An SSH server built on libssh 0.8.1, vulnerable to CVE-2018-10933: the server state machine accepts SSH2_MSG_USERAUTH_SUCCESS sent by the client, so a client that sends it instead of credentials gets an authenticated session and runs commands.
Pas commencéDockercommit b47f945x86_64 · aarch64Secret
Exploit CVE-2018-10933 to bypass libssh authentication and run commands on the server.
Le brief de ce lab se trouve dans son dépôt.