EvilZone

Hacking and Security => Hacking and Security => Topic started by: noob on March 17, 2012, 12:27:34 AM

Title: [POC] Windows RDP Vulnerability Exploit
Post by: noob on March 17, 2012, 12:27:34 AM
(http://2.bp.blogspot.com/-lRpjz6TH-Ag/T2NTfgq03SI/AAAAAAAAFQ8/YraGNwdSgjc/s640/%5BPOC%5D+Windows+RDP+Vulnerability+Exploit.jpg)

Code: [Select]
http://pastebin.com/UzDKcCQy
Code: [Select]
http://pastie.org/private/feg8du0e9kfagng4rrg
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: noob on March 17, 2012, 12:36:23 AM
http://gun.io/open/48/metasploit-module-for-cve-2012-002

1500$ to see a working exploit for CVE-2012-0002 (the new RDP hole) as a Metasploit module.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: FuyuKitsune on March 17, 2012, 12:40:04 AM
Welp, time to disable RDP
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Infinityexists on March 17, 2012, 09:56:16 AM
could you please add some more description ?
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: I_Learning_I on March 17, 2012, 10:58:30 AM
Is this supposed to be triggered after you're logged in and then you get access, or simply execute a remote exploit to a server and you will, after executing, gain access?
I know this works with the RDP protocol itself, but I don't know if the authentication is made with the protocol.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: ca0s on March 17, 2012, 11:09:10 AM
As far as I have read in twitter, the most one of these PoCs can do is crash the victim.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Stackprotector on March 17, 2012, 01:18:55 PM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Infinityexists on March 17, 2012, 02:07:32 PM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.


What is the procedure , i mean how it works ?
Any Documentation for this please
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Stackprotector on March 17, 2012, 02:34:22 PM

What is the procedure , i mean how it works ?
Any Documentation for this please
You will have to google it yourself, its a 0day,   no 100% working poc  yet,   
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Kulverstukas on March 17, 2012, 05:11:21 PM
Holy Jesus! It's times like this I'm glad I use linux :D
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Stackprotector on March 17, 2012, 05:24:19 PM
Holy Jesus! It's times like this I'm glad I use linux :D

Linux also get 0days like these,    they only get fixed in quicker.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: ande on March 18, 2012, 06:17:00 AM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.

I highly doubt it will work if you have not enabled remote access on your computer. After all, there are no service or application even listening to the port..?
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Kulverstukas on March 18, 2012, 11:21:51 AM
I highly doubt it will work if you have not enabled remote access on your computer. After all, there are no service or application even listening to the port..?
You never know when MS decides to have fun.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: I_Learning_I on March 20, 2012, 09:09:06 AM
I think Factionwars means WITH Remote Desktop enabled, you're able to login unauthenticated.
Thanks for the info to everyone.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: redblack on March 20, 2012, 06:20:42 PM
as far as I tested, all the poc just bsod the victim
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: ca0s on March 20, 2012, 09:42:37 PM
as far as I tested, all the poc just bsod the victim
Yep. As I said earlier, I don't know any public exploit for this being able to bypass login or execute arbitrary code.
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: newer on March 23, 2012, 07:14:03 PM
just bluescreen? and working on linux?
Title: Re: [POC] Windows RDP Vulnerability Exploit
Post by: Stackprotector on March 23, 2012, 07:34:05 PM
just bluescreen? and working on linux?
Pleaseeee,    WINDOWSS  and its all explained right here,   i will not remove your message.
Just so you will know its plain stupidity, try posting a introduction message first ;)