Skip to content

ssh

The ssh identity: Secure Shell. Every field and what is required.

ssh is the Secure Shell protocol (RFC 4253). The target is host:port (default 22). The step sends and receives raw bytes as hex, and the session persists across steps, so a solution can stage an exchange and continue it.

Fields

ssh uses the byte-session fields from tcp:

fieldrequiredwhat it does
sendyesthe bytes to send, as hex or hex "text"; empty when a step only reads
recvhow many bytes to read at most
recv_untilstop reading once this hex marker appears
timeouthow long to wait, in seconds
closeend the session after this step
capturepull a value out of the received hex for later steps

Example

ssh banner
  meaning: read the SSH version banner
  recv: 4096
  timeout: 5
  assert: regex "5353482d"

Write attacks down. Verify them.

Download the binary, point it at a target you own, and get a verified result. The corpus is open and the format is plain text.