The State of SSH on the Internet: Key Findings from 34M+ Hosts
Introduction
SSH (Secure Shell) remains one of the most widely deployed protocols on the internet. Using Zondex's database of over 34 million indexed hosts, we analyzed the current state of SSH deployment globally.
Key Findings
1. SSH Version Distribution
OpenSSH dominates the SSH landscape, accounting for over 90% of all SSH servers indexed by Zondex. Here's the breakdown:
- OpenSSH 8.x: 38% of all SSH servers
- OpenSSH 7.x: 29% — still widely deployed
- OpenSSH 9.x: 18% — growing adoption
- OpenSSH 6.x and older: 8% — concerning legacy deployments
- Other implementations: 7% — including Dropbear, libssh, etc.
2. Geographic Distribution
The top 5 countries by SSH host count:
- United States — hosting the most SSH servers globally
- China — significant growth in recent years
- Germany — major European hub
- France — strong hosting infrastructure
- Japan — key Asia-Pacific presence
3. Non-Standard Ports
While port 22 remains the default, we found significant SSH deployments on alternative ports:
- Port 2222: Common alternative, often used by containers
- Port 22222: Another popular alternative
- Port 2022: Frequently used in development environments
4. Security Concerns
We identified several concerning patterns:
- Outdated versions: ~8% of SSH servers run versions with known vulnerabilities
- Default configurations: Many servers still advertise full version strings
- Weak key exchange: Some servers still support deprecated algorithms
How to Search
Explore SSH data on Zondex:
Conclusion
While SSH security has generally improved over time, the persistence of outdated versions and configurations presents ongoing risks. Organizations should regularly audit their SSH deployments and ensure they're running current, properly configured versions.
auto_awesome Related Posts
Global Distribution of Lighttpd Servers by Country
Zondex's comprehensive scans reveal the United States as the top country with Lighttpd servers, hosting approximately 35% of all publicly accessible instances. This article dissects global distribution, security implications, and how Zondex aids in discovery and risk assessment for this lightweight
May 16, 2026Global Distribution of Lighttpd Servers by Country
Zondex data reveals the United States hosts the largest number of publicly accessible Lighttpd servers globally. This article details the geographical distribution, common security risks, and provides practical Zondex queries for identification.
May 13, 2026Jenkins Servers Exposed to Internet: Security Analysis
Thousands of Jenkins servers are critically exposed to the internet, creating severe risks for organizations. This exposure often leads to remote code execution, sensitive data breaches, and supply chain attacks, which Zondex actively identifies through its comprehensive indexing capabilities.
May 12, 2026