黑客、渗透测试和网络安全工具,武装您的安全武器库!
通过经过身份验证的 PoC 脚本利用 Microsoft Exchange ProxyNotShell 漏洞(CVE-2022-41040 和 CVE-2022-41082),在易受攻击的服务器上执行命令。
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
要求:
用法:
python poc_aug3.py <host> <username> <password> <command>
致谢:
ProxyShell PoC 脚本来自:https://blog.viettelcybersecurity.com/pwn2own-2021-microsoft-exchange-exploit-chain/
Gtsc 的博客文章
https://www.zerodayinitiative.com/blog/2022/11/14/control-your-types-or-get-pwned-remote-code-execution-in-exchange-powershell-backend