rpc universal offset exploit. go to shields up security (search for it on google) and make sure port 135 is not steathled, mainly for remote testing.
^RB^
Dec 2 2003, 02:53 PM
hmm dunno what it is, but I'll give it a try... Finding shields up website now...
btw this can be run on a local network too, right?
^RB^
edit: just to answer my own question... yes it can be run on a local network... Stupid question anywayz... Now for another thing... This doesn't work for me... for rpc3scan I get "program too big to fit in memory" rpc3 just crashes...
here is the link to shields up. do a common port scan, and make sure port 135 is open (only do this if you are testing from a remote computer, on the remote computer, it will ALWAYS work locally) even then, it is a good local rights elevation exploit, since code can still be executed, and the service is running as system. The DoS will always work, but it is made so the exploit itself won't. You don't need bshell, this is a little bit different. . . . . Code is in the exploit, makes it all go smoother. I would like some feedback please, tell me how it worked, or if it didn't, or anything that happened. By the way, you need cygwin and rpc3 in the same directory to use the program. That's why you might have gotten the "program will not fit in memory" problem.
^RB^
Dec 4 2003, 08:25 PM
QUOTE (what @ Dec 4 2003, 02:29 PM)
By the way, you need cygwin and rpc3 in the same directory to use the program. That's why you might have gotten the "program will not fit in memory" problem.
hmm they are in the same dir... But still no go... I'll just try out another version of cygwin1.dll, maybe that'll work better...
Thanks for the reply m8!!!!
edit: that's strange... I tried with 2 diff versions of cygwin1.dll (701KB and 949KB), but either one of them works... Maybe you could also upload your cygwin1.dll???
what
Dec 9 2003, 01:23 PM
I'd like to know the results of attempted exploiting. Try it and see, then post the results here. Here is cygwin1.dll, see if it helps a little bit better.
mumiak
Dec 9 2003, 01:52 PM
I've downloaded your cygwin1.dll and still does not work for me
DJVASTVASTY2K
Dec 9 2003, 01:58 PM
Thanks For This
It's Been Here A While And I Never Noticed Hmm... Thats Funny Hehe
As For The Site You Are Reffering To I Think It Is A Site Called GRC
A Site Designed By The Security Expert "Steve Gibson"
The Link Is www.GRC.Com
Thanks "What"
Many Thanks
Best Regards
Adam
Vast Gsm
what
Dec 13 2003, 08:15 PM
ok, I am an IDIOT. Flame me later. I created bshell2 a long time ago, and, um, forgot about it. I am really sorry. Put bshell2 and rpc3 in the %systemroot% folder, open a command prompt, and fire it off. Should work like a charm.
vnet576
Dec 13 2003, 08:21 PM
Thats not a valid shellcode...the exploit just calls whatever is in that bshell2 file. Its up to you to find put a valid shell into bshell2.
Freaky
Dec 13 2003, 08:48 PM
Well, First I want to thank u for the compiled exploit .
Second, I've got a question:
I found a ( erm I think I found don't really know ) unpatched server. I tried it and what I got was that:
xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx - send exploit to Win2K 2703
It started with 1 and I aborted the operation at 2703 . Erm well.. Call me dumbass but did the exploit work or not ?
Thanks
vnet576
Dec 13 2003, 09:01 PM
QUOTE (Freaky @ Dec 13 2003, 03:48 PM)
Well, First I want to thank u for the compiled exploit .
Second, I've got a question:
I found a ( erm I think I found don't really know ) unpatched server. I tried it and what I got was that:
xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx - send exploit to Win2K 2703
It started with 1 and I aborted the operation at 2703 . Erm well.. Call me dumbass but did the exploit work or not ?
Thanks
Did you bother to read my post before asking that question. You can't get root without a valid shellcode..you will never be able to get root without a valid shellcode. The exploit may have worked but u're not getting a shell.
boshcash
Dec 13 2003, 09:49 PM
ok where could we get a valid shellcode , do u have a valid shellcode ??
what
Dec 13 2003, 10:05 PM
search for it on google, this is just a DoS POC. There are a lot out there, pick one you like. I don't want to give everyone the key into someones system to just do as they like. If you want it, you will need to work for it a little.
vnet576
Dec 13 2003, 10:21 PM
QUOTE (boshcash @ Dec 13 2003, 04:49 PM)
ok where could we get a valid shellcode , do u have a valid shellcode ??
No, I don't have one..but then I didn't really try looking for one.
boshcash
Dec 13 2003, 10:22 PM
ok ok , i found a bshell2 but its 417 bytes from securitylab.ru , i tried this and i think it creates a user 'a' with password 'a' .. , any one has the compiled bindshell bshell2 file ? a cmd shell is alot better than adding a user 'a' with pass 'a'
so i compile the exe and rename it as bshell ?? i tried that didnt work , anyopne has bshell2 compiled file
boshcash
Dec 13 2003, 10:40 PM
i know metasploit.com has a cmdshell , adduser and reversecmdshell i tried them all and worked , best is bindshell not adduser
what
Dec 14 2003, 05:00 PM
Most of the time, this exploit will now be used as privelege escalation. With some more modifying, it can once again bypass most firewall due to high level ports that the RPC services run on (135, 445, etc, etc) including UDP. I'm just doing what is conventional at the time. The best shellcode is the shellcode that you make yourself.
boshcash
Dec 14 2003, 11:15 PM
plz anyone assemble the bindshellcode from the metasploit site and plz post it , and did anyone get a succesful cmshell with that exploit ??
DJVASTVASTY2K
Dec 15 2003, 04:11 PM
anyone here find a Valid Shell Code That Work Yet ??
Would Be Nice To Share And See What We Can Do So We Can Undertstand how to secure our box a little better.
Best Regards
Adam
Vast Gsm
boshcash
Dec 15 2003, 04:19 PM
there is a valid shellcode at k-otik in assembly, so if anyone can assemble that source code , plz post it here , btw i tried the bshell2 by securitylab.ru and it failed to create user
boshcash
Dec 15 2003, 06:00 PM
this is an assembled file from metasploit.com it should bind shell to port 8721 , any one can get it to any use ? i cant make it run , i replaced it with bshell2 file , a question to exploit this vulnerability should i add characters before the exploit or what should i exactly do because i tried that and didnt work but im sure the assembled shellcode i assembled should work thnx
Kakarott
Dec 27 2003, 03:18 AM
thx 4 sharing dude
ill try it out
greetz to @ll
boshcash
Jan 26 2004, 06:20 PM
btw i asked a good exploit coder , we must compile that asm file at k-otik guys and to "what": there is not that many shellcodes , this is a heap overflow not a buffer overflow , so the shellcode differs , and currently i dont think there is any working shellcode ..
X-FloppY
Jan 26 2004, 09:01 PM
CODE
C:\WINDOWS>rpc3 RPC universal exploit. Exploit MS09-039 vulnerability unpatched host - to codee xecution patched host - to DoS based on original XFocus RPCDCOM2 exploit modification and shellcode (c) by karlss0n published by www.security.nnov.ru
usage: rpc3 <target_ip>
C:\WINDOWS>rpc3 157.158.29.12 157.158.29.12 157.158.29.12 - send exploit to Win2K 711
it counts and keep counting ? wtf is that? can someone explain please? Thank's
X-Floppy
hifil0wlife
Feb 7 2004, 06:35 PM
yes, Im wondering the same thing myself. I heard from someone that this was a d.o.s. "proof of concept" and not a real remote exploit. I've tested this exploit with the assembled shellcodes at metaspolit on targets confirmed by scanners to be vulnerable and nothing, the damn thing just keeps on counting untill I get "send error". this was released sometime in september and still not many knows what to do with it. thats a shame. someone please shed some light on this. I would even agree to pay $$$ for a working exploit for ms03039.
boshcash
Feb 8 2004, 10:54 PM
me 2 , i think l33t ppl and coders can work it out , i can pay $ for working that ... i dunno why ppl still cant make it work
icedealer
Feb 10 2004, 10:23 PM
hey can anyone publish working source?
would be great
thanks guys
boshcash
Feb 12 2004, 08:26 PM
if anyone has source code or have the files needed to make this work to get cmdshell won't share with us , because he is a l33t one , and we r n00bz we shouldnt know right , i think one or more ppl said they know how it works but the wont upload anything , i think so
xoro
Feb 13 2004, 10:27 AM
hmm, i have only that... if that can help you..
boshcash
Feb 14 2004, 05:00 AM
guys we already have the exploit we need a working bshell2 to bind a cmd shell . or any other bshell2 working , but plz not a DoS bshell2 that contains "ax400"
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.