hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Ms03-049
tibbar
After receiving many PM's to supply source code etc, I've decided to post the code with a batch file to feed off scan500.exe.

usage is simple.

first run scan500.exe to generate a list of ip with open port 139 - i.e.:

scan500 -p 139 startip endip

this will generate scan.txt for you.

edit scan txt to remove 1st line - i.e. you only want ips in this file, no text.


Now simply run scanlist.bat to automatically test each ip in scan.txt.

Enjoy ;-)

(for educational purposes only).
ST.
QUOTE (tibbar @ Mar 2 2004, 11:48 PM)
(for educational purposes only)

okey, i'll use it for all *.edu in my area smile.gif

thanks!
tibbar
heh it's best for .edu...use it remotely to bypass the blocked 139...
nowhere
thx for sharing i will ve a look
lv4
great...might become handy...

THX for sharing!!
tibbar
i am going to recode this as a single .c prog, as it runs a lot slower like this through batch file.

i will post it here in a few days...
stonebreaker
i think there are too many virus for this hole
and now many machines install a firewall
further more the isp has block the port 139 445
tibbar
very true stonebreaker, but that is not it's only use.

Suppose you have remote access to a box on a lan or wan. Behind the corporate firewall, all the netbios ports are open...and this exploit will work perfectly on the pre-Nov '03 patched.
x1`
is this a auto hacker then it goes through scans and then checks for shell?
or just a checker to find vun servers , if so does it make a output file saying what vunrable etc?
tibbar
by typing scan500 -p 139 ipstart ipend it will generate a ip list of possible targets (i.e. ones with one port 139).

you then type scanlist.bat to run this list through the exploit prog.
pdf
and it's undetectable by antivirus biggrin.gif tnx smile.gif
limbox
thanks a lot, do you have the source code of the exploit as well ?
Paul
Ill try it @ my school, when im on some pc.
Going to be fun i hope, thnx smile.gif
Bombers
thanx for your work
but i try 60000 computers on a lan network
it's sends the exoplit but it's allways says
connect() to the bindshell failed

hmm maybe i need to list NC on port 4445 ??
or its auto ?
THoRaX
QUOTE (Bombers @ Mar 3 2004, 08:26 PM)
thanx for your work
but i try 60000 computers on a lan network
it's sends the exoplit but it's allways says
connect() to the bindshell failed

hmm maybe i need to list NC on port 4445 ??
or its auto ?

Same error here. Just before it sais that an error comes, but it is away within a second. maybe a little bug?
boshcash
QUOTE (ST. @ Mar 2 2004, 11:53 PM)
QUOTE (tibbar @ Mar 2 2004, 11:48 PM)
(for educational purposes only)

okey, i'll use it for all *.edu in my area smile.gif

thanks!

lool nice one man laugh.gif
clubfed
not that it matters, but FYI the scan500.exe is detected by Kaspersky as 'Exploit.Win32.WebDav.n" .. to the person who said it was undetected.
tibbar
KAV detects most things. this is undetected by the mainsteam AV's...no one except hackers use KAV anyway biggrin.gif
technoboy
CODE
[+] 172.16.1.13: Assuming alive, checking 139.
[+] 172.16.1.13: 139 open, creating exploit thread.
[+] 172.16.1.13: Waiting.
[+] 172.16.1.13: Attacking, attempting a null session.
[+] 172.16.1.13: Success.
[+] 172.16.1.13: GetProcAddr: 71c7c8f8.
[+] 172.16.1.13: Sending exploit.
[+] 172.16.1.13: Connecting to port 4445.
[x] 172.16.1.13: connect() to bindshell failed.


172.16.1.13 = vmware win2k vanilla

i also receive an error, see attached file.

anyone have a full working sploit handy for this, i want to update my attack tree and dont feel like browsing tons of crap and half working sploit.
liquidSilver
I get the same error, on each boxes I try!

Must be a bug, or everyone of them are patched! tongue.gif
bl00dyviper
yes i get this error too and every time connect to bindshell failed anything wrong ?
tibbar
if you get the error:

[+] 172.16.1.13: Assuming alive, checking 139.
[+] 172.16.1.13: 139 open, creating exploit thread.
[+] 172.16.1.13: Waiting.
[+] 172.16.1.13: Attacking, attempting a null session.
[+] 172.16.1.13: Success.
[+] 172.16.1.13: GetProcAddr: 71c7c8f8.
[+] 172.16.1.13: Sending exploit.
[+] 172.16.1.13: Connecting to port 4445.
[x] 172.16.1.13: connect() to bindshell failed.


that means the box is patched. N.B. you dont need to run netcat, the exploit does it for you.

I have only had success running this on a LAN / WAN...i generally find about 1 in 10 boxes are unpatched.

However, if you try this on a commerical LAN, you should not be surprised if 99% of boxes are patched. Most firms apply updates weekly.

I have never seen the error window pop up that technoboy got, and I cant think of why it happened, maybe his AV didnt like it?

For those asking for working exploit, this is it. I have heard it enjoys great success on .edus...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.