Forums: Ms04-22 Job File Execution - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Ms04-22 Job File Execution marvel at the glory of notepad

#1 User is offline   nuorder 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 574
  • Joined: 01-April 04

Posted 18 July 2004 - 05:55 AM

based off
www.k-otik.com/exploits/07182004.ms04_022.cpp.php
and
www.microsoft.com/technet/security/bulletin/MS04-022.mspx

Quote

//*************************************************************
// Microsoft Windows 2K/XP Task Scheduler Vulnerability (MS04-022)
// Proof-of-Concept Exploit for English WinXP SP1
// 15 Jul 2004
//
// Running this will create a file "j.job".  When explorer.exe or any
// file-open dialog box accesses the directory containing this file,
// notepad.exe will be spawn.
//
// Greetz: snooq, sk and all guys at SIG^2 www security org sg
//
//*************************************************************


compiles fine under lcc which you can get here www.cs.virginia.edu/~lcc-win32/

Attached File(s)


0

#2 User is offline   Ecko 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 220
  • Joined: 02-March 04

Posted 18 July 2004 - 12:39 PM

thx 4 compiling :D
0

#3 User is offline   Zimmergren 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 486
  • Joined: 17-July 03

Posted 18 July 2004 - 01:03 PM

Nice one.
Got any good ideas on howto use this exploit?
I want to test it at work (where I'm admin) to see what it can do. I want a real badass :P
http://www.zimmergren.net

Formerly known as t0bban.
0

#4 User is offline   Serhat 

  • Second Lieutenant
  • Icon
  • Group: Members
  • Posts: 803
  • Joined: 13-January 04

Posted 18 July 2004 - 02:17 PM

I already installed the newest patches etc.. and it crashed explorer here :)

Serhat
0

#5 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 18 July 2004 - 02:23 PM

no worky for me.. not sure if i was already patched too lazy to look
0

#6 User is offline   Zimmergren 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 486
  • Joined: 17-July 03

Posted 18 July 2004 - 02:39 PM

It didn't work here either mate.
http://www.zimmergren.net

Formerly known as t0bban.
0

#7 User is offline   nuorder 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 574
  • Joined: 01-April 04

Posted 18 July 2004 - 07:35 PM

works on an unpatched system
doesnt work on a patched system
and make sure task scheduler is running
0

#8 User is offline   JDog45 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 257
  • Joined: 08-September 03

Posted 18 July 2004 - 11:32 PM

nuorder, on Jul 19 2004, 03:35 AM, said:

and make sure task scheduler is running

ah that's the key, because I had no luck with it on my network... :huh:
0

#9 User is offline   =k3Rn= 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 158
  • Joined: 17-September 03

Posted 26 July 2004 - 10:44 AM

Would be a really nice new exploit !

But this one is only a proof of concept code.
It would be great if someone could mod it so that it spawn a shell ! =)

Greetz
=k3Rn=
0

#10 User is offline   mortello 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 25-August 03

Posted 26 July 2004 - 11:51 AM

Its already done....you already posted in 3 other threads about it....just wait for someone to compile it, or compile it yourself using the tips from other users (check the scriptgod thread).
0

#11 User is offline   =k3Rn= 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 158
  • Joined: 17-September 03

Posted 26 July 2004 - 05:23 PM

ok, i'll try to compile it and then i'll have a look at it ...

do you have any experiance with it? does it work?
0

#12 User is offline   mortello 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 25-August 03

Posted 26 July 2004 - 07:02 PM

Scriptgod coded one, ask him, I'm not interested into trying that...I patched my computer....but I know people made it work, so I guess its functionnal.....also there is a compiled exploit on illwill's site if you want it...
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting