This article is a mirror article of machine translation, please click here to jump to the original article.

View: 12177|Reply: 1

[Safety Tutorial] Windows elevation 0day (MS15-051) can be executed under WebShell

[Copy link]
Posted on 1/25/2016 6:49:44 PM | | |

Added support for 2003, streamlined some code, added the ntdll.lib library, and finally supported running under webshell.
Even if the original code is compiled into a 2003-compatible format, it cannot be executed on 03, because the system below win7 does not export user32!gSharedInfo, and can only parse pdb or search for the feature code to locate it; In addition, the EPROCESS->Token offset varies from system to system, and these modifications have been added within the project.
The project is the source code of VS2010 and can be compiled directly. Two compiled exps were included in the project, which were successfully tested on both 64-bit and 32-bit in 2003. The virtual machine version I used for testing is sp2, and other versions are not guaranteed.
If you find that a certain version is not usable, tell me the version number, and I will modify it again (it would be best to have the download address of the corresponding version of the system image).
This vulnerability does not affect win8 and above, so it can only be done.
Note: If you execute the exe in the attachment with a kitchen knife, you will not get the echo, but the command has actually been executed (if the pid is output).
There is no problem with executing in aspxspy, and the asp horse of the kitchen knife can use the following script:








Previous:C# program runs with startup parameters to rewrite OnStartup
Next:c# method of executing CMD commands
Posted on 4/20/2016 6:35:25 PM |
Yes, thank you!!
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com