
CVE-2021-42278 और CVE-2021-42287 के लिए पहचान स्क्रिप्ट
CVE-2021-42278 और CVE-2021-42287 के लिए पहचान स्क्रिप्ट
The detection script uses the domain account credentials to determine the possibility of the vulnerabilities.
usage: noPac-detection.py [-h] [-debug] -dc-ip <IP address> -targetUser <Target Username> credentials
optional arguments:
-h, --help show this help message and exit
-debug Turn DEBUG output ON
mandatory:
-dc-ip <IP address> IP of the domain controller to use. Useful if you can't translate the FQDN.specified in the
account parameter will be used
-targetUser <Target Username>
The target user to retrieve the PAC of
credentials domain/username[:password]. Valid domain credentials to use for grabbing targetUser's PAC
नोट: स्क्रिप्ट के कार्य करने के लिए सभी अनिवार्य मान आवश्यक हैं, डीबग मोड का समर्थन करता है, TargetUser कोई भी डोमेन से जुड़ा उपयोगकर्ता खाता हो सकता है, हमेशा डोमेन को domain.local के रूप में सेट करें उदाहरण के लिए: megacorp.local, cars.local आदि।
$ python noPac-detection.py MARVEL.local/pparker:P#%DG323c89 -targetUser fcastle -dc-ip 192.168.10.13
