Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-51385- — CVE-2023-51385 | Kitploit
Tools/GitHubGitHub/thinkliving2020/cve-2023-51385-
Vulnerability AnalysisExploitationPenetration TestingCommand and ControlLearning & EducationPayload Development
GitHubthinkliving2020/cve-2023-51385-

CVE-2023-51385-

CVE-2023-51385

View Repository
42 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

RCE via insecure ~/.ssh/config Use of tokens like %h, %p in is quite popular to use tunnels and connection proxying using SSH.ProxyCommand

Vulnerable config host *.example.com ProxyCommand /usr/bin/nc -X connect -x 192.0.2.0:8080 %h %p Note: in my initial assessment I was under the impression that using '%h` (single quotes) would avoid this, but looks like that is still going to be vulnerable with something like:

ssh://echo helloworld > cve.txt`foo.example.com/bar Taken from: https://man.openbsd.org/ssh_config#ProxyCommand

What is in this repository A submodule which would exploit this vulnerability to pop a calculator on OSX.

Try it out using:

git clone https://github.com/vin01/poc-proxycommand-vulnerable --recurse-submodules

or

git clone [email protected]:vin01/poc-proxycommand-vulnerable.git --recurse-submodules

Download Tool