hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Pages: 1, 2
Gurou
Microsoft IIS 5.0 SSL Remote buffer overflow Exploit (MS04-011)

http://www.k-otik.com/exploits/04212004.THCIISSLame.c.php

biggrin.gif
Khran
Compiled version here:

http://www.thc.org/download.php?t=e&f=THCIISSLame.zip
jead99
Anyone tried it ?
Alien
I try a few IP:
CODE

[*] building buffer
[*] connecting the target
[*] Exploit send successfully ! Sleeping a while ....
[*] Trying to get a shell

can't connect to port 31337;( maybe firewalled ...

MxMx
you should scan 4 pcs which have iis 5.0 installed and are running on SSL
Deltax
QUOTE (jead99 @ Apr 21 2004, 11:57 AM)
Anyone tried it ?

yeah

i've got some shells so it works biggrin.gif
MxMx
you have got a scanner 4 us?
Deltax
QUOTE (MxMx @ Apr 21 2004, 12:31 PM)
you have got a scanner 4 us?

just do a banner scan on port 80 wink.gif
cyrixx
sounds very intresting!
FakoLy
did somone know how to patchthe hole ?
101
QUOTE (FakoLy @ Apr 21 2004, 01:30 PM)
did somone know how to patchthe hole ?


mspatch.exe -q (computer will reboot then)
Nightdemon
should I do a portscan on p443 and than bannerscan the results on p80? huh.gif
cyrixx
works great tongue.gif
Divx_dude
tested @ some pc's no shell @ all smile.gif going further for more mabey i get some tongue.gif

and thx for the Exploit tongue.gif
Nurgle
QUOTE (Deltax @ Apr 21 2004, 12:32 PM)
QUOTE (MxMx @ Apr 21 2004, 12:31 PM)
you have got a scanner 4 us?

just do a banner scan on port 80 wink.gif

Sorry what is a Banner Scan first Scan Port 443 and the resulst then on Port 80.

Please Answer smile.gif
Divx_dude
QUOTE (Nurgle @ Apr 21 2004, 02:56 PM)
QUOTE (Deltax @ Apr 21 2004, 12:32 PM)
QUOTE (MxMx @ Apr 21 2004, 12:31 PM)
you have got a scanner 4 us?

just do a banner scan on port 80 wink.gif

Sorry what is a Banner Scan first Scan Port 443 and the resulst then on Port 80.

Please Answer smile.gif

before u ask search google :-)

try searching for SL.exe

wink.gif
greetz
will_do
Is this what we want?

195.*.*.*
Responds with ICMP unreachable: No
TCP ports: 80


TCP 80:
[HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Content-Location: http://10.41.2.20/Default.htm Date: Wed, 21 Apr 2004 14:47:12 GMT Content-Type: text/html Accept-]
night^man
I build a auto one and steal trying to get a shell / nothing..
x1`
thanks for the sploit smile.gif
charon255
Exploit works perfectly, IIS 5 on Win2k Server W/SSL

S'pose it would make sense to recompile the sploit with the remote shell port as a command line option, since most firewalls aren't going to allow an inbound connection on port 31337. Maybe I'll do that tonight.



ivan288
yea tru, that would be cool if you could do that. biggrin.gif
x1`
yeh also a nice batch autohacker would be nice ,
thanks for the exploit
Alien
yeah good sploit ;]

[*] connecting the target
[*] Exploit send successfully ! Sleeping a while ....
[*] Trying to get a shell

Microsoft Windows 2000 [Version 5.00.2195]
© Copyright 1985-2000 Microsoft Corp.

C:\WINNT\system32>
BuzzDee
got about 50 shells by now. the sploit is nice smile.gif

x1`
sl.exe -bhpt 80,443 -f scan.txt -o vulnerable.txt

thats what u use to get results with port 80 and 443 open biggrin.gif
Eyeless
are yall using the compilied or .c sploit?
MxMx
.exe I think
cyrixx
LoL biggrin.gif
Nurgle
QUOTE (MxMx @ Apr 21 2004, 07:10 PM)
.exe I think

he he he, I am Working on an Authox0r. Till Tomorow it will be ready biggrin.gif
BuzzDee
anyone figured out how 2 secure the hacked boxes?
night^man
close port 443
firewall.exe 443
BuzzDee
but isnt port 443 required to be open for ssl? i dont think this is a good idea ^^
Fantafour
dont publish this exploit to everybody

every leet scrip kiddie use it for his "ownage..." think about it

this thread is a really "how to hack iis 5 ssl remote exploit" thread...
Eyeless
Anyone just crashing alot of machines with this sploit? Try nmapin them out again and check things out... Oh and yes Scriptys are using it for 0wnage.. But its avaliable EVERYWHERE if the can type gcc sploit.c -o 0wnage then they are gonna useit anyway, and in anthor thread there are auto hackers galore... Why complain and make a usless post?
charon255
This is hardly the first spot in the world to post the exploit, it wasn't written by GSO.

This'll be a good motivator to get admins off their asses and patch.


Ooops, hearing reports from the field that the MS04-011 patch required is causing probs on a lot of systems... Slow Boot, BSOD, 100% utes eeeeek.


Thanks for the nice choice M$....

1) Apply patch = broken server

2) Don't apply patch = owned server


bah... doesn't matter anyhow, TCP RST DoS against all those BGP routers will be here soon and no one will be on the internet to even give a sheeeeeeeeiiiit.
Eyeless
Lol and Micro$oft slowly collapses upon itsself, down with the internet micro$oft must survive.. rolleyes.gif
ComSec
here is a scanner for the MS04-011 vu

EDITED...program been posted but not original link...edited the Downloads section lsass thread to reflect Foundstone link

cheers
ivan288
but i thought this vuln has nothing to do with the other LSASS one.
Stevy
well the exploit works but not for me, can't code so have to wait on connect back version cool.gif
DumpZ
Some peeps said that they are working on an autohacker. but that's already included in the sploit right?
DumpZ
Some peeps said that they are working on an autohacker. but that's already included in the sploit right?


/EDIT
Sorry for this double post something went wront with my inet connection could someone please delete this?
KoNh
QUOTE (DumpZ @ Apr 22 2004, 12:26 PM)
Some peeps said that they are working on an autohacker. but that's already included in the sploit right?

one more time please i didn't understand ^^ ... hey just kidding m8
isaiah
al there auto hackers are just really bats anyone can make them
marteltor
looks like a good exploit, but i can`t really find lots of servers sad.gif
DumpZ
QUOTE (isaiah @ Apr 22 2004, 01:46 PM)
al there auto hackers are just really bats anyone can make them

Yeah but i thought that there was as autohacker included in the source of the sploit.

Because the syntax is,
CODE

sploit.exe c:\scan.txt
cyrixx
this was the one which vnet576 has edited!
G36K
QUOTE (Khran @ Apr 21 2004, 11:47 AM)
Compiled version here:

http://www.thc.org/download.php?t=e&f=THCIISSLame.zip

down ;(
brOmstar
http://www.thc.org/download.php?t=e&f=THCIISSLame.c

...
Feanor
When i compiled with Dev C++ it gave 1 error i couldn't understand:
CODE
C:\DEV-C_~1\Include\winsock2.h:46: unbalanced `#endif'



With /\/\$ Visual C++ it gave 120 errors.

Can somebody pls tell me what's wrong, or post a working compiled link?
Slann
Very good Exploit guys smile.gif

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.