¶ñÒâGIFʹÓÃMicrosoft TeamsÎó²îÐ®ÖÆÕÊ»§
Ðû²¼Ê±¼ä 2020-04-290x00 ÊÂÎñÅä¾°
CyberArkµÄÑо¿Ö°Ô±·¢Ã÷Microsoft TeamsÖб£´æ×ÓÓòÃû½ÓÊÜÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹ¹¥»÷ÕßÏòÓû§·¢ËͶñÒâGIFͼÏñµÖ´ïÇÔÈ¡Óû§Êý¾Ý²¢Ð®ÖÆTeamsÕË»§µÄÄ¿µÄ¡£¡£¡£¡£¡£
Microsoft Teams ÊÇÒ»¿î»ùÓÚ̸ÌìµÄÖÇÄÜÍŶÓÐ×÷¹¤¾ß£¬£¬£¬£¬£¬£¬¿ÉÒÔͬ²½¾ÙÐÐÎĵµ¹²Ïí£¬£¬£¬£¬£¬£¬²¢Îª³ÉÔ±Ìṩ°üÀ¨ÓïÒô¡¢ÊÓÆµ¾Û»áÔÚÄڵļ´Ê±Í¨Ñ¶¹¤¾ß¡£¡£¡£¡£¡£
ÓÉÓÚÓû§²»±Ø¹²ÏíGIF£¬£¬£¬£¬£¬£¬Ö»ÊÇ¿´µ½Ëü¾ÍÄÜÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²î¿ÉÒÔ×Ô¶¯Èö²¥£¬£¬£¬£¬£¬£¬²¢Ó°ÏìʹÓÃTeams×ÀÃæ»òWebä¯ÀÀÆ÷°æ±¾µÄÿ¸öÓû§¡£¡£¡£¡£¡£
0x01 Îó²îÆÊÎö
¸ÃȱÏÝÓëMicrosoft Teams´¦Öóͷ£Í¼Ïñ×ÊÔ´Éí·ÝÑéÖ¤µÄ·½·¨Óйء£¡£¡£¡£¡£Ã¿´Î·¿ªTeams¿Í»§¶Ëʱ»á½¨ÉèÒ»¸öÔÝʱµÄtoken»òaccess token¡£¡£¡£¡£¡£´ËÁîÅÆÒÔJWTµÄÐÎʽÓÉMicrosoftÊÚȨºÍÉí·ÝÑé֤ЧÀÍÆ÷¡°login.microsoftonline.com¡±½¨É裬£¬£¬£¬£¬£¬ÔÊÐíÓû§Éó²éСÎÒ˽¼Ò»ò»á»°ÖзÖÏíµÄͼÏñ¡£¡£¡£¡£¡£
¸ÃÓ¦ÓóÌÐòʹÓÃÁ½¸öÁîÅÆ¾ÙÐÐÉí·ÝÑéÖ¤£ºauthtokenºÍskypetoken¡£¡£¡£¡£¡£ÎªÁËÑо¿Á½¸öÁîÅÆµÄ¹ØÏµ£¬£¬£¬£¬£¬£¬ÎÒÃÇÌáÈ¡ÁËTeams¿Í»§¶ËµÄÁ÷Á¿£¬£¬£¬£¬£¬£¬ÆäÖлñÈ¡ÐÂÎÅÇëÇóÈçÏ£º
GET https://amer.ng.msg.teams.microsoft.com/v1/users/ME/conversations/19%3A...%40unq.gbl.spaces/messages?view=msnp24Equivalent|supportsMessageProperties&pageSize=200&startTime=1 HTTP/1.1
Host: amer.ng.msg.teams.microsoft.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
x-ms-session-id: 00000000000-0000-0000-0000-00000000000
BehaviorOverride: redirectAs404
x-ms-scenario-id: 00
x-ms-client-cpm: ApplicationLaunch
x-ms-client-env:
x-ms-client-type:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36
ClientInfo:
Accept: json
Sec-Fetch-Dest: empty
x-ms-client-version:
x-ms-user-type: user
Authentication: skypetoken=eyJhbGciOiJSUzI1NiIsImtpZCI6IkVhc3RlckVnZyA6KSIsInR5cCI6IkpXVCJ9.eyJ...
Origin: https://teams.microsoft.com
Sec-Fetch-Site: same-site
Sec-Fetch-Mode: cors
Referer: https://teams.microsoft.com/_
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
´Ó±¨ÎÄÖп´³ö£¬£¬£¬£¬£¬£¬¿Í»§¶Ë½ö·¢ËÍÁËÒ»¸öÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬£¬£¬¸ÃÁîÅÆ¿ÉÒÔÔÚ¡°Authentication¡±×Ö¶ÎÖÐÕÒµ½£¬£¬£¬£¬£¬£¬Ãû³ÆÎª¡°skypetoken¡±¡£¡£¡£¡£¡£ÏÔȻҪÏë·¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬£¬ÎÒÃÇÐèÒª»ñµÃÒ»¸öSkypeÁîÅÆ¡£¡£¡£¡£¡£SkypeÁîÅÆ´ÓºÎ¶øÀ´ÄØ£¿£¿£¿£¿£¿ÎÒÃǽøÒ»²½Ñо¿ÁËÁ÷Á¿£¬£¬£¬£¬£¬£¬ÕÒµ½ÁËTeams¿Í»§½¨ÉèskypetokenÇëÇóµÄ»á»°£º
POST /api/authsvc/v1.0/authz HTTP/1.1
Host: teams.microsoft.com
Connection: close
Content-Length: 0
Pragma: no-cache
Cache-Control: no-cache
x-ms-session-id: 00000000000-0000-0000-0000-00000000000
x-ms-scenario-id: 00
x-ms-user-type: user
x-ms-client-env:
x-ms-client-type:
Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6IktleXMiLCJraWQiOiJLZXlzRXZlcnlXaGVyZSJ9.eyJ...
Accept: application/json, text/plain, */*
X-Client-UI-Language: en-us
Sec-Fetch-Dest: empty
ms-teams-authz-type: TokenRefresh
x-ms-client-version:
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36
Origin: https://teams.microsoft.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Referer: https://teams.microsoft.com/_
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: {redacted}
´Ó±¨ÎÄ¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬authtokenÌìÉúÁËskype token¡£¡£¡£¡£¡£ÓÐÁËÕâÁ½¸öÁîÅÆ£¬£¬£¬£¬£¬£¬ÎÒÃǾͿÉÒÔͨ¹ýŲÓÃTeams API½Ó¿Ú£¬£¬£¬£¬£¬£¬ÊµÏÖ·¢ËÍÐÂÎÅ¡¢ÔĶÁÐÂÎÅ¡¢½¨Éè×é¡¢Ìí¼ÓÐÂÓû§»ò´ÓÖÐɾ³ýÓû§×é¡¢¸ü¸Ä×éµÄȨÏ޵ȹ¦Ð§¡£¡£¡£¡£¡£
authtoken cookieÉèÖÃÊÇ·¢Ë͸øteams.microsoft.team»òÆäËû×ÓÓòÃû£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÁ½¸ö±£´æÐ®Öƹ¥»÷Îó²îµÄ×ÓÓòÃû£º
1. aadsync-test.teams.microsoft.com
2. data-dev.teams.microsoft.com
ÈôÊǹ¥»÷Õß¿ÉÒÔÈÃÓû§»á¼ûÐ®ÖÆµÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬ÔòÊܺ¦ÕßµÄä¯ÀÀÆ÷»á½«cookie·¢Ë͵½¹¥»÷ÕßµÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÔÚÊÕµ½authtokenÖ®ºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½¨ÉèÒ»¸öskype token£¬£¬£¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕßµÄTeamsÕÊ»§Êý¾Ý¡£¡£¡£¡£¡£
ÓÐÁËÉÏÊö±»ºÚµÄ×ÓÓòÃûºó£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔͨ¹ýÏòÊܺ¦Õß»òȺÁĵÄËùÓгÉÔ±·¢ËͶñÒâÁ´½Ó£¨¼´GIFͼÏñ£©À´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£½«Í¼ÏñµÄ¡°src¡±ÊôÐÔÉèÖÃΪ±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬²¢·¢Ë͸øÊܺ¦Õß¡£¡£¡£¡£¡£µ±ÎüÊÕÕß·¿ªÐÂÎź󣬣¬£¬£¬£¬£¬ä¯ÀÀÆ÷¾Í»á·¢ËÍauthtoken cookiesµ½±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬£¬È»ºóʵÑé¼ÓÔØ¸ÃͼÏñ¡£¡£¡£¡£¡£Ö®ºó¹¥»÷ÕßʹÓÃauthtoken cookies½¨ÉèÒ»¸öskype token£¬£¬£¬£¬£¬£¬²¢×îÖÕ»ñÈ¡Êܺ¦ÕßµÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£
0x02 Îó²îÑéÖ¤
1. Ñо¿Ö°Ô±»¹×öÁËÒ»¸öÎó²îʹÓõÄPoCÊÓÆµ£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º
https://fast.wistia.com/embed/medias/f4b25lcyzm
2. ±ðµÄ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹±àдÁËÒ»¸ö¾ç±¾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾¿ÉץȡÊܺ¦ÕߵĶԻ°²¢¾ÙÐÐÏ̴߳¦Öóͷ££¬£¬£¬£¬£¬£¬²¢½«ÆäÉúÑĵ½ÍâµØÎļþÖУ¬£¬£¬£¬£¬£¬ÈçͼËùʾ£º
0x03 ½áÂÛ
ÓÉÓÚ¸ÃÎó²î¿ÉÒÔ×Ô¶¯Èö²¥£¬£¬£¬£¬£¬£¬ÀàËÆÓÚÈ䳿²¡¶¾£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆÆËðÄ¿µÄ×éÖ¯ÖеÄËùÓÐÕÊ»§¡£¡£¡£¡£¡£×îÖÕ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»á¼ûÄú×éÖ¯µÄTeamsÕÊ»§ÖеÄËùÓÐÊý¾Ý£¬£¬£¬£¬£¬£¬ÍøÂçÉñÃØÐÅÏ¢¡¢¾Û»áºÍÈÕÀúÐÅÏ¢¡¢¾ºÕùÐÔÊý¾Ý¡¢ÃÜÂ롢˽ÈËÐÅÏ¢¡¢ÉÌÒµÍýÏëµÈ¡£¡£¡£¡£¡£Õâ¸öÎÊÌâºÜÒªº¦£¬£¬£¬£¬£¬£¬ÓÉÓÚMicrosoft TeamsºÍZoomµÈÊÓÆµ¾Û»á½â¾ö¼Æ»®ÊÇÔÚCOVID-19Ê¢ÐÐʱ´ú£¬£¬£¬£¬£¬£¬ÆóÒµ¡¢Ñ§Ð£ÉõÖÁÕþ¸®×é֯ѡÔñµÄÖ÷ҪͨѶÇþµÀ£¬£¬£¬£¬£¬£¬ÕâЩӦÓóÌÐòÖеÄÊý¾ÝÁ¿Öش󣬣¬£¬£¬£¬£¬²¢ÇÒͨ³£°üÀ¨Óû§Ãû¡¢ÃÜÂëºÍÉñÃØÓªÒµÐÅÏ¢£¬£¬£¬£¬£¬£¬ÕâʹËüÃdzÉΪ¹¥»÷ÕßµÄÖ÷ҪĿµÄ¡£¡£¡£¡£¡£Î¢ÈíÓÚ3ÔÂ20ÈÕɾ³ýÁËÁ½¸ö×ÓÓòµÄ¹ýʧÉèÖõÄDNS¼Í¼£¬£¬£¬£¬£¬£¬²¢ÔÚ4ÔÂ20ºÅÐû²¼Á˲¹¶¡¸üУ¬£¬£¬£¬£¬£¬»º½âδÀ´ÀàËÆµÄÇ徲Σº¦¡£¡£¡£¡£¡£
0x04 ²Î¿¼Á´½Ó
https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/
https://securityaffairs.co/wordpress/102344/hacking/hacking-microsoft-teams-accounts.html