Tectia SSH Server Authentication Bypass Metasploit Demo

Опубликовано: 20 Февраль 2026
на канале: Eric Romang (wow)
4,467
10

Blog : http://eromang.zataz.com
Twitter :   / eromang  

Timeline :

Vulnerability discovered by @kingcope
Vulnerability disclosed by @kingcope the 2012-12-01
Metasploit PoC the 2012-12-04

PoC provided by:

kingcope
bperry
sinn3r

Reference(s) :

Full Disclosure
Tectia Support

Affected versions :

All versions of Tectia SSH Server

Tested on Centos 5.8 x86 with:

SSH Tectia Server 6.3.2-33

Description :

This module exploits a vulnerability in Tectia SSH server for Unix-based platforms. The bug is caused by a SSH2_MSG_USERAUTH_PASSWD_CHANGEREQ request before password authentication, allowing any remote user to bypass the login routine, and then gain access as root.

More informations on http://eromang.zataz.com/2012/12/04/t...