这绝对不是你会在任何你在乎的东西上运行的东西。
基于 @obfuscatee 和另一个来源的 writeup 及其工作成果构建
使用了以下代码:
https://github.com/dirkjanm/CVE-2020-1472
https://github.com/SecuraBV/CVE-2020-1472
https://github.com/VoidSec/CVE-2020-1472
https://github.com/SecureAuthCorp/impacket
基本上会执行 zerologon 漏洞利用、转储 hives(注册表配置单元)、提取机器密码并重新安装机器密码。 它似乎可用,但我还没有足够的时间进行全面测试。
运行它需要最新的 impacket
示例运行
./python cve-2020-1472-easymode.py -n iddc1 -i 192.168.74.130 -d internaldomain.internal