
Scanner di vulnerabilità SMB che rileva CVE-2019-1040 inviando pacchetti di autenticazione NTLM non validi, abilitando attacchi di tipo MIC Remove relay per il compromesso dell'amministratore di dominio.
Controlla la vulnerabilità CVE-2019-1040 su SMB. Lo script stabilirà una connessione con l'host target e invierà un'autenticazione NTLM non valida. Se questa viene accettata, l'host è vulnerabile a CVE-2019-1040 e puoi eseguire l'attacco MIC Remove con ntlmrelayx.
Nota: questo non genera tentativi di login falliti poiché le informazioni di login sono valide, è solo il codice di integrità del messaggio NTLM ad essere assente, motivo per cui l'autenticazione viene rifiutata senza incrementare badpwdcount.
Lo script richiede una versione recente di impacket. Dovrebbe funzionare con Python 2 e 3 (Python 3 richiede l'uso di impacket da git).
[*] CVE-2019-1040 scanner by @_dirkjan / Fox-IT - Based on impacket by SecureAuth
usage: scan.py [-h] [-target-file file] [-port [destination port]]
[-hashes LMHASH:NTHASH]
target
CVE-2019-1040 scanner - Connects over SMB and attempts to authenticate with
invalid NTLM packets. If accepted, target is vulnerable to MIC remove attack
positional arguments:
target [[domain/]username[:password]@]<targetName or address>
optional arguments:
-h, --help show this help message and exit
connection:
-target-file file Use the targets in the specified file instead of the
one on the command line (you must still specify
something as target name)
-port [destination port]
Destination port to connect to SMB Server
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH