NetExec SSH Auth & Spray
Validate credentials against SSH. Supports password, key file, and spraying across user/password lists. NetExec also detects when the resulting session is root.
- Tool
- nxc
- Category
- Authentication / Credential Testing
- Platform
- linux
- Requires
- password
- Protocols
- SSH
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc ssh <ip> -u <user> -p <password>
Credential variants
The same attack using a different authentication material.
Private Key requires no credentials
nxc ssh <ip> -u <user> --key-file <id_rsa>
Spray With User+Password Lists requires no credentials
nxc ssh <subnet> -u <users.txt> -p <passwords.txt> --continue-on-success
Run a Command requires password
nxc ssh <ip> -u <user> -p <password> -x '<command>'
Examples
nxc ssh 10.10.10.10 -u root -p 'toor'
nxc ssh 10.10.10.10 -u ubuntu --key-file ~/.ssh/id_rsa -x 'sudo -l'
Tags
References
Related commands
- NetExec FTP Auth & Listing Validate FTP credentials and check anonymous access. Combine with --ls to list the root…
- NetExec RDP Auth Check Validate credentials against the RDP service (TCP/3389) without opening a graphical…
- NetExec SMB Auth Test Test SMB authentication with various credential types
- NetExec SMB with Kerberos Auth Authenticate to SMB using a Kerberos ticket from a ccache file instead of NTLM. Required…
- NetExec WinRM Auth Check Validate credentials against the WinRM (PowerShell Remoting) service. A successful login…