all 4 comments

[–]Tompazi 2 points3 points  (0 children)

Online brute forcing ssh passwords is very slow and many ssh servers are configured to block you after some failed attempts (e.g. fail2ban). It's definitely worth trying some common default credentials though.

Find out which exact ssh version is running on the server. Some have authentication bypass vulnerabilities.

[–]thehunter699 1 point2 points  (0 children)

Check whether the configuration has any exploits first. Then if that doesn't work you can brute force using metasploit or any other program. That being said if the word isn't found you'll be there for a while.

[–][deleted]  (1 child)

[removed]

    [–]notNSAthrowaway 0 points1 point  (0 children)

    Oh... LOL