文章预览
本文为永恒之黑 CVE-2020-0796 的分析及漏洞利用。 环境搭建 下载并安装w10 1909版本,iso如下: https://news.mydrivers.com/1/658/658025.htm 安装好如下图所示,版本为1909 影响范围 Windows 10 Version 1903 for 32-bit Systems Windows 10 Version 1903 for x64-based Systems Windows 10 Version 1903 for ARM64-based Systems Windows Server, Version 1903 (Server Core installation) Windows 10 Version 1909 for 32-bit Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for ARM64-based Systems Windows Server, Version 1909 (Server Core installation) 只影响 SMB v3.1.1,1903和1909 漏洞检测 Ladon: Ladon 192.168.10.17 SMBGhost 奇安信exe: http://dl.qianxin.com/skylar6/CVE-2020-0796-Scanner.zip 漏洞复现 本地提权poc: 使用exp:https://github.com/chompie1337/SMBGhost_RCE_PoC 本地普通用户Bypass执行提权exp后弹出cmd
………………………………