SSH’s Hidden Attack Surface
SSH leaks data before authentication. The TCP/IP stack, server version, cipher extensions, and banner all expose information. OpenSSH and Dropbear make up 98% of installations. The remaining 2% includes ICS, OT, and custom Cisco demons. Those oddball servers are rare but critical. Moore showed how to take someone else’s public key from GitHub and test it against servers to see if they can log in, without needing the private key. That technique confirms username access and finds stale credentials.
A Year of Wild SSH Bugs
Terrapin truncated TCP sessions to force weaker ciphers. The XZ utils backdoor took three years of trust-building before the attacker twisted the knife. RegreSSHion was the first default OpenSSH RCE in years, though hard to exploit outside 32-bit x86. MoveIt’s SSH stack treated a public key blob as a file path, enabling NTLM relay. Qualys turned an out-of-memory bug in the client into a man-in-the-middle attack. The Go SSH library let attackers authenticate with a different key than the one verified. Cisco shipped another backdoor credential in a narrow set of appliance versions.
2025 Internet Scan: 23 Million Servers, 130,000 Shells
Moore scanned all IPv4 on port 22 and 110 other top SSH ports. He found 23 million servers with port 22 open, down from 27 million last year. About 14 million negotiated authentication. He collected 130,000 shells. The extra ports added 2.3 million demons and 20,000 more shells. He revisited last year’s vulnerable devices. Digi routers, Panasonic switches, and others remained unpatched. “Nobody patched anything,” Moore said. “It’s actually worse than it was last year.” He found more vulnerabilities in the already-disclosed devices than in new ones.
New Zero-Days and Bonus Credentials
Moore disclosed several new bugs pending release. Carrier Ethernet switches across Asia accept a single null byte as an auth method, logging in with no credentials. An older PBX drops to a shell after three failed login attempts. A Chinese ISP contractually requires customers to run a custom SSH demon on a high port. That demon accepts any public key and drops into a shell as user “none”. WatchGuard firewalls started throwing domain admin credentials at Moore’s scanner when they received port scan alerts. He recommended running Responder and TPU dump during any internet scan to collect bonus zero-day credentials.
SSHamble: New Features and Nuclei Integration
SSHamble gained version skipping, auth bypass checks, and the hanobox bad keys database. That database includes leaked Fortinet appliance keys. The tool now checks if any SSH key in your environment is compromised. It provides an interactive shell for TCP/IP forwarding and port scanning. Moore is porting SSHamble checks into Nuclei templates, sharing the same codebase. Users will soon run nuclei normally and get all the same SSH bug detections.
Notable Quotes
nobody patched anything HD Moore · ▶ 14:53
it’s actually worse than it was last year HD Moore · ▶ 14:54
you can do all the research you want. You can tell the world, but no one’s going to patch your stuff HD Moore · ▶ 15:03
the ISP in this case contractually obligated a back door that was trivial to exploit HD Moore · ▶ 17:36
always run responder when you’re doing scans cuz you get bonus zero day HD Moore · ▶ 19:09
Key Takeaways
- SSHamble found 9 new zero-days across 130,000 shells from 23 million SSH servers.
- Most vendors never patch; vulnerable devices from last year are still exposed.
- Run Responder and TPU dump during internet scans to collect leaked credentials.
About the Speaker(s)
HD Moore is a pioneer of the cybersecurity industry who has dedicated his career to vulnerability research, network discovery, and software development since the 1990s. He is most recognized for creating Metasploit and is a passionate advocate for open-source software and vulnerability disclosure. HD serves as the CEO and founder of runZero, a provider of cutting-edge attack surface management and exposure management software. Prior to founding runZero, he held leadership positions at Atredis Partners, Rapid7, and BreakingPoint. HD’s professional journey began with exploring telephone networks, developing exploits for the Department of Defense, and breaking into financial institutions. When he’s not working, he enjoys hacking on weird Go projects, building janky electronics, running in circles, and playing single-player RPGs.