mirror of
				https://github.com/jtesta/ssh-audit.git
				synced 2025-11-04 03:02:15 +01:00 
			
		
		
		
	Added two KEX algorithms: diffie-hellman-group16-sha256 and diffie-hellman-group-exchange-sha512@ssh.com.
This commit is contained in:
		@@ -46,7 +46,7 @@ usage: ssh-audit.py [-1246pbnvlt] <host>
 | 
				
			|||||||
 - Added RSA certificate key length test.
 | 
					 - Added RSA certificate key length test.
 | 
				
			||||||
 - Added Diffie-Hellman modulus size test.
 | 
					 - Added Diffie-Hellman modulus size test.
 | 
				
			||||||
 - Now outputs host key fingerprints for RSA and ED25519.
 | 
					 - Now outputs host key fingerprints for RSA and ED25519.
 | 
				
			||||||
 - Added 3 new key exchanges: `sntrup4591761x25519-sha512@tinyssh.org`, `diffie-hellman-group-exchange-sha256@ssh.com`, `diffie-hellman-group17-sha512`.
 | 
					 - Added 5 new key exchanges: `sntrup4591761x25519-sha512@tinyssh.org`, `diffie-hellman-group-exchange-sha256@ssh.com`, `diffie-hellman-group-exchange-sha512@ssh.com`, `diffie-hellman-group16-sha256`, `diffie-hellman-group17-sha512`.
 | 
				
			||||||
 - Added 3 new encryption algorithms: `des-cbc-ssh1`, `blowfish-ctr`, `twofish-ctr`.
 | 
					 - Added 3 new encryption algorithms: `des-cbc-ssh1`, `blowfish-ctr`, `twofish-ctr`.
 | 
				
			||||||
 - Added 10 new MACs: `hmac-sha2-56`, `hmac-sha2-224`, `hmac-sha2-384`, `hmac-sha3-256`, `hmac-sha3-384`, `hmac-sha3-512`, `hmac-sha256`, `hmac-sha256@ssh.com`, `hmac-sha512`, `hmac-512@ssh.com`.
 | 
					 - Added 10 new MACs: `hmac-sha2-56`, `hmac-sha2-224`, `hmac-sha2-384`, `hmac-sha3-256`, `hmac-sha3-384`, `hmac-sha3-512`, `hmac-sha256`, `hmac-sha256@ssh.com`, `hmac-sha512`, `hmac-512@ssh.com`.
 | 
				
			||||||
 - Added command line argument (-t / --timeout) for connection & reading timeouts.
 | 
					 - Added command line argument (-t / --timeout) for connection & reading timeouts.
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -321,12 +321,14 @@ class SSH2(object):  # pylint: disable=too-few-public-methods
 | 
				
			|||||||
				'diffie-hellman-group14-sha1': [['3.9,d0.53,l10.6.0'], [], [WARN_HASH_WEAK]],
 | 
									'diffie-hellman-group14-sha1': [['3.9,d0.53,l10.6.0'], [], [WARN_HASH_WEAK]],
 | 
				
			||||||
				'diffie-hellman-group14-sha256': [['7.3,d2016.73']],
 | 
									'diffie-hellman-group14-sha256': [['7.3,d2016.73']],
 | 
				
			||||||
				'diffie-hellman-group15-sha512': [[]],
 | 
									'diffie-hellman-group15-sha512': [[]],
 | 
				
			||||||
 | 
									'diffie-hellman-group16-sha256': [[]],
 | 
				
			||||||
				'diffie-hellman-group16-sha512': [['7.3,d2016.73']],
 | 
									'diffie-hellman-group16-sha512': [['7.3,d2016.73']],
 | 
				
			||||||
				'diffie-hellman-group17-sha512': [[]],
 | 
									'diffie-hellman-group17-sha512': [[]],
 | 
				
			||||||
				'diffie-hellman-group18-sha512': [['7.3']],
 | 
									'diffie-hellman-group18-sha512': [['7.3']],
 | 
				
			||||||
				'diffie-hellman-group-exchange-sha1': [['2.3.0', '6.6', None], [FAIL_OPENSSH67_UNSAFE], [WARN_HASH_WEAK]],
 | 
									'diffie-hellman-group-exchange-sha1': [['2.3.0', '6.6', None], [FAIL_OPENSSH67_UNSAFE], [WARN_HASH_WEAK]],
 | 
				
			||||||
				'diffie-hellman-group-exchange-sha256': [['4.4']],
 | 
									'diffie-hellman-group-exchange-sha256': [['4.4']],
 | 
				
			||||||
				'diffie-hellman-group-exchange-sha256@ssh.com': [[]],
 | 
									'diffie-hellman-group-exchange-sha256@ssh.com': [[]],
 | 
				
			||||||
 | 
									'diffie-hellman-group-exchange-sha512@ssh.com': [[]],
 | 
				
			||||||
				'ecdh-sha2-nistp256': [['5.7,d2013.62,l10.6.0'], [WARN_CURVES_WEAK]],
 | 
									'ecdh-sha2-nistp256': [['5.7,d2013.62,l10.6.0'], [WARN_CURVES_WEAK]],
 | 
				
			||||||
				'ecdh-sha2-nistp384': [['5.7,d2013.62'], [WARN_CURVES_WEAK]],
 | 
									'ecdh-sha2-nistp384': [['5.7,d2013.62'], [WARN_CURVES_WEAK]],
 | 
				
			||||||
				'ecdh-sha2-nistp521': [['5.7,d2013.62'], [WARN_CURVES_WEAK]],
 | 
									'ecdh-sha2-nistp521': [['5.7,d2013.62'], [WARN_CURVES_WEAK]],
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user