目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2017-0143 PoC — Microsoft Windows SMB 输入验证错误漏洞

来源
关联漏洞
标题: Microsoft Windows SMB 输入验证错误漏洞 (CVE-2017-0143)
Description:Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。SMBv1 server是其中的一个服务器协议组件。 Microsoft Windows中的SMBv1服务器存在远程代码执行漏洞。远程攻击者可借助特制的数据包利用该漏洞执行任意代码。以下版本受到影响:Microsoft Windows Vista SP2,Windows Server 2008 SP2和R2 SP1,Windows 7 SP1,Windows 8.1,Windows Server 2012 Gold
Description
This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).
介绍
# EthernalBlue Report

## What is it?

This is an exploit developed by the NSA, stolen by hacker group, primarily known for being used in ransomware attacks, such as WannaCry or NotPetya...

## Why did you make this report?

I've been asked to do this report on the Tryhackme EthernalBlue room, but without using Metasploit, the primary purpose of this room.

## More information?

If you want to learn more about EthernalBlue, you can check these resources:

[Wikipedia](https://en.wikipedia.org/wiki/EternalBlue)

[Microsoft](https://learn.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010)

[Youtube - Cybernews](https://youtu.be/3-MSlNVqzYY?si=7s0nKptCkBu04-i_)

[Youtube - The TWS Channel](https://youtu.be/PKHH_gvJ_hA?si=zbpC7VvHbXu2pRr-)

[Youtube - Micode](https://youtu.be/nIRDzPnJAro?si=I1NJsHUotSEurbWo)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →