Cbrutekrag Versions Save

Penetration tests on SSH servers using brute force or dictionary attacks. Written in C.

0.5

4 years ago

Added

  • Support for custom port (argument: -p <PORT>) both on scan and bruteforce phases.
  • Dry-run (argument: -D)
  • Added the initial basis to support different ports on different targets
  • Now is possible to specify the port on targets list (ex: 10.10.1.10:2222) (see #5)
  • Shows time elapsed on each phase.
  • Increase the maximum file descriptor number that can be opened by this process.
  • manpages (man cbrutekrag)
  • Debug bracktrace symbols
  • Ignore as default non OpenSSH servers (argument flag -a to accept)
  • Detects and skip NON SSH servers (tcpwrapped).
  • Ignoring servers that don't support password authentication.

Changed

  • Separate Cbrutekrag verbosity from SSHLIB verbosity. (arguments: -v and -V respectively).
  • The default maximum number of threads is calculated automatically.
  • Allow servers detected as honeypot (argument flag -A)
  • Improved detection of non-eligible servers.

Removed

  • Removed port option (-p ) in favor of new targets syntax (191.168.0.0/24:2222)

Fixed

  • Wait until all forks finished her work.
  • Ignore SIGPIPE
  • Fixed false positives in servers which login are interactive.

0.4

5 years ago

Added

  • Support for target list as arguments. It can be combined with targets file.
  • Targets can be a CIDR IPv4 block
  • Service scan phase with filtering
  • Honeypot detection (?)

Fixed

  • Initialize hostnames wordlist
  • Abort if there is no work to do

0.3

5 years ago
- Debian and RPM package
- Fixed segfault when does not have an output file
- Improved logging
- Splitted logic into smallest files
- Improved help screen

0.2.6

5 years ago

Debian and RPM packages

0.1

5 years ago

0.2

6 years ago