Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cve-2021-38647 — https://github.com/corelight/CVE-2021-38647 无冗余版本 | Kitploit
工具/GitHubGitHub/abousteif/cve-2021-38647
漏洞分析漏洞利用网络安全云安全入侵检测事件响应
GitHubabousteif/cve-2021-38647

cve-2021-38647

https://github.com/corelight/CVE-2021-38647 无冗余版本

查看仓库
1155年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

cve-2021-38647

https://github.com/corelight/CVE-2021-38647 去除冗余内容

CVE-2021-38647 又名 "OMIGOD"

一个用于检测 CVE-2021-38647(又名 OMIGOD)利用尝试的 Zeek 包。

https://corelight.com/blog/detecting-cve-2021-38647-omigod
https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647

利用

该利用方式非常简单,只需省略 Authorization 头,下图即为 tl;dr 说明。
利用原理图

安装

在在线环境中作为 Zeek 包安装
zkg install corelight/CVE-2021-38647 或使用直接 URL。
zkg install https://github.com/corelight/CVE-2021-38647/

在已有的 pcap 上使用
zeek -Cr scripts/__load__.zeek your.pcap

选项与说明:

  • 该包可在集群或非集群环境中运行。

  • omigod.zeek 脚本中的可配置选项可根据您的实施需求进行修改,具体如下所述。

  • TCP 端口设置为 OMI 的默认服务端口。若存在非默认端口,请将其添加到以下集合中。
    option OMI_ports = set(1270/tcp, 5985/tcp, 5986/tcp);

  • 为协助对 EXPLOIT_REQUEST 和 EXPLOIT_RESPONSE 通知进行 IR 研判,'sub' 字段将包含通知中的前 'bytes_of_data_in_notice' 字节数据。将该值设置为较大的数字可收集全部有效载荷 —— 默认值 10000 应足以捕获所有相关数据。
    option bytes_of_data_in_notice = 10000;

  • 为协助 IR 研判与威胁狩猎,独立的 'EXPLOIT_ATTEMPT' 通知将在 'sub' 字段中包含客户端头的名称和值。
    option raise_seperate_notice_for_missing_auth_header = T;

  • 请谨慎使用 User-Agent 白名单,以减少来自您自己的扫描器或合法系统的误报。请记住,攻击者可以轻松伪造此用户代理。示例:
    option user_agent_whitelist = /^Microsoft WinRM Client$/;

示例

以下通知展示了最大详细级别的示例。虽然可能显得过于冗长,但通知的 'sub' 字段提供了对 IR 研判和狩猎有用的数据。

  • EXPLOIT_ATTEMPT 通知提供了通过相对粗粒度攻击判定条件的请求的头名称和值。这是一种保守的通知,可按上述方式关闭,但在事件响应、威胁狩猎和规则调优时,将此类数据置于触手可及的位置(即通知本身,而非 pcap)可能很有用。例如,该通知的一个有用方面是 User-Agent —— 某些利用工具(POC)未能正确伪装它。在以下示例中,UA 为 curl/7.52.1,这(视使用场景而定)可能是合法访问 OMI 服务的极不寻常方式。此 EXPLOIT_ATTEMPT 通知可能(也可能不会)随后根据更精细的指标产生 EXPLOIT_REQUEST 或 EXPLOIT_RESPONSE 通知。
#separator \x09
#set_separator  ,
#empty_field    (empty)
#unset_field    -
#path   notice
#open   2021-09-20-14-23-48
#fields ts      uid     id.orig_h       id.orig_p       id.resp_h       id.resp_p       fuid    file_mime_type  file_desc       proto   note    msg     sub     src     dst     p       n       peer_descr      actions suppress_for    remote_location.country_code    remote_location.region  remote_location.city    remote_location.latitude        remote_location.longitude
#types  time    string  addr    port    addr    port    string  string  string  enum    enum    string  string  addr    addr    port    count   string  set[enum]       interval        string  string  string  double  double
1631859865.669975       CUoF9i1epohx0Xkycj      127.0.0.1       57592   127.0.0.1       5985    -       -       -       tcp     CVE_2021_38647::EXPLOIT_ATTEMPT A request to an OMI/WMI uri is missing the Authorization header, this is possibly a CVE-2021-38647 (AKA OMIGOD) exploit attempt. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution, see sub field for raw data       headers= '{\x0a\x09[1] = [original_name=Host, name=HOST, value=127.0.0.1:5985],\x0a\x09[2] = [original_name=User-Agent, name=USER-AGENT, value=curl/7.52.1],\x0a\x09[3] = [original_name=Accept, name=ACCEPT, value=*/*],\x0a\x09[5] = [original_name=Content-Length, name=CONTENT-LENGTH, value=2035],\x0a\x09[6] = [original_name=Expect, name=EXPECT, value=100-continue],\x0a\x09[4] = [original_name=Content-Type, name=CONTENT-TYPE, value=application/soap+xml]\x0a}'    127.0.0.1       127.0.0.1       5985    -       -       Notice::ACTION_LOG      3600.000000     -       -       -       -       -
  • EXPLOIT_REQUEST 通知显示 POST 请求的有效载荷。若 POST 数据较大(如下例所示),可能会被拆分为多条通知。
#separator \x09
#set_separator  ,
#empty_field    (empty)
#unset_field    -
#path   notice
#open   2021-09-20-14-23-48
#fields ts      uid     id.orig_h       id.orig_p       id.resp_h       id.resp_p       fuid    file_mime_type  file_desc       proto   note    msg     sub     src     dst     p       n       peer_descr      actions suppress_for    remote_location.country_code    remote_location.region  remote_location.city    remote_location.latitude        remote_location.longitude
#types  time    string  addr    port    addr    port    string  string  string  enum    enum    string  string  addr    addr    port    count   string  set[enum]       interval        string  string  string  double  double
1631859866.672356       CUoF9i1epohx0Xkycj      127.0.0.1       57592   127.0.0.1       5985    -       -       -       tcp     CVE_2021_38647::EXPLOIT_REQUEST A REQUEST to an OMI/WMI uri has a missing Authorization header - this is possibly a CVE-2021-38647 (AKA OMIGOD) exploit. See sub of this notice field for the raw Request data. Refer to https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution    The first 10000 bytes of data = '<?xml version="1.0"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:n="http://schemas.xmlsoap.org/ws/2004/09/enumeration" xmlns:w="http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema" xmlns:h="http://schemas.microsoft.com/wbem/wsman/1/windows/shell" xmlns:p="http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd">\x09  <s:Header>\x09\x09      <a:To>HTTP://127.0.0.1:5985/wsman/</a:To>\x09\x09          <w:ResourceURI s:mustUnderstand="true">http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem</w:ResourceURI>\x09\x09\x09      <a:ReplyTo>\x09\x09\x09\x09            <a:Address s:mustUnderstand="true">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address>\x09\x09\x09\x09\x09        </a:ReplyTo>\x09\x09\x09\x09\x09\x09    <a:Action>http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem/ExecuteScript</a:Action>\x09\x09\x09\x09\x09\x09        <w:MaxEnvelopeSize s:mustUnderstand="true">102400</w:MaxEnvelopeSize>\x09\x09\x09\x09\x09\x09\x09    <a:MessageID>uuid:00B60932-CC01-0005-0000-313370010000</a:MessageID>\x09\x09\x09\x09\x09\x09\x09        <w:OperationTimeout>PT1M30S</w:OperationTimeout>\x09\x09\x09\x09\x09\x09\x09\x09    <w:Locale xml:lang="en-us" s:mustUnderstand="false"/>\x09\x09\x09\x09\x09\x09\x09\x09        <p:DataLocale xml:lang="en-us" s:mustUnderstand="false"/>\x09\x09\x09\x09\x09\x09\x09\x09\x09    <w:OptionSet s:mustUnderstand="true"/>\x09\x09\x09\x09\x09\x09\x09\x09\x09        <w:SelectorSet>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09      <w:Selector Name="__cimnamespace">root/scx</w:Selector>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09          </w:SelectorSet>\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09\x09    </s:Header>\x09\x09\x09'    127.0.0.1       127.0.0.1       5985    -       -       Notice::ACTION_LOG
      3600.000000     -       -       -       -       -```

第二条通知显示了有效载荷,即 base64 编码的字符串 ZWNobyAiT01JR09EIGl0IHdvcmtzISINCmlkDQp1bmFtZQ0KZGF0ZQ0KZWNobyAiR29vZGJ5ZSINCg==,解码后得到以下 shell 脚本。

下载工具