OpenSSH deployment trivia

Philipp Marek philipp at marek.priv.at
Mon Feb 16 18:40:31 AEDT 2026


Am 2026-02-13 20:14, schrieb Chris Rapier:
> On 2/13/26 09:56, Lars Noodén via openssh-unix-dev wrote:
>> Here is a bit of deployment trivia according to Shodan.
>> 
>> A search today¹ for SSH on port 22, shows OpenSSH on slightly over 90% 
>> of the hosts in the Shodan database (16327749 OpenSSH / 18106285 
>> total).   With Dropbear at a distant second with just under 3% but 
>> just over 3% if some Dropbear variants are included.
>> 
>> A similar search² for SSH on any port, shows open SSH at just over 88% 
>> of the hosts in the Shodan database (27331336 OpenSSH / 3100284 
>> total).   There Dropbear was at just over 2%.
>> 
>> Other than that, there is a very, very long tail of odd server strings 
>> claiming to speak SSH.
> 
> So I tried looking at the version numbers that are out there. Turns out 
> one of the more common versions is 8.0 at 1,475,365 installs. 6,783,467 
> are still using 7.4. 104,510 are using 10.2 and 697,747 are using 9.9.

I guess

7.4 being RHEL7 (or derivatives),
8.0 being RHEL8,
8.7 being RHEL9,
9.9 being RHEL10,
and 10.2 is Debian testing/unstable/trixie-backports, Ubuntu Resolute, 
Arch, openSUSE Tumbleweed, ....



More information about the openssh-unix-dev mailing list