hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Pages: 1, 2
mekros
this one could really be helpful sometimes if you know how to use it properly... neway for those who cant see the downloads section... here's pipeupadmin...
be sure to check out the other files there, fochrissakes... there's alot of them there... laugh.gif
maZer`-
QUOTE
//user="e" pass="asd#321"
unsigned char sc_add_user[]=
"\xEB\x10\x5A\x4A\x33\xC9\x66\xB9\x3E\x01\x80\x34\x0A\x99\xE2\xFA"


This exploit will create a user wink.gif
tztrh
nice one. i have tried thic xploit and it looks promissing.
thx!

btw. some say that there is a new tool ( it has been distibuted over some chinese sites ) that can grant access using same methods as blaster.F worm, and if I got it right you could get access even to computers that have been patched for blaster worm
QuadMedic
I think it's on www.cnhonker.com or something,a real cool chinese site wink.gif

Just a question,once u exploited succesfully a dcom2,how and what u use to connect to the machine?
mekros
netcat?
QuadMedic
it doesnt work here,telnet neither,also tryed with dntu but nothing..maybe i'm putting the wrong port after the ip,which port u use with netcat?
gekkegabber
getting a not a win32 applecation msg??????
raptor
finally, a frontend gui for this exploit as kaht2 for rpc1 is out!!!
but i don't know where to find!!!
could anyone help?
Nick
Don't know I'm looking for it too and also for this exploit compiled for WinXp but I think I can dream a long time again

laugh.gif
--Elite--
i can`t compile the exp. code on my linux box .
was it a win32 code , or u changed it to work on win32 , throught cygwin .... ?

anyway , i`m still looking for a fully working code , for Linux based OS... dry.gif
ZakOpath
w00t im gonna install windows 2000 right now so i can use this smile.gif
low_rider
thnx will try it
man-FIRE
[+] Prepare shellcode completed.
[+] Connect to 127.0.0.1:135 success.
[+] send 72 bytes.
[+] recv 60 bytes.
[+] send 1592 bytes.
[-] recv 40 bytes. Bad luck!


All time is Not GOod is oki? sad.gif
r3L4x
ok i got a Target or or crash message, but how do i login as that user on the remote computer?
lasantarosa
[+] Prepare shellcode completed.
[+] Connect to 192.168.0.54:135 success.
[+] send 72 bytes.
[+] recv 60 bytes.
[+] send 1592 bytes.
[-] recv 40 bytes. Bad luck!


why do i get this message on a host where i know that it is vulnerable ? its on my own private network and sure not patched ! its a win2k sp4 os...

cya

p.s. anyone got the windows messenger exploit spawning a shell ?
HardcoreKiller
On a WinXP SP1a, using r3L4x's GUI tool, I was able to access and open remote shell on an unpatched system (prescanned with KB2 tool from MS or Foundstone). I then was able to FTP a NC client and run it on remote system.

Question-
Does anyone know how to create reset the ADMINISTRATOR PW on the local system account from the shell? I don't want to have to FTP a remote control client to the system if I do not have to.

Thank you,

-HK
hifil0wlife
r3L4x's GUI tool is for dcom1...
jetprice
Well to be hounest i'm really surprised that you guys are still trying to get this crippled code working. To me its simple wait for another exploit a new one, one that exploits the bug but uses DIFFERENT shellcodes as you can see these just don't work ... or rarely work.

I don't know what your drive is to keep editing crippled codes, i saw a reply with editing the shellcode. I think its a good idea but if i read the replies in here i would be really surprised if anyone in here is capable of writing up a new shellcode! Tho don't feel offended, that is not my point...

greets
T3cHn0b0y
QUOTE (HardcoreKiller @ Oct 21 2003, 09:38 PM)
On a WinXP SP1a, using r3L4x's GUI tool, I was able to access and open remote shell on an unpatched system (prescanned with KB2 tool from MS or Foundstone). I then was able to FTP a NC client and run it on remote system.

Question-
Does anyone know how to create reset the ADMINISTRATOR PW on the local system account from the shell? I don't want to have to FTP a remote control client to the system if I do not have to.

Thank you,

-HK

net user administrator [newpassword]

and thats it!

...or if you want to add your own user then do this:

net user [username] [password] /add
net localgroup administrators [username] /add

simple. biggrin.gif
r3L4x
Remember, its v2 of the DCOM1 exploit. Since i havnt found any shell code or scripts that were as reliable as some of the DCOM1 ones were, i havnt put the time into making a newer version.
gogu258
It doesn't work, simple.
HardcoreKiller
Thanks...I get lost in InfoSec land sometime.

The NET USE xxx commands work great with r3L4x's tool. Guess I'll stop and think to type NET USE /?...smile.gif
At shell prompt, I was able to create local accounts, then access then through a NULL session.

Thanks!

r3L4x's V2 tool works Great!

-HK
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.