Skip to main content

sshcatch

A quick-deploy SSH server for tunneling (local/remote/dynamic) and simple SCP / SFTP transfers - it never opens a shell.

By default all features are disabled: connections are logged and closed. Turn on only what you need with the flags described below. Handy on an engagement when you want a controlled SSH endpoint (a tunnel relay or a file drop) without setting up a full sshd.

Built on asyncssh.

This is a pentesting tool. Only point it at systems and networks you are authorized to test.

Install

With pipx (recommended, installs into an isolated environment and puts sshcatch on your PATH):

pipx install sshcatch

With pip:

pip install sshcatch

From source:

git clone https://github.com/LorenzMap/sshcatch
cd sshcatch
pipx install .          # or: pip install .

Needs Python 3.10+. A host key is auto-generated in the working directory on first run (or point --host-key at your own).

How it works

Without any flags sshcatch is in log-only mode: It accepts the connection, records the client version, username, offered passwords and public keys, then closes. Nothing else is enabled until you ask for it.

Adjust the amount of logging using -vv and -q. Or put everything into a logfile using -o.

Tunnels

Because no shell is ever created, tunnel clients must pass -N (e.g. ssh -NL ...) or they get disconnected instantly.

Turning tunneling on with --open-auth means anyone who connects can pivot through your host!

Only plain TCP forwards are ever available. UNIX-domain-socket forwards (ssh -L /sock:... / -R /sock:...) and TUN/TAP tunnels (ssh -w) are always denied, even with --forward / --reverse set.

SCP / SFTP

Symlinks are handled very restrictively: On upload they create a placeholder file that contains the original target. On download they are outright denied.

The host key, authorized_keys, logfile and the sshcatch script itself are protected and hidden when they live inside the SCP directory.

Uploads never overwrite an existing file. The new file gets a numeric suffix (loot.tar -> loot_1.tar). Non-existent parent folders are created.

Renames, deletes and directory removal are denied.

Examples

Let one user pull/put files from the current directory via SCP/SFTP:

# Server
sshcatch -u user:pass --scp-download --scp-upload

# Client
scp user@host:secret.txt .
scp -r loot/ user@host:pete/pc/
sftp user@host

Let anyone tunnel through the server (local and dynamic forwards): Be careful with this one!

# Server
sshcatch --open-auth --forward

# Client
ssh -NL 8080:internal:80 user@host      # local forward
ssh -ND 1080 user@host                  # dynamic (SOCKS)

Using single-mode to return something to the first successful authentication by closing the server afterwards, while printing timestamped logs to the console and saving them into a file:

# Server
sshcatch -1 -u arthur:42 --version-banner debian \
         --pre-auth-banner "What is the answer to life the universe and everything" \
         --post-auth-banner "flag{So_Long_and_Thanks_for_All_the_Fish}" \
         -o sshcatch.log -t

My favorite one: Reverse tunnel and SCP uploads for the keys in ./authorized-keys while posing as an Ubuntu SSH server on port 2222:

# Server
sshcatch --reverse --authorized-keys ./authorized-keys --scp-upload --version-banner ubuntu -p 2222

# Client
ssh -NR 9000:localhost:22 user@host -p 2222     # reverse tunnel
scp -P 2222 loot.tar user@host:.                # upload

Options

sshcatch -h prints a short summary with just the flags you need to get going. The full reference below is sshcatch --help:

usage: sshcatch [-h] [--help] [-p PORT] [-b BIND] [-1] [--host-key FILE]
                [--version] [-u USER:PASS] [--open-auth]
                [--authorized-keys FILE] [--forward] [--reverse]
                [--scp-upload] [--scp-download] [--scp-dir DIR]
                [--version-banner STRING] [--pre-auth-banner STRING]
                [--post-auth-banner STRING] [-q | -v] [-o FILE] [-t] [--plain]

sshcatch - a quick-deploy SSH server for tunneling (local/remote/dynamic)
and simple SCP transfers (NEVER opens a shell!).
By default all features are disabled. Use flags to enable features.

options:
  -h                    show a short help message and exit
  --help                show the full help and exit
  -p PORT, --port PORT  listen port (default: 22)
  -b BIND, --bind BIND  bind address (default: all IPv4/v6 interfaces)
  -1, --single          close the listener after first successful auth (and
                        exit when that connection ends)
  --host-key FILE       server host key file (default: auto-generate)
  --version             show program's version number and exit

authentication:
  -u USER:PASS, --user USER:PASS
                        allowed user:password (repeatable)
  --open-auth           accept any credentials (open mode)
  --authorized-keys FILE
                        authorized_keys file for key auth (username
                        independent)

tunneling:
  --forward             enable forward tunnels (client: ssh -NL / -ND)
  --reverse             enable reverse tunnels (client: ssh -NR)

SCP / SFTP file transfer:
  --scp-upload          enable file upload (SCP/SFTP write) - files get suffix
                        instead of overwriting
  --scp-download        enable file download (SCP/SFTP read) - symlinks are
                        denied
  --scp-dir DIR         directory for SCP/SFTP (default: cwd) - sensitive
                        sshcatch files (host-key, authorized_keys, logfile)
                        are protected

banners:
  --version-banner STRING
                        sent as 'SSH-2.0-STRING' version banner - only first-
                        glance deception, it can still be identified as
                        asyncssh - presets (case-insensitive): ubuntu, debian,
                        dropbear, windows, macos
  --pre-auth-banner STRING
                        banner shown to every client before login
  --post-auth-banner STRING
                        banner shown only to clients that authenticate
                        successfully

logging:
  -q, --quiet           print nothing on console
  -v, --verbose         print additional information to the console
                        (repeatable)
  -o FILE, --output FILE
                        append the log to FILE (plain with timestamps)
  -t, --timestamps      prefix console lines with a timestamp
  --plain               disable ANSI colors on the console

examples: (also check README on Github)
  sshcatch                                   Log-only (capture creds)
  sshcatch -u user:pass --scp-download       Allow one user to download via SCP/SFTP
  sshcatch --open-auth --forward             Allow ANYONE! to tunnel through this SSH server
  # My favorite one
  #   Allows reverse tunnels and uploads via SCP for the keys in ./authorized_keys
  #   while posing shallowly as an Ubuntu SSH server on port 2222
  sshcatch --reverse --authorized-keys ./authorized-keys --scp-upload --version-banner ubuntu -p 2222

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sshcatch-0.2.1.tar.gz (18.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sshcatch-0.2.1-py3-none-any.whl (15.1 kB view details)

Uploaded Python 3

File details

Details for the file sshcatch-0.2.1.tar.gz.

File metadata

  • Download URL: sshcatch-0.2.1.tar.gz
  • Upload date:
  • Size: 18.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for sshcatch-0.2.1.tar.gz
Algorithm Hash digest
SHA256 557cb45b3c56116d4b109b34cf0aa51a324c84223c9662a626ba09e92140a4a7
MD5 82a6965e418a3605836a2037f93c27f1
BLAKE2b-256 c5713885dbc0b4a45043a5d27846f752ea1c06e2fdff067304a7f6b9f08dd10b

See more details on using hashes here.

File details

Details for the file sshcatch-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: sshcatch-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 15.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for sshcatch-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 f37d0520b1746417d364d37956e24c895af28241c5785847b3d99e05da59ebd5
MD5 fbc94025e4627f2e34cdd7fb69021710
BLAKE2b-256 e5f368863890204a544397f3f6aba70c3f18f607531b7499f334b8bf9636ef8e

See more details on using hashes here.

Release history Release notifications | RSS feed

0.4.0

2 files

0.3.0

2 files

0.2.2

2 files

This release

0.2.1 This release

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page