operations notes
MobaXterm guides
Procedures taken from vendor docs and from tickets people actually file: an empty SFTP pane, X11 after sudo, Home's 12-session ceiling, and antivirus holds on the portable exe.
SFTP browser not showing
The graphical SFTP browser is tied to SSH. If the left file tree never appears, the remote sshd is usually missing an SFTP subsystem, or the session is not SSH.
- Open Session settings and confirm the type is SSH, not Telnet, raw serial or a local shell.
- On the server, keep a line such as
Subsystem sftp /usr/lib/openssh/sftp-serverinsshd_config, thensudo systemctl reload sshd. - In MobaXterm, show the SSH browser if it was closed. From v26.4, click the SSH browser title icon to place the tree so sessions and files stay visible together.
- If Follow terminal is on and you jump tabs quickly, wait for the listing or toggle the feature. v26.4 notes an empty browser in that race.
- Try the right-click action "open SFTP with the same parameters" added in v26.4.
X11 missing after sudo, or DISPLAY looks wrong
If echo $DISPLAY on the server prints localhost:10.0, that is expected for X11-forwarding. SSH builds a local virtual display and sends it through the tunnel. It is not a bug.
- Keep X11-forwarding enabled on the SSH session. MobaXterm starts the X server for you.
- On the server,
X11Forwarding yesmust be set insshd_config. - After
sudo -i, DISPLAY is often cleared. Usesudo -Eor copy DISPLAY into the root shell:sudo DISPLAY=$DISPLAY xclock. - The banner IP is informational. The X server listens on every adapter, including VPN interfaces. You do not have to edit DISPLAY to the VPN address for forwarded SSH.
- Test with
xclockbefore blaming a larger GUI toolkit. If that class of X11 window never appears, fix forwarding first.
Portable vs Installer
Portable is a folder you unzip. Installer writes shortcuts and a Documents-based profile. Neither one is "safer" by default. Portable still stores sessions and may store credentials next to the exe.
- Choose Installer for a normal personal Windows 11 desktop.
- Choose Portable for a USB toolkit or a machine where you cannot run setup.
- Protect the Portable folder. Treat
MobaXterm.inias sensitive. - Do not assume USB portability bypasses site firewall or MFA rules.
Master password and MobaXterm.ini
Settings live in MobaXterm.ini:
- Installer: usually
Documents\MobaXterm. - Portable: the same folder as the exe.
- Some builds:
%AppData%\MobaXterm. - Set a master password if you save session secrets. Close the app before you copy the INI to another PC.
- v26.4 keeps the master-password prompt from staying top-most after you sign back into Windows.
Antivirus or SmartScreen stopped the file
Packed portable tools get generic "heuristic" hits. That is common and not proof of malware. It is also not proof the file is clean if you grabbed it from a random mirror.
- Confirm the filename and version: Home Edition v26.5, Portable or Installer.
- Hash the file and compare it to the digest the package owner publishes. This site does not invent a 26.5 SHA.
- If your AV quarantines it, restore only after that check, then send the sample to the vendor.
- Do not turn the scanner off globally to "make MobaXterm work".
Home Edition hit 12 sessions
Home Edition stores 12 sessions, 2 SSH tunnels and 4 macros. Imports that look like they "stop at 14" are the same ceiling showing up in older forum threads.
- Count saved entries in the user sessions tree, not open tabs.
- Fold hosts behind one SSH gateway if you only need a jump path.
- For a lab or a company desktop, buy Professional. Home is not licensed for company use.
Why 26.5 after the 26.4 CVE fixes
v26.4 stopped MobaTextEditor, Xorg, MoTTY and Cygwin from loading unused libraries at startup (CVE-2026-11879) and stopped probing winspool.drv at launch (CVE-2026-11967). v26.5 adds the CygUtils integrity check, tighter install-folder permissions and skips a winsta.dll probe.
- Export sessions (right-click User sessions) before you overwrite a Portable folder.
- Install Home Edition v26.5.
- Re-enter the master password and open one SSH session as a smoke test.
Daily habits that prevent the usual tickets
- Company desk: Professional license, not a Home exe copied from a USB key.
- Read the paste confirmation added in 26.2 before you dump a wiki snippet into root shells.
- Use an SSH gateway for hosts that are not directly reachable.
- Keep plugin
.mxtfiles next to the exe only if you trust that folder.