
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
This builds on other exploits for this vuln. Other exploits (like MSFconsole) would trunkate output, and I wanted to see the entirety of ALL tickets.
python3 solar_exploit.py -u https://target.com [-o output_directory] [-d delay_seconds]
This tool is provided for EDUCATIONAL PURPOSES ONLY. The author accepts no liability for any misuse of this software. Users must:
Only use against systems they own or have explicit written permission to test Follow all applicable laws and regulations Understand that unauthorized access to computer systems is illegal
By using this tool, you take full responsibility for your actions. The author cannot be held responsible for any damages resulting from its use.