<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://aznot.com/index.php?action=history&amp;feed=atom&amp;title=Terrapin</id>
	<title>Terrapin - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://aznot.com/index.php?action=history&amp;feed=atom&amp;title=Terrapin"/>
	<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=Terrapin&amp;action=history"/>
	<updated>2026-04-28T03:27:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>https://aznot.com/index.php?title=Terrapin&amp;diff=6723&amp;oldid=prev</id>
		<title>Kenneth: /* Scanner */</title>
		<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=Terrapin&amp;diff=6723&amp;oldid=prev"/>
		<updated>2024-01-05T06:12:52Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Scanner&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 06:12, 5 January 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scanner ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scanner ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;blockquote&amp;gt;If you want to check an SSH client or server for its susceptibility to Terrapin, the Ruhr University Bochum team provides a vulnerability scanner.&amp;lt;ref&amp;gt;Nearly 11 million SSH servers vulnerable to new Terrapin attacks - https://www.bleepingcomputer.com/news/security/nearly-11-million-ssh-servers-vulnerable-to-new-terrapin-attacks/&amp;lt;/ref&amp;gt;&amp;lt;/blockquote&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  RUB-NDS/Terrapin-Scanner: This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper &amp;quot;Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation&amp;quot;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  RUB-NDS/Terrapin-Scanner: This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper &amp;quot;Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation&amp;quot;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key aznot:diff:1.41:old-6722:rev-6723:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Kenneth</name></author>
	</entry>
	<entry>
		<id>https://aznot.com/index.php?title=Terrapin&amp;diff=6722&amp;oldid=prev</id>
		<title>Kenneth at 06:11, 5 January 2024</title>
		<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=Terrapin&amp;diff=6722&amp;oldid=prev"/>
		<updated>2024-01-05T06:11:45Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 06:11, 5 January 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l74&quot;&gt;Line 74:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 74:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;https://i.imgur.com/zcWtsfI.png&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;https://i.imgur.com/zcWtsfI.png&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;== keywords ==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key aznot:diff:1.41:old-6721:rev-6722:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Kenneth</name></author>
	</entry>
	<entry>
		<id>https://aznot.com/index.php?title=Terrapin&amp;diff=6721&amp;oldid=prev</id>
		<title>Kenneth: Created page with &quot;== Scanner ==   RUB-NDS/Terrapin-Scanner: This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper &quot;Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation&quot;.  https://github.com/RUB-NDS/Terrapin-Scanner   export $GOPATH=~/.gobin  go install github.com/RUB-NDS/Terrapin-Scanner@latest  ln -s ../.go/bin/Terrapin-Scanner ~/.bin/Terrapin-Scanner  Scan the SSH server available at localhost port 2222  ./Terrapi...&quot;</title>
		<link rel="alternate" type="text/html" href="https://aznot.com/index.php?title=Terrapin&amp;diff=6721&amp;oldid=prev"/>
		<updated>2024-01-05T06:11:08Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Scanner ==   RUB-NDS/Terrapin-Scanner: This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper &amp;quot;Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation&amp;quot;.  https://github.com/RUB-NDS/Terrapin-Scanner   export $GOPATH=~/.gobin  go install github.com/RUB-NDS/Terrapin-Scanner@latest  ln -s ../.go/bin/Terrapin-Scanner ~/.bin/Terrapin-Scanner  Scan the SSH server available at localhost port 2222  ./Terrapi...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Scanner ==&lt;br /&gt;
&lt;br /&gt;
 RUB-NDS/Terrapin-Scanner: This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper &amp;quot;Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation&amp;quot;.&lt;br /&gt;
 https://github.com/RUB-NDS/Terrapin-Scanner&lt;br /&gt;
&lt;br /&gt;
 export $GOPATH=~/.gobin&lt;br /&gt;
 go install github.com/RUB-NDS/Terrapin-Scanner@latest&lt;br /&gt;
 ln -s ../.go/bin/Terrapin-Scanner ~/.bin/Terrapin-Scanner&lt;br /&gt;
&lt;br /&gt;
Scan the SSH server available at localhost port 2222&lt;br /&gt;
 ./Terrapin-Scanner --connect localhost:2222&lt;br /&gt;
&lt;br /&gt;
If no port is specified, the tool will default to port 22 instead&lt;br /&gt;
 ./Terrapin-Scanner --connect localhost&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Bad Result ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ Terrapin-Scanner -connect host1.com&lt;br /&gt;
================================================================================&lt;br /&gt;
==================================== Report ====================================&lt;br /&gt;
================================================================================&lt;br /&gt;
&lt;br /&gt;
Remote Banner: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.4&lt;br /&gt;
&lt;br /&gt;
ChaCha20-Poly1305 support:   true&lt;br /&gt;
CBC-EtM support:             false&lt;br /&gt;
&lt;br /&gt;
Strict key exchange support: false&lt;br /&gt;
&lt;br /&gt;
The scanned peer is VULNERABLE to Terrapin.&lt;br /&gt;
&lt;br /&gt;
Note: This tool is provided as is, with no warranty whatsoever. It determines&lt;br /&gt;
      the vulnerability of a peer by checking the supported algorithms and&lt;br /&gt;
      support for strict key exchange. It may falsely claim a peer to be&lt;br /&gt;
      vulnerable if the vendor supports countermeasures other than strict key&lt;br /&gt;
      exchange.&lt;br /&gt;
&lt;br /&gt;
For more details visit our website available at https://terrapin-attack.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://i.imgur.com/cbKxWe7.png&lt;br /&gt;
&lt;br /&gt;
=== Ok Result ===&lt;br /&gt;
&lt;br /&gt;
(same host, but after apt update, apt upgrade...)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ Terrapin-Scanner -connect host1.com&lt;br /&gt;
================================================================================&lt;br /&gt;
==================================== Report ====================================&lt;br /&gt;
================================================================================&lt;br /&gt;
&lt;br /&gt;
Remote Banner: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.6&lt;br /&gt;
&lt;br /&gt;
ChaCha20-Poly1305 support:   true&lt;br /&gt;
CBC-EtM support:             false&lt;br /&gt;
&lt;br /&gt;
Strict key exchange support: true&lt;br /&gt;
&lt;br /&gt;
The scanned peer supports Terrapin mitigations and can establish&lt;br /&gt;
connections that are NOT VULNERABLE to Terrapin. Glad to see this.&lt;br /&gt;
For strict key exchange to take effect, both peers must support it.&lt;br /&gt;
&lt;br /&gt;
Note: This tool is provided as is, with no warranty whatsoever. It determines&lt;br /&gt;
      the vulnerability of a peer by checking the supported algorithms and&lt;br /&gt;
      support for strict key exchange. It may falsely claim a peer to be&lt;br /&gt;
      vulnerable if the vendor supports countermeasures other than strict key&lt;br /&gt;
      exchange.&lt;br /&gt;
&lt;br /&gt;
For more details visit our website available at https://terrapin-attack.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://i.imgur.com/zcWtsfI.png&lt;/div&gt;</summary>
		<author><name>Kenneth</name></author>
	</entry>
</feed>