Sploitus

Exploit for Server-Side Request Forgery in Microsoft

githubexploit · 2021-08-10

Exploit Code

README14 lines
## https://sploitus.com/exploit?id=B3DDE0DD-F0B0-542D-8154-F61DCD2E49D9
# Proxyshell-Scanner
nuclei scanner for Proxyshell RCE (CVE-2021-34423,CVE-2021-34473,CVE-2021-31207) discovered by orange tsai in Pwn2Own, which affect microsoft exchange server.


# POC

![alt text](https://github.com/cyberheartmi9/Proxyshell-Scanner/blob/main/screenshot/proxyshell.PNG)


# Resource
https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html
https://blog.orange.tw/2021/08/proxyoracle-a-new-attack-surface-on-ms-exchange-part-2.html
https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1