BruteForce...
LOL, you've gotta be kidding me (sorry to be so mean, but here goes).
First off, the openssh (or ssh) libs will let you do it, just down load the ones that you need (run hydra's ./configure and it will link you).
But secondly, do you have a death wish? Haven't you been reading Incidents securityfocus mailing list? The days of SSH (and other SSL based protocols) hiding from an (N)IDS are over. SSH failed logins are now logged. So, if the admin sees 5,000 failed logins, you've pretty much set off the biggest alarm you ever could have.
Now, many people will say that bruteforcing is lame. Its actually a very common used practice during pen-tests and red-teaming events. But if you ever do it in the wild, you've fucked yourself.
Thats all i'm gonna say…..
oh… i know that SSH logs all, i run my own server and get many people trying to get in every day… i just want to do a pen-test on my server to test my users passwords… trust me, i know all about logs and that shit… i'm not retarded like those who try to get into my server, i've had 100 people try in 3 weeks and not a single person has every gotten in …
meh, PNG based crackers are fundamentally flawed….
Best way to attack an SSH deamon is to find and code your own 0-day….
BTW, you say that you have your own SSH server. Have you noticed how long it takes the attacker to run through one dictionary cycle? Hehe, just the amount fo time a bruteforce takes against SSH is a deterrent in itself….