DEF CON 32: SSHamble: Unexpected Exposures in SSH (PDF)

The Secure Shell (SSH) has evolved from a remote shell service to a standardized secure transport that is second only to Transport Layer Security (TLS) in terms of exposure and popularity. SSH is no longer just for POSIX operating systems; SSH services can be found in everything from network devices, to source code forges, to Windows-based file transfer tools. While OpenSSH is still the most prominent implementation, it's now just one of dozens, and these include a handful of libraries that drive a wide range of applications. This presentation digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to exploit them. As part of this talk, we released an open source tool, dubbed "SSHamble", that assists with research and security testing of SSH services.


Related Resources

Talks
Your Next Incident Won't Have a CVE
HD Moore dissects why your next breach won’t be tied to a CVE. HD will reveal why your security stack is failing you through the lens of an...
Talks
LASCON 2024 Keynote: HD Moore - Hacker Numerology
In this keynote HD Moore explores the numbers that define our lives and how to use limited observations of identifiers to reason about the security...
Talks
DEF CON 32: SSHamble: Unexpected Exposures in SSH (Video)
This talk digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to exploit them.
Talks
CypherCon 7.0 Keynote: 25 Years of Vulnerability Mismanagement
HD Moore, Founder and CEO of runZero, gives the keynote address at CypherCon 7.0.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.

Discover the new era of exposure management!