Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
OS.docx
Скачиваний:
0
Добавлен:
01.04.2025
Размер:
3 Мб
Скачать
☆
  1. Vulnerability in Server Service Could Allow Remote Code Execution (917159)

Дата публикации уязвимости: 2006/07/12.

Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.

Описание: The remote host is vulnerable to heap overflow in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with 'SYSTEM' privileges. 

In addition to this, the remote host is also affected by an information disclosure vulnerability in SMB that may allow an attacker to obtain portions of the memory of the remote host.

Фактор риска: High/ CVSS Base Score: 7.5

Идентификатор CVE: CVE-2006-1314, CVE-2006-1315.

Решение: Исправление опубликовано в Microsoft Security Bulletin MS06-035.

  1. Microsoft Windows smb Vulnerabilities Remote Code Execution (958687)

Дата публикации уязвимости: 2008/09/14.

Резюме: It is possible to crash the remote host due to a flaw in SMB.

Описание: The remote host is affected by a memory corruption vulnerability in SMB that may allow an attacker to execute arbitrary code or perform a denial of service against the remote host.

Фактор риска: Critical/ CVSS Base Score: 10.0

Идентификатор CVE: CVE-2008-4834, CVE-2008-4835, CVE-2008-4114.

Решение: Исправление опубликовано в Microsoft Security Bulletin MS09-001.

  1. Microsoft Windows Server Service Crafted rpc Request Handling Remote Code Execution (958644)

Дата публикации уязвимости: 2008/10/23.

Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.

Описание: The remote host is vulnerable to a buffer overrun in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with the 'System' privileges.

Фактор риска: Critical/ CVSS Base Score: 10.0

Идентификатор CVE: CVE-2008-4250.

Решение: Исправление опубликовано в Microsoft Security Bulletin MS08-067.

  1. Vulnerability in Server Service Could Allow Remote Code Execution (921883)

Дата публикации уязвимости: 2006/08/23.

Резюме: Arbitrary code can be executed on the remote host due to a flaw in the 'Server' service.

Описание: The remote host is vulnerable to a buffer overrun in the 'Server' service that may allow an attacker to execute arbitrary code on the remote host with 'SYSTEM' privileges.

Фактор риска: Critical/ CVSS Base Score: 10.0

Идентификатор CVE: CVE-2006-3439.

Решение: Исправление опубликовано в Microsoft Security Bulletin MS06-040.

  1. Пример удачного выполнения эксплойта

  1. Поиск машины-жертвы и выполнение эксплойта:

  1. Запустить Metasploit Armitage;

  2. Выбрать Hosts-> Nmap Scan-> Quick Scan (OS detect) и в открывшемся окне ввести диапазон IP адресов, которые будут сканироваться при поиске машины или добавить машину с известным IP через Hosts-> Add Hosts;

  3. Выделить атакуемую машину и выбрать Attacks-> Find Attacks;

  4. В свойствах атакуемой машины выбрать нужный эксплойт.

  1. Выберем эксплойт ms08_067_netapi – он использует уязвимость MS08-067:Microsoft Windows Server Service Crafted RPC Request Handling Remote Code Execution(958644);

  2. В появившемся окне ставим галочку «Use a reverse connection» и нажимаем Launch;

Появление вкладки Meterpreter говорит о том, что эксплойт успешно применен.

  1. Создание нового пользователя на машине Oracle:

  1. Выбрать Meterpreter-> Interact-> Command Shell;

  2. Создадим нового пользователя ROOT и паролем «toor» – для этого воспользуемся командой «net user».

  3. Проверим, какие пользователи уже есть в системе. Выполним: «net user»;

  4. Добавляем пользователя: «net user ROOT toor /add»;

  5. Добавляем пользователя в группу Администраторы: «net localgroup Adminisrtators ROOT /add»;

  6. Проверяем: «net user».

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]