module

VMware vCenter Forge SAML Authentication Credentials

Disclosed
Apr 20, 2022
Created
May 13, 2022

Description

This module forges valid SAML credentials for vCenter server
using the vCenter SSO IdP certificate, IdP private key, and
VMCA certificates as input objects; you must also provide
the vCenter SSO domain name and vCenter FQDN. The module will
return a session cookie for the /ui path that grants access to
the SSO domain as a vSphere administrator. The IdP trusted
certificate chain can be retrieved using Metasploit post
exploitation modules or extracted manually from
/storage/db/vmware-vmdir/data.mdb using binwalk.

Author

npm npm@cesium137.io

Platform

Linux

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/admin/vmware/vcenter_forge_saml_token
msf auxiliary(vcenter_forge_saml_token) > show actions
...actions...
msf auxiliary(vcenter_forge_saml_token) > set ACTION < action-name >
msf auxiliary(vcenter_forge_saml_token) > show options
...show and set options...
msf auxiliary(vcenter_forge_saml_token) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.