Sploitus

Exploit for SIGRed

kitploit · 2026-08-27

Exploit Code

MARKDOWN22 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-CORELIGHT-SIGRED
# CVE-2020-1350 (AKA SIGRed) v0.30

## Краткое описание:

Пакет Zeek для обнаружения попыток эксплуатации DNS-сервера Microsoft Windows через CVE-2020-1350 (AKA SIGRed - оценка CVE 10.0)

## Ссылки:

https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/  
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350  
https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350

## Создаваемые уведомления :

Уведомление| Достоверность  
---|---  
CVE_2020_1350::CVE_2020_1350_Detected_High_Confidence CVE-2020-1350 Windows DNS exploit (CVE10) has been detected (High Confidence, large SIG/KEY response) Refer to links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 and https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/| Высокая  
Potential CVE-2020-1350 Windows DNS exploit (CVE10) has been detected (large DNS RRSIG/TKEY response). Refer to links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 and https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/| Средняя/Высокая  
Potential CVE-2020-1350 Windows DNS exploit (CVE10) has been detected (large DNS response). Refer to links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 and https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/| Средняя/Высокая  
  
По умолчанию все уведомления включены, однако если вы хотите включить только уведомление высокой достоверности (из-за шума/производительности или других причин) вы можете изменить опцию в `scripts/CVE-2020-1350.zeek` на `True`, т.е. `option only_enable_high_fidelity_notice: bool = T;`