<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Decryption in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259687#M73617</link>
    <description>&lt;P&gt;Thanks, I already know this. I was hoping for a more automated tool to extract username/passwords without manually going through packets in Wireshark.....&lt;/P&gt;</description>
    <pubDate>Fri, 03 May 2019 02:53:34 GMT</pubDate>
    <dc:creator>djohnson229</dc:creator>
    <dc:date>2019-05-03T02:53:34Z</dc:date>
    <item>
      <title>SSH Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259568#M73586</link>
      <description>&lt;P&gt;Hi. If my FW is doing SSH decryption and sending all decrypted traffic out of a mirror port where my Kali machine is, what tools would be able to "read" the username/password from the decrypted SSH traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was looking for something similar to what "dsniff" does for telnet;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TELNET : 10.1.1.1:23 -&amp;gt; USER: myuser PASS: mypassword&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically, something similar to the above but for SSH. I was thinking this would be easy, as the traffic is already decrypted but I have spent a while Googling this with no joy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone point me in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DJ&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 04:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259568#M73586</guid>
      <dc:creator>djohnson229</dc:creator>
      <dc:date>2019-05-02T04:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259632#M73604</link>
      <description>&lt;P&gt;You could just run Wireshark on your Kali machine and filter for SSH traffic. You should be able to see the decrypted information.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 14:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259632#M73604</guid>
      <dc:creator>yllib1213</dc:creator>
      <dc:date>2019-05-02T14:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259687#M73617</link>
      <description>&lt;P&gt;Thanks, I already know this. I was hoping for a more automated tool to extract username/passwords without manually going through packets in Wireshark.....&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 02:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259687#M73617</guid>
      <dc:creator>djohnson229</dc:creator>
      <dc:date>2019-05-03T02:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259763#M73628</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure about Kali, however have you looked into SecurityOnion? Its a Ubuntu build that does packet capture and IDS. You might be able to setup a rule that looks for this and alerts. However not entirely sure. They have a KB and forum you can ask about this on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 17:45:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/259763#M73628</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-03T17:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Decryption</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/260225#M73768</link>
      <description>&lt;P&gt;Interesting. I won't spend time setting this up and testing, unless I know whether it would work or not. I may check the KB and forums though, as you suggested.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 08:11:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-decryption/m-p/260225#M73768</guid>
      <dc:creator>djohnson229</dc:creator>
      <dc:date>2019-05-08T08:11:54Z</dc:date>
    </item>
  </channel>
</rss>

