Skip to content

Resolve Incompatibility with MobaXterm and Problem with DisableMTAES - #161

Merged
rapier1 merged 4 commits into
masterfrom
bug-moba-aes
Sep 17, 2026
Merged

rapier1 merged 4 commits into
masterfrom
bug-moba-aes

Conversation

@rapier1

@rapier1 rapier1 commented Sep 16, 2026

Copy link
Copy Markdown
Owner
  1. DisableMATES wasn't working correctly, On rekeys the flag to disable the parallel AES-CTR cipher wasn't being used which meant that it would be started on a rekey. Likely had no error reports because of the 32GB rekey limit.
  2. MobaXterm uses a SFTP modules for the GUI that would lead to the seqnr getting out of sync on rekeys. This led to a corrupted MAC on input immediately after a rekey. Created a compat flag for this to push the kex-strict marker to MobaXterm (and the sftp module they use from n-software called SecureBlackBox) on every rekey.
  3. Crank version number to 18.11.1

  Turns out that the guard against using AES-CTR-MT only applied on the
  initial post-auth rekey and was never checked again for subsequent rekeys.
  This was never fully tested until trying to resolve an issue with
  MobaXterm (using SecureBlackbox 9). This patch shoudl resolve this issue.
MobaXterm uses SecureBlackBox for their SFTP GUI. The version they
are using expects to see a kex-strict marker for each rekey KEXINIT.
If it doesn't see that it won't reset the sequence number while
OpenSSH will reset the seqnr. This leads to the seqnr being out of
sync and generates a corrupt MAC on input error. I do not knwo if this
applies to all versions of SBB but the banner in the server debug log
lists it as SecureBlackBox.9 but that's an arbitrary string.

This means that the fix is to create a compat flag for all matches on
SecureBlackBox. If the flag is present then we issue a kex-strict marker
on every rekey/KEXINIT. This forces the remote side to reset their seqnr
and everything ends up being in sync again.
@rapier1
rapier1 merged commit f4cb96a into master Sep 17, 2026
87 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant