hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

rayden5_
hi there,

just wonder if anyone else has problems with it ? I got the compiled exe with 48 offsets. My Testsystem is a Laptop with W2k German running, on which I applied the SP3.

When running DCOM48 i see there are two possible targets:

#20 W2k German +SP3
#37 W2K German SP3

..well i think i need the first one (+sp3 ) since i installed the ServicePack seperately. But unfortunately i always get a Exception Fault on my targets system instead of a root shell on my netcat listener sad.gif

I tried both targets and iam 100% sure its SP3 wink.gif . Anyone else having problems using these offsets even u are 100% sure its the correct one ? Ok i could try the left 46 targets but i dot think they will work either.


I always heard from "universal Offset exploit" but was not able to find it, so if anyone could point my in the right direction please.

As usual excuse me English, but aim from Germany wink.gif

TiA
Ray
OneNight
Sorry, cant help you there.

BUt indeed, a "universal Offset exploit" would be very cool. If it exists...
rayden5_
Hi,

well i heard much about it and a friend claims to use it instead of individuell offsets. I got some offsets but iam not sure if these are to correct ones:

Windows 2000 (english) 0x010016C6
Windows XP (english) 0x0100139d

..well i cant compile C code here, also my target is German OS so the above offsets are useless for me, but if you want to try and recompile it let me know if u succeded smile.gif

Ray
GSecur
QUOTE
tried both targets and iam 100% sure its SP3  . Anyone else having problems using these offsets even u are 100% sure its the correct one ? Ok i could try the left 46 targets but i dot think they will work either.


The dcom exploit is not a 100% sure thing. So even if it seems that the machine perfectly matches ala SP and windows language it still might not work. But it does seem like it DoS's every time.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.