module

MS17-010 SMB RCE Detection

Disclosed
N/A
Created
2018-05-30

Description

Uses information disclosure to determine if MS17-010 has been patched or not.
Specifically, it connects to the IPC$ tree and attempts a transaction on FID 0.
If the status returned is "STATUS_INSUFF_SERVER_RESOURCES", the machine does
not have the MS17-010 patch.

If the machine is missing the MS17-010 patch, the module will check for an
existing DoublePulsar (ring 0 shellcode/malware) infection.

This module does not require valid SMB credentials in default server
configurations. It can log on as the user "\" and connect to IPC$.

Authors

Sean Dillon sean.dillon@risksense.com
Luke Jennings

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/scanner/smb/smb_ms17_010
msf auxiliary(smb_ms17_010) > show actions
...actions...
msf auxiliary(smb_ms17_010) > set ACTION < action-name >
msf auxiliary(smb_ms17_010) > show options
...show and set options...
msf auxiliary(smb_ms17_010) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.