
Ein Python-Skript zum Extrahieren von Informationen aus einer Microsoft Remote Desktop Web Access (RDWA)-Anwendung

Ein Python-All-in-One-Werkzeug zum Extrahieren von Informationen, zum Sprayen und Erraten von Passwörtern auf einer Microsoft Remote Desktop Web Access (RDWA)-Anwendung.
Dieses Python-Werkzeug ermöglicht es, verschiedene Informationen aus einer Microsoft Remote Desktop Web Access (RDWA)-Anwendung zu extrahieren, wie z.B. den FQDN des entfernten Servers, den internen AD-Domänennamen (aus dem FQDN) und die Version des entfernten Windows-Servers.
$ rdwatool -h
____ ____ _ _____ __ __
/ __ \/ __ \ | / / | / /_____ ____ / /
/ /_/ / / / / | /| / / /| |/ __/ __ \/ __ \/ / @podalirius_
/ _, _/ /_/ /| |/ |/ / ___ / /_/ /_/ / /_/ / /
/_/ |_/_____/ |__/|__/_/ |_\__/\____/\____/_/ v2.0
usage: rdwatool recon [-h] [-tf TARGETS_FILE] [-tu TARGET_URLS] [-v] [--no-colors] [--debug] [-T THREADS] [-PI PROXY_IP] [-PP PROXY_PORT] [-rt REQUEST_TIMEOUT] [-k] [-L] [--export-xlsx EXPORT_XLSX] [--export-json EXPORT_JSON]
[--export-sqlite EXPORT_SQLITE]
options:
-h, --help show this help message and exit
-v, --verbose Verbose mode. (default: False)
--no-colors Disable colored output. (default: False)
--debug Debug mode, for huge verbosity. (default: False)
-T THREADS, --threads THREADS
Number of threads (default: 250)
Targets:
-tf TARGETS_FILE, --targets-file TARGETS_FILE
Path to file containing a line by line list of targets.
-tu TARGET_URLS, --target-url TARGET_URLS
Target URL of the RDWA login page.
Advanced configuration:
-PI PROXY_IP, --proxy-ip PROXY_IP
Proxy IP.
-PP PROXY_PORT, --proxy-port PROXY_PORT
Proxy port
-rt REQUEST_TIMEOUT, --request-timeout REQUEST_TIMEOUT
Set the timeout of HTTP requests.
-k, --insecure Allow insecure server connections when using SSL (default: False)
-L, --location Follow redirects (default: False)
Export results:
--export-xlsx EXPORT_XLSX
Output XLSX file to store the results in.
--export-json EXPORT_JSON
Output JSON file to store the results in.
--export-sqlite EXPORT_SQLITE
Output SQLITE3 file to store the results in.
Im recon-Modus:
rdwatool recon -tf ./subdomains.txt

Im spray-Modus:
rdwatool spray -tu https://rds.podalirius.net/RDWeb/Pages/en-US/login.aspx
Im brute-Modus:
rdwatool brute -tu https://rds.podalirius.net/RDWeb/Pages/en-US/login.aspx
Pull-Requests sind willkommen. Erstellen Sie gerne ein Issue, wenn Sie weitere Funktionen hinzufügen möchten.
Auf der Seite login.aspx der Remote Desktop Web Access (RDWA)-Anwendung gibt es viele vorausgefüllte Informationen. In den Eingabefeldern WorkSpaceID und/oder RedirectorName finden wir den FQDN des entfernten Servers, und WorkspaceFriendlyName kann eine Textbeschreibung des Arbeitsbereichs enthalten.
<form id="FrmLogin" name="FrmLogin" action="login.aspx?ReturnUrl=%2FRDWeb%2FPages%2Fen-US%2FDefault.aspx" method="post" onsubmit="return onLoginFormSubmit()">
<input type="hidden" name="WorkSpaceID" value="DC01.lab.local"/>
<input type="hidden" name="RDPCertificates" value="E7100C72B6C11A5D14DE115D801E100C79143C19"/>
<input type="hidden" name="PublicModeTimeout" value="20"/>
<input type="hidden" name="PrivateModeTimeout" value="240"/>
<input type="hidden" name="WorkspaceFriendlyName" value="Workspace%20friendly%20name%20or%20description"/>
<input type="hidden" name="EventLogUploadAddress" value=""/>
<input type="hidden" name="RedirectorName" value="DC01.lab.local"/>
<input type="hidden" name="ClaimsHint" value=""/>
<input type="hidden" name="ClaimsToken" value=""/>
<input name="isUtf8" type="hidden" value="1"/>
<input type="hidden" name="flags" value="0"/>
...
</form>
Das rdwatool-Werkzeug parst dieses Formular automatisch und extrahiert alle Informationen.
Wenn die entfernte RDWeb-Installation nicht gehärtet ist, besteht eine hohe Wahrscheinlichkeit, dass die Standardversionsbilddatei /RDWeb/Pages/images/WS_h_c.png noch zugänglich ist (auch wenn sie nicht auf der Anmeldeseite verlinkt ist). Das ist wirklich großartig, da wir ihren SHA256-Hashwert direkt mit einer bekannten Tabelle der Windows-Banner dieses Dienstes vergleichen können:
Das rdwatool-Werkzeug ruft diese Datei automatisch ab und vergleicht ihren Hash, um die Version des entfernten Windows-Servers zu ermitteln.
| Windows OS | SHA256 hash | Banner |
|---|
| Windows Server 2008 R2 | 5a8a77dc7ffd463647987c0de6df2c870f42819ec03bbd02a3ea9601e2ed8a4b | ![]() |
| Windows Server 2012 R2 | 4560591682d433c7fa190c6bf40827110e219929932dc6dc049697529c8a98bc | ![]() |
| Windows Server 2012 R2 | 3d9b56811a5126a6d3b78a692c2278d588d495ee215173f752ce4cbf8102921c | ![]() |
| Windows Server 2016 | fb1505aadeab42d82100c4d23d421f421c858feae98332c55a4b9595f4cea541 | ![]() |
| Windows Server 2016 | 3dbbeff5a0def7e0ba8ea383e5059eaa6acc37f7f8857218d44274fc029cfc4b | ![]() |
| Windows Server 2019 | 2da4eb15fda2b7c80a94b9b2c5a3e104e2a9a2d9e9b3a222f5526c748fadf792 | ![]() |
| Windows Server 2022 | 256a6445e032875e611457374f08acb0565796c950eb9c254495d559600c0367 | ![]() |