OpenSSH 7.7, vulnerable to CVE-2018-15473: the server bails out before parsing a malformed publickey userauth request only when the user is invalid, so the reply (or its absence) tells whether an account exists; with the names found, weak passwords open a shell.
Not startedDockercommit 1eafcafx86_64 · aarch64Secret
Exploit CVE-2018-15473 to enumerate the server's users, then get a shell on it.
The brief for this lab lives in its repository.