But on the subject of passwords, best practice for SSH for a long time has been to disable password based login entirely and rely on keys.
But on the subject of passwords, best practice for SSH for a long time has been to disable password based login entirely and rely on keys.
For instance, an OpenBSD box running Tor may have a user "_tor", a Debian-based box (e.g. Ubuntu) may have a user "debian-tor", and so on (depending on how Tor was installed, in my case via pkg_add & apt-get; usernames might vary for different OS/repo versions). I have tested this using the PoC against some of my own systems (the ones that have PasswordAuthentication still enabled) and it works for those.
Shodan shows some 66k services identifying as SSH-2.0-dropbear [2], as opposed to some 15k identifying as SSH-2.0-OpenSSH [3].
Issue has been reported to the vendor today.
[0] https://www.reddit.com/r/blackhat/comments/97ywnm/openssh_us...
[1] https://github.com/mkj/dropbear/blob/master/svr-auth.c#L175-...