less than 1 minute read

Gather SSH public keys from servers

ssh-keyscan -t rsa 10.10.10.3 -p 22

Public key

Can be used in authorized_keys for login id_rsa.pub

Private key

Can be cracked with ssh2john  and john

Cracking with John

locate *2john*
ssh2john.py SSH.private > ssh.hash
cat ssh.hash 

Cracking SSH Keys

john --wordlist=rockyou.txt ssh.hash
john ssh.hash --show

Remember

chmod 600 id_rsa

Connect

ssh -i id_rsa john@10.10.10.3

ssh john@10.10.10.3