¶ñÒâGIFʹÓÃMicrosoft TeamsÎó²îÐ®ÖÆÕÊ»§

Ðû²¼Ê±¼ä 2020-04-29

0x00 ÊÂÎñÅä¾°


CyberArkµÄÑо¿Ö°Ô±·¢Ã÷Microsoft TeamsÖб£´æ×ÓÓòÃû½ÓÊÜÎó²î£¬£¬£¬£¬£¬ £¬¸ÃÎó²îʹ¹¥»÷ÕßÏòÓû§·¢ËͶñÒâGIFͼÏñµÖ´ïÇÔÈ¡Óû§Êý¾Ý²¢Ð®ÖÆTeamsÕË»§µÄÄ¿µÄ¡£¡£¡£¡£ ¡£

Microsoft Teams ÊÇÒ»¿î»ùÓÚ̸ÌìµÄÖÇÄÜÍŶÓЭ×÷¹¤¾ß£¬£¬£¬£¬£¬ £¬¿ÉÒÔͬ²½¾ÙÐÐÎĵµ¹²Ïí£¬£¬£¬£¬£¬ £¬²¢Îª³ÉÔ±Ìṩ°üÀ¨ÓïÒô¡¢ÊÓÆµ¾Û»áÔÚÄڵļ´Ê±Í¨Ñ¶¹¤¾ß¡£¡£¡£¡£ ¡£

ÓÉÓÚÓû§²»±Ø¹²ÏíGIF£¬£¬£¬£¬£¬ £¬Ö»ÊÇ¿´µ½Ëü¾ÍÄÜÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬Òò´Ë¸ÃÎó²î¿ÉÒÔ×Ô¶¯Èö²¥£¬£¬£¬£¬£¬ £¬²¢Ó°ÏìʹÓÃTeams×ÀÃæ»òWebä¯ÀÀÆ÷°æ±¾µÄÿ¸öÓû§¡£¡£¡£¡£ ¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x01 Îó²îÆÊÎö


¸ÃȱÏÝÓëMicrosoft Teams´¦Öóͷ£Í¼Ïñ×ÊÔ´Éí·ÝÑéÖ¤µÄ·½·¨ÓйØ¡£¡£¡£¡£ ¡£Ã¿´Î·­¿ªTeams¿Í»§¶Ëʱ»á½¨ÉèÒ»¸öÔÝʱµÄtoken»òaccess token¡£¡£¡£¡£ ¡£´ËÁîÅÆÒÔJWTµÄÐÎʽÓÉMicrosoftÊÚȨºÍÉí·ÝÑé֤ЧÀÍÆ÷¡°login.microsoftonline.com¡±½¨É裬£¬£¬£¬£¬ £¬ÔÊÐíÓû§Éó²éСÎÒ˽¼Ò»ò»á»°ÖзÖÏíµÄͼÏñ¡£¡£¡£¡£ ¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¸ÃÓ¦ÓóÌÐòʹÓÃÁ½¸öÁîÅÆ¾ÙÐÐÉí·ÝÑéÖ¤£ºauthtokenºÍskypetoken¡£¡£¡£¡£ ¡£ÎªÁËÑо¿Á½¸öÁîÅÆµÄ¹ØÏµ£¬£¬£¬£¬£¬ £¬ÎÒÃÇÌáÈ¡ÁËTeams¿Í»§¶ËµÄÁ÷Á¿£¬£¬£¬£¬£¬ £¬ÆäÖлñÈ¡ÐÂÎÅÇëÇóÈçÏ£º

GET https://amer.ng.msg.teams.microsoft.com/v1/users/ME/conversations/19%3A...%40unq.gbl.spaces/messages?view=msnp24Equivalent|supportsMessageProperties&pageSize=200&startTime=1 HTTP/1.1

Host: amer.ng.msg.teams.microsoft.com

Connection: keep-alive

Pragma: no-cache

Cache-Control: no-cache

x-ms-session-id: 00000000000-0000-0000-0000-00000000000

BehaviorOverride: redirectAs404

x-ms-scenario-id: 00

x-ms-client-cpm: ApplicationLaunch

x-ms-client-env:

x-ms-client-type:

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36

ClientInfo:

Accept: json

Sec-Fetch-Dest: empty

x-ms-client-version:

x-ms-user-type: user

Authentication: skypetoken=eyJhbGciOiJSUzI1NiIsImtpZCI6IkVhc3RlckVnZyA6KSIsInR5cCI6IkpXVCJ9.eyJ...

Origin: https://teams.microsoft.com

Sec-Fetch-Site: same-site

Sec-Fetch-Mode: cors

Referer: https://teams.microsoft.com/_

Accept-Encoding: gzip, deflate, br

Accept-Language: en-US,en;q=0.9

´Ó±¨ÎÄÖп´³ö£¬£¬£¬£¬£¬ £¬¿Í»§¶Ë½ö·¢ËÍÁËÒ»¸öÉí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬£¬ £¬¸ÃÁîÅÆ¿ÉÒÔÔÚ¡°Authentication¡±×Ö¶ÎÖÐÕÒµ½£¬£¬£¬£¬£¬ £¬Ãû³ÆÎª¡°skypetoken¡±¡£¡£¡£¡£ ¡£ÏÔȻҪÏë·¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬ £¬ÎÒÃÇÐèÒª»ñµÃÒ»¸öSkypeÁîÅÆ¡£¡£¡£¡£ ¡£SkypeÁîÅÆ´ÓºÎ¶øÀ´ÄØ£¿£¿£¿£¿£¿ÎÒÃǽøÒ»²½Ñо¿ÁËÁ÷Á¿£¬£¬£¬£¬£¬ £¬ÕÒµ½ÁËTeams¿Í»§½¨ÉèskypetokenÇëÇóµÄ»á»°£º

POST /api/authsvc/v1.0/authz HTTP/1.1

Host: teams.microsoft.com

Connection: close

Content-Length: 0

Pragma: no-cache

Cache-Control: no-cache

x-ms-session-id: 00000000000-0000-0000-0000-00000000000

x-ms-scenario-id: 00

x-ms-user-type: user

x-ms-client-env:

x-ms-client-type:

Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6IktleXMiLCJraWQiOiJLZXlzRXZlcnlXaGVyZSJ9.eyJ...

Accept: application/json, text/plain, */*

X-Client-UI-Language: en-us

Sec-Fetch-Dest: empty

ms-teams-authz-type: TokenRefresh

x-ms-client-version:

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36

Origin: https://teams.microsoft.com

Sec-Fetch-Site: same-origin

Sec-Fetch-Mode: cors

Referer: https://teams.microsoft.com/_

Accept-Encoding: gzip, deflate

Accept-Language: en-US,en;q=0.9

Cookie: {redacted}

´Ó±¨ÎÄ¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬ £¬authtokenÌìÉúÁËskype token¡£¡£¡£¡£ ¡£ÓÐÁËÕâÁ½¸öÁîÅÆ£¬£¬£¬£¬£¬ £¬ÎÒÃǾͿÉÒÔͨ¹ýŲÓÃTeams API½Ó¿Ú£¬£¬£¬£¬£¬ £¬ÊµÏÖ·¢ËÍÐÂÎÅ¡¢ÔĶÁÐÂÎÅ¡¢½¨Éè×é¡¢Ìí¼ÓÐÂÓû§»ò´ÓÖÐɾ³ýÓû§×é¡¢¸ü¸Ä×éµÄȨÏ޵ȹ¦Ð§¡£¡£¡£¡£ ¡£

authtoken cookieÉèÖÃÊÇ·¢Ë͸øteams.microsoft.team»òÆäËû×ÓÓòÃû£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±·¢Ã÷ÁËÁ½¸ö±£´æÐ®Öƹ¥»÷Îó²îµÄ×ÓÓòÃû£º

1. aadsync-test.teams.microsoft.com

2. data-dev.teams.microsoft.com

ÈôÊǹ¥»÷Õß¿ÉÒÔÈÃÓû§»á¼ûÐ®ÖÆµÄ×ÓÓòÃû£¬£¬£¬£¬£¬ £¬ÔòÊܺ¦ÕßµÄä¯ÀÀÆ÷»á½«cookie·¢Ë͵½¹¥»÷ÕßµÄЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬ÔÚÊÕµ½authtokenÖ®ºó£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔ½¨ÉèÒ»¸öskype token£¬£¬£¬£¬£¬ £¬ÇÔÈ¡Êܺ¦ÕßµÄTeamsÕÊ»§Êý¾Ý¡£¡£¡£¡£ ¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÓÐÁËÉÏÊö±»ºÚµÄ×ÓÓòÃûºó£¬£¬£¬£¬£¬ £¬¹¥»÷Õ߾ͿÉÒÔͨ¹ýÏòÊܺ¦Õß»òȺÁĵÄËùÓгÉÔ±·¢ËͶñÒâÁ´½Ó£¨¼´GIFͼÏñ£©À´Ê¹ÓôËÎó²î¡£¡£¡£¡£ ¡£½«Í¼ÏñµÄ¡°src¡±ÊôÐÔÉèÖÃΪ±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬ £¬²¢·¢Ë͸øÊܺ¦Õß¡£¡£¡£¡£ ¡£µ±ÎüÊÕÕß·­¿ªÐÂÎźó£¬£¬£¬£¬£¬ £¬ä¯ÀÀÆ÷¾Í»á·¢ËÍauthtoken cookiesµ½±»ºÚµÄ×ÓÓòÃû£¬£¬£¬£¬£¬ £¬È»ºóʵÑé¼ÓÔØ¸ÃͼÏñ¡£¡£¡£¡£ ¡£Ö®ºó¹¥»÷ÕßʹÓÃauthtoken cookies½¨ÉèÒ»¸öskype token£¬£¬£¬£¬£¬ £¬²¢×îÖÕ»ñÈ¡Êܺ¦ÕßµÄËùÓÐÊý¾Ý¡£¡£¡£¡£ ¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x02 Îó²îÑéÖ¤


1. Ñо¿Ö°Ô±»¹×öÁËÒ»¸öÎó²îʹÓõÄPoCÊÓÆµ£¬£¬£¬£¬£¬ £¬ÈçÏÂËùʾ£º

https://fast.wistia.com/embed/medias/f4b25lcyzm

2. ±ðµÄ£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±»¹±àдÁËÒ»¸ö¾ç±¾£¬£¬£¬£¬£¬ £¬¸Ã¾ç±¾¿ÉץȡÊܺ¦ÕߵĶԻ°²¢¾ÙÐÐÏ̴߳¦Öóͷ££¬£¬£¬£¬£¬ £¬²¢½«ÆäÉúÑĵ½ÍâµØÎļþÖУ¬£¬£¬£¬£¬ £¬ÈçͼËùʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


0x03 ½áÂÛ


ÓÉÓÚ¸ÃÎó²î¿ÉÒÔ×Ô¶¯Èö²¥£¬£¬£¬£¬£¬ £¬ÀàËÆÓÚÈ䳿²¡¶¾£¬£¬£¬£¬£¬ £¬´Ó¶øµ¼ÖÂÆÆËðÄ¿µÄ×éÖ¯ÖеÄËùÓÐÕÊ»§¡£¡£¡£¡£ ¡£×îÖÕ£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔ»á¼ûÄú×éÖ¯µÄTeamsÕÊ»§ÖеÄËùÓÐÊý¾Ý£¬£¬£¬£¬£¬ £¬ÍøÂçÉñÃØÐÅÏ¢¡¢¾Û»áºÍÈÕÀúÐÅÏ¢¡¢¾ºÕùÐÔÊý¾Ý¡¢ÃÜÂ롢˽ÈËÐÅÏ¢¡¢ÉÌÒµÍýÏëµÈ¡£¡£¡£¡£ ¡£Õâ¸öÎÊÌâºÜÒªº¦£¬£¬£¬£¬£¬ £¬ÓÉÓÚMicrosoft TeamsºÍZoomµÈÊÓÆµ¾Û»á½â¾ö¼Æ»®ÊÇÔÚCOVID-19Ê¢ÐÐʱ´ú£¬£¬£¬£¬£¬ £¬ÆóÒµ¡¢Ñ§Ð£ÉõÖÁÕþ¸®×é֯ѡÔñµÄÖ÷ҪͨѶÇþµÀ£¬£¬£¬£¬£¬ £¬ÕâЩӦÓóÌÐòÖеÄÊý¾ÝÁ¿Öش󣬣¬£¬£¬£¬ £¬²¢ÇÒͨ³£°üÀ¨Óû§Ãû¡¢ÃÜÂëºÍÉñÃØÓªÒµÐÅÏ¢£¬£¬£¬£¬£¬ £¬ÕâʹËüÃdzÉΪ¹¥»÷ÕßµÄÖ÷ҪĿµÄ¡£¡£¡£¡£ ¡£Î¢ÈíÓÚ3ÔÂ20ÈÕɾ³ýÁËÁ½¸ö×ÓÓòµÄ¹ýʧÉèÖõÄDNS¼Í¼£¬£¬£¬£¬£¬ £¬²¢ÔÚ4ÔÂ20ºÅÐû²¼Á˲¹¶¡¸üУ¬£¬£¬£¬£¬ £¬»º½âδÀ´ÀàËÆµÄÇ徲Σº¦¡£¡£¡£¡£ ¡£


0x04 ²Î¿¼Á´½Ó


https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/

https://securityaffairs.co/wordpress/102344/hacking/hacking-microsoft-teams-accounts.html



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨