social @ 2024-08-30SSHamble v0.0.3 is live with support for compromised host key detection through a data integration with Hanno Böck's lovely @badkeys project:https://github.com/runZeroInc/sshamble$ go install github.com/runZeroInc/sshamble@latest$ sshamble badkeys-update$ sshamble scan --checks=badkeys-blocklist 192.168.0.0/24[*] 192.168.0.9:22 badkeys-blocklist found compromised hostkey: https://github.com/SecurityFail/kompromat/blob/master/src/firmware/rapid7-ssh-badkeys/host/Trendnet_tew816drm_rsa.key