The following code is functional code to exploit the lsass.exe flaw discovered by eeye. This is the local version of the exploit. I will release a remote version if someone pays me;) Use at your free will, to test for the vulnerability or for malicious means. I do not give a (filtered).
Greetz: Dayle, Sc, breezah, RaFa, netmaniac, nightforce, prog, illmob group and everyone else i forgot to mention.
Big thanks to netmaniac for hints on the undocumented api and making me aware of the bug etc.
Obstacles encountered during developing the code:
The biggest problem was probably the fact that the area pointed to by ESP was actually a very limited place where we had control of (8 bytes to be precised). There is no way decent shellcode would fit into it. So what i done was relocated my shellcode somewhere else in the buffer and performed a bit of hackery to jump backwards into the place where the shellcode was located. I also had to make sure the registers were kept intact and cleaned up but this was not a problem.
--------------
C:\Documents and Settings\ronan>nc 127.0.0.1 31337
Microsoft Windows XP [Version 5.1.2600] (C) Copyright 1985-2001 Microsoft Corp.
thx. local exploits are great, specially for physical breakins = ). Its one of the most effective ways of running pwdump with admin rights and getting the admin hash = ).
Nick
Apr 25 2004, 08:49 AM
it gives you a root access ?
h3llraz0r
Apr 25 2004, 10:30 AM
compiled and posted in download section. gets detected as a bloodhound.exploit/hack tool
Gurou
Apr 25 2004, 11:58 AM
this is for ms04-011 or older ?
gsicht
Apr 25 2004, 12:06 PM
QUOTE
it gives you a root access ?
lol, this is not for linux
r3L4x
Apr 25 2004, 03:55 PM
admin & root its all the same
tribalgoa
Apr 25 2004, 06:48 PM
great ... another local root sploit .... just when all the 'remote user shell' sploits are dead (wms, fp)
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.