Search



Categories

News

Videos

Underground

Vblogs

Hacking Challenges



Affiliates

Security Distro
LCN Crew

Underground - Windows SMB Relay Exploit

August 5th, 2008 by Patchy
In this Underground video, Overide demonstrates how to obtain root access on a fully patched Windows XP SP3 Machine. He exploits a flaw in Windows Server Message Block (SMB) which is used to provide shared access to files between hosts on a network. Overide utilizes the Metasploits Framework to run the exploit. It works by relaying a SMB authentication request to another host which provides Metasploit with a authenticated SMB session, and if the user is an administrator, Metasploits will be able to execute code on the target computer such as a reverse shell. For this exploit to run, the target computer must try to authenticate to Metasploit. Overide forces the target computer to perform a SMB authentication attempt by using a Ettercap Filter. Full Scale Video Here
Download Here
Download Ettercap Filter Here

For more information on the Metasploit Framework and Ettercap Filters check out Video Archive - Exploit Hacking, Underground - Metasploit Autopwn, and Episode 20 - Ettercap.

If you would like to submit a video to Infinity Exists Underground send a email describing your video to underground@infinityexists.com

Posted in Underground |

13 Responses

  1. Copy Says:

    great video, loved this exploit ever since i saw it in the “Tactical Exploitation” seminar at defcon

    just note that if your victim is using firefox, firefox is set not to load a local file share, especially \\smb\\image.jpg shares

  2. CrashOverron Says:

    really liked the video m8, not usually one for using metasploit but was still a good video =]]

  3. overide Says:

    you can make this exploit work with firefox you just have to change the code a little bit.
    Internet Explorer

    Older versions of firefox

    new firefox

  4. Copy Says:

    lol sorry, I missed the part where you explained the different codes in the video ._.
    my bad

  5. excid3 Says:

    great video! i also liked the background music…made it seem a little more professional! :D

  6. overide Says:

    No problem Copy i sent Patchy the code so hopefully he can post it for everyone, and thanks for the positive feedback everyone.

  7. randrex Says:

    nice video…hopefully patchy post the code up…..

  8. Patchy Says:

    I did already

  9. T3d Says:

    Just wondering, What songs are playing in the background?

  10. overide Says:

    T3d its Tears Dont Fall by Bullet For My Valentine

  11. randrex Says:

    hey patchy..can u tell me whr u posted the code….thnks…

  12. Patchy Says:

    http://infinityexists.com/downloads/SMB%20Relay%20Filters.filter

  13. randrex Says:

    would this exploit work with a firewall on & if it works with vista…thnks

You must be logged in to leave a comment.