Tardcircus / CVE2016-6210

CVE 2016-6210 OpenSSH 7.2p2 Time response vulnerability to enumerate usernames

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE2016-6210

CVE 2016-6210 OpenSSH 7.2p2 Time response vulnerability to enumerate usernames

Description A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses.

This tool was created to take advantage of CVE2016-6210 to enumerate username on OpenSSH 7.2p2. I updated the deprecated modules to keep it going.

About

CVE 2016-6210 OpenSSH 7.2p2 Time response vulnerability to enumerate usernames


Languages

Language:Python 100.0%