Network and Protocol Vulnerabilities in Exploitarium: A Complete Taxonomy of PoC Exploits

Exploitarium documents eight major families of network and protocol vulnerabilities, including protocol downgrade attacks, message scope bypasses, command injection via protocol commands, and packet-parsing memory safety bugs.

Exploitarium is a curated collection of proof-of-concept (PoC) exploits maintained by bikini that focuses heavily on network-level and protocol-level flaws. The repository groups dozens of independent research entries, each targeting distinct communication stacks (TCP, UDP, TLS, RPC, HTTP, DNS) or specific protocol implementations. This article examines the vulnerability taxonomy found in the source code, with direct references to implementation files and runnable reproduction steps.

Protocol Downgrade and Plaintext Fallback Attacks

One of the most dangerous network protocol vulnerabilities documented in Exploitarium involves services that silently fall back to insecure modes when security metadata is missing or malformed.

The RustDesk Session Downgrade Vulnerability

In rustdesk-session-permission-pocs/README.md, researchers document how the RustDesk client proceeds without a peer-encryption key when the signed key is empty. This architectural flaw allows an attacker controlling the relay to observe and inject plaintext messages.

The PoC generates .frame files that demonstrate the attack:


# Build and run the RustDesk session-downgrade PoC

cd rustdesk-session-permission-pocs/session-downgrade
RUSTDESK_REPO_ROOT=/path/to/rustdesk cargo run -- \
    --repo-root $RUSTDESK_REPO_ROOT \
    --out ./payloads

The output includes 00_client_empty_downgrade_handshake.frame—a zero-length handshake that forces the client into non-encrypted relay mode. The same directory contains 02_injected_mouse_move.frame, demonstrating how an attacker can inject MouseEvent messages after downgrading the session.

Protocol Message Scope Bypass Vulnerabilities

Services often fail to restrict message types after authentication, creating protocol message scope bypass conditions where a connection authorized for one purpose can execute unrelated operations.

RustDesk FileTransfer Scope Bypass

As documented in rustdesk-session-permission-pocs/README.md, the RustDesk server uses a generic self.authorized flag instead of fine-grained AuthConnType checking. After authenticating a file-transfer connection, the server continues to dispatch remote-control messages (mouse, keyboard, screenshot) because the authorization check is too broad.

This represents a fundamental network protocol design mistake: conflating connection authentication with operation authorization.

Command Injection via Protocol Commands

Multiple network protocol vulnerabilities in Exploitarium stem from services interpreting client-supplied command strings directly without proper sanitization.

Redis Vector-Set RCE via RESP Protocol

The redis-vset-duplicate-hnsw-id-rce-poc/README.md entry demonstrates command injection through the Redis Serialization Protocol (RESP). Crafted HNSW commands create duplicate node IDs, triggering heap corruption that reaches system("/bin/sh").

Reproduction steps:


# Start a vanilla Redis server on the default port

redis-server &

# Run the PoC which sends specially-crafted HNSW commands

cd redis-vset-duplicate-hnsw-id-rce-poc
python3 exploit.py \
   --host 127.0.0.1 --port 6379 \
   --output /tmp/poc_marker

The exploit.py script constructs a sequence of RESP commands that ultimately corrupt the HNSW vector set index.

c-ares DNS-over-TCP Use-After-Free

The c-ares-tcp-uaf-calc-poc/README.md entry describes how a malicious DNS-over-TCP server can drive a use-after-free in ares_getaddrinfo(). This vulnerability reaches an indirect call through the TCP resolver path, demonstrating that protocol implementation flaws in network libraries can be as severe as application-level bugs.

curl SMTP CRLF Injection

Documented in curl-smtp-expn-recipient-crlf-injection/README.md, this vulnerability allows CR/LF character injection into the SMTP protocol line. The EXPN recipient handling in curl fails to sanitize input, breaking command parsing and enabling attacker-controlled SMTP commands.

Packet-Parsing Memory Safety Bugs

Low-level network protocol parsers frequently copy packet header fields without proper bounds checks, enabling classic memory corruption vulnerabilities.

Nmap IPv6 Extension Length Wrap

The nmap-ipv6-extlen-wrap-poc/docs/research-inventory.md entry catalogs raw-socket scanner vulnerabilities where transport headers are copied after insufficient length checks. The IPv6 extension length field can wrap, exposing SCTP, ICMP, and TCP parsers to overflow-style exploits during active scanning operations.

These packet-parsing memory safety bugs demonstrate that even mature security tools contain dangerous assumptions about protocol data integrity.

Authentication Protocol Abuse

Weak authentication flows allow malicious clients to obtain valid tokens or sessions without proper verification.

OpenSSH Agent Lock Provider Bypass

As detailed in openssh-agent-lock-provider-bypass/README.md, the SSH agent's lock protocol can be abused to obtain a locked-provider token without user interaction. The vulnerability exploits overly permissive state transitions in the agent's authentication flow, permitting unauthorized key access.

Cross-Origin Network Fetch Leakage

Web-based components that expose internal fetch APIs or allow dangerous URL schemes create network fetch leakage vulnerabilities.

Firefox SmartWindow Private URL Exfiltration

The firefox-smartwindow-private-url-exfil-poc/README.md entry shows how Firefox's "private" browser state can be bypassed, allowing a later get_page_content network fetch to leak data from supposedly isolated sessions.

Discord Activity Native RCE

The discord-activity-stock-client-rce-poc/README.md documents a local HTTP server implementing a custom protocol handshake that can be abused to launch Windows Calculator payloads. The server rejects non-HTTPS origins but permits custom sub-domains that can be spoofed, demonstrating TLS/HTTPS handling errors in custom protocol implementations.

Container Orchestration Protocol Misuse

Network configuration in container runtimes creates exploitable attack surfaces when namespaces are improperly shared.

Gitea Act-Runner Container Options

The gitea-act-runner-container-options-poc/README.md entry describes how host namespace flags (--pid=host, --network=host) expose the container to host-level network attacks. This represents container-orchestration protocol misuse where the communication channel between runner and orchestrator becomes a privilege escalation vector.

Summary

Exploitarium documents these key network and protocol vulnerability patterns:

  • Protocol downgrade attacks where missing metadata triggers insecure fallbacks
  • Message scope bypasses from overly broad authorization checks
  • Command injection through unsanitized protocol command parsing
  • Memory safety bugs in packet-parsing routines
  • Authentication protocol abuse via weak or permissive token flows
  • Network fetch leakage from improperly isolated web components
  • TLS/HTTPS validation errors in custom protocol handlers
  • Container network misconfiguration exposing host-level attack surfaces

Frequently Asked Questions

What is Exploitarium used for?

Exploitarium is a research repository that provides reproducible proof-of-concept exploits for network and protocol vulnerabilities. Security researchers use it to study implementation flaws in communication protocols, while developers reference it to understand common design mistakes that lead to exploitable conditions.

How are the vulnerabilities in Exploitarium categorized?

The repository organizes network protocol vulnerabilities by architectural cause rather than specific CVE. Categories include protocol downgrade attacks, message scope bypasses, command injection, packet-parsing memory corruption, authentication abuse, network fetch leakage, TLS handling errors, and container network misconfiguration.

Can I reproduce these vulnerabilities locally?

Yes. Each entry includes a complete PoC with reproduction instructions. For example, the RustDesk downgrade and Redis vector-set RCE both provide runnable scripts with documented command-line arguments. Most PoCs target local or containerized instances to enable safe research.

What communication protocols are represented in the repository?

Exploitarium covers TCP, UDP, TLS, RPC, HTTP, DNS, SMTP, SSH, and custom application protocols. The network protocol vulnerabilities span both standard Internet protocols (IPv6, DNS-over-TCP, SMTP) and application-specific protocols (Redis RESP, RustDesk relay protocol, Discord Activity handshake).

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →