Search



Categories

News

Videos

Underground

Vblogs

Hacking Challenges



Servers

Server.InfinityExists.com
  -IRC Server (Java Client)
    (#Infinity_Exists Port 6667)
  -Vent Server (Port 3784)



Affiliates

Security Distro

LCN Crew

Security Override

SecurityTube

Underground – Windows SMB Relay Exploit

August 5th, 2008 by Patchy
In this Underground video, Overide demonstrates how to obtain root access on a fully patched Windows XP SP3 Machine. He exploits a flaw in Windows Server Message Block (SMB) which is used to provide shared access to files between hosts on a network. Overide utilizes the Metasploits Framework to run the exploit. It works by relaying a SMB authentication request to another host which provides Metasploit with a authenticated SMB session, and if the user is an administrator, Metasploits will be able to execute code on the target computer such as a reverse shell. For this exploit to run, the target computer must try to authenticate to Metasploit. Overide forces the target computer to perform a SMB authentication attempt by using a Ettercap Filter. Full Scale Video Here
Download Here
Download Ettercap Filter Here

For more information on the Metasploit Framework and Ettercap Filters check out Video Archive – Exploit Hacking, Underground – Metasploit Autopwn, and Episode 20 – Ettercap.

If you would like to submit a video to Infinity Exists Underground send a email describing your video to underground@infinityexists.com

Posted in Underground | 14 Comments »

14 Responses

  1. Copy Says:

    great video, loved this exploit ever since i saw it in the “Tactical Exploitation” seminar at defcon

    just note that if your victim is using firefox, firefox is set not to load a local file share, especially \\smb\\image.jpg shares

  2. CrashOverron Says:

    really liked the video m8, not usually one for using metasploit but was still a good video =]]

  3. overide Says:

    you can make this exploit work with firefox you just have to change the code a little bit.
    Internet Explorer

    Older versions of firefox

    new firefox

  4. Copy Says:

    lol sorry, I missed the part where you explained the different codes in the video ._.
    my bad

  5. excid3 Says:

    great video! i also liked the background music…made it seem a little more professional! :D

  6. overide Says:

    No problem Copy i sent Patchy the code so hopefully he can post it for everyone, and thanks for the positive feedback everyone.

  7. randrex Says:

    nice video…hopefully patchy post the code up…..

  8. Patchy Says:

    I did already

  9. T3d Says:

    Just wondering, What songs are playing in the background?

  10. overide Says:

    T3d its Tears Dont Fall by Bullet For My Valentine

  11. randrex Says:

    hey patchy..can u tell me whr u posted the code….thnks…

  12. Patchy Says:

    http://infinityexists.com/downloads/SMB%20Relay%20Filters.filter

  13. randrex Says:

    would this exploit work with a firewall on & if it works with vista…thnks

  14. linux80 Says:

    because it gives me this error :
    FAILED! The remote host has only provided us with Guest privileges. Please make sure that the correct username and password have been provided. Windows XP systems that are not part of a domain will only provide Guest privileges to network logins by default.

You must be logged in to leave a comment.