
CVE-2021-26855 exp
CVE-2021-26855 SSRF simple exploitation golang practice
This vulnerability is different from previous Exchange vulnerabilities. It does not require an authenticated user identity and can access internal user resources without authorization. Combined with CVE-2021-27065, it can achieve remote command execution.
Prerequisites for triggering the vulnerability
Among the above four items, the FQDN can be captured via NTLM Type2 messages; the email address can be directly enumerated.
Exploiting this vulnerability is more convenient using scripting languages such as Ruby or Python. Writing it in Golang is mainly for learning Golang, so this tool is only a half-finished product. I will update it when I have time.
This tool supports vulnerability detection and user enumeration. It can also read simple email IDs and subjects (essentially by modifying XML content). For further exploitation, refer to 8581, both involve submitting XML.
Usage:
go run CVE-2021-21978.go -h <target ip>
-h string Required, target IP or domain
-U string Optional, user list to enumerate
-d Optional, download emails
-l Optional, list emails
-n string Optional, specify FQDN (if needed)
-t string Optional, request delay (default "1")
-u string Optional, specify target (default "administrator")
Updated download functionality
