Metasploit mailing list archives

smb2_negotiate_func_index problem


From: professor0110 at gmail.com (Professor 0110)
Date: Fri, 2 Oct 2009 09:23:34 +1000

Thanks for the quick reply, Darren.
The vista machine I am trying to exploit is located on my Local Area
Network. My setup showed the attacking machine with Metasploit, which is a
Win XP laptop, and the victim machine on the same network running Win
Vista.

If you look at my configuration again, you'll see that both laptops are
connected to the same wireless network. The network router then connects to
a modem which *leads *to the Internet Cloud.

I'm trying to connect to Port 445 on the vulnerable system over my own
network.

On Fri, Oct 2, 2009 at 9:06 AM, Darren Shady <Darren.Shady at sunh.com> wrote:

Are u trying to connect to 445 over the Internet? Most isps block that. Or
did I just misunderstand your setup?
Darren Shady

This E-mail and any attachments may be privileged, confidential, and/or
proprietary. If you are not the intended recipient of this email, please
delete it and do not read, distribute, or reproduce it. The unauthorized use
of this e-mail is strictly prohibited.
Thank you.

------------------------------
 *From*: framework-bounces at spool.metasploit.com <
framework-bounces at spool.metasploit.com>
*To*: framework at spool.metasploit.com <framework at spool.metasploit.com>
*Sent*: Thu Oct 01 16:44:39 2009
*Subject*: [framework] smb2_negotiate_func_index problem

Hi all,
I recently tried out the new smb2_negotiate_func_index exploit on a Windows
Vista machine in my LAN. As you know, there are no patches for this
vulnerability, so I expected it to work like a charm. However, nothing
happened after waiting for 180 seconds and the output said: "Exploit
completed, but no session was created". I looked to my Vista machine, and
nothing at all happened.

Can anyone please explain why the 'sploit did not work as expected?

Here is the configuration.


Windows XP Laptop
     (attacker)             --------------------------- Wireless Router
------------------------------- Windows Vista Laptop
                                                                       |
                                              (victim)
                                                                       |
                                                                       |
                                                                       |
                                                                 Modem
(Internet Gateway)
                                                                       |
                                                                       |
                                                             (Internet
cloud)


Any help on this matter will be greatly appreciated!

Sincerely,

Professor 0110

This e-mail and any attachments may be privileged, confidential, and/or proprietary. If you are not the intended 
recipient of this email, please delete it and do not read, distribute, or reproduce it. The unauthorized use of this 
e-mail is strictly prohibited. Thank you.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.metasploit.com/pipermail/framework/attachments/20091002/8f0fb6a0/attachment-0001.html>


Current thread: