An SSH server built on libssh 0.8.1, vulnerable to CVE-2018-10933: the server state machine accepts SSH2_MSG_USERAUTH_SUCCESS sent by the client, so a client that sends it instead of credentials gets an authenticated session and runs commands.
Not startedDockercommit b47f945x86_64 · aarch64Secret
Exploit CVE-2018-10933 to bypass libssh authentication and run commands on the server.
The brief for this lab lives in its repository.