crowbar fails when iterating over list
I am working on a box that is vulnerable to CVE-2008-0166. Crowbar fails when iterating over a list of keys, but works when given the key directly. This issue relates to a box in a lab so I must omit some info.
crowbar -b sshkey -s 10.1.1.1/32 -u user -k delme -vv -n 1 2018-09-24 10:13:38 START 2018-09-24 10:13:38 Crowbar v0.3.5-dev 2018-09-24 10:13:38 Brute Force Type: sshkey 2018-09-24 10:13:38 Output File: crowbar.out 2018-09-24 10:13:38 Log File: crowbar.log 2018-09-24 10:13:38 Discover Mode: False 2018-09-24 10:13:38 Verbose Mode: 2 2018-09-24 10:13:38 Debug Mode: False 2018-09-24 10:13:38 Trying 10.1.1.1:22 2018-09-24 10:13:38 LOG-SSH: 10.1.1.1:22 - user:delme/fff7c17579cdd3eead443fdcf5afd99f-7155:10 2018-09-24 10:13:39 LOG-SSH: 10.1.1.1:22 - user:delme/fff89cb8c06a76685805116ecf18540f-4011:10 2018-09-24 10:13:39 LOG-SSH: 10.1.1.1:22 - user:delme/fff0a62ab322540e196ddc1c7d01b70a-10480:10 2018-09-24 10:13:39 LOG-SSH: Skipping Public Key - delme/id_del.pub 2018-09-24 10:13:40 LOG-SSH: 10.1.1.1:22 - user:delme/fffd9dbef2ed8d1edca5886810e79692-3708:10 2018-09-24 10:13:40 LOG-SSH: 10.1.1.1:22 - user:delme/fffdcbd2e868eb3b470fc7d2f027281b-17828:10 2018-09-24 10:13:41 LOG-SSH: 10.1.1.1:22 - user:delme/id_del:10 2018-09-24 10:13:41 LOG-SSH: 10.1.1.1:22 - user:delme/ffff3deee93bffa75796343739ab035b-23195:10 2018-09-24 10:13:42 LOG-SSH: 10.1.1.1:22 - user:delme/fff981bda97d6e867ae1b82d2f2c3c37-2194:10 2018-09-24 10:13:42 LOG-SSH: 10.1.1.1:22 - user:delme/fffc345a2645384066c0a295de0c5e52-15968:10 2018-09-24 10:13:43 LOG-SSH: 10.1.1.1:22 - user:delme/fffe87765dc2bdc2ba3df57166fb5d1c-9581:10 2018-09-24 10:13:43 LOG-SSH: 10.1.1.1:22 - user:delme/fff4a9d9faabb6fd6f474111ed2c4621-23504:10 2018-09-24 10:13:44 LOG-SSH: 10.1.1.1:22 - user:delme/f1fb2162a02f0f7c40c210e6167f05ca-16858:10 2018-09-24 10:13:44 STOP 2018-09-24 10:13:44 No results found...
Yet this will succeed
crowbar -b sshkey -s 10.1.1.1/32 -u user -k delme/fffc345a2645384066c0a295de0c5e52-15968 -vv -n 1 2018-09-24 10:13:59 START 2018-09-24 10:13:59 Crowbar v0.3.5-dev 2018-09-24 10:13:59 Brute Force Type: sshkey 2018-09-24 10:13:59 Output File: crowbar.out 2018-09-24 10:13:59 Log File: crowbar.log 2018-09-24 10:13:59 Discover Mode: False 2018-09-24 10:13:59 Verbose Mode: 2 2018-09-24 10:13:59 Debug Mode: False 2018-09-24 10:13:59 Trying 10.1.1.1:22 2018-09-24 10:13:59 LOG-SSH: 10.1.1.1:22 - user:delme/fffc345a2645384066c0a295de0c5e52-15968:10 2018-09-24 10:13:59 SSH-SUCCESS: 10.1.1.1:22 - user:delme/fffc345a2645384066c0a295de0c5e52-15968 2018-09-24 10:13:59 STOP
As you can see, the first pass attempted this key and failed. Yet when going directly to the key, it works. Is this a problem with my method or crowbar?
Thanks
I have exactly the same problem! version: Crowbar v0.3.5-dev