finds.dev← search

// the find

davidbombal/ssh_bruteforcing

★ 220 · Python · updated Dec 2022

Simple Python SSH Brute Forcing (Credential Stuffing)

A small Python script that reads username and password pairs from a CSV and tries them against an SSH server, which is credential stuffing in its plainest form. It is a teaching proof of concept for showing why reused and weak SSH passwords get accounts compromised, and it only makes sense for auditing hosts you own or are authorized to test.

- The repo is four files: main.py, passwords.csv, requirements.txt, and the README. There is almost nothing to untangle before you can read the whole thing.

- Credentials live in a CSV rather than in the source, so changing the list is a data edit, not a code change.

- The README says plainly that this is a proof of concept that could be improved in many ways. That sets the right expectations, which many repos in this genre do not do.

- The setup steps mix platforms. They create the venv with the Windows-style `python -m venv` command, then activate it with the bash `source ./sshbruteforcer_env/bin/activate`, which does not work in cmd or PowerShell. The step numbering also skips 2.

- The repo was last pushed in December 2022 and the README names no Python version, so expect dependency and interpreter drift on a current setup.

- The educational disclaimer does most of the safety work. Nothing in the README asks the user to confirm they are authorized to test the target, and the README says nothing about what the script reports per attempt or how it stops on a success, so its behaviour is undocumented from the outside.

- No license is mentioned in the README, which leaves reuse terms unclear for anyone who wants to build on it.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →