or CSV formats. The Dockerfile allows for containerized execution of the exploit. Example input and output files are provided for demonstration. The exploit targets network-accessible SSH services and requires the attacker to specify the target's hostname or IP address and port (default 22). The exploit is operational and can be used to enumerate valid usernames on vulnerable OpenSSH servers.
This repository contains three Python scripts (sshuserenum3.py, casi.py, casi2.py) designed to exploit the OpenSSH user enumeration vulnerability (CVE-2018-15473) on versions prior to 7.7. The main exploit capability is to determine whether specific usernames exist on a target SSH server by sending specially crafted authentication requests and analyzing the server's response. - 'sshuserenum3.py' is a direct Python3 port of a known exploit, allowing the user to check a single username against a target IP and port. - 'casi.py' extends this functionality, supporting both single username checks and bulk enumeration from a wordlist, with options for output formatting (list, JSON, CSV) and multithreading for efficiency. - 'casi2.py' is similar to 'casi.py', providing both single and wordlist-based enumeration, and is structured for modular use. All scripts use the paramiko library to interact with the SSH service, manipulate the authentication process, and distinguish valid from invalid usernames based on subtle differences in server responses. The exploit is network-based, targeting the SSH service (typically on TCP port 22) of a remote host. No hardcoded endpoints are present; the target IP/hostname and port are provided as command-line arguments. The repository is a practical tool for penetration testers to enumerate SSH users on vulnerable OpenSSH installations.
This repository contains a Python3 exploit script (Exploit.py) targeting CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions 2.3 through 7.6. The exploit leverages the paramiko library to interact with the SSH protocol, modifying internal message handlers to detect valid usernames based on the server's authentication responses. The script can check a single username or use a wordlist (username.txt) to enumerate multiple usernames. The README.md provides usage instructions and background on the vulnerability. The requirements.txt lists dependencies (argparse, paramiko). The exploit is a proof-of-concept and does not provide post-exploitation capabilities; its sole function is to enumerate valid SSH usernames on a vulnerable target. The main attack vector is network-based, targeting the SSH service (default port 22) on the specified host.
This repository provides a proof-of-concept exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions 2.3 up to 7.4. The main entry point is the Bash script 'bin/massh-enum', which orchestrates the enumeration process. It uses Nmap to scan a given network range for hosts with port 22 (SSH) open, then iterates through a list of usernames (from 'wordlists/users') and invokes a Python script ('lib/init.py') for each username/host combination. The Python script leverages the Paramiko library to interact with the SSH server and distinguishes valid from invalid usernames based on subtle differences in the server's response to authentication attempts. The exploit does not provide shell access or code execution, but allows an attacker to enumerate which usernames exist on vulnerable OpenSSH servers. The repository is structured with clear separation between the Bash orchestration logic, the Python exploit logic, and the wordlist. No hardcoded IPs or domains are present; targets are supplied by the user at runtime. The exploit is operational and automates mass username enumeration across a network.
This repository provides a Python-based proof-of-concept exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions up to 7.7. The main script, 'ssh-username-enum.py', uses the paramiko library with a monkey-patch to craft malformed SSH authentication requests. By analyzing the server's response, the script can determine whether a given username exists on the target system. The exploit supports both single username checks and bulk enumeration using a wordlist, with multithreading for efficiency. It can target both IPv4 and IPv6 addresses and allows specification of the SSH port. The repository includes a README with usage instructions and examples, a requirements.txt for dependencies, and standard project files. No hardcoded IPs or domains are present; the target is specified at runtime. The exploit is a POC and does not provide post-exploitation capabilities.
This repository contains a Python3 proof-of-concept exploit for CVE-2018-15473, a username enumeration vulnerability in OpenSSH versions 2.3 through 7.6. The main script, 'CVE-2018-15473.py', uses the paramiko library to interact with the SSH service on a target host. By sending specially crafted authentication requests and analyzing the server's responses, the script can determine which usernames are valid on the system. The exploit can check a single username or use a wordlist to enumerate multiple usernames. The repository also includes a README.md with usage instructions and a requirements.txt listing dependencies. The exploit targets the SSH service (default port 22) and is effective against vulnerable OpenSSH servers accessible over the network. No hardcoded endpoints are present; the target is specified by the user at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.