# Authentication and Session Bypass Vulnerabilities in Exploitarium: Technical Analysis of 10 Critical PoCs

> Explore 10 critical authentication and session bypass vulnerabilities in bikini/exploitarium. Discover technical analysis of flaws in remote desktop software, SSH agents, API gateways, and web platforms. Learn about exploit tec...

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: deep-dive
- Published: 2026-09-06

---

**The bikini/exploitarium repository archives ten proof-of-concept implementations demonstrating authentication and session bypass vulnerabilities across remote desktop software, SSH agents, API gateways, and web platforms, each exploiting flawed authorization flags, credential scope manipulation, or token replay attacks.**

The bikini/exploitarium repository maintains a curated collection of security research documenting critical **authentication and session bypass vulnerabilities** in widely-deployed open-source applications. Each proof-of-concept targets specific weaknesses in session management, authorization enforcement, or authentication middleware that allow attackers to circumvent security controls, escalate privileges, or hijack legitimate user sessions.

## RustDesk Session Permission Bypasses

The `rustdesk-session-permission-pocs/` directory contains two distinct vulnerabilities affecting RustDesk's remote desktop implementation, both stemming from improper session authorization checks.

### FileTransfer Authorization Scope Bypass

The first vulnerability targets the `AuthConnType::FileTransfer` authorization scope. When a connection is authorized only for file-transfer operations, the dispatcher checks a broad `self.authorized` flag rather than validating the specific connection type. This architectural flaw allows a file-transfer session to invoke post-authentication handlers intended for screen capture and mouse input operations, effectively bypassing the restricted permission model.

According to [`rustdesk-session-permission-pocs/README.md`](https://github.com/bikini/exploitarium/blob/main/rustdesk-session-permission-pocs/README.md), the dispatcher fails to couple the authorization flag with fine-grained capability tokens, enabling privilege escalation within a legitimate session.

### Relay Session Security Downgrade

The second RustDesk vulnerability demonstrates how a malicious relay server can downgrade an authenticated session to plaintext traffic. After the legitimate login completes, the attacker can inject control messages into the unencrypted stream, hijacking the session without possessing valid credentials. This bypass exploits the lack of transport security validation during the relay negotiation phase.

## SSH and API Gateway Authentication Bypasses

Three vulnerabilities demonstrate **authentication and session bypass vulnerabilities** in infrastructure components, exploiting pre-authentication processing and credential scope manipulation.

### OpenSSH Agent Lock Provider Bypass

Located in `openssh-agent-lock-provider-bypass/`, this vulnerability affects the SSH agent's state management. When the agent transitions from a *locked* to *unlocked* state, forwarded-agent connections retain access to the `provider-add` path without requiring re-authentication. This allows an attacker to extend the unlocked state indefinitely, bypassing the intended security boundary that should require credentials to add new providers after a lock event.

### Discourse Scoped API-Key Pre-Auth Bypass

The `discourse-scoped-api-key-preauth-bypass/` implementation targets Discourse's request routing middleware. A scoped API key restricted to `topics:read` permissions can execute `PUT` requests for privileged updates when the request includes a crafted `X-Request-Start` header:

```http
PUT /admin/settings HTTP/1.1
Host: target.discourse.instance
X-Request-Start: 1234567890
Authorization: Token token=topics_read_only_key

```

The vulnerability occurs because the pre-route authentication middleware caches the user identity before determining the final HTTP verb, allowing the request to "pre-authenticate" with read permissions and later execute write operations.

### Floci API Gateway IAM Bypass

In `floci-apigateway-vtl-rce-poc/`, the vulnerability exploits AWS SigV4 header validation. By supplying a credential scope of `iam` instead of `apigateway`, an attacker bypasses the IAM enforcement layer entirely:

```http
Authorization: AWS4-HMAC-SHA256 Credential=AKIA.../20240101/us-east-1/iam/aws4_request

```

The authentication middleware trusts the client-presented credential scope without validation, granting access to vulnerable VTL (Velocity Template Language) RCE paths that should require specific API Gateway permissions.

## Trust Boundary and Token Validation Failures

These vulnerabilities demonstrate how improper trust validation and token scope checking enable **authentication and session bypass vulnerabilities** in system management and file sharing applications.

### SystemInformer Trusted-Host LPE

The `systeminformer-phsvc-trusted-host-lpe-poc/` directory documents an authorization boundary failure in SystemInformer's helper service. The process validates that client binaries are *Authenticode-trusted* but fails to verify the specific binary identity. Consequently, any Authenticode-signed executable—not just the legitimate SystemInformer binary—can invoke privileged helper actions, allowing malicious trusted-signed processes to execute local privilege escalation attacks.

### Nextcloud Federated-Share Bearer Token Bypass

Located in `nextcloud-federated-share-bearer-token-poc/`, this vulnerability exposes a permanent authentication token through the pending-share API. Attackers can reuse this token as an OAuth-style bearer token to gain full WebDAV access:

```http
GET /remote.php/dav/files/user/ HTTP/1.1
Host: nextcloud.instance
Authorization: Bearer leaked_federated_share_token

```

This bypasses the intended one-time use model, effectively granting persistent access without re-authentication.

## Web Application Session Manipulation

Three additional **authentication and session bypass vulnerabilities** target web platforms, exploiting federation protocols and administrative interface weaknesses.

### NodeBB ActivityPub Author Binding Spoof

The `nodebb-activitypub-attributedto-local-uid-spoof-poc/` implementation targets NodeBB's ActivityPub integration. When processing remote notes, the application accepts the `attributedTo` field as a local UID without verification. An attacker can specify any local user's UID in this field, causing the system to attribute the content to that user after passing normal posting checks, effectively spoofing authenticated local users via federation.

### MyBB Limited ACP-to-Admin Privilege Escalation

In `mybb-limited-acp-to-admin/`, an authenticated administrator can grant ACP (Admin Control Panel) capabilities to other users without proper authorization verification. This bypasses the intended separation between ACP access and full administrative privileges, allowing limited administrators to escalate any user to full admin status.

### Gogs Admin CSRF to Git-Hook RCE

The `gogs-admin-csrf-git-hook-rce-poc/` vulnerability chains cross-site request forgery with privilege escalation. An attacker can trick an authenticated site administrator into submitting an admin-only form that grants the attacker administrative rights. With admin privileges, the attacker can edit Git hooks to achieve remote code execution, bypassing authentication requirements through session hijacking.

## Common Architectural Patterns in Authentication Bypasses

The **authentication and session bypass vulnerabilities** cataloged in Exploitarium share several architectural weaknesses that enable exploitation:

- **Broad authorization flags**: Services like RustDesk and OpenSSH rely on single "authorized" boolean flags rather than capability-specific tokens. When disparate actions (file transfer vs. screen control) consult the same flag, narrow permissions effectively grant broad access.

- **Credential scope misuse**: Cloud services including Floci and Discourse trust client-provided credential scopes without validation. Manipulating SigV4 headers or API key metadata defeats policy enforcement layers.

- **Token replay across components**: Nextcloud's federated-share flow leaks tokens that function across authentication boundaries, violating the principle of least privilege.

- **Pre-authentication routing**: Discourse processes authentication middleware before determining the final HTTP method, allowing header manipulation to cache unauthorized states.

- **Binary trust without identity verification**: SystemInformer's helper validates certificate chains but ignores runtime binary identity, allowing any trusted signed executable to assume privileged roles.

## Summary

The bikini/exploitarium repository documents critical **authentication and session bypass vulnerabilities** through ten distinct proof-of-concept implementations:

- **RustDesk** vulnerabilities exploit broad `self.authorized` flags and plaintext session downgrades to bypass permission scopes and hijack sessions.
- **OpenSSH** agent bypass allows extended unlocked states through the `provider-add` path without re-authentication.
- **Discourse** and **Floci** API bypasses demonstrate credential scope manipulation via `X-Request-Start` headers and SigV4 header tampering.
- **SystemInformer** and **Nextcloud** failures result from inadequate trust boundary validation and token replay attacks.
- **NodeBB**, **MyBB**, and **Gogs** web applications suffer from federation spoofing, privilege escalation, and CSRF-based administrative hijacking.

These examples illustrate how authorization checks performed too early, too generically, or without sufficient context enable attackers to piggyback on legitimate sessions or manipulate request metadata.

## Frequently Asked Questions

### What is the bikini/exploitarium repository?

The bikini/exploitarium repository is an open-source archive of proof-of-concept implementations documenting security vulnerabilities in widely-used software. It specifically catalogs **authentication and session bypass vulnerabilities** with detailed technical explanations of exploitation techniques, targeting systems including RustDesk, OpenSSH, Discourse, and Nextcloud.

### How do broad authorization flags lead to session bypasses?

Broad authorization flags create **session bypass vulnerabilities** when a single boolean flag like `self.authorized` grants access to multiple distinct capabilities. In RustDesk, a session authorized only for `AuthConnType::FileTransfer` can invoke screen capture handlers because the dispatcher checks the general authorization flag rather than validating specific connection type permissions, allowing privilege escalation within legitimate sessions.

### What is credential scope misuse in cloud API authentication?

Credential scope misuse occurs when authentication middleware trusts the scope presented in client requests without validation. In the Floci API Gateway bypass, attackers change the SigV4 credential scope from `apigateway` to `iam` in request headers, bypassing IAM enforcement layers. Similarly, Discourse's pre-authentication router caches user identity based on API key metadata before validating the HTTP method, allowing scope-restricted keys to execute privileged operations.

### How can developers prevent authentication bypass vulnerabilities like those in Exploitarium?

Developers should implement **fine-grained capability tokens** rather than broad authorization flags, validate credential scopes server-side against allowed policy definitions, enforce strict token binding to specific components, and verify binary identity at runtime rather than relying solely on Authenticode signatures. Additionally, authentication middleware should process the complete request context including HTTP method and headers before establishing session state to prevent pre-authentication poisoning attacks.