- •Установка дистрибутива BackTrack
- •Настройка сети
- •Установка сканера Nessus
- •Сканирование машины Oracle
- •Список уязвимостей
- •Пример удачного выполнения эксплойта
- •Vulnerability in Server Service Could Allow Remote Code Execution (917159)
- •Microsoft Windows smb Vulnerabilities Remote Code Execution (958687)
- •Microsoft Windows Server Service Crafted rpc Request Handling Remote Code Execution (958644)
- •Vulnerability in Server Service Could Allow Remote Code Execution (921883)
- •Уязвимые приложения
- •Vulnerability in Microsoft sql Server Could Allow Remote Code Execution (959420)
- •Microsoft sql Server 2000 'sqlvdir.Dll' ActiveX Buffer Overflow Vulnerability
- •Sql Extended Procedure Functions Contain Unchecked Buffers (q319507)
- •Buffer Overruns in sql Server 2000 Resolution Service Could Enable Code Execution (q323875)
- •Malformed rpc Request Can Cause Service Failure
- •Sql Server Text Formatting Functions Contain Unchecked Buffers
- •Microsoft msdtc Service Denial of Service Vulnerability
- •Buffer Overruns in sql Server 2000 Resolution Service Could Enable Code Execution (q323875)
- •Unauthenticated Remote Compromise in ms sql Server 2000
- •1. Internet Information Service remote set password
- •2. Vulnerability in Internet Information Services (iis) ftp Service Could Allow Remote Code Execution (2489256)
- •3. Vulnerability in Windows Internet Printing Service Could Allow Remote Code Execution (953155)
- •4. Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666)
- •5. Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666)
- •6. Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)
- •7. Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)
- •8. Vulnerability in Internet Information Services Could Allow Elevation of Privilege (942831)
Vulnerability in Server Service Could Allow Remote Code Execution (917159)
Дата публикации уязвимости: 2006/07/12.
Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.
Описание: The remote host is vulnerable to heap overflow in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with 'SYSTEM' privileges.
In addition to this, the remote host is also affected by an information disclosure vulnerability in SMB that may allow an attacker to obtain portions of the memory of the remote host.
Фактор риска: High/ CVSS Base Score: 7.5
Идентификатор CVE: CVE-2006-1314, CVE-2006-1315.
Решение: Исправление опубликовано в Microsoft Security Bulletin MS06-035.
Microsoft Windows smb Vulnerabilities Remote Code Execution (958687)
Дата публикации уязвимости: 2008/09/14.
Резюме: It is possible to crash the remote host due to a flaw in SMB.
Описание: The remote host is affected by a memory corruption vulnerability in SMB that may allow an attacker to execute arbitrary code or perform a denial of service against the remote host.
Фактор риска: Critical/ CVSS Base Score: 10.0
Идентификатор CVE: CVE-2008-4834, CVE-2008-4835, CVE-2008-4114.
Решение: Исправление опубликовано в Microsoft Security Bulletin MS09-001.
Microsoft Windows Server Service Crafted rpc Request Handling Remote Code Execution (958644)
Дата публикации уязвимости: 2008/10/23.
Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.
Описание: The remote host is vulnerable to a buffer overrun in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with the 'System' privileges.
Фактор риска: Critical/ CVSS Base Score: 10.0
Идентификатор CVE: CVE-2008-4250.
Решение: Исправление опубликовано в Microsoft Security Bulletin MS08-067.
Vulnerability in Server Service Could Allow Remote Code Execution (921883)
Дата публикации уязвимости: 2006/08/23.
Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.
Описание: The remote host is vulnerable to a buffer overrun in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with 'SYSTEM' privileges.
Фактор риска: Critical/ CVSS Base Score: 10.0
Идентификатор CVE: CVE-2006-3439.
Решение: Исправление опубликовано в Microsoft Security Bulletin MS06-040.
Пример удачного выполнения эксплойта
Поиск машины-жертвы и выполнение эксплойта:
Запустить Metasploit Armitage;
Выбрать Hosts-> Nmap Scan-> Quick Scan (OS detect) и в открывшемся окне ввести диапазон IP адресов, которые будут сканироваться при поиске машины или добавить машину с известным IP через Hosts-> Add Hosts;
Выделить атакуемую машину и выбрать Attacks-> Find Attacks;
В свойствах атакуемой машины выбрать нужный эксплойт.
Выберем эксплойт ms08_067_netapi – он использует уязвимость MS08-067:Microsoft Windows Server Service Crafted RPC Request Handling Remote Code Execution(958644);
В появившемся окне ставим галочку «Use a reverse connection» и нажимаем Launch;
Появление вкладки Meterpreter говорит о том, что эксплойт успешно применен.
Создание нового пользователя на машине Oracle:
Выбрать Meterpreter-> Interact-> Command Shell;
Создадим нового пользователя ROOT и паролем «toor» – для этого воспользуемся командой «net user».
Проверим, какие пользователи уже есть в системе. Выполним: «net user»;
Добавляем пользователя: «net user ROOT toor /add»;
Добавляем пользователя в группу Администраторы: «net localgroup Adminisrtators ROOT /add»;
Проверяем: «net user».
