Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-53770-Scanner — ToolShell scanner - CVE-2025-53770 and detection information | Kitploit
Tools/GitHubGitHub/zephrfish/cve-2025-53770-scanner
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability ScannersExploitationWeb Application ExploitationPenetration TestingThreat IntelligenceIncident ResponseLog Analysis
GitHubzephrfish/cve-2025-53770-scanner

CVE-2025-53770-Scanner

185171 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

ToolShell scanner - CVE-2025-53770 and detection information

View Repository
Share

CVE-2025-53770 SharePoint Vulnerability Scanner

100% hacked together with all the tweets floating around with payloads and different attacks, so comes with zero warranty etc. The scanner is designed to identify vulnerable instances and has a config with known uses in the wild of exploitation, it's primarily designed for defensive use to identify vulnerable instances and allow you to patch things.

This scanner performs automated checks of SharePoint deployments by:

  • Sending crafted POST requests to SharePoint ToolPane endpoints with exploit payloads
  • Detecting machine key extraction attempts and successful exploitation
  • Identifying secondary payload deployment (spinstall0.aspx)
  • Analyzing responses for vulnerability indicators based on observed attack patterns
  • Providing detailed reporting with confidence levels and immediate action alerts
  • Supporting concurrent scanning for efficiency

Key Detection Capabilities

CRITICAL: Machine Key Extraction Detection

  • Detects successful machine key extraction responses
  • Identifies ValidationKey, DecryptionKey, and CompatibilityMode exposure
  • Recognizes pipe-delimited machine key patterns (ValidationKey|Validation|DecryptionKey|Decryption|CompatibilityMode)
  • Triggers immediate action alerts for compromised systems

Secondary Payload Detection

  • Identifies spinstall0.aspx deployment attempts
  • Detects C# ASP.NET payload code patterns
  • Recognizes System.Web.Configuration.MachineKeySection usage
  • Version-specific path detection (SP2013: WEBSER~1\15\ vs SP2016+: WEBSER~1\16\)

Installation

  1. Clone the repository:
git clone https://github.com/ZephrFish/CVE-2025-53770-Scanner
cd CVE-2025-53770-Scanner
  1. Install dependencies:
pip install -r requirements.txt

Usage

Basic Usage

Create a text file with target hosts (one per line):

sharepoint1.example.com
sharepoint2.example.net
internal-sp.company.local

Run the scanner:

python3 scanner.py -i hosts.txt

python3 scanner.py -i hosts.txt -o results.json -l scan.log -t 20 -v

Command Line Options

OptionDescriptionDefault
-i, --inputPath to host list file (required)-
-o, --outputOutput file for results (.json, .csv, .txt)None
-l, --logfileLog file path for detailed loggingNone
-t, --threadsNumber of concurrent threads10
-v, --verboseEnable verbose output and loggingFalse

Output Formats

JSON Output (-o results.json)

[
  {
    "host": "sharepoint.example.com",
    "url": "https://sharepoint.example.com/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx",
    "scan_time": "2025-07-21T10:30:00.123456",
    "vulnerable": true,
    "status_code": 200,
    "response_size": 15432,
    "error": null,
    "response_time": 1.23
  }
]

CSV Output (-o results.csv)

Provides tabular data suitable for spreadsheet analysis with columns for all scan metrics.

Text Output (-o results.txt)

Human-readable format with vulnerability status and scan details.

Vulnerability Details

CVE-2025-53770 targets a deserialization vulnerability in SharePoint's ExcelDataSet component that has been actively exploited in the wild. The scanner detects:

Identified Attack Patterns

  1. Initial Exploitation: POST request to /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx with serialized payload
  2. Machine Key Extraction: Successful exploitation returns pipe-delimited machine configuration:
    ValidationKey|Validation|DecryptionKey|Decryption|CompatibilityMode
    Example: [128-256 hex chars]|HMACSHA256|[48-96 hex chars]|AES|Framework45
    
  3. Secondary Payload: Deployment of spinstall0.aspx for persistent access and key extraction
  4. Version Targeting: Different paths for SharePoint versions (15/ vs 16/ layouts)

Confirmed IOCs from Active Exploitation

  • User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
  • Referer: /_layouts/SignOut.aspx
  • Content-Length: Typically 7699-8000+ bytes
  • Payload Size: Large base64-encoded CompressedDataTable parameters
  • Response Indicators: Machine key strings, spinstall0.aspx deployment
  • Attack Infrastructure: 65.38.121.198, 162.243.204.189, 165.22.18.129

Detection Logic

The scanner analyzes responses for:

  1. Machine key extraction patterns (CRITICAL confidence)
  2. Secondary payload indicators (HIGH confidence)
  3. ExcelDataSet/Scorecard component processing (MEDIUM confidence)
  4. ToolPane error patterns and anomalous response characteristics (LOW confidence)

Security Considerations

  • This tool is designed for authorized security testing only
  • Ensure proper authorization before scanning any systems
  • Scanner uses HTTPS by default but accepts self-signed certificates
  • Logs may contain sensitive information - secure appropriately
  • Consider network impact when using high thread counts

Example Scan Session

$ python3 scanner.py -i corporate-sharepoint.txt -o vuln-results.json -l scan.log -v

Starting scan of 150 hosts with 10 threads...
Target CVE: CVE-2025-53770 (SharePoint ExcelDataSet deserialization)
Logging to: scan.log
Results will be saved to: vuln-results.json

[+] VULNERABLE [CRITICAL]: sp-prod-01.acme.local
[-] Not vulnerable: sp-dev-02.acme.local  
[!] ERROR: offline-sp.acme.local - Connection timeout
[+] VULNERABLE [HIGH]: sp-legacy.acme.local
Progress: 50/150 (33.3%)
Progress: 100/150 (66.7%)
Progress: 150/150 (100.0%)

============================================================
SCAN COMPLETE
============================================================
Total hosts scanned: 150
Vulnerable hosts: 3
Success rate: 97.3%

VULNERABLE HOSTS (CVE-2025-53770):

  CRITICAL - MACHINE KEY EXTRACTED (1 hosts):
    • sp-prod-01.acme.local (Response time: 0.85s, Version: 2016+)
      WARNING: IMMEDIATE ACTION REQUIRED: Machine keys compromised

  HIGH CONFIDENCE (1 hosts):
    • sp-legacy.acme.local (Response time: 1.23s, Version: 2013-2016)

  LOW CONFIDENCE (1 hosts):
    • sp-archive.acme.local (Response time: 2.10s, Version: Unknown)

Detailed results saved to: vuln-results.json

Troubleshooting

Common Issues

  1. Connection Timeouts: Increase timeout or reduce thread count
  2. SSL Errors: Scanner disables SSL warnings by default
  3. Permission Errors: Ensure write access for output/log files
  4. Memory Usage: Monitor with large host lists

Log Analysis

Enable verbose logging (-v) and log files (-l) for detailed troubleshooting:

tail -f scan.log

Exploitation Analysis

Observed Attack Payloads

The scanner incorporates detection for confirmed exploitation patterns observed in active attacks:

Primary Payload Structure

POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx HTTP/1.1
Host: target.domain.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Content-Length: 7699
Content-Type: application/x-www-form-urlencoded
Referer: /_layouts/SignOut.aspx
Connection: close

MSOTlPn_Uri=http%3A%2F%2F{{host}}%2F_controltemplates%2F15%2FAclEditor.ascx
&MSOTlPn_DWP=[ExcelDataSet payload with CompressedDataTable containing serialized exploit]
Download Tool