Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SSH Audit - file #10640

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

Conversation

pussycat0x
Copy link
Contributor

@pussycat0x pussycat0x commented Aug 31, 2024

Template / PR Information


nuclei -u  /etc/ssh/sshd_config  -t .             

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.2.7

                projectdiscovery.io

[INF] Current nuclei version: v3.2.7 (outdated)
[INF] Current nuclei-templates version: v9.9.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 56
[INF] Templates loaded for current scan: 15
[WRN] Loading 15 unsigned templates for scan. Use with caution.
[INF] Targets loaded for current scan: 1
[ssh-key-auth-required] [file] [info] /etc/ssh/sshd_config
[hide-last-login-information] [file] [info] /etc/ssh/sshd_config
[change-default-port] [file] [info] /etc/ssh/sshd_config
[disable-ssh-forwarding] [file] [info] /etc/ssh/sshd_config
[disable-empty-password] [file] [info] /etc/ssh/sshd_config
[disable-ssh-protocol-1] [file] [info] /etc/ssh/sshd_config
[idle-timeout-interval] [file] [info] /etc/ssh/sshd_config
[limit-maximum-authentication-attempts] [file] [info] /etc/ssh/sshd_config
[enable-ssh-privilege-separation] [file] [info] /etc/ssh/sshd_config
[limit-ssh-users-access] [file] [info] /etc/ssh/sshd_config
[ssh-ip-whitelist] [file] [info] /etc/ssh/sshd_config
[limit-ssh-group] [file] [info] /etc/ssh/sshd_config



Template Validation

I've validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Additional References:

@pussycat0x pussycat0x mentioned this pull request Aug 31, 2024
2 tasks
@DhiyaneshGeek
Copy link
Member

Hi @pussycat0x

Weak Matcher (Need to Add Valid Matcher) - the below mentioned templates contains only negative matcher & extension - all , results in False Positive

  • Disable SSH Protocol 1
  • Disable SSH Empty Password
  • Enable Privilege Separation in SSH
  • Hide SSH Last Login Information
  • Set SSH Idle Timeout Interval
  • Limit SSH Users Group Access
  • Limit SSH Users Access

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants