Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: SharePoint Pre-Auth RCE chain #339

Open
secureness opened this issue Sep 28, 2023 · 5 comments
Open

PRP: SharePoint Pre-Auth RCE chain #339

secureness opened this issue Sep 28, 2023 · 5 comments
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted

Comments

@secureness
Copy link
Contributor

Hi, I have a vulnerable version of the SharePoint server and want to implement a tsunami plugin.

ref: https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/

@secureness
Copy link
Contributor Author

if the server is vulnerable to JWT authentication bypass with none algorithm method and also if there is a default client id "00000003-0000-0ff1-ce00-000000000000" then it is easy to find out if this version of SharePoint is vulnerable or not.

@maoning
Copy link
Collaborator

maoning commented Oct 7, 2023

Hi @secureness,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

@tooryx
Copy link
Member

tooryx commented Feb 1, 2024

Hi @secureness,

I have labeled your other issues as "Contributor queue" for now. We are enforcing more strictly the one review per contributor as we cannot keep up with review otherwise. We will review this plugin and then dequeue the other ones progressively. I choose this plugin because it seems to me to be the one that would be the fastest to merge, but let me know if you would prefer to go with the F5 or VMWare ones.

If you think I incorrectly labeled one of the issues, please let me know.
~tooryx

@tooryx tooryx added the Contributor main The main issue a contributor is working on (top of the contribution queue). label Feb 1, 2024
@secureness
Copy link
Contributor Author

secureness commented Feb 1, 2024

@tooryx I already submitted the VMware PR because it was the oldest submission, please check out here.

@tooryx
Copy link
Member

tooryx commented Feb 1, 2024

I understand, but I also felt that getting the sharepoint one merged would be faster (because I will take us longer to reproduce the VMWare one internally). But it is totally up to you. Just let me know which one you would like to prioritize.

@tooryx tooryx added Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. and removed Contributor main The main issue a contributor is working on (top of the contribution queue). labels May 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted
Projects
None yet
Development

No branches or pull requests

3 participants