DEF CON 32: SSHamble: Unexpected Exposures in SSH (Video)

The Secure Shell (SSH) has evolved from a remote shell service to a standardized secure transport that is second only to Transport Layer Security (TLS) in terms of exposure and popularity. SSH is no longer just for POSIX operating systems; SSH services can be found in everything from network devices, to source code forges, to Windows-based file transfer tools. While OpenSSH is still the most prominent implementation, it's now just one of dozens, and these include a handful of libraries that drive a wide range of applications. This presentation (download PDF) digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to exploit them. As part of this talk, we released an open source tool, dubbed "SSHamble", that assists with research and security testing of SSH services.

Meet Our Speakers

Rob King

Director of Applied Research, runZero

HD Moore

Founder & CEO, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Talks
Detecting Forbidden White Labeled and Counterfeit Devices (SecTor 2025)
Learn how to tell if your expensive router (bought cheap!) really is the real thing, and whether your network really is free from forbidden devices.
Talks
Turbo Tactical Exploitation: 22 Tips for Tricky Targets
This rapid-fire session delivers 22 practical tips to help you find juicy targets faster, pivot cleaner, and avoid wasting time on noise.
Talks
The once and future rules of cybersecurity (SecTor keynote)
In this session, HD revisits the rules we lived by in the 2000s, reveal which ones still matter, which ones failed us, and what new rules we'll...
Talks
Vulnerability haruspicy: using woo to confirm your biases (NorthSec 25)
This talk digs into the strengths, weaknesses, and absurdities of CVSS, EPSS, and SSVC, comparing them to the reality of how security teams...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.