目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2018-8174 PoC — Microsoft Windows VBScript引擎缓冲区错误漏洞

来源
关联漏洞
标题: Microsoft Windows VBScript引擎缓冲区错误漏洞 (CVE-2018-8174)
Description:Microsoft Windows 7等都是美国微软(Microsoft)公司发布的一系列操作系统。Windows VBScript engine是其中的一个VBScript(脚本语言)引擎。 Microsoft Windows VBScript引擎中存在远程代码执行漏洞。远程攻击者可利用该漏洞在当前用户的上下文中执行任意代码,造成内存损坏。以下系统版本受到影响:Microsoft Windows 7,Windows Server 2012 R2,Windows RT 8.1,Windows Server
Description
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising.  In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page,  which includes an exploit for CVE-2018-8174 and shellcode.  This enables remote code execution of the shellcode obfuscated in the landing page.  After successful exploitation, a second-stage downloader is retrieved,  which appears to be a variant of SmokeLoader due to the URL.  It would then download the final payload, a Monero miner.
介绍
# Rig-Exploit-for-CVE-2018-8174
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising.  In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page,  which includes an exploit for CVE-2018-8174 and shellcode.  This enables remote code execution of the shellcode obfuscated in the landing page.  After successful exploitation, a second-stage downloader is retrieved,  which appears to be a variant of SmokeLoader due to the URL.  It would then download the final payload, a Monero miner.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →