Skip to content
@ssh-mitm

SSH-MITM - ssh audits made simple

ssh mitm server for security audits supporting public key authentication, session hijacking and file manipulation

SSH-MITM — ssh audits made simple

Open-source man-in-the-middle SSH proxy for security audits and penetration testing.
Intercepts live SSH sessions in real time — credentials, keys, file transfers, and tunnels.

SSH-MITM intercepting an SSH session

Download as an AppImage    Download on Flathub    Get it from the Snap Store

Documentation   PyPI   License


CVE Research

SSH-MITM was used to discover 6 previously unknown vulnerabilities in widely-deployed SSH software:

CVE Software Description
CVE-2021-36367 PuTTY FIDO2 hardware token phishing via SSH proxy
CVE-2021-36368 OpenSSH Trivial authentication enables FIDO2 bypass
CVE-2021-36369 Dropbear Trivial authentication
CVE-2021-36370 MobaXterm Trivial authentication
CVE-2022-38336 MobaXterm Credential disclosure
CVE-2022-38337 MobaXterm Credential disclosure

Pinned Loading

  1. ssh-mitm ssh-mitm Public

    SSH-MITM - ssh audits made simple

    Python 1.5k 155

  2. appimage appimage Public

    Package Python applications as self-contained AppImages

    Python 2 1

Repositories

Showing 6 of 6 repositories

Top languages

Loading…

Most used topics

Loading…