
يستغل ثغرات ProxyNotShell في Microsoft Exchange (CVE-2022-41040 وCVE-2022-41082) عبر سكربت إثبات مفهوم (PoC) مُصادَق ينفّذ أوامرًا على الخوادم المعرّضة للثغرات.
المتطلبات:
الاستخدام:
python poc_aug3.py <host> <username> <password> <command>
الاعتمادات:
نص برمجي لإثبات مفهوم ProxyShell من: https://blog.viettelcybersecurity.com/pwn2own-2021-microsoft-exchange-exploit-chain/
مقالة مدونة Gtsc