{"id":5400,"date":"2012-10-16T14:42:59","date_gmt":"2012-10-16T17:42:59","guid":{"rendered":"http:\/\/www.ethicalhacker.com.br\/site\/?p=5400"},"modified":"2019-07-16T14:44:28","modified_gmt":"2019-07-16T17:44:28","slug":"explorando-falha-ms12-020-rdp-windows-7-ultimate","status":"publish","type":"post","link":"https:\/\/www.ethicalhacker.com.br\/site\/2012\/10\/exploits\/explorando-falha-ms12-020-rdp-windows-7-ultimate\/","title":{"rendered":"Explorando Falha MS12-020 RDP Windows 7 Ultimate"},"content":{"rendered":"<p>Neste pequeno tutorial voc\u00ea aprender\u00e1 explorar a vulnerabilidade MS12-020 RDP, contida no Windows 7 Ultimate. Para saber mais sobre a vulnerabilidade voc\u00ea pode ler o artigo http:\/\/aluigi.org\/adv\/ms12-020_leak.txt.<\/p>\n<p>A vulnerabilidade afeta todos os sistemas operacionais Windows com acesso a Desktop Remoto, caso ocorra sucesso no ataque a tela azul ser\u00e1 mostrada.<\/p>\n<p>1.)\u00a0\u00a0\u00a0 Utilizar o exploit ms12_020_maxchannelids mostrado na tela a seguir:<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit1.jpg\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5401\" title=\"exploit1\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit1-300x124.jpg\"  alt=\"\" width=\"300\" height=\"124\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit1-300x124.jpg 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit1.jpg 1011w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>2.)\u00a0\u00a0\u00a0 Nosso alvo:<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit2.jpg\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5402\" title=\"exploit2\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit2-300x185.jpg\"  alt=\"\" width=\"300\" height=\"185\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit2-300x185.jpg 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploit2.jpg 728w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>3.) \u00a0 \u00a0Setar o host remoto, no caso, 192.168.1.108 e aplicar o exploit:<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/sucesso_exploit.jpg\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5403\" title=\"sucesso_exploit\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/sucesso_exploit-300x155.jpg\"  alt=\"\" width=\"300\" height=\"155\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/sucesso_exploit-300x155.jpg 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/sucesso_exploit-1024x531.jpg 1024w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/sucesso_exploit.jpg 1025w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>4.) O sistema fora do ar:<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploitado.jpg\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-5404\" title=\"exploitado\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploitado-300x225.jpg\"  alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploitado-300x225.jpg 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/exploitado.jpg 641w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Contramedidas: n\u00e3o permitir acesso remoto Desktop e atualizar o sistema com a corre\u00e7\u00e3o oferecida pela Microsoft.<\/p>\n<p>At\u00e9 a pr\u00f3xima<\/p>\n\r\n\t\t<div class='author-shortcodes'>\r\n\t\t\t<div class='author-inner'>\r\n\t\t\t\t<div class='author-image'>\r\n\t\t\t<img src='https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/186048_100001838322519_1550894_n-11668_57x57.jpg' alt='' \/>\r\n\t\t\t<div class='author-overlay'><\/div>\r\n\t\t<\/div> <!-- .author-image --> \r\n\t\t<div class='author-info'>\r\n\t\t\t<p>Autor: S\u00edlvio C\u00e9sar Roxo Giavaroto<\/p>\n<p>\u00c9 MBA Especialista em Gest\u00e3o de Seguran\u00e7a da Informa\u00e7\u00e3o,\nTecn\u00f3logo em Redes de Computadores, C|EH Certified Ethical Hacker,\natua como Pentest e Analista de Seguran\u00e7a em Servidores Linux no\nGoverno do Estado de S\u00e3o Paulo, Professor Universit\u00e1rio , Instrutor\nC|EH e C|HFI.<\/p>\r\n\t\t<\/div> <!-- .author-info --><\/p>\r\n\t\t\t<\/div> <!-- .author-inner -->\r\n\t\t<\/div> <!-- .author-shortcodes -->\n","protected":false},"excerpt":{"rendered":"<p>Neste pequeno tutorial voc\u00ea aprender\u00e1 explorar a vulnerabilidade MS12-020 RDP, contida no Windows 7 Ultimate. Para saber mais sobre a vulnerabilidade voc\u00ea pode ler o artigo http:\/\/aluigi.org\/adv\/ms12-020_leak.txt. A vulnerabilidade afeta todos os sistemas operacionais Windows com acesso a Desktop Remoto, caso ocorra sucesso no ataque a tela azul ser\u00e1 mostrada. 1.)\u00a0\u00a0\u00a0 Utilizar o exploit ms12_020_maxchannelids [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3938,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,101],"tags":[],"class_list":["post-5400","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exploits","category-tutorial-backtrack"],"_links":{"self":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/5400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/comments?post=5400"}],"version-history":[{"count":5,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/5400\/revisions"}],"predecessor-version":[{"id":10498,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/5400\/revisions\/10498"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media\/3938"}],"wp:attachment":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media?parent=5400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/categories?post=5400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/tags?post=5400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}