EvilZone

Hacking and Security => Hacking and Security => : noob March 17, 2012, 12:27:34 AM

: [POC] Windows RDP Vulnerability Exploit
: noob March 17, 2012, 12:27:34 AM
(http://2.bp.blogspot.com/-lRpjz6TH-Ag/T2NTfgq03SI/AAAAAAAAFQ8/YraGNwdSgjc/s640/%5BPOC%5D+Windows+RDP+Vulnerability+Exploit.jpg)

:
http://pastebin.com/UzDKcCQy
:
http://pastie.org/private/feg8du0e9kfagng4rrg
: Re: [POC] Windows RDP Vulnerability Exploit
: noob March 17, 2012, 12:36:23 AM
http://gun.io/open/48/metasploit-module-for-cve-2012-002

1500$ to see a working exploit for CVE-2012-0002 (the new RDP hole) as a Metasploit module.
: Re: [POC] Windows RDP Vulnerability Exploit
: FuyuKitsune March 17, 2012, 12:40:04 AM
Welp, time to disable RDP
: Re: [POC] Windows RDP Vulnerability Exploit
: Infinityexists March 17, 2012, 09:56:16 AM
could you please add some more description ?
: Re: [POC] Windows RDP Vulnerability Exploit
: I_Learning_I March 17, 2012, 10:58:30 AM
Is this supposed to be triggered after you're logged in and then you get access, or simply execute a remote exploit to a server and you will, after executing, gain access?
I know this works with the RDP protocol itself, but I don't know if the authentication is made with the protocol.
: Re: [POC] Windows RDP Vulnerability Exploit
: ca0s March 17, 2012, 11:09:10 AM
As far as I have read in twitter, the most one of these PoCs can do is crash the victim.
: Re: [POC] Windows RDP Vulnerability Exploit
: Stackprotector March 17, 2012, 01:18:55 PM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.
: Re: [POC] Windows RDP Vulnerability Exploit
: Infinityexists March 17, 2012, 02:07:32 PM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.


What is the procedure , i mean how it works ?
Any Documentation for this please
: Re: [POC] Windows RDP Vulnerability Exploit
: Stackprotector March 17, 2012, 02:34:22 PM

What is the procedure , i mean how it works ?
Any Documentation for this please
You will have to google it yourself, its a 0day,   no 100% working poc  yet,   
: Re: [POC] Windows RDP Vulnerability Exploit
: Kulverstukas March 17, 2012, 05:11:21 PM
Holy Jesus! It's times like this I'm glad I use linux :D
: Re: [POC] Windows RDP Vulnerability Exploit
: Stackprotector March 17, 2012, 05:24:19 PM
Holy Jesus! It's times like this I'm glad I use linux :D

Linux also get 0days like these,    they only get fixed in quicker.
: Re: [POC] Windows RDP Vulnerability Exploit
: ande March 18, 2012, 06:17:00 AM
With this flaw you are able to connect to a remote desktop without the need of a password and or remote desktop having to be enabled.

I highly doubt it will work if you have not enabled remote access on your computer. After all, there are no service or application even listening to the port..?
: Re: [POC] Windows RDP Vulnerability Exploit
: Kulverstukas March 18, 2012, 11:21:51 AM
I highly doubt it will work if you have not enabled remote access on your computer. After all, there are no service or application even listening to the port..?
You never know when MS decides to have fun.
: Re: [POC] Windows RDP Vulnerability Exploit
: I_Learning_I March 20, 2012, 09:09:06 AM
I think Factionwars means WITH Remote Desktop enabled, you're able to login unauthenticated.
Thanks for the info to everyone.
: Re: [POC] Windows RDP Vulnerability Exploit
: redblack March 20, 2012, 06:20:42 PM
as far as I tested, all the poc just bsod the victim
: Re: [POC] Windows RDP Vulnerability Exploit
: ca0s March 20, 2012, 09:42:37 PM
as far as I tested, all the poc just bsod the victim
Yep. As I said earlier, I don't know any public exploit for this being able to bypass login or execute arbitrary code.
: Re: [POC] Windows RDP Vulnerability Exploit
: newer March 23, 2012, 07:14:03 PM
just bluescreen? and working on linux?
: Re: [POC] Windows RDP Vulnerability Exploit
: Stackprotector March 23, 2012, 07:34:05 PM
just bluescreen? and working on linux?
Pleaseeee,    WINDOWSS  and its all explained right here,   i will not remove your message.
Just so you will know its plain stupidity, try posting a introduction message first ;)