Skip to content
OthmaneBlialPublic

About

Free, open-source MobaXterm alternative built with Rust: SSH, SFTP, SCP, terminals, tunnels, serial, Telnet, diagnostics, and remote administration.

Topics

Resources

Contributing

Security policy

Stars

151 stars

Watchers

1 watching

Forks

Repository files navigation

MobaRust — Free, open-source MobaXterm alternative built with Rust

Free, open-source MobaXterm alternative built with Rust

SSH • SFTP/SCP • terminal tabs & splits • remote editing • tunnels • reviewed automation

Mac preview Rust + Tauri Apache 2.0

⬇️ Download · 🎬 Watch the app · 🌐 Website · 🧭 Roadmap · 📖 Docs · 🤝 Contribute

🎬 See the real app

mobarust-desktop-demo.mp4

From a shell to a working remote workspace. A real macOS ARM64 application recording: independent terminal panes, an authenticated SSH session, SFTP browsing and editing, a completed file download, an HTTP request through an SSH tunnel, reusable snippets, and light/dark themes.

▶ Watch / download the full walkthrough · Recording details & chapters

The server, keys, files and HTTP service are disposable loopback fixtures. The recording shows working product flows; it is not evidence of production-server or cross-platform compatibility.

✨ One workspace, from connection to completion

Connect with SSH, work in terminal tabs and splits, move files with SFTP/SCP, and reach services through tunnels.

🖥️ Keep your terminals together

Local shells and SSH terminals share a workspace. Open tabs, split panes, search scrollback and keep independent tasks in view. Organize saved sessions with folders, tags, favorites, recents and search.

Two independent terminals in the real MobaRust macOS application

📂 Work directly with remote files

Browse SFTP files, download or upload, and edit remote text without leaving the app. Transfers expose progress and cancellation; the editor checks for remote changes before saving.

Editing a generated remote configuration file over an actual SFTP connection

🔐 Make trust explicit

Connect with passwords, keys, encrypted keys or an SSH agent. Verify unknown host fingerprints, import an OpenSSH config deliberately, and use jump hosts to reach another network. Saved profiles hold credential references.

🌐 Reach the services you need

Create local or remote forwards and SOCKS5 proxies with explicit bind addresses. Inspect tunnel state and byte counts; stop a listener when you're done. Network diagnostics and SSH monitoring are available on demand.

🧩 Review before you automate

Save snippets with variables and a rendered preview. Review macros before running them. Broadcast input uses selected targets and an emergency disable, so remote execution stays deliberate.

🌗 Make it your workspace

Switch light/dark themes, adjust terminal fonts and shortcuts, and keep settings locally. No cloud account required. Telnet and serial are also available, with their unencrypted transport boundaries made explicit.

⬇️ Pick your platform

Platform Download Available version
🍎 macOS · Apple Silicon ARM64 DMG 0.1.31
🍎 macOS · Intel x64 DMG 0.1.31
🪟 Windows · x64 Installer 0.1.12
🐧 Ubuntu / Debian · x64 DEB 0.1.12
🐧 Other Linux · x64 AppImage 0.1.12

Preview distribution: no publisher signing; macOS is ad hoc signed and not notarized. Windows/Linux installers are older and do not include the latest main changes. RDP is excluded from normal installers.

📝 Mac release notes & SHA-256 files · Windows/Linux release files · Installation help

On Mac, move MobaRust to Applications. On Debian/Ubuntu, use sudo apt install ./MobaRust-0.1.12-linux-x64.deb. AppImage prerequisites vary by distribution. Checksums verify downloaded bytes; they do not establish publisher identity.

🚀 What's new — 0.1.31

  • Live tunnel traffic: local, SOCKS5 and remote forwards now show payload bytes while clients remain connected.
  • Accurate stopped totals: Stop and copy errors retain accepted bytes; completed copies count once and SOCKS5 framing is excluded.
  • Native checks: the ARM64 installer copy passed live/stopped totals, SSH-tab Close and normal Quit with eight byte-matched clients and clean fixture shutdown.
  • Locally checked release: the full suite passed, including 114 desktop tests, four forwarding cases and 25 OpenSSH cases. Both Mac packages passed mounted layout, architecture, signature and CLI checks.

All four published assets matched anonymous downloads byte for byte. This fixes the v0.1.30 active/cancelled counter defect. Broader workloads, Intel GUI and Windows/Linux acceptance remain open. Windows/Linux downloads remain v0.1.12; the walkthrough remains v0.1.17. Native checks · Release limits.

Known v0.1.31 issue: Files can retain a busy error after a successful Refresh. A source correction scopes listing errors and clears them on a new request; corrected native acceptance and a new installer remain pending.

🧭 Progress and next steps

Updated 2026-10-03. The roadmap has 57 of 76 checked items (75%). This is checklist completion, not production readiness: implementation, tests, downloadable binaries and hardware evidence are separate milestones.

Area Verified so far Next acceptance gate
✅ SSH reliability OpenSSH lab covers keys, jumps, agent, IPv6 and recovery. Earlier Mac authentication/reconnect receipts remain available. The v0.1.29 ARM64 copy passed Escape before connection, approved startup, replacement startup timeout with no further retry, and normal local-PTY Quit. Receipts · v0.1.29 check. Release-copy successful startup/output ordering, queued expiry/overflow, prompt/backpressure/resize acceptance, Windows/Linux, OpenSSH password/PAM and sustained workloads.
✅ Native workflow demo macOS ARM64 terminals, SSH, remote edit/save, file download and local tunnel. Wider keyboard, failure-recovery and GUI coverage across all three OSes.
✅ Editor recovery Mac candidate passed conflict/reopen recovery and both Save as policies. The v0.1.26 ARM64 copy passed encoding Save/new Save as; the v0.1.27 copy passed explicit legacy Open/Save/reopen and UTF-8 conversion, with exact bytes/modes and normal-Quit cleanup. Receipts. Windows/Linux, saved-with-warning focus and uncertain promotion recovery.
✅ Quality baseline One complete green Ubuntu/macOS/Windows run on source ac70e39; local checks continue. New repeated Windows startups and Linux zsh/fish runtime evidence. GitHub CI is disabled by request.
🟡 Native dialogues Mac lab verified file policies, reconnect-safe approvals, settings imports and visible error focus. Included in the v0.1.25 Mac preview. Broader collision/recovery checks and native Windows/Linux acceptance. Evidence.
🟡 Distribution Mac ARM64/x64 0.1.31 previews; Windows/Linux 0.1.12 downloads. Align versions, clean install/uninstall, signing and notarization.
🧪 RDP / VNC / X11 / serial Isolated helpers and controlled fixtures exist. Real servers, physical adapters and platform interoperability. RDP security gates remain open.

Next priorities: sustained failure/recovery and transfer-control acceptance → current Windows/Linux installers → signing and notarization. Wider SSH authentication/recovery remains open.

📍 Detailed roadmap & completion criteria · Platform evidence · SSH lab · Benchmark receipt

🛡️ Keep trust and data local

Rust owns protocols, processes, saved credentials and persistence. Unknown SSH host keys are not silently accepted. Multiline paste and remote execution have explicit review boundaries. VNC TCP and Telnet are unencrypted; experimental support is documented separately.

Local test safety: protocol fixtures listen only on 127.0.0.1 or ::1, with disposable data and generated credentials. They do not enable Remote Login, change firewall/router rules or expose a home-network port. Native checks use an isolated app copy; owned test processes are stopped afterwards. Testing boundaries.

Threat model · Dependency audit · Private vulnerability reporting

🛠️ Build and contribute

Use Rust stable 1.90+, Node.js 22, pnpm 10, and the native Tauri prerequisites.

git clone https://github.com/OthmaneBlial/MobaRust.git
cd MobaRust
pnpm install --dir apps/desktop --frozen-lockfile
cargo xtask check
pnpm --dir apps/desktop tauri dev
cargo xtask test-ssh    # Disposable OpenSSH lab on Unix
cargo xtask check-rust  # Native workspace tests and Clippy

The full check covers frontend, Rust, isolated protocol helpers, package layouts and fuzz compilation. Fixtures use disposable state and generated credentials.

Contributing · Architecture · Safe testing · Benchmarks

Build your next remote workspace with us.

Report a bug · Explore the roadmap · Star MobaRust ⭐

Independent project; not affiliated with Mobatek or MobaXterm. Licensed under Apache-2.0.

About

Free, open-source MobaXterm alternative built with Rust: SSH, SFTP, SCP, terminals, tunnels, serial, Telnet, diagnostics, and remote administration.

Topics

Resources

Contributing

Security policy

Stars

151 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages