
Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag stored behind the windows security
Challenge Name: BlueDoor
CVE: CVE-2017-0144 (EternalBlue)
Difficulty: 3/5
Category: Exploitation, Windows
Author(s): Seth Davis
BlueDoor simulates a real-world vulnerability (EternalBlue - CVE-2017-0144) in a Windows 7 system. The objective is to exploit the vulnerability, escalate privileges, and retrieve a hidden flag.
nmap, netlify, google drive, msfvenom, for payload generation, and a network connection between both VMs.To avoid network issues during exploitation: netsh advfirewall set allprofiles state off
Scan for Vulnerability
Use nmap to verify if the target system is vulnerable to EternalBlue:
nmap -p 139,445 --script smb-vuln-ms17-010
Exploit the Vulnerability
msfvenom or similar tools.Privilege Escalation
After obtaining access, ensure you have escalated to administrator-level privileges.
Locate the Flag
Search the system for the flag, which is stored in a restricted location.
If you need to regenerate the challenge:
CTF Submission Site Checker, email [email protected] if link is down! CTF Submission Site.