DistCC 1.0.0 Remote Code Execution (CVE-2004-2687) with Manual and Metasploit Examples

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 ธ.ค. 2024

ความคิดเห็น • 17

  • @KrzysztofMakowski-k1k
    @KrzysztofMakowski-k1k ปีที่แล้ว

    very useful!! I'm doing my lab and I was stuck with some stderr. wasn't sure what to do next, I've tried set manual payload, but with no luck, and thanks to your advice to try other payloads it actually worked. so, you've made my day. thanks very much!!!

  • @levnikitin7432
    @levnikitin7432 2 ปีที่แล้ว +2

    thank you so much for this!!! It seems entering a payload wasn`t always required for this module and has really confused why the exploit didn't run like the guides from earlier years showed

  • @rutvikpatel9071
    @rutvikpatel9071 2 ปีที่แล้ว +1

    Awesome! Great Editing!

  • @kimberlyowens7695
    @kimberlyowens7695 ปีที่แล้ว

    Awesome! Thank you so much!

  • @chriskirkpatrick5331
    @chriskirkpatrick5331 ปีที่แล้ว

    That was awesome! So helpful! Thanks!

  • @aketza176
    @aketza176 ปีที่แล้ว

    really good video!

  • @sagisar
    @sagisar 7 หลายเดือนก่อน

    Very good video. Anyway I would thank you really much if you can explain the Python script part by part because I want to understand how exactly this RCE is made of, didn’t found in the internet a full explanation of the vulnerability

  • @bird271828
    @bird271828 11 หลายเดือนก่อน

    Nice video. It would have been more useful if you could show how to escalate daemon's privileges to become root.

  • @kamillorek6159
    @kamillorek6159 ปีที่แล้ว

    Is it possible to use Ubuntu 20 instead of Metasploitable2?

    • @officialexploitacademy
      @officialexploitacademy  ปีที่แล้ว

      Sure, If you could install DistCC on it

    • @kamillorek6159
      @kamillorek6159 ปีที่แล้ว

      @@officialexploitacademy I get an error saying exploit failed, connection refused. Could it be because I only installed distcc on the machine that is being attacked? Do I have to set up distcc for this exploit to work?

    • @officialexploitacademy
      @officialexploitacademy  ปีที่แล้ว

      @@kamillorek6159 well it has to be the same version of DistCC and of course it has to be up and running to receive the exploit

    • @kamillorek6159
      @kamillorek6159 ปีที่แล้ว

      @@officialexploitacademy Another question, do you have any solution to this exploit to stop it from working?

    • @officialexploitacademy
      @officialexploitacademy  ปีที่แล้ว

      @@kamillorek6159 update DistCC. You shouldn’t be using this version, it’s severely outdated