May 2017
Intermediate to advanced
416 pages
21h 33m
English
Open your terminal and enter the following Nmap command:
$ nmap -p445 --script smb-vuln-double-pulsar-backdoor <target>
If the system is running the DOUBLEPULSAR backdoor, you should see a report like the following:
| smb-vuln-double-pulsar-backdoor: | VULNERABLE: | Double Pulsar SMB Backdoor | State: VULNERABLE | Risk factor: HIGH CVSSv2: 10.0 (HIGH) (AV:N/AC:L/Au:N/C:C/I:C/A:C) | The Double Pulsar SMB backdoor was detected running on the remote machine. | | Disclosure date: 2017-04-14 | References: | https://isc.sans.edu/forums/diary/Detecting+SMB+Covert+Channel+Double+ Pulsar/22312/ | https://github.com/countercept/doublepulsar-detection-script |_ https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in- ...
Read now
Unlock full access