Home Secure Shell (SSH) ScanSSH – Fast SSH Server And Open Proxy Scanner

ScanSSH – Fast SSH Server And Open Proxy Scanner

By sk
Published: Last Updated on 2K views

ScanSSH is a free and open source utility that scans the given list of addresses or networks for open proxies, SSH protocol servers, Web and SMTP servers. It not just scans, but also displays the version of the running services. You can use it to collect statistics on the deployment of SSH protocol servers in your company or the Internet as whole. You can also use it to ensure all your machines are running the latest SSH protocol versions. The common use case of this utility could be information gathering for the pentesters and security professionals. In this guide, we will see how to install ScanSSH on Linux and Unix-like operating systems and how to use ScanSSH for gathering details of running services.

Install ScanSSH

On Arch Linux and derivatives, you can install it from AUR using any AUR helper programs such as Yay.

$ yay -S scanssh

On Fedora:

$ sudo dnf install scanssh

On Debian, Ubuntu, Linux Mint:

$ sudo apt install scanssh

On other distributions, you can download the source from the GitHub page given at the end of this guide and manually compile and install it yourself.

ScanSSH Usage

The typical syntax of ScanSSH is:

scanssh [-VIERph] [-s scanners,...] [-n ports,...] [-u socks hosts,...] [-e excludefile] addresses...

Let us see some examples. The following command will scan for ssh servers in a network:

$ sudo scanssh -s ssh 192.168.43.0/24
Scan SSH Servers With ScanSSH

Scan SSH Servers With ScanSSH

If you want to scan for SSH servers on port 22 only, you could use:

$ sudo scanssh -n 22 -s ssh 192.168.43.0/24

Also, you can specify only one host IP address to scan like below:

$ sudo scanssh -s ssh 192.168.43.192
Scan specific host

Scan specific host

And, this command will scan the given network for open proxies.

$ sudo scanssh -p 192.168.43.0/24

Here, -p flag is used for scanning open proxies.

Not just SSH and open proxies, ScanSSH will scan for the following modules.

  • socks5 - detects SOCKS v5 proxy
  • socks4 - detects SOCKS v4 proxy
  • http-proxy - detects HTTP get proxy
  • http-connect - detects HTTP connect proxy
  • telnet-proxy - detects telnet proxy

For more details, check man pages.

$ man scanssh

Resource:

You May Also Like

Leave a Comment

* By using this form you agree with the storage and handling of your data by this website.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

This website uses cookies to improve your experience. By using this site, we will assume that you're OK with it. Accept Read More