raptor
Sep 17 2003, 08:20 PM
I finally found working dcom2 exploit !!!
here is following the exploit and the scanner !!!
(that's not the one wasn't working !)
a buddy of mine modified it so it really creates administrator acount "e"
(please compile it for windows cause many friends ask for it !!!
works perfect anyway on suse 7.2 !!!)
StreetZone_
Sep 17 2003, 08:27 PM
Ok , Thx , Will See If It Works , Thx Alot For The Tool ........
EDIT : PLz Note That Is Isn't Complied.......
raptor
Sep 17 2003, 08:35 PM
---------------------------------CAUTION!!!------------------------------------
----------------------------------------------------------------------------------
This is source file for C on linux OS !!! (works in win i think)
(cause i used win headers in linux!!!) i use wine emulator !
----------------------------------------------------------------------------------
----------------------------------------------------------------------------------
crackie
Sep 17 2003, 08:40 PM
sb pls compile scanner !
Rampage
Sep 17 2003, 08:44 PM
mhmh a linux code?? with winsok.h as an include file??
sounds strange

anyway compiled in windows
raptor
Sep 17 2003, 08:53 PM
send me the compiled versions for windows please !!!
some buddies want these !!!
toscana@otenet.gr
Inoculation X
Sep 17 2003, 09:01 PM
Exploit compiled in windows, no success as of yet.
crackie
Sep 17 2003, 09:03 PM
ahhhhh DUDES ! we need correct scanner ! it filters real vuln ips out and give them out ! xfrpcss shows ips that are not vuln so pls someone compile the scanner !
Inoculation X
Sep 17 2003, 09:08 PM
Im using the eeye rpc ms03-039 scanner
thatsmej
Sep 17 2003, 09:10 PM
| QUOTE |
MS03-039 RPC DCOM long filename heap buffer overflow exp v1 Base on flashsky's MS03-026 exp Code by ey4s<eyas#xfocus.org> 2003-09-16 Welcome to http://www.xfocus.net Thanks to flashsky & benjurry & Dave Aitel If success, target will add a user "e" and password is "asd#321"
|
this is just the old exploit
and this is NOT linux code...
Certox
Sep 17 2003, 09:25 PM
The guy who posted it said his buddy mod. it to acually work... so who knows...
Vosgia
Sep 17 2003, 09:28 PM
the exploit ist from the 16th september but the scanner looks very interesting

maybe better than the ms shit
raptor
Sep 17 2003, 09:30 PM
this code compiled ok for linux !
of cource i use more headers than provided by OS (i entered and win headers)
also it is xploit for dcom2 and not old one !
it creates acounts with username "e"
i sploited a remote server 212.205.12*.** can't say more
if someone has the xploit compiled for win and the scanner too please send me to :
toscana@otenet.gr cause a frient of mine requested this !
thanmx men i hope this helped !
also the cheat is that you try exploit not really vulnerable systems !!! (look 4 posts before !!!) that's the solution!!! (crackie told the solution!)
Hyp3r
Sep 17 2003, 09:31 PM
I have compiled The Code!
raptor
Sep 17 2003, 09:46 PM
guys just found !!!
this exploit uses shellcode for win2000 with sp3 and sp4
so that's why it doesn't work for xp!!!
someone change the shellcode?
(sorry for the incovinience! but when i sploited the sytem 212.205.12*.**
i was happy and wanted to share this info!)
so now we need someone to modify source for win xp!!!
eddy
Sep 17 2003, 09:49 PM
someone can post scanner plz
arhamz
Sep 17 2003, 09:49 PM
rpc is back....yahoo.... man i need a scanner if possible.... cant compile it .... wat compiler u guyz use ?
Vosgia
Sep 17 2003, 09:50 PM
whats with the scanner ? have anyone checked it?
ps: damn i must go sleeping
arhamz
Sep 17 2003, 09:52 PM
ill do anything for the scanner .... someone help

... my compiler wont compile shit ...
Hyp3r
Sep 17 2003, 10:24 PM
hmm only win2k.....
have you a "win2k machine scanner" ? ^^
Hyp3r
Sep 17 2003, 10:26 PM
Here the Dcom v2 scanner
Grezz
Hyp3r
arhamz
Sep 17 2003, 10:38 PM
many many many thanx to all who helped dcom2 to actully work ... thanx all u coders for all ur hard work for this

....
canadianthug
Sep 17 2003, 10:48 PM
Has anyone compiled the exploit ?
Certox
Sep 17 2003, 10:49 PM
Can anyone post what it says when u are successful. And also does the user it adds have admin rights?
sattete
Sep 17 2003, 10:51 PM
Thanks for sharing!! kisses!! now we only try to compile with winxp
Certox
Sep 17 2003, 11:13 PM
[+] Prepare shellcode completed.
[+] Connect to ------------------:135 success.
[+] send 72 bytes.
[+] recv 60 bytes.
[+] send 1592 bytes.
[+] Target crash or exploit success?

.....................
sattete
Sep 17 2003, 11:28 PM
For me its the same
[+] send 72 bytes.
[+] recv 60 bytes.
[+] send 1592 bytes.
[-] recv 40 bytes. Bad luck!
tried 100 hosts with VULN
sattete
Sep 17 2003, 11:31 PM
| QUOTE (Certox @ Sep 17 2003, 11:13 PM) |
[+] Prepare shellcode completed. [+] Connect to ------------------:135 success. [+] send 72 bytes. [+] recv 60 bytes. [+] send 1592 bytes. [+] Target crash or exploit success? 
..................... |
you connect then

?
Certox
Sep 18 2003, 12:03 AM
ok, so how do we do things with the user name... ? what is the point of it being made?
el3ment
Sep 18 2003, 12:05 AM

doesnt sound like an admin account to me hehe
arhamz
Sep 18 2003, 12:11 AM
didnt work for me either ( if thats the compiled one which someone posted

)
Certox
Sep 18 2003, 12:17 AM
no it works, works perfectly, only u cant do anything with the user name it makes.
arhamz
Sep 18 2003, 12:23 AM
can someone add " net localgroup administrators e /add " to the code some how ? that would help ALOT ...... dont know how to do that ( i shouldve learned c instead of java )
mrfastass
Sep 18 2003, 12:30 AM
| QUOTE (Certox @ Sep 18 2003, 12:03 AM) |
| ok, so how do we do things with the user name... ? what is the point of it being made? |
well i'll tell u what i do:
i love those servers with "Terminal Service - Remote Desktop Enabled". coz i got a shell-like thing...
anyway im still looking 4 a hackable server so i didnt test it, but im almost sure that this iS the purpuse of the user..
i dont do Serv-u, i love 2 get the "full-on" shit ;P
The watcher
Sep 18 2003, 12:38 AM
well seems that it works for some Os , will need to try it out

and c what we can do with the current rights

thx for sharing and compiling guys
mrfastass
Sep 18 2003, 12:48 AM
damn soooooo many
"[port closed]"
im so madddd about the a$$hole who made the msblast... that was such a BAD idea. he's soooo idiot..
anyway if i get a msg that its vurn, it still doesnt work... so, hehe
=k3Rn=
Sep 18 2003, 01:04 AM
hm i found many vuln servers when scanning.
but when trying to exploit em, i always get the following echo:
[+] Prepare shellcode completed.
[+] Connect to 212.***.***.***:135 success.
[+] send 72 bytes.
[+] recv 60 bytes.
[+] send 1592 bytes.
[-] recv 40 bytes. Bad luck!
=/
mrfastass
Sep 18 2003, 01:09 AM
Address Status
194.80.225.255 [port closed]
194.80.225.254 [VULN]
194.80.225.4 [ptch]
194.80.225.9 [ptch]
194.80.225.1 [port closed]
194.80.225.252 [port closed]
194.80.225.253 [port closed]
194.80.225.64 [port closed]
194.80.225.65 [port closed]
all get "Bad Luck"... so, or im a very unlucky guy ;P or there's something (filtered) up with the exploit ?
Certox
Sep 18 2003, 01:15 AM
ok... The exploit is fine, is not un-natural to go through 100s of IPs before u get a true VULN Ip... I have done well over 10 now. the exp does give the user "e" Admin rights, as soon as someone make this exploit bindshell or net localgroup Administrators e /add
I dont see anyone getting newhere with this

I hope someone can figure something. I am trying to find out how to code the net localgroup command if/when I get it I will post... just hope somone beats me to it
arhamz
Sep 18 2003, 02:16 AM
some one edit this code more to bind the shell... use the shell code from
or sumthing .... just make the thing work .... plz ....

(dieing to get a shell )
][no0b][
Sep 18 2003, 07:53 AM
first thx a lot gys !
a) so many ppl r so crasy to get dcom2, but it would be not so easy how dcom1

and so many "Skriptkiddys" will hack and most of them dont anderstud the simpelst dos commands ...
what should i say ...
the best think in the last time was to change to lnx
( there r not so many noobs )
greetz and
have a nice day
raptor
Sep 18 2003, 08:31 AM
Guys !!!
I don't believe what i just read !?!
it can't be you !
you get an acount on a remopte system (no admin rights) and you think the code needs modification?
that's terrific!
but why?
there are lot of exploits and programs making a guest or any user (restricted)
to get admin rights !!!
it's just if you get a guest shell on a linux system!
after that there are a lot of ways to become root !!!
don't take the hard way !!! (rewriting exploit !!!)
i hope this helped you !!!
sattete
Sep 18 2003, 09:10 AM
mmmmmh this recompiled exploit dont seems good for me , I use the original ....
Rampage
Sep 18 2003, 09:31 AM
so it's not enaugh to add a new target in the target list to make it work?? a new shellcode is required?
raptor
Sep 18 2003, 10:42 AM
no!
nothing is required to be done !!!
this exploit gives us an account on any remote vulnerable target running win2k sp3,sp4
aftrer that we can use other exploits to make this account root!!!(administrator priviledges !!!)
use pipeuadmin and other are great!!!
the only thing should be done is make the code works for winxp (now only win2k is working)
and maybe for win2k3
i'm waiting for new posts with the new exploits modified !!!
Elftor
Sep 18 2003, 01:15 PM
Thank for this tool.
Certox
Sep 18 2003, 03:17 PM
If you have such a tool you should post it. Everyone needs that kind of tool. Getting Admin Rights, from user/guest would be great.
dinox
Sep 18 2003, 09:59 PM

.....what the F**K
can not success....why? can work at xp?
Anarchy
Sep 19 2003, 05:03 AM
its a good tool!
u can recompiled it when u get the SEH & JMP whit the other OSs
raptor
Sep 19 2003, 08:48 AM
pipeuadmin is somewhere in the download are!!!
also tools like this can be easily found !!!
(search anywhere! it will find this!)
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.