Sploitus

Exploit for UltraRealy_with_CVE-2019-1040

kitploit ยท 2026-08-25

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-LAZAARS-ULTRAREALY_WITH_CVE-2019-1040
# Lazaar Sami๊ฐ€ CVE-2019-1040 ์ต์Šคํ”Œ๋กœ์ž‡์„ ์œ„ํ•ด ์—…๋ฐ์ดํŠธํ•œ UltraRelay

UltraRelay๋Š” LLMNR ์ค‘๋… ๋ฐ NTLM ์ž๊ฒฉ ์ฆ๋ช… ๋ฆด๋ ˆ์ด๋ฅผ ์œ„ํ•œ ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. Responder์™€ impack์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

์›๋ณธ ๋ฒ„์ „(https://github.com/5alt/ultrarelay)์„ CVE-2019-1040 ์ต์Šคํ”Œ๋กœ์ž‡์„ ์œ„ํ•ด ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค. Dirk-jan Mollema๋Š” ntlmrelayx(https://github.com/CoreSecurity/impacket์˜ ์ผ๋ถ€)๋ฅผ ์—…๋ฐ์ดํŠธํ•˜์—ฌ --remove-mic ํ”Œ๋ž˜๊ทธ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด ํ”Œ๋ž˜๊ทธ๋Š” Preempt ์—ฐ๊ตฌ์›๋“ค์˜ ๊ธฐ์ˆ  ์„ค๋ช…(https://blog.preempt.com/drop-the-mic)์„ ๊ธฐ๋ฐ˜์œผ๋กœ CVE-2019-1040์„ ์ต์Šคํ”Œ๋กœ์ž‡ํ•ฉ๋‹ˆ๋‹ค. ์ฐธ์กฐ: https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/ ํŠนํžˆ, ์ด ๋„๊ตฌ๋Š” JAVA HTTP ์š”์ฒญ์—์„œ ๋กœ์ปฌ SMB ์„œ๋ฒ„๋กœ ์ž๊ฒฉ ์ฆ๋ช…์„ ๋ฆด๋ ˆ์ดํ•˜์—ฌ RCE๋ฅผ ๋‹ฌ์„ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

## ์ข…์†์„ฑ

  * Responder
  * impack



## ์‚ฌ์šฉ๋ฒ•

์›๋ณธ ๋ฒ„์ „ https://github.com/5alt/ultrarelay ์—์„œ Jianing Wang๊ณผ Junyu Zhou์—๊ฒŒ ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค. `python ultrarelay.py -ip 192.168.1.100`

ip ์ธ์ˆ˜ ๊ฐ’์€ ๊ณต๊ฒฉ์ž์˜ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.

CVE-2019-1040 ์ต์Šคํ”Œ๋กœ์ž‡์„ ์œ„ํ•ด --remove-mic ํ”Œ๋ž˜๊ทธ(์ตœ์‹  NTLM ์™„ํ™”๋ฅผ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•ด MIC ์ œ๊ฑฐ, https://blog.preempt.com/drop-the-mic ์ฐธ์กฐ)์™€ -remove-target ํ”Œ๋ž˜๊ทธ(์ฑŒ๋ฆฐ์ง€ ๋ฉ”์‹œ์ง€์—์„œ ๋Œ€์ƒ์„ ์ œ๊ฑฐ, CVE-2019-1019 ํŒจ์น˜๊ฐ€ ์„ค์น˜๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ)๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” Dirk-jan Mollema๊ฐ€ ์—…๋ฐ์ดํŠธํ•œ ์ƒˆ๋กœ์šด ntlmrelayx ๋ฒ„์ „(https://github.com/CoreSecurity/impacket)์—์„œ ์˜๊ฐ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค. ์˜ˆ: python ultrarelay.py -ip 192.168.1.3 --remove-mic --escalate-user ntu -t ldap://s2016dc.testsegment.local -smb2support

## ๋ฐ๋ชจ ๋น„๋””์˜ค

https://www.youtube.com/watch?v=VyoyA2GgKck

## ์—ฐ๋ฝ์ฒ˜

Lazaar sami, some-email@example.com

# UltraRealy_with_CVE-2019-1040