In order to test this, I have installed three virtual machines. . . 1-2 XP did 2003, which essential conditions ravel finally needs, wrote and everybody share, hoped that to left successfully also misses step schoolmates to have the help, thanks illusory image Niu Ren emits MS08-067 Exp, free, sharing.
After a N+1 time test discovered that this aircraft and the target machine must open the following service, otherwise opposite party has not had the patch to be also defeated.
Server, Computer Browser, Workstation.
The following test starts (and my local area network's schoolmates' computer I can the first time be called them to have the patch. . . This time had no way with theirs computer to test, I had to install the virtual machine test)
Moves under cmd MS08-067.exe to present the order help directly
MS08-067.exe
Very simple, only needed to input MS08-067.exe IP to be possible.
MS08-067 Exploit for CN by EMM@ph4nt0m.org
The target machine is the virtual machine (the IP 192.168.1.2), the aggressor is this aircraft (the IP 192.168.1.188)
The virtual machine port opens as follows:

Input order:
MS08-067.exe 192.168.1.2
Prompt:
SMB Connect OK!
Send Payload Over!

Examines virtual machine's port once more:

We saw, when after we moved the MS08-067.exe 192.168.1.2, virtual machine's port presented 4444 port, the condition is LISTENING, by now explained already overflowed has been successful, then we move in this aircraft
Telnet 192.168.1.2 4444
Might Telnet land to the target machine.
An execution order added an account to have a look, to succeed ~

004.jpg (22.36 KB)
2008-10-28 15:47
Tested this conclusion, the following several questions which time tested everybody about this possibly to meet I under here centralism reply.
Q: How in my service doesn't have Server this to serve to manage?
A: In local connects - in the attribute the installment - service - increase - Microsoft network document and printer sharing, selects the determination, will prompt whether to restart, actually will not need to restart may, had this in the service according to F5 refurbishing to serve.
Q: Prompt
SMB Connect OK!
RpcExceptionCode() = 1722
Like this overflowed successfully?
A: The overflow defeat, opposite party has opened the firewall.
Q: Prompt
Make SMB Connection error:1203
Is how a matter?
A: Opposite party does not have the starting company net or has not installed the Microsoft network the document and the printer sharing agreement or has not started the Server service.
|