Flatsonar

SSH-MITM

by Manfred Kaiser

SSH-MITM - ssh audits made simple

Sandboxed Verified creator GPL-3.0 v5.0.0
Screenshot 1 of SSH-MITM Screenshot 2 of SSH-MITM

About

SSH-MITM is a man in the middle SSH Server for security audits and malware analysis.

Password and publickey authentication are supported and SSH-MITM is able to detect, if a user is able to login with publickey authentication on the remote server. This allows SSH-MITM to accept the same key as the destination server. If publickey authentication is not possible, the authentication will fall back to password-authentication.

When publickey authentication is possible, a forwarded agent is needed to login to the remote server. In cases, when no agent was forwarded, SSH-MITM can rediredt the session to a honeypot.

Features

  • publickey and password authentication
  • Phishing FIDO Tokens (Information from OpenSSH)
  • hijacking and logging of terminal sessions
  • store and replace files during SCP/SFTP file transferes
  • port porwarding with SOCKS 4/5 support
  • intercept MOSH connections
  • audit clients against known vulnerabilities
  • plugin support

Permissions

Everything this app can reach outside its sandbox. Nothing here weakens it.

  • network
    --share=network

Who publishes this

The creator demonstrably controls this app id: Flathub verification, the hosting account owns the namespace, or a well-known file on their domain.

  • verified on Flathub: the developer proved they control this app id
    publisher:flathub

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.