Skip to content

DevOps Security - Scanning SSH keys for Weak credentials

Scanning SSH keys for Weak credentials.

Santhosh Baswa

21 February 2017, 1 min read

Most of the enterprise companies were migrating their infrastructure to cloud. They focused mainly on security in cloud, and DevOps teams were implementing CI/CD pipeline and integrating their tools with security tooling. In our article i would like to discuss to detect weak SSH credentials in DevOps environments using Metasploit tool.

DevOps Environment - Security Checks (SSH Keys):

  1. Most of the DevOps environment VMs/Machines are using default credentials (vagrant/vagrant , root/vagrant)
  2. Scanning the default SSH keys using metasploit - ssh_login_pubkey module.
  3. Identify the weak SSH keys versions after the scan.
  4. Login with Private key.
  5. Get the vagrant/root shell.
DevOps - SSH weak keys scan:
DevOps - Security Checks
Steps to Reproduce - DevSecOps (SSH Keys)

Tools used:

Metasploit

Written by

Santhosh Baswa

I hunt and defend organisations’ environments, and in my free time I write up what I learn here and give technical sessions in open security communities.

Get new articles by email

One email when something substantial goes up. No tracking pixels, and one click to unsubscribe.