This penetration testing tool allows an auditor to intercept SSH connections. A patch applied to the OpenSSH v7.5p1 source code causes it to act as a proxy between the victim and their intended SSH server; all plaintext passwords and sessions are logged to disk. Of course, the victim's SSH client will complain that the server's key has changed. But because 99.99999% of the time this is caused by a legitimate action (OS re-install, configuration change, etc), many/most users will disregard the warning and continue on. NOTE: Only run the modified sshd_mitm in a VM or container! Ad-hoc edits were made to the OpenSSH sources in critical regions, with no regard to their security implications. Its not hard to imagine these edits introduce serious vulnerabilities.

Features

  • The quickest & easiest way to get started is to use the Docker image with SSH MITM pre-built
  • Find targets on the LAN, and ARP spoof them
  • Shell and SFTP sessions will be logged in the ssh_mitm_logs directory
  • To test out changes to the OpenSSH source code, use the dev/redeploy.sh script
  • To re-generate a full patch to the OpenSSH sources, use the dev/regenerate_patch.sh script
  • Only run the modified sshd_mitm in a VM or container

Project Samples

Project Activity

See All Activity >

License

MIT License

Follow SSH MITM

SSH MITM Web Site

Other Useful Business Software
$300 in Free Credit for Your Google Cloud Projects Icon
$300 in Free Credit for Your Google Cloud Projects

Build, test, and explore on Google Cloud with $300 in free credit. No hidden charges. No surprise bills.

Launch your next project with $300 in free Google Cloud credit—no hidden charges. Test, build, and deploy without risk. Use your credit across the Google Cloud platform to find what works best for your needs. After your credits are used, continue building with free monthly usage products. Only pay when you're ready to scale. Sign up in minutes and start exploring.
Start Free Trial
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of SSH MITM!

Additional Project Details

Programming Language

C

Related Categories

C MiTM (Man-in-The-Middle) Attack Tool

Registered

2023-08-14