Rév O'Conner
All tools

EFI SSH Server

TypeDeveloper Tools
KindDesktop App
StatusActive
SourceOpen source
LanguageC
Description

An SSH server that runs inside the UEFI pre-boot shell. As far as I can tell it is the first working one: boot a machine to the EFI shell, start the server, and log in from any ordinary SSH client on the network. Tested on type 1 and type 2 hypervisors.

An SSH session into the UEFI shell

What it does

The server opens a TCP4 listener on top of the firmware's network stack, speaks SSH 2.0 (curve25519 key exchange, ed25519 host key, AES-CTR ciphers, SHA-2 HMACs), authenticates a single user with a password, and then launches a nested copy of the EFI Shell whose console is redirected over the channel. Text input, output and the extended key protocol are shimmed so the remote terminal behaves like the local one, with colours mapped to the 16 ANSI colours.

SshShell [-p port] [-u user] [-w password] [-s \path\Shell.efi] [-o "shell options"] [-d]

Defaults are port 22, user admin, password admin. The nested Shell is found from the -s path, the firmware volume (OVMF and most EDK2 firmwares), or the usual Shell.efi / shellx64.efi locations on the boot volume, which is what Hyper-V ends up using since its firmware ships no shell. -d traces every packet when a client hangs.

Build

Freestanding clang and lld-link build against the UEFI target, with wolfCrypt supplying the crypto. A tiny C runtime, string headers and entropy source are part of the repo, and a native Windows harness runs the SSH layer against real clients without rebooting anything. If you build from source, regenerate the host key seed with genkey.py rather than shipping the committed one.

Limitations

Password auth only, one user and one session at a time, no server-initiated rekeying. The host key seed lives in the binary and the server is not hardened against a hostile network, so treat it as a lab tool.