Authored by Sedat Ozdemir

MTPutty version 1.0.1 suffers from an SSH password disclosure vulnerability.

# Exploit Title: MTPutty - SSH Password Disclosure
# Exploit Author: Sedat Ozdemir
# Version:
# Date: 06/12/2021
# Vendor Homepage:
# Tested on: Windows 10

Proof of Concept

Step 1: Open MTPutty and add a new SSH connection.
Step 2: Click double times and connect to the server.
Step 3: Run run “Get-WmiObject Win32_Process | select name, commandline |
findstr putty.exe” on powershell.
Step 4: You can see the hidden password on PowerShell terminal.