What problem does it solve?
On-prem Microsoft SharePoint Server deployments are high-value enterprise attack surfaces, but they often run end-of-life versions with unpatched CVEs, legacy protocol weaknesses, and misconfigured anonymous endpoints that are trivial to exploit if left unassessed. This Skill eliminates the guesswork of identifying these critical weaknesses by providing a field-validated, step-by-step hunting methodology tailored specifically to SharePoint's unique attack surface.
Core Features & Use Cases
- Version Fingerprinting & CVE Mapping: Automatically map leaked SharePoint build numbers to their corresponding unpatched CVEs, with special focus on EoL 2013/2016/2019 farms where post-EoL CVEs are permanently unpatched.
- Anonymous Endpoint Enumeration: Probe a curated list of anonymous-accessible SharePoint endpoints to discover attack vectors including legacy SOAP login bypass, ToolShell CVE-2025-53770 preconditions, NTLM AD topology disclosure, and SafeControl reflection enumeration.
- Defense Bypass & Validation: Includes proven bypass techniques for common controls like branded login pages, WAFs, AWS ELB request smuggling, and ViewState encryption, plus a Gate 0 validation framework to ensure findings are reproducible and impactful.
- Use Case: A red teamer targeting an enterprise dealer portal built on SharePoint 2013 can use this Skill to quickly confirm the farm is EoL, identify the anonymous Authentication.asmx login endpoint, validate the ToolShell precondition chain, and package all findings into a critical-severity bug bounty report in under 30 minutes.
Quick Start
Use the hunt-sharepoint skill to assess a target SharePoint Server URL for exposed anonymous endpoints, version-specific unpatched CVEs, and critical attack chains including legacy SOAP login bypass and ToolShell preconditions.