Likes Likes:  0
Resultaten 1 tot 6 van de 6
Geen
  1. #1
    S G Masood
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    Hello list,


    The Dcom.c compiles neatly on Cygwin with GCC 3.2 when
    the "#include <error.h>" line is removed.

    *Very* accurate. If the machine is vulnerable, the
    exploit will almost always succeed on the first
    attempt.

    I've successfully tested it on about 16 boxes and each
    one was rooted on the first try. Among these were
    Win2k with SP0, SP1, SP3 while two were WinXP(SP level
    not known). Before running the exploit, the machines
    were confirmed as vulnerable with the Eeye tool(on a
    side note, while the Eeye tool did recognise many
    vulnerable boxes, it failed to recognise some of them,
    though, they were vulnerable).

    One glitch is that the exploitation is not very
    stealth. All RPC/COM based functions stop working
    completely after exploitation and fail to heal until
    the machine is restarted. Many of these functions are
    quite visible and easily noticeable(drag&drop,
    clipboard, property sheets, etc., for example). This
    happens without exception.

    The exploit mostly times out when run against remote
    hosts.

    Hope we are all patched before Tim Mullen's
    "Mescaline"(http://securityfocus.com/columnists/174)
    becomes a reality.

    One last advice - think twice before doing any thing
    risky with the exploit. Though highly accurate, it is
    very noisy.


    Regards,

    S.G.Masood

    Hyderabad,
    India.

    __________________________________
    Do you Yahoo!?
    Yahoo! SiteBuilder - Free, easy-to-use web site design software
    http://sitebuilder.yahoo.com

  2. #2
    S G Masood
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    Hello list,


    The Dcom.c compiles neatly on Cygwin with GCC 3.2 when
    the "#include <error.h>" line is removed.

    *Very* accurate. If the machine is vulnerable, the
    exploit will almost always succeed on the first
    attempt.

    I've successfully tested it on about 16 boxes and each
    one was rooted on the first try. Among these were
    Win2k with SP0, SP1, SP3 while two were WinXP(SP level
    not known). Before running the exploit, the machines
    were confirmed as vulnerable with the Eeye tool(on a
    side note, while the Eeye tool did recognise many
    vulnerable boxes, it failed to recognise some of them,
    though, they were vulnerable).

    One glitch is that the exploitation is not very
    stealth. All RPC/COM based functions stop working
    completely after exploitation and fail to heal until
    the machine is restarted. Many of these functions are
    quite visible and easily noticeable(drag&drop,
    clipboard, property sheets, etc., for example). This
    happens without exception.

    The exploit mostly times out when run against remote
    hosts.

    Hope we are all patched before Tim Mullen's
    "Mescaline"(http://securityfocus.com/columnists/174)
    becomes a reality.

    One last advice - think twice before doing any thing
    risky with the exploit. Though highly accurate, it is
    very noisy.


    Regards,

    S.G.Masood

    Hyderabad,
    India.

    __________________________________
    Do you Yahoo!?
    Yahoo! SiteBuilder - Free, easy-to-use web site design software
    http://sitebuilder.yahoo.com

  3. #3
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    In-Reply-To: <20030727025321.64988.qmail@web11001.mail.yahoo.co m>

    >One glitch is that the exploitation is not very
    >stealth. All RPC/COM based functions stop working
    >completely after exploitation and fail to heal until
    >the machine is restarted. Many of these functions are
    >quite visible and easily noticeable(drag&drop,
    >clipboard, property sheets, etc., for example). This
    >happens without exception.


    If the shellcode exit via ExitThread(), RPCSS will not die, everything
    rock as usual, and you can run the exploit over and over again.

    sk

  4. #4
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    In-Reply-To: <20030727025321.64988.qmail@web11001.mail.yahoo.co m>

    >One glitch is that the exploitation is not very
    >stealth. All RPC/COM based functions stop working
    >completely after exploitation and fail to heal until
    >the machine is restarted. Many of these functions are
    >quite visible and easily noticeable(drag&drop,
    >clipboard, property sheets, etc., for example). This
    >happens without exception.


    If the shellcode exit via ExitThread(), RPCSS will not die, everything
    rock as usual, and you can run the exploit over and over again.

    sk

  5. #5
    Martin Peikert
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    Hello,

    S G Masood wrote:
    > The Dcom.c compiles neatly on Cygwin with GCC 3.2 when
    > the "#include <error.h>" line is removed.


    s/error.h/errno.h/ and dcom.c will compile on cygwin/gcc3.2.

    GTi




  6. #6
    Martin Peikert
    Re: DCOM RPC exploit (dcom.c)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: DCOM RPC exploit (dcom.c)

    Hello,

    S G Masood wrote:
    > The Dcom.c compiles neatly on Cygwin with GCC 3.2 when
    > the "#include <error.h>" line is removed.


    s/error.h/errno.h/ and dcom.c will compile on cygwin/gcc3.2.

    GTi




Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics