Commit Graph
100 Commits
Author SHA1 Message Date
Joe Testa 13fd7102d9 Added tabulation for "Not allowed at this time" banners (when the PerSourcePenalties directive triggers in OpenSSH 9.8 and later), along with tabulation for invalid SSH banners. 2026-07-04 14:40:38 -04:00
Joe Testa 419df1b788 Added hardening policy for OpenSSH 10.4. 2026-07-03 11:14:28 -04:00
Joe Testa 859cb7012e Added ssh-mldsa44-ed25519@openssh.com host key type. 2026-07-03 10:59:16 -04:00
Joe Testa 0f8bbdbfd9 Fixed bug where algorithm added in OpenSSH 10.x was being recommended for OpenSSH 9.x targets. 2026-07-03 10:58:48 -04:00
Joe Testa 1eb11050b3 Added 9 new host key types: 'mldsa-44', 'mldsa-65', 'mldsa-87', 'ssh-mldsa-44', 'ssh-mldsa-65', 'ssh-mldsa-87', 'ssh-mldsa44', 'ssh-mldsa65', 'ssh-mldsa87'. 2026-06-20 19:02:08 -04:00
Joe Testa 240840f580 Added note in README that support was added for Python 3.14. 2026-06-20 10:32:43 -04:00
Joe Testa 36def4b5ac Expanded SOCKS5 protocol support, refactored exception handling, updated documentation, added more tests. (#347) 2026-06-20 10:07:14 -04:00
Joe Testa 3bd2dd95a9 Updated built-in policy for Debian 12 to match latest hardening guide. (#341) 2026-06-19 21:33:53 -04:00
Joe Testa b7749a7e17 Added built-in policies for OpenSSH 10.1, 10.2, and 10.3. 2026-06-19 20:50:58 -04:00
Joe Testa 974dd324a6 Added Rocky Linux 10 hardening guides and policies. (#354) 2026-06-17 20:20:19 -04:00
Joe Testa e42d993b07 Added hardening guides and policies for Ubuntu 26.04. 2026-06-14 19:55:06 -04:00
Joe Testa 0ccb915f37 Added support for scanning servers over UNIX sockets. (#351) 2026-06-14 17:21:13 -04:00
Joe Testa abf5b8326a Fixed image pull command when using podman. 2026-06-14 17:05:43 -04:00
Joe Testa e01bd61df0 Added usedforsecurity=False to hashlib.md5() call to suppress security scanner warning. 2026-06-13 10:54:54 -04:00
Joe Testa f2ed8c01ae Added new host key: webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com (#348) 2026-06-13 10:27:07 -04:00
Joe Testa bbec6dbf23 Bumped copyright year. 2026-06-13 10:23:36 -04:00
Joe Testa 2573235f6a Added support for Python 3.14. Dropped support for Python 3.9. 2026-06-13 09:08:15 -04:00
Joe Testa 4f9a630de4 Added Debian 13 policies and hardening guides. 2025-09-01 18:22:46 -04:00
Joe Testa f821565ff9 Renamed hardeningguides.py. 2025-09-01 17:39:07 -04:00
Joe Testa 062a1f3cb4 Updated changelog message for version 2 of Ubuntu Server 24 policy. 2025-09-01 16:43:59 -04:00
Joe Testa c900874406 Added policy option to allow host key subsets and/or reorderings. 2025-09-01 16:22:40 -04:00
Joe Testa 0382cf9b2d Aside from linking to online hardening guides, mention that built-in guides are also available. 2025-08-30 16:26:57 -04:00
Joe Testa d8d90a3a89 Dropped support for Python 3.8, as it reached its end-of-life in October 2024. 2025-08-24 15:50:58 -04:00
Joe Testa aaa7d24565 Updated GEX fallback detection for OpenSSH 10.0 and later, as version 9.9 was the last to include it. (#310) 2025-08-24 15:41:14 -04:00
Joe Testa d3b1551520 Added OpenSSH 10.0 policy. 2025-08-24 12:52:22 -04:00
Joe Testa 970d747dcb Smoothed out some rough edges from PR #307. 2025-08-17 16:34:32 -04:00
Joe Testa 4845a8fdee Updated README. 2025-08-06 08:40:36 -04:00
Joe Testa 11a902cb14 Removed SSHv1 support (#298). 2025-07-26 19:57:11 -04:00
Joe Testa b456bb31b9 Added note on mlkem768x25519-sha256 that it is the default key exchange since OpenSSH 10.0. 2025-06-16 18:59:36 -04:00
Joe Testa 32085b2fa5 Added two new ciphers: AEAD_CAMELLIA_128_GCM, AEAD_CAMELLIA_256_GCM. 2025-05-18 18:46:40 -04:00
Joe Testa 5ddd8cca5b Added 2 new key exchanges: mlkem768nistp256-sha256, mlkem1024nistp384-sha384. 2025-04-18 18:29:18 -04:00
Joe Testa b90db2c1af Fixed mypy failure. 2025-04-18 17:06:29 -04:00
Joe Testa e318787a5c Batch mode no longer automatically enables verbose mode. 2024-12-05 10:06:58 -05:00
Joe Testa d9c703c777 When running against multiple hosts, now prints each target host regardless of output level. (#309) 2024-12-05 09:41:26 -05:00
Joe Testa 28a1e23986 Added warnings to all key exchanges that do not provide protection against quantum attacks. 2024-11-25 15:56:51 -05:00
Joe Testa a01baadfa8 Additional cleanups after merging #304. 2024-11-22 12:28:02 -05:00
Joe Testa 99c64787d9 Updated description of -m option. 2024-10-16 16:39:11 -04:00
Joe Testa 3fa62c3ac5 Fixed man page parsing error. (#301) 2024-10-16 16:23:20 -04:00
Joe Testa d7fff591fa Bumped version to v3.4.0-dev. 2024-10-15 18:30:08 -04:00
Joe Testa 84647ecb32 Updated packaging notes. 2024-10-15 18:29:25 -04:00
Joe Testa 772204ce8b Bumped version to v3.3.0. 2024-10-15 13:28:38 -04:00
Joe Testa c0133a8d5f Listing built-in policies will now hide older versions, unless -v is used. 2024-10-11 15:43:09 -04:00
Joe Testa 3220043aaf Added note regarding hardening instructions. 2024-10-10 16:10:52 -04:00
Joe Testa 40ed92bbe6 Run tests against stable version of Python 3.13. 2024-10-10 16:06:18 -04:00
Joe Testa 720150b471 Issue a warning if an out-dated policy is used. 2024-10-10 15:57:29 -04:00
Joe Testa d0628f6eb4 Updated ext-info-c and ext-info-s key exchanges to include versions of OpenSSH they were first included in. (#291) 2024-10-07 17:41:39 -04:00
Joe Testa 1e060a94c0 Updated built-in server and client policies for Amazon Linux 2023. 2024-10-01 18:15:02 -04:00
Joe Testa 8563c2925b Updated built-in client policy for Debian 12. 2024-10-01 17:48:49 -04:00
Joe Testa 556306be5e Updated built-in client policy for Rocky Linux 9. 2024-10-01 17:39:42 -04:00
Joe Testa 7ab6d20454 Updated built-in client policy for Ubuntu 22.04. 2024-10-01 17:32:49 -04:00
Joe Testa 1f1a51d591 Updated Ubuntu 22.04 built-in policy. 2024-10-01 17:06:03 -04:00
Joe Testa 77a63de133 Updated Rocky Linux 9 built-in policy. 2024-10-01 16:21:23 -04:00
Joe Testa cffa126277 Updated Debian 12 built-in policy. (#283) 2024-10-01 15:01:44 -04:00
Joe Testa dc615cef7f Fixed DH rate testing on Windows. (#261) 2024-09-28 18:39:55 -04:00
Joe Testa cb6142c609 Ignore mypy errors on colorama import. 2024-09-28 17:43:32 -04:00
Joe Testa 629008e55e Updated test commands. 2024-09-26 18:34:40 -04:00
Joe Testa 016a5d89f7 Updated Github Actions workflow to use Tox through pip instead of the platform version. 2024-09-26 18:31:21 -04:00
Joe Testa 93b30b4258 Removed version-based CVE information. (#240) 2024-09-26 13:15:58 -04:00
Joe Testa 3b8a75e407 Server kex/host key parsing failures no longer output a stack trace unless in debug mode. 2024-09-25 17:34:18 -04:00
Joe Testa 67e11f82b3 Updated --targets description. 2024-09-25 17:12:16 -04:00
Joe Testa 2cd96f1785 Ensure ECDSA and DSS fingerprints are only output in verbose mode. Clean up Docker tests from merge of #286. 2024-09-25 17:05:17 -04:00
Joe TestaandGitHub ac540c8b5f Created FUNDING.yml. 2024-09-25 16:20:45 -04:00
Joe Testa e11492b7a3 Updated shields. 2024-09-25 16:07:01 -04:00
Joe Testa 02bc48c574 Bumped supported Python range. 2024-09-25 14:18:41 -04:00
Joe Testa 24d7d46c42 Updated PyPI downloads shield. 2024-09-25 10:05:35 -04:00
Joe Testa e97bbd9782 Added Python 3.13 support. 2024-09-24 18:20:07 -04:00
Joe Testa 6d57c7c0f7 The -p/--port option will now set the default port for multi-host scans (specified with -T/--targets). (#294) 2024-09-24 16:42:53 -04:00
Joe Testa ea3258151e Fixed invalid JSON output when a socket error occurs while performing a client audit. (#295) 2024-09-24 15:48:14 -04:00
Joe Testa f9032c8277 Added built-in policy for OpenSSH 9.9. 2024-09-24 15:05:05 -04:00
Joe Testa d7398baad7 Added two new key exchanges: mlkem768x25519-sha256, sntrup761x25519-sha512. 2024-09-19 17:40:49 -04:00
Joe Testa 4621d52223 Updated unknown algorithm message. 2024-09-19 17:01:37 -04:00
Joe Testa 2a7cb13895 Added grasshopper-ctr128 cipher. 2024-09-18 17:59:45 -04:00
Joe Testa 06ebdbd0fe Updated README. 2024-08-26 16:46:34 -04:00
Joe Testa a6f02ae8e8 Added debugging output for key exchanges. 2024-08-26 16:25:32 -04:00
Joe Testa 9049c8476a Updated README. 2024-07-06 21:01:19 -04:00
Joe Testa 92db5f0138 Updated docker tests and README due to merge of PR #281. 2024-07-05 10:53:00 -04:00
Joe Testa ea117b203b Updated README. 2024-07-05 10:16:06 -04:00
Joe Testa e42961fa9a Added built-in policy for OpenSSH 9.8. 2024-07-02 21:31:36 -04:00
Joe Testa dcbc43acdf Fixed crash when running with '-P' and '-T' options simultaneously. (#273) 2024-07-02 20:56:11 -04:00
Joe Testa 87e22ae26b Added IPv6 support for DHEat and connection rate tests. (#269) 2024-06-29 19:05:20 -04:00
Joe Testa 46ec4e3edc Added built-in policies for Ubuntu 24.04 LTS server and client. 2024-04-29 19:11:47 -04:00
Joe Testa d19b154a46 Bumped version to v3.3.0-dev. 2024-04-22 17:57:26 -04:00
Joe Testa c5d90106e8 Updated docker run command. 2024-04-22 17:54:37 -04:00
Joe Testa 68cf05d0ff Set version to 3.2.0 for release. 2024-04-22 16:32:57 -04:00
Joe Testa 2d9ddabcad Updated DHEat rate connection warning message. 2024-04-22 16:26:03 -04:00
Joe Testa 986f83653d Added multi-line real-time output for connection rate testing. 2024-04-22 13:56:50 -04:00
Joe Testa 3c459f1428 Revised connection rate warning during standard audits. 2024-04-22 11:58:52 -04:00
Joe Testa 46b89fff2e Sockets now time out after 30 seconds during connection rate testing. 2024-04-21 17:05:57 -04:00
Joe Testa 81718d1948 Fixed non-interactive connection rate tests. Revised warning for lack of connection throttling. 2024-04-21 15:08:38 -04:00
Joe Testa 8124c8e443 Added aes128-ocb@libassh.org cipher. 2024-04-18 21:09:02 -04:00
Joe Testa b9f569fdf8 Added warnings for Windows platform. 2024-04-18 20:51:14 -04:00
Joe Testa 9126ae7d9c Improved DHEat statistics output. 2024-04-18 20:01:28 -04:00
Joe Testa d2f1a295a1 Removed vulture from Tox (it rarely made any findings, and when it did, pylint reported the same issues). 2024-04-18 19:36:13 -04:00
Joe Testa 8190fe59d0 Added implementation for DHEat denial-of-service attack (CVE-2002-20001). (#211, #217) 2024-04-18 13:58:13 -04:00
Joe Testa d7f8bf3e6d Updated notes on OpenSSH default key exchanges. (#258) 2024-03-19 18:24:22 -04:00
Joe Testa 3d403b1d70 Updated availability of algorithms in Dropbear. (#257) 2024-03-19 15:47:09 -04:00
Joe Testa 9fae870260 Added allow_larger_keys flag to custom policies to control whether targets can have larger keys, and added Docker tests to complete work started in PR #242. 2024-03-19 14:45:19 -04:00
Joe Testa 3c31934ac7 Added tests and other cleanups resulting from merging PR #252. 2024-03-18 17:48:50 -04:00
Joe Testa 7b3402b207 Added note that sntrup761x25519-sha512@openssh.com is the default OpenSSH kex since version 9.0. 2024-03-15 17:24:21 -04:00
Joe Testa b2f46eb71a Added extra GSS wildcard matching test. 2024-03-15 17:05:40 -04:00