¶ñÒâGIFÀûÓÃMicrosoft Teams·ì϶½Ù³ÖÕÊ»§
°ä²¼¹¦·ò 2020-04-290x00 ÊÂÎñ²¼¾°
CyberArkµÄ×êÑÐÈËÔ±·¢ÏÖMicrosoft TeamsÖдæÔÚ×ÓÓòÃûÊÕÊÜ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ʹ¹¥»÷ÕßÏòÓû§·¢ËͶñÒâGIFͼÏñ´ïµ½ÇÔÈ¡Óû§Êý¾Ý²¢½Ù³ÖTeamsÕË»§µÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£
Microsoft Teams ÊÇÒ»¿î»ùÓÚ̸ÌìµÄÖÇÄÜÍŶӺÏ×÷¹¤¾ß£¬£¬£¬£¬£¬Äܹ»Í¬²½½øÐÐÎĵµ¹²Ïí£¬£¬£¬£¬£¬²¢Îª³ÉÔ±ÌṩÔ̺¬ÓïÒô¡¢ÊÓÆµ»áÒéÔÚÄڵļ´Ê±Í¨Ñ¶¹¤¾ß¡£¡£¡£¡£¡£¡£
ÓÉÓÚÓû§²»Óù²ÏíGIF£¬£¬£¬£¬£¬Ö»ÊÇ¿´µ½Ëü¾ÍÄÜÊܵ½Ó°Ï죬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶Äܹ»×Ô¶¯´«²¼£¬£¬£¬£¬£¬²¢Ó°ÏìʹÓÃTeams×ÀÃæ»òWebä¯ÀÀÆ÷°æ±¾µÄÿ¸öÓû§¡£¡£¡£¡£¡£¡£
0x01 ·ì϶·ÖÎö
¸ÃȱµãÓëMicrosoft Teams´¦ÖÃͼÏñ×ÊÔ´Éí·ÝÑéÖ¤µÄ·½Ê½Óйء£¡£¡£¡£¡£¡£Ã¿´Î´ò¿ªTeams¿Í»§¶Ëʱ»á´´½¨Ò»¸öһʱµÄtoken»òaccess token¡£¡£¡£¡£¡£¡£´ËÁîÅÆÒÔJWTµÄ´ó¾ÖÓÉMicrosoftÊÚȨºÍÉí·ÝÑéÖ¤·þÎñÆ÷¡°login.microsoftonline.com¡±´´½¨£¬£¬£¬£¬£¬ÔÊÐíÓû§²é¿´Ó×ÎÒ»ò»á»°ÖзÖÏíµÄͼÏñ¡£¡£¡£¡£¡£¡£
¸ÃÀûÓ÷¨Ê½Ê¹ÓÃÁ½¸öÁîÅÆ½øÐÐÉí·ÝÑéÖ¤£ºauthtokenºÍskypetoken¡£¡£¡£¡£¡£¡£ÎªÁË×êÑÐÁ½¸öÁîÅÆµÄ¹ØÏµ£¬£¬£¬£¬£¬ÎÒÃÇÌáÈ¡ÁËTeams¿Í»§¶ËµÄÁ÷Á¿£¬£¬£¬£¬£¬ÆäÖлñÈ¡ÐÂÎÅÒªÇóÈçÏ£º
GET https://amer.ng.msg.teams.microsoft.com/v1/users/ME/conversations/19%3A...%40unq.gbl.spaces/messages?view=msnp24Equivalent|supportsMessageProperties&pageSize=200&startTime=1 HTTP/1.1
Host: amer.ng.msg.teams.microsoft.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
x-ms-session-id: 00000000000-0000-0000-0000-00000000000
BehaviorOverride: redirectAs404
x-ms-scenario-id: 00
x-ms-client-cpm: ApplicationLaunch
x-ms-client-env:
x-ms-client-type:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36
ClientInfo:
Accept: json
Sec-Fetch-Dest: empty
x-ms-client-version:
x-ms-user-type: user
Authentication: skypetoken=eyJhbGciOiJSUzI1NiIsImtpZCI6IkVhc3RlckVnZyA6KSIsInR5cCI6IkpXVCJ9.eyJ...
Origin: https://teams.microsoft.com
Sec-Fetch-Site: same-site
Sec-Fetch-Mode: cors
Referer: https://teams.microsoft.com/_
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
´Ó±¨ÎÄÖп´³ö£¬£¬£¬£¬£¬¿Í»§¶Ë½ö·¢ËÍÁËÒ»¸öÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬£¬¸ÃÁîÅÆÄܹ»ÔÚ¡°Authentication¡±×Ö¶ÎÖÐÕÒµ½£¬£¬£¬£¬£¬Ãû³ÆÎª¡°skypetoken¡±¡£¡£¡£¡£¡£¡£ÏÔȻҪÏë·¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬ÎÒÃDZØÒª»ñµÃÒ»¸öSkypeÁîÅÆ¡£¡£¡£¡£¡£¡£SkypeÁîÅÆ´ÓºÎ¶øÀ´ÄØ£¿£¿£¿£¿£¿£¿ÎÒÃǽøÒ»²½×êÑÐÁËÁ÷Á¿£¬£¬£¬£¬£¬ÕÒµ½ÁËTeams¿Í»§´´½¨skypetokenÒªÇóµÄ»á»°£º
POST /api/authsvc/v1.0/authz HTTP/1.1
Host: teams.microsoft.com
Connection: close
Content-Length: 0
Pragma: no-cache
Cache-Control: no-cache
x-ms-session-id: 00000000000-0000-0000-0000-00000000000
x-ms-scenario-id: 00
x-ms-user-type: user
x-ms-client-env:
x-ms-client-type:
Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6IktleXMiLCJraWQiOiJLZXlzRXZlcnlXaGVyZSJ9.eyJ...
Accept: application/json, text/plain, */*
X-Client-UI-Language: en-us
Sec-Fetch-Dest: empty
ms-teams-authz-type: TokenRefresh
x-ms-client-version:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36
Origin: https://teams.microsoft.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Referer: https://teams.microsoft.com/_
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: {redacted}
´Ó±¨ÎÄÄܹ»¿´³ö£¬£¬£¬£¬£¬authtokenÌìÉúÁËskype token¡£¡£¡£¡£¡£¡£ÓÐÁËÕâÁ½¸öÁîÅÆ£¬£¬£¬£¬£¬ÎÒÃǾÍÄܹ»Í¨¹ýŲÓÃTeams API½Ó¿Ú£¬£¬£¬£¬£¬ÊµÏÖ·¢ËÍÐÂÎÅ¡¢ÔĶÁÐÂÎÅ¡¢´´½¨×é¡¢Ôö³¤ÐÂÓû§»ò´ÓÖÐɾ³ýÓû§×é¡¢¸ü¸Ä×éµÄȨÏÞµÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£
authtoken cookieÉèÖÃÊÇ·¢Ë͸øteams.microsoft.team»òÆäËû×ÓÓòÃû£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÁ½¸ö´æÔÚ½Ù³Ö¹¥»÷·ì϶µÄ×ÓÓòÃû£º
1. aadsync-test.teams.microsoft.com
2. data-dev.teams.microsoft.com
ÈôÊǹ¥»÷ÕßÄܹ»ÈÃÓû§½Ó¼û½Ù³ÖµÄ×ÓÓòÃû£¬£¬£¬£¬£¬ÔòÊܺ¦ÕßµÄä¯ÀÀÆ÷»á½«cookie·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷£¬£¬£¬£¬£¬ÔÚÊÕµ½authtokenÖ®ºó£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»´´½¨Ò»¸öskype token£¬£¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕßµÄTeamsÕÊ»§Êý¾Ý¡£¡£¡£¡£¡£¡£
ÓÐÁËÉÏÊö±»ºÚµÄ×ÓÓòÃûºó£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»Í¨¹ýÏòÊܺ¦Õß»òȺÁĵÄËùÓгÉÔ±·¢ËͶñÒâÁ´½Ó£¨¼´GIFͼÏñ£©À´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£½«Í¼ÏñµÄ¡°src¡±ÊôÐÔÉèÖÃΪ±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬²¢·¢Ë͸øÊܺ¦Õß¡£¡£¡£¡£¡£¡£µ±½Ó¹ÜÕß´ò¿ªÐÂÎź󣬣¬£¬£¬£¬ä¯ÀÀÆ÷¾Í»á·¢ËÍauthtoken cookiesµ½±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬¶øºó³¢ÊÔ¼ÓÔØ¸ÃͼÏñ¡£¡£¡£¡£¡£¡£Ö®ºó¹¥»÷ÕßÀûÓÃauthtoken cookies´´½¨Ò»¸öskype token£¬£¬£¬£¬£¬²¢×îÖÕ»ñÈ¡Êܺ¦ÕßµÄËùº±¼û¾Ý¡£¡£¡£¡£¡£¡£
0x02 ·ì϶ÑéÖ¤
1. ×êÑÐÈËÔ±»¹×öÁËÒ»¸ö·ì϶ÀûÓõÄPoCÊÓÆµ£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º
https://fast.wistia.com/embed/medias/f4b25lcyzm
2. ´Ë±í£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹±àдÁËÒ»¸ö¾ç±¾£¬£¬£¬£¬£¬¸Ã¾ç±¾¿ÉץȡÊܺ¦ÕߵĶԻ°²¢½øÐÐÏ̴߳¦Ö㬣¬£¬£¬£¬²¢½«Æä±£Áôµ½±¾µØÎļþÖУ¬£¬£¬£¬£¬ÈçͼËùʾ£º
0x03 ½áÂÛ
ÓÉÓڸ÷ì϶Äܹ»×Ô¶¯´«²¼£¬£¬£¬£¬£¬ÀàËÆÓÚÈ䳿²¡¶¾£¬£¬£¬£¬£¬´Ó¶øµ¼Ö·ÛËéÖ¸±ê×éÖ¯ÖеÄËùÓÐÕÊ»§¡£¡£¡£¡£¡£¡£×îÖÕ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½Ó¼ûÄú×éÖ¯µÄTeamsÕÊ»§ÖеÄËùº±¼û¾Ý£¬£¬£¬£¬£¬ÍøÂç»úÃÜÐÅÏ¢¡¢»áÒéºÍÈÕÀúÐÅÏ¢¡¢¾ºÕùÐÔÊý¾Ý¡¢ÃÜÂë¡¢¸öÈËÐÅÏ¢¡¢Ã³Ò×´òËãµÈ¡£¡£¡£¡£¡£¡£Õâ¸öÎÊÌâºÜ¹Ø¼ü£¬£¬£¬£¬£¬ÓÉÓÚMicrosoft TeamsºÍZoomµÈÊÓÆµ»áÒé½â¾ö¹æ»®ÊÇÔÚCOVID-19Ê¢ÐÐÆÚ¼ä£¬£¬£¬£¬£¬ÆóÒµ¡¢Ñ§ÌÃÉõÖÁµ±¾Ö×é֯ѡÔñµÄÖØÒªÍ¨Ñ¶Çþ·£¬£¬£¬£¬£¬ÕâЩÀûÓ÷¨Ê½ÖеÄÊý¾ÝÁ¿¾Þ´ó£¬£¬£¬£¬£¬²¢ÇÒͨ³£Ô̺¬Óû§Ãû¡¢ÃÜÂëºÍ»úÃÜÒµÎñÐÅÏ¢£¬£¬£¬£¬£¬ÕâʹËüÃdzÉΪ¹¥»÷ÕßµÄÖØÒªÖ¸±ê¡£¡£¡£¡£¡£¡£Î¢ÈíÓÚ3ÔÂ20ÈÕɾ³ýÁËÁ½¸ö×ÓÓòµÄÃýÎóÅäÖõÄDNS¼Í¼£¬£¬£¬£¬£¬²¢ÔÚ4ÔÂ20ºÅ°ä²¼Á˲¹¶¡¸üУ¬£¬£¬£¬£¬»º½â½«À´ÀàËÆµÄ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£
0x04 ²Î¿¼Á´½Ó
https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/
https://securityaffairs.co/wordpress/102344/hacking/hacking-microsoft-teams-accounts.html


¾©¹«Íø°²±¸11010802024551ºÅ