hm the RET's don't work , i've tried it on 3 pcs @ my network ... no way on the highway
axl
Sep 14 2003, 11:03 AM
can u helop me get the exploit ?
sattete
Sep 14 2003, 12:08 PM
seems not work with those Ret , anyone confirm?
KoNh
Sep 14 2003, 12:42 PM
QUOTE (sattete @ Sep 14 2003, 12:08 PM)
seems not work with those Ret , anyone confirm?
doesn't work neither =( maybe is another to call the service
temp
Sep 14 2003, 01:27 PM
u need more than just new offsets...
and by the way the "secret" RET's are pulibc since weeks.. (from dcom1 exploit).
goldsun
Sep 14 2003, 03:09 PM
I use my correct RET Address(for sure),It DOESN'T WORK.
QUOTE
Checking.... Done Connecting... Connection Error / No Shell
Can You Check The Exploit Code?
Thx A lot!
TekKracker
Sep 14 2003, 03:38 PM
All ret's listed above are either from old dcom 1 code or they are not working. I tried on my network @ home and no go.
and axl dont you think if we had the xploit we wouldnt be here still compiling? Go back to hacking webdav or something......
eus
Sep 14 2003, 03:43 PM
Same problem with me... I've tried on stock xp and stock 2k, no luck. In fact, the daemon haven't crashed too... Even if we don't have the good RET, it should have crashed the daemon since it wouldn't exit via the Exit cmd?
goldsun
Sep 14 2003, 04:22 PM
The Key Problem is RET ADDRESS,I use my Correct Address To Attack,then In Ollydebug It resaise exception[System: Win2k sp4+RPC1Patch]:
Continue going...
Lemongreen
Sep 14 2003, 05:30 PM
The RET address are 100% working, the problem in my proof of concept , it that the overflows codes dont overwrites the informations located in 0x761BC258 (rpcss.dll).
Which means my overflows only target ".data" 0x761BC258 without overwitring it.
Why? Well i dont have the knocklegde to overwrite that offser with my own EIP...
stop to say it not work,,, bad ossfet crash deamon
arhamz
Sep 14 2003, 07:33 PM
no wonder i tried everything but didnt work.... lol....
gogu258
Sep 14 2003, 10:09 PM
How EEye scanner handle this hole?!Just an ideea, if scanner can find exploit then I think we can find how that's done....sorry for my poor english....
Rampage
Sep 15 2003, 01:08 PM
QUOTE (31337powa @ Sep 14 2003, 07:24 PM)
stop to say it not work,,, bad ossfet crash deamon
u were able to crash the daemon with the ret addresses posted above? can u explainhow?? i tested a bit of them but there was no way to crash the daemon... else the nice countdown of 60 secs would have appeared
sorry for my bad english
Imps2
Sep 16 2003, 09:58 AM
Maybe this will help u to find the return adres
1/ How do I find the right return address for my system ?
- Get the right KERNEL32.DLL file (you can find it directly in the SP file). - Open it in your favorite disassembler (IDA, WDASM, ...). - Look for the following byte sequence : "FF D3" (call ebx). - Note the corresponding address (should look like 0x7???????, otherwise your disassembler is not smart enough to add the section base address to relative addresses).
Greetz Imps2
Rampage
Sep 16 2003, 10:29 AM
thnx Imps2... gonna try as soon as possible
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.