CVE-2018-10933 is an improper authentication vulnerability in libssh's server-side state machine affecting versions before 0.7.6 and 0.8.4. A remote client can send an SSH2_MSG_USERAUTH_SUCCESS message where the server expects SSH2_MSG_USERAUTH_REQUEST, causing the server to accept authentication and permit channel creation without valid credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a small standalone exploit PoC for CVE-2018-10933, containing one documentation file (README.md) and one executable Python script (exploit.py). The README explains the libssh server-side authentication bypass, affected versions, impact, and mitigation. The Python script is the actual exploit entry point. The exploit uses Paramiko's Transport layer to connect to a target SSH service, start the SSH client handshake, then manually send SSH_MSG_USERAUTH_SUCCESS from the client side. On vulnerable libssh servers, this causes the server to incorrectly mark the session as authenticated. The script then locally overrides Paramiko's authentication check with transport.is_authenticated = lambda: True and opens a session channel. Main capabilities: - Unauthenticated command execution via channel.exec_command() - Direct interactive shell over the SSH session via channel.invoke_shell() - Reverse shell delivery using bash, Python, or netcat payloads - Optional built-in listener for reverse shell callbacks - Automatic PTY upgrade attempts for reverse shells using python3, python, or script Repository structure and purpose: - README.md: vulnerability overview, affected versions, exploitation concept, impact, and defensive guidance - exploit.py: operational exploit with CLI argument parsing, payload generation, reverse-shell listener support, direct shell mode, and command execution mode The exploit is clearly offensive and functional rather than a detector. It targets network-accessible SSH services using vulnerable libssh in server mode. It does not include scanning logic or target discovery; the operator must supply the target host and port manually.
This repository contains a single Python exploit script (exploit.py) that targets SSH servers using the Paramiko library, exploiting a vulnerability related to libssh authentication. The script attempts to bypass SSH authentication by sending a fake USERAUTH_SUCCESS message, thereby granting the attacker an interactive shell on the target system without requiring valid credentials. The script prompts the user for a hostname and port, connects to the specified SSH server, and, if successful, provides an interactive shell. The exploit is a proof-of-concept and does not include advanced payloads or post-exploitation features. The only fingerprintable endpoint is the user-supplied SSH server (hostname and port). The code is straightforward, with clear separation between the connection logic, authentication bypass, and shell interaction.
This repository contains a proof-of-concept exploit for CVE-2018-10933, an authentication bypass vulnerability in libssh. The exploit is implemented in Python (SSH_auth_bypass.py) and uses the paramiko library to interact with the SSH service. The script connects to a specified IP address and port (default 22), sends a crafted SSH2_MSG_USERAUTH_SUCCESS message to bypass authentication, and then opens a session to execute arbitrary commands (demonstrated with 'ifconfig -a'). The README.md provides background on the vulnerability, affected versions, and usage instructions. The exploit targets servers running vulnerable versions of libssh and allows remote command execution if successful. No hardcoded credentials or detection logic are present; the script is a direct exploit for the authentication bypass.
This repository contains a single Metasploit auxiliary scanner module: 'libssh_auth_bypass.rb'. The module targets a critical authentication bypass vulnerability in libssh (CVE-2018-10933) affecting versions 0.6.0 through 0.7.5 and 0.8.0 through 0.8.3. The exploit works by sending a USERAUTH_SUCCESS message to the SSH server, bypassing authentication and potentially granting shell access or command execution capabilities. The module is configurable to either spawn a shell or execute a specific command on the target. It includes logic to check the SSH banner for vulnerable libssh versions and reports successful exploitation. The only fingerprintable endpoint is the SSH service (typically TCP port 22) on the target host. The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository contains a single Python script (CVE-2018-10933.py) that exploits the authentication bypass vulnerability in libssh (CVE-2018-10933). The script uses the paramiko library to connect to a target SSH server (default port 22), sends a crafted USERAUTH_SUCCESS message to bypass authentication, and attempts to open a shell session. The exploit is a proof-of-concept and requires the target to be running a vulnerable version of libssh. The script takes the target hostname as a command-line argument. No hardcoded credentials or additional payloads are present; the exploit's main capability is unauthorized shell access via SSH. The only fingerprintable endpoint is the SSH service on port 22 of the specified target.
This repository contains a Python proof-of-concept exploit for CVE-2018-10933, a critical authentication bypass vulnerability in libssh (tested against version 0.7.4). The main exploit file, CVE-2018-10933.py, uses the paramiko library to connect to a target SSH server and sends a crafted USERAUTH_SUCCESS message, bypassing authentication and spawning an interactive shell without credentials. The README provides setup instructions for testing the exploit against a vulnerable libssh server, including where to download the affected version and how to run the sample SSH daemon. The repository is structured simply, with one main exploit script, a requirements file specifying paramiko, and documentation. The exploit targets network-accessible SSH servers running vulnerable libssh versions and demonstrates successful exploitation by allocating a session and shell.
This repository provides a proof-of-concept exploit for CVE-2018-10933, a critical authentication bypass vulnerability in libSSH (versions 0.6.x through 0.7.5). The main exploit script, 'libsshauthbypass.py', uses the Python 'paramiko' library to connect to a target SSH server and sends a crafted USERAUTH_SUCCESS message, bypassing authentication. It then opens a session and executes an arbitrary command specified by the user, returning the output. The script is configurable via command-line arguments for host, port, command, and log file. The repository also includes 'checkversionofserver.py', a helper script to check if a target server is running a vulnerable version of libSSH by connecting to the SSH port and reading the banner. The 'requirements.txt' specifies the required version of paramiko. The README provides usage instructions, references, and additional resources. The exploit targets network-accessible SSH servers running vulnerable libSSH versions, typically on port 22 but potentially on other ports as well.
This repository provides a proof-of-concept (PoC) exploit for CVE-2018-10933, an authentication bypass vulnerability in libssh server implementations (versions 0.6 and above, prior to 0.8.4/0.7.6). The repository includes Dockerfiles and scripts to build and run a vulnerable libssh server inside a container, as well as patches to both the server and client code to demonstrate the exploit. The main exploit works by sending an SSH2_MSG_USERAUTH_SUCCESS message to the server, tricking it into authenticating the attacker without credentials. The exploit is demonstrated using a patched libssh client and server, with the server listening on port 2222 (host-mapped). The repository structure includes build and run scripts, Dockerfiles for both vulnerable and legacy (non-vulnerable) libssh versions, and patch files that implement the authentication bypass. The README provides detailed instructions for building, running, and exploiting the vulnerable server. The exploit demonstrates successful authentication bypass, but notes that further exploitation (such as spawning a shell) may require additional server-side changes. The repository is intended for research and testing of the CVE-2018-10933 vulnerability.
This repository contains a Python exploit for CVE-2018-10933, a critical authentication bypass vulnerability in libssh's server implementation. The exploit script (libssh-CVE-2018-10933-jas502n.py) uses the paramiko library to connect to a target SSH server, sends a crafted MSG_USERAUTH_SUCCESS message before authentication, and then executes an arbitrary command provided by the user. The README provides a brief description of the vulnerability and references for further information. The exploit is operational and allows unauthenticated remote command execution on vulnerable libssh servers. The only code file is the exploit script, which takes three command-line arguments: target host, port, and the command to execute. No hardcoded endpoints are present; the target is specified at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability in libssh server implementations. Affected versions can incorrectly accept an SSH authentication-success message from a client, enabling unauthenticated access under vulnerable configurations.
An authentication bypass vulnerability in libssh.
An authentication bypass vulnerability in libssh that allows remote attackers to authenticate to a server without proper credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.