social @ 2024-08-30

SSHamble v0.0.3 is live with support for compromised host key detection through a data integration with Hanno Böck's lovely @badkeys project:

github.com/runZeroInc/sshamble

$ go install github.com/runZeroInc/sshamble@latest

$ sshamble badkeys-update

$ sshamble scan --checks=badkeys-blocklist 192.168.0.0/24

[*] 192.168.0.9:22 badkeys-blocklist found compromised hostkey: github.com/SecurityFail/kompro