Sploitus

Exploit for CVE-2017-0144

gitee Β· 2020-04-26

Exploit Code

MARKDOWN10 lines
## https://sploitus.com/exploit?id=98FBBCC9-D78B-5D42-A5BB-2789F933EF52
PoC exploit for CVE-2017-0144 (Eternalblue-Doublepulsar). 

The target product/service is Windows operating system, specifically the SMB (Server Message Block) protocol. The vulnerability class/vector is a remote code execution (RCE) vulnerability, which allows an attacker to execute arbitrary code on the target system. 

The probable entry point is the Metasploit module, which is a framework for developing and executing exploits. The notable dependency/tooling is the Doublepulsar backdoor, which is a malicious tool used to establish a persistent presence on the compromised system. 

The execution context is a Metasploit module, which can be invoked using the Metasploit framework. The preconditions for exploitation are a vulnerable version of the Windows operating system and the presence of the Doublepulsar backdoor. The expected impact of the exploit is remote code execution, allowing an attacker to execute arbitrary code on the target system. 

The observable network or file artifacts/IO include the presence of the Doublepulsar backdoor on the compromised system, which can be detected through network traffic analysis or file system monitoring.