Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-10933 PoC — libssh server-side state machine 安全漏洞

Source
Associated Vulnerability
Title:libssh server-side state machine 安全漏洞 (CVE-2018-10933)
Description:A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Readme
# https://github.com/ensimag-security/CVE-2018-10933 #

Rapport : `rapport/rapport.pdf`


# Reference #
- https://github.com/hackerhouse-opensource/cve-2018-10933
- https://medium.com/@AshishGodivale/exploiting-libssh-authentication-bypass-vulnerability-cve-2018-10933-2366d0bf7939
- https://github.com/vulhub/vulhub/tree/master/libssh/CVE-2018-10933
- https://www.cvedetails.com/cve/CVE-2018-10933/
- https://github.com/blacknbunny/libSSH-Authentication-Bypass

# Shodan #
Please give me french server using libssh-0.6.3

https://www.shodan.io/search?query=product%3A%22libssh%22+version%3A%220.6.3%22

![Shodan screenshot](./rapport/images/2018-11-21-Shodan.png "Shodan screenshot")
File Snapshot

[4.0K] /data/pocs/5fb973e384a8d501b504fdfb83717cebeba98554 ├── [4.0K] libssh-7.4-ssh_server_fork │   ├── [1.3K] Dockerfile │   └── [ 557] server.patch ├── [4.0K] rapport │   ├── [4.0K] images │   │   ├── [169K] 2018-11-21-Shodan.png │   │   └── [ 30K] draw-cve-2018-10933.jpg │   ├── [160K] rapport.pdf │   └── [ 11K] rapport.tex ├── [ 685] README.md └── [4.0K] script ├── [1.2K] exploit.py ├── [ 959] homputersecu.py └── [ 8] requirements.txt 4 directories, 10 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →