Description
This module uses a dictionary to brute force valid usernames from Cerberus FTP server via SFTP. This issue affects all versions of the software older than 6.0.9.0 or 7.0.0.2 and is caused by a discrepancy in the way the SSH service handles failed logins for valid and invalid users. This issue was discovered by Steve Embling.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/ssh/cerberus/sftp_enumusersmsf undefined(sftp_enumusers) > show actions ...actions...msf undefined(sftp_enumusers) > set ACTION < action-name >msf undefined(sftp_enumusers) > show options ...show and set options...msf undefined(sftp_enumusers) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub