worawit / MS17-010

MS17-010
2.14k stars 1.1k forks source link

Could i use a connected IPC conn to ? #42

Open John21534 opened 4 years ago

John21534 commented 4 years ago

Thanks for your great code! I found a connected IPC$, But I don't know the password. Could I use this IPC$ to attack it and how to?

replace conn.login(USERNAME, PASSWORD, maxBufferSize=4356) to conn.getconnectionsfromlist(connected list)

tomovic commented 4 years ago

The exploit only works on SMB1.0 Microsoft has deactivated this version.

The source code only takes the IPC to connect to send multiple data.