Temporary Advertisements:
Ad
Ad
Ad
COLLECTION Thread: Juicy North Korean IIS Server - Tons of Vulns!
by PulseCipher - Wednesday June 19, 2024 at 06:02 PM
#1
Hey Breachers,

Stumbled upon a potential North Korean IIS server running on Windows 7 with some sweet vulnerabilities. Thought I’d drop the deets for anyone wanting to have a bit of fun. Check this out:

Target Info:
  • IP Address: 175.45.176.72

  • Server Type: Microsoft IIS

  •   Operating System: Windows 7 (Windows build 6.1.7600)

Vulnerabilities:

  1. MS15-034 (CVE-2015-1635) ->
    • Remote Code Execution via HTTP.sys.
    • Super critical. RCE just by sending a crafted HTTP request.

  2. CVE-2010-3972 ->
    • Remote Code Execution.
    • Mess with fonts and boom, you’re in.

  3. CVE-2010-2730 ->
    • Privilege Escalation.
    • Tweak those file and registry permissions.

  4. CVE-2010-1899 ->
    • Remote Code Execution.
    • Authenticode Signature Verification. Deliver a bad file and pwn the system.

Web Services:
  • Port 80: HTTP
  • Port 443: HTTPS

This box is practically begging for some action. Who's gonna be the first to dive in and see what goodies we can find?
Happy hunting, stay safe, and don’t forget to share any juicy finds. and also don't forget to add my name in the credits with yours!
Reply
#2
Hello,

Your Thread was moved to the "Other Leaks" category as it fits better there.

Please note that the "Databases" section is only for leaked databases. Scrapes, Consumer Data, Collections of data or any other types of data should be shared in the "Other Leaks" section. The Databases section is strictly for databases which were breached and nothing else.

Threads that are also too vague (I.e. stuff titled "USA DATABASE") will be moved to Other Leaks as you didn't provide the source where the information originated from.

This message is automatically posted when a thread is moved to the Other Leaks Section. If this message seems to be a mistake, please disregard.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Legend
Reply
#3
probably a honeypot

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban (Retired) | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
Reply
#4
@ctf Dunno try yourself if you got balls
Reply
#5
(Jun 19, 2024, 07:53 PM)PulseCipher Wrote: @ctf Dunno try yourself if you got balls

Cant attack my own nation

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban (Retired) | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
Reply
#6
(Jun 19, 2024, 08:14 PM)ctf Wrote:
(Jun 19, 2024, 07:53 PM)PulseCipher Wrote: @ctf Dunno try yourself if you got balls

Cant attack my own nation

AYO
Reply
#7
I agree with Ctf, it's likely a honeypot. SSL cert was renewed in late 2023 so someone is aware that the server is in use.
Reply
#8
The north korean gov will find you XDD

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Kurdistan official government website data leak! spirits 14 1,797 15 minutes ago
Last Post: samkurdii
  DOCUMENTS [USA] CONFIDENTIAL Lockheed Martin / US ARMY RFID/WIRELESS CONNECTION MANUALS jrintel 61 8,627 1 hour ago
Last Post: Zhato
  DOCUMENTS [RUS] Top Secret GRU Advanced Weapons Report 2025 LEAK mosad 10 1,485 1 hour ago
Last Post: Zhato
  Instagram 17M Leaked scraped data kkkreoifezrg 173 18,397 3 hours ago
Last Post: onereax
  Venom RAT v5.6 Cracked GONEZMANZANILLO 7 1,378 3 hours ago
Last Post: onereax

Forum Jump:


 Users browsing this forum: 1 Guest(s)