
DEF CON 32 - Sshamble Unexpected Exposures in the Secure Shell - HD Moore, Rob King
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 45:25
The video explores the security landscape of SSH, revealing how widespread vulnerabilities and misconfigurations expose millions of devices to attackers. A major focus is on the discovery of "free shells" across the internet through a tool called shamble, which scans SSH services using public keys from platforms like GitHub and Launchpad. The analysis uncovers a vast attack surface due to post-authentication flaws, signal injection, shell injection, and broken SSH state transitions—many of which go unnoticed because they occur behind secondary authentication layers. The presentation highlights real-world examples, including vulnerable Ruckus access points, Digi transport gateways, and netbit devices, all of which allow remote shell access with minimal effort. The research also reveals how different SSH implementations—such as openSSH, Dropbear, and PKIX SSH—introduce unique security risks due to forked codebases and patching, with Windows SSH being particularly compromised due to poor implementation.
Key Takeaways:
• The XU Tails backdoor in SSH was a multi-year campaign targeting openSSH, discovered just before release by Andre Frond, and involved an encrypted key accessible only to the attacker 2:33-2:48.
• A critical vulnerability in Ruckus access points allows password injection via shell commands, enabling remote code execution on devices with 36,000 exposed units 16:45-17:25.
• The shamble tool, designed to scan public keys across the internet, revealed over 27 million devices listening on port 22 and uncovered 110,000 sessions with exploitable post-authentication flaws 11:26-11:37.
• SSH implementations like Dropbear and Windows SSH have severe security gaps due to poor code hygiene, with Windows’ version of SSH removing core security features and enabling arbitrary command ex
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hey guys uh so we're going to talk about SSH and this has been probably the most exciting year in SSH since x2. C got x2. C got leaked by teso so um props anyone who use that uh so uh shsh for folks who aren't aware um You probably probably should be here if you don't what sh is but um sh secure shell Port 22 the thing we've been using to add in the internet for many years like almost 30 years um there's really two flavors of of sh that we use the most there's open sh which is like 80 something % of all sh installations and then there's drop bear which is like another like 5 to 8% and then this long taale of random weird stuff out there so we decided to do some research into first looking into the XE back door and then part of that we just accidentally found a couple tens of thousands of s…