[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fl10VLYl45AkV7aTLmo8u2WKjlRgeXI8epiA-ExBEO7E":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},144,"What is Smbtouch and what vulnerabilities does it detect?","Smbtouch is a tool within the NSA's leaked FuzzBunch framework that detects SMB and NBT remote privilege escalation vulnerabilities on target hosts. It specifically tests for [ETERNALBLUE](\u002Fnews\u002Fintranet-security-using-nsa-smbtouch-for-batch-detection-of-intranet), ETERNALCHAMPION, ETERNALROMANCE, and ETERNALSYNERGY, which are among the most harmful exploits for intranet workgroup environments.","\u003Cp>Smbtouch is a tool within the NSA&#39;s leaked FuzzBunch framework that detects SMB and NBT remote privilege escalation vulnerabilities on target hosts. It specifically tests for [ETERNALBLUE](\u002Fnews\u002Fintranet-security-using-nsa-smbtouch-for-batch-detection-of-intranet), ETERNALCHAMPION, ETERNALROMANCE, and ETERNALSYNERGY, which are among the most harmful exploits for intranet workgroup environments.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fintranet-security-using-nsa-smbtouch-for-batch-detection-of-intranet\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-smbtouch-and-what-vulnerabilities-does-it-detect-1777484923640","Smbtouch, ETERNALBLUE, ETERNALCHAMPION, ETERNALROMANCE, ETERNALSYNERGY, SMB, NBT, vulnerability detection",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},39,"Intranet Security - Using NSA Smbtouch for Batch Detection of Intranet","intranet-security-using-nsa-smbtouch-for-batch-detection-of-intranet","Learn how to use NSA Smbtouch for batch detection of SMB\u002FNBT vulnerabilities like EternalBlue in intranet environments. Step-by-step guide for defenders.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, NSA penetration tools were exposed, including multiple Windows remote exploitation tools, which have a significant impact\u003C\u002Fp>\u003Cp>This article will not specifically introduce the usage of these remote vulnerability tools, but from the defender's perspective, explain how to use these tools to better protect your own intranet\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>FuzzBunch usage process\u003C\u002Fli>\u003Cli>Smbtouch feature introduction\u003C\u002Fli>\u003Cli>Writing a Python script to achieve batch detection of whether vulnerabilities exploitable via SMB and NBT protocols exist in the intranet\u003C\u002Fli>\u003Cli>Grasping intranet host information based on logs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The list of detected SMB and NBT remote privilege escalation vulnerabilities is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALBLUE\u003C\u002Fli>\u003Cli>ETERNALCHAMPION\u003C\u002Fli>\u003Cli>ETERNALROMANCE\u003C\u002Fli>\u003Cli>ETERNALSYNERGY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my opinion, the above four vulnerabilities are the most harmful, especially suitable for intranet workgroup environments\u003C\u002Fp>\u003Ch2>0x02 FuzzBunch\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The FuzzBunch framework is similar to Metasploit, including various functions such as detection, attack, and exploitation (based on currently leaked information)\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FuzzBunch is extracted from https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Ch3>1. Configure the environment\u003C\u002Fh3>\u003Cp>Install Python 2.6, reference download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdl.nexiao.com\u002Ffile.html?url=http%3A\u002F\u002Fb9.gpxz.net\u002F201402\u002Fpython-2_gpxz.6_gpxz.6_gpxz.rar\u003C\u002Fp>\u003Cp>Install pywin32, reference download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Fpywin32\u002Ffiles\u002Fpywin32\u002FBuild%20221\u002Fpywin32-221.win32-py2.6.exe\u002Fdownload\u003C\u002Fp>\u003Ch3>2. Add environment variable c:\\python26\u003C\u002Fh3>\u003Ch3>3. Execute fb.py to enter command line operation mode\u003C\u002Fh3>\u003Cp>Error\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The leaked data is missing the listeningposts folder\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a listeningposts folder under shadowbroker-master\\windows\\\u003C\u002Fp>\u003Cp>Or modify fb.py, the modified file can be downloaded at the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.py\u003C\u002Fp>\u003Cp>Execute fb.py again, success\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019801847_0_14b732f7b7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute start_lp.py to enter the GUI operation mode, as shown in the figure below, which will not be further elaborated here\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019816907_1_4ef2de7620.jpeg\">\u003C\u002Fp>\u003Ch3>4. Set the startup parameters as follows:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[?] Default Target IP Address [] : \u003Cbr>[?] Default Callback IP Address [] : \u003Cbr>[?] Use Redirection [yes] : \u003Cbr>[?] Base Log directory [D:\\logs] :\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After entering the fb shell, type 'use' to get the list of supported plugins:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Plugin Category: Touch\u003Cbr>======================\u003Cbr>\u003Cbr>  Name                     Versi\u003Cbr>  ----                     -----\u003Cbr>  Architouch               1.0.0\u003Cbr>  Domaintouch              1.1.1\u003Cbr>  Eclipsedwingtouch        1.0.4\u003Cbr>  Educatedscholartouch     1.0.0\u003Cbr>  Emeraldthreadtouch       1.0.0\u003Cbr>  Erraticgophertouch       1.0.1\u003Cbr>  Esteemaudittouch         2.1.0\u003Cbr>  Explodingcantouch        1.2.1\u003Cbr>  Iistouch                 1.2.2\u003Cbr>  Namedpipetouch           2.0.0\u003Cbr>  Printjobdelete           1.0.0\u003Cbr>  Printjoblist             1.0.0\u003Cbr>  Rpctouch                 2.1.0\u003Cbr>  Smbtouch                 1.1.1\u003Cbr>  Webadmintouch            1.0.1\u003Cbr>  Worldclienttouch         1.0.1\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: ImplantConfig\u003Cbr>==============================\u003Cbr>\u003Cbr>  Name           Version\u003Cbr>  ----           -------\u003Cbr>  Darkpulsar     1.1.0\u003Cbr>  Mofconfig      1.0.0\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Exploit\u003Cbr>========================\u003Cbr>\u003Cbr>  Name                   Version\u003Cbr>  ----                   -------\u003Cbr>  Easybee                1.0.1\u003Cbr>  Easypi                 3.1.0\u003Cbr>  Eclipsedwing           1.5.2\u003Cbr>  Educatedscholar        1.0.0\u003Cbr>  Emeraldthread          3.0.0\u003Cbr>  Emphasismine           3.4.0\u003Cbr>  Englishmansdentist     1.2.0\u003Cbr>  Erraticgopher          1.0.1\u003Cbr>  Eskimoroll             1.1.1\u003Cbr>  Esteemaudit            2.1.0\u003Cbr>  Eternalromance         1.4.0\u003Cbr>  Eternalsynergy         1.0.1\u003Cbr>  Ewokfrenzy             2.0.0\u003Cbr>  Explodingcan           2.0.2\u003Cbr>  Zippybeer              1.0.2\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Payload\u003Cbr>========================\u003Cbr>\u003Cbr>  Name              Version\u003Cbr>  ----              -------\u003Cbr>  Doublepulsar      1.3.1\u003Cbr>  Jobadd            1.1.1\u003Cbr>  Jobdelete         1.1.1\u003Cbr>  Joblist           1.1.1\u003Cbr>  Pcdlllauncher     2.3.1\u003Cbr>  Processlist       1.1.1\u003Cbr>  Regdelete         1.1.1\u003Cbr>  Regenum           1.1.1\u003Cbr>  Regread           1.1.1\u003Cbr>  Regwrite          1.1.1\u003Cbr>  Rpcproxy          1.0.1\u003Cbr>  Smbdelete         1.1.1\u003Cbr>  Smblist           1.1.1\u003Cbr>  Smbread           1.1.1\u003Cbr>  Smbwrite          1.1.1\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Special\u003Cbr>========================\u003Cbr>\u003Cbr>  Name                Version\u003Cbr>  ----                -------\u003Cbr>Eternalblue 2.2.0\u003Cbr>Eternalchampion 2.0.0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Plugins are divided into five major categories:\u003C\u002Fp>\u003Cul>\u003Cli>Touch - Information detection, vulnerability testing\u003C\u002Fli>\u003Cli>ImplantConfig - Implant tools\u003C\u002Fli>\u003Cli>Exploit - Vulnerability exploitation\u003C\u002Fli>\u003Cli>Payload - Payload\u003C\u002Fli>\u003Cli>Special - Specialized\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Each plugin corresponds to three files in the folder:\u003C\u002Fp>\u003Cul>\u003Cli>.exe\u003C\u002Fli>\u003Cli>.fb\u003C\u002Fli>\u003Cli>.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For example, Eternalblue-2.2.0 under Special corresponds to:\u003C\u002Fp>\u003Cul>\u003Cli>Eternalblue-2.2.0.exe\u003C\u002Fli>\u003Cli>Eternalblue-2.2.0.fb\u003C\u002Fli>\u003Cli>Eternalblue-2.2.0.0.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Viewing the file content reveals:\u003C\u002Fp>\u003Cul>\u003Cli>The exe can run independently (provided the required dll files are found)\u003C\u002Fli>\u003Cli>The exe reads configuration parameters saved in the xml file (requires secondary modification)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>That is to say, only the standalone exe and xml configuration file, along with necessary support files, are needed to execute the corresponding plugin, without fully installing the FuzzBunch framework\u003C\u002Fp>\u003Ch2>0x03 Smbtouch\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Located under the Touch class, the file is in \u002Fwindows\u002Ftouches\u002F, used to detect whether the target host contains SMB and NBT remote privilege escalation vulnerabilities, mainly testing the following four vulnerabilities:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALBLUE\u003C\u002Fli>\u003Cli>ETERNALCHAMPION\u003C\u002Fli>\u003Cli>ETERNALROMANCE\u003C\u002Fli>\u003Cli>ETERNALSYNERGY\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Command line testing\u003C\u002Fh3>\u003Cp>Execute fb.py to enter command line operation mode\u003C\u002Fp>\u003Cp>Set the scanning parameters and execute in sequence:\u003C\u002Fp>\u003Cp>use Smbtouch\u003C\u002Fp>\u003Cp>execute\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019827857_2_334d6762ef.jpeg\">\u003C\u002Fp>\u003Cp>then execute the plugin, the echo is as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019838797_3_7a235cf5a5.jpeg\">\u003C\u002Fp>\u003Cp>detection successful, obtained the following information:\u003C\u002Fp>\u003Cp>System: Windows Server 2003 3790 Service Pack 2 x86\u003C\u002Fp>\u003Cp>Available vulnerabilities:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALROMANCE - FB\u003C\u002Fli>\u003Cli>ETERNALCHAMPION - DANE\u002FFB\u003C\u002Fli>\u003C\u002Ful>\u003Cp>then use specific vulnerability attacks\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The target host needs to have port 445 open; for testing environments, you can choose to disable the firewall or manually open port 445\u003C\u002Fp>\u003Cp>The command line code to open port 445 is as follows:\u003C\u002Fp>\u003Cp>netsh advfirewall firewall add rule name=\"445\" protocol=TCP dir=in localport=445 action=allow\u003C\u002Fp>\u003Ch3>2. Execute the exe directly\u003C\u002Fh3>\u003Cp>Enter the folder shadowbroker-master\\windows\\touches and directly execute Smbtouch-1.1.1.exe\u003C\u002Fp>\u003Cp>Prompt indicates missing dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860192_4_cc5d93c82c.jpeg\">\u003C\u002Fp>\u003Cp>Find the missing dll in the folder shadowbroker-master\\windows\\lib\\x86-Windows and complete it\u003C\u002Fp>\u003Cp>Directly execute Smbtouch-1.1.1.exe, echo prompt:\u003C\u002Fp>\u003Cp>TargetIp must have a value assigned.\u003C\u002Fp>\u003Cp>So next, need to edit the Smbtouch-1.1.1.0.xml file\u003C\u002Fp>\u003Cp>Need to add the following parameters:\u003C\u002Fp>\u003Cul>\u003Cli>NetworkTimeout: 60\u003C\u002Fli>\u003Cli>TargetIp: 127.0.0.1\u003C\u002Fli>\u003Cli>TargetPort: 445\u003C\u002Fli>\u003Cli>Protocol: SMB\u003C\u002Fli>\u003Cli>Credentials: Anonymous\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Refer to the XML file format, add the code \u003Cvalue>data\u003C\u002Fvalue>, and rename it to Smbtouch-1.1.1.xml\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The file name is not the original Smbtouch-1.1.1.0.xml\u003C\u002Fp>\u003Cp>The modified XML file can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Execute Smbtouch-1.1.1.exe again\u003C\u002Fp>\u003Cp>The echo is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019865933_5_ad2f03b3ad.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019869834_6_9cbdf11992.jpeg\">\u003C\u002Fp>\u003Cp>Successfully executed, and the XML file content is echoed\u003C\u002Fp>\u003Ch2>0x04 Smbtouch Scanner\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above content, if you want to attempt scanning a specified network segment, you need to repeatedly modify the XML configuration file, then execute Smbtouch-1.1.1.exe for detection\u003C\u002Fp>\u003Cp>Using Python to automatically implement the above operations, the following issues need to be considered:\u003C\u002Fp>\u003Cul>\u003Cli>Execute Smbtouch-1.1.1.exe and obtain the echo\u003C\u002Fli>\u003Cli>Parse the echo content and remove redundant parts\u003C\u002Fli>\u003Cli>Parse range IP addresses\u003C\u002Fli>\u003Cli>Automatically read and write XML files\u003C\u002Fli>\u003Cli>Generate log files\u003C\u002Fli>\u003Cli>Improve efficiency with multithreading\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual testing:\u003C\u002Fh3>\u003Ch3>1. Set the scanning IP segment\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874380_7_c40435e213.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute SmbtouchScanner.py\u003C\u002Fh3>\u003Cp>Wait for the scan to complete, echo displays brief information\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019877997_8_79b23f3ae5.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate log files in the same directory, displaying detailed information\u003C\u002Fh3>\u003Cp>Includes specific existing vulnerabilities, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881427_9_eb8d1722f6.jpeg\">\u003C\u002Fp>\u003Ch3>4. Supplement\u003C\u002Fh3>\u003Cp>Due to security reasons, this open-source code does not yet support multithreading\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For NSA's SMB and NBT remote privilege escalation vulnerabilities, it is recommended to upgrade system patches, enable the firewall, and restrict port 445\u003C\u002Fp>\u003Cp>The command-line code to restrict port 445 is as follows:\u003C\u002Fp>\u003Cp>netsh advfirewall firewall add rule name=\"445\" protocol=TCP dir=in localport=445 action=block\u003C\u002Fp>\u003Cp>At the same time, to ensure intranet security, SmbtouchScanner.py can be used to scan and detect the intranet\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Currently, Smbtouch-1.1.1.exe has been detected and removed by antivirus software\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to use Python to automatically detect vulnerabilities in internal networks that can be exploited via SMB and NBT protocols. Of course, the disclosed vulnerabilities are not limited to the four mentioned above, and the Touch plugin is not limited to Smbtouch.\u003C\u002Fp>\u003Cp>Subsequent updates will be synchronized to GitHub: an open-source project.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, NSA penetration tools were exposed, including multiple Windows remote exploitation tools, which have a significant impact\u003C\u002Fp>\u003Cp>This article will not specifically introduce the usage of these remote vulnerability tools, but from the defender's perspective, explain how to use these tools to better protect your own intranet\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>FuzzBunch usage process\u003C\u002Fli>\u003Cli>Smbtouch feature introduction\u003C\u002Fli>\u003Cli>Writing a Python script to achieve batch detection of whether vulnerabilities exploitable via SMB and NBT protocols exist in the intranet\u003C\u002Fli>\u003Cli>Grasping intranet host information based on logs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The list of detected SMB and NBT remote privilege escalation vulnerabilities is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALBLUE\u003C\u002Fli>\u003Cli>ETERNALCHAMPION\u003C\u002Fli>\u003Cli>ETERNALROMANCE\u003C\u002Fli>\u003Cli>ETERNALSYNERGY\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my opinion, the above four vulnerabilities are the most harmful, especially suitable for intranet workgroup environments\u003C\u002Fp>\u003Ch2>0x02 FuzzBunch\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The FuzzBunch framework is similar to Metasploit, including various functions such as detection, attack, and exploitation (based on currently leaked information)\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FuzzBunch is extracted from https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Ch3>1. Configure the environment\u003C\u002Fh3>\u003Cp>Install Python 2.6, reference download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdl.nexiao.com\u002Ffile.html?url=http%3A\u002F\u002Fb9.gpxz.net\u002F201402\u002Fpython-2_gpxz.6_gpxz.6_gpxz.rar\u003C\u002Fp>\u003Cp>Install pywin32, reference download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Fpywin32\u002Ffiles\u002Fpywin32\u002FBuild%20221\u002Fpywin32-221.win32-py2.6.exe\u002Fdownload\u003C\u002Fp>\u003Ch3>2. Add environment variable c:\\python26\u003C\u002Fh3>\u003Ch3>3. Execute fb.py to enter command line operation mode\u003C\u002Fh3>\u003Cp>Error\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The leaked data is missing the listeningposts folder\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Create a listeningposts folder under shadowbroker-master\\windows\\\u003C\u002Fp>\u003Cp>Or modify fb.py, the modified file can be downloaded at the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.py\u003C\u002Fp>\u003Cp>Execute fb.py again, success\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019801847_0_14b732f7b7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute start_lp.py to enter the GUI operation mode, as shown in the figure below, which will not be further elaborated here\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019816907_1_4ef2de7620-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Set the startup parameters as follows:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[?] Default Target IP Address [] : \u003Cbr>[?] Default Callback IP Address [] : \u003Cbr>[?] Use Redirection [yes] : \u003Cbr>[?] Base Log directory [D:\\logs] :\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After entering the fb shell, type 'use' to get the list of supported plugins:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Plugin Category: Touch\u003Cbr>======================\u003Cbr>\u003Cbr>  Name                     Versi\u003Cbr>  ----                     -----\u003Cbr>  Architouch               1.0.0\u003Cbr>  Domaintouch              1.1.1\u003Cbr>  Eclipsedwingtouch        1.0.4\u003Cbr>  Educatedscholartouch     1.0.0\u003Cbr>  Emeraldthreadtouch       1.0.0\u003Cbr>  Erraticgophertouch       1.0.1\u003Cbr>  Esteemaudittouch         2.1.0\u003Cbr>  Explodingcantouch        1.2.1\u003Cbr>  Iistouch                 1.2.2\u003Cbr>  Namedpipetouch           2.0.0\u003Cbr>  Printjobdelete           1.0.0\u003Cbr>  Printjoblist             1.0.0\u003Cbr>  Rpctouch                 2.1.0\u003Cbr>  Smbtouch                 1.1.1\u003Cbr>  Webadmintouch            1.0.1\u003Cbr>  Worldclienttouch         1.0.1\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: ImplantConfig\u003Cbr>==============================\u003Cbr>\u003Cbr>  Name           Version\u003Cbr>  ----           -------\u003Cbr>  Darkpulsar     1.1.0\u003Cbr>  Mofconfig      1.0.0\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Exploit\u003Cbr>========================\u003Cbr>\u003Cbr>  Name                   Version\u003Cbr>  ----                   -------\u003Cbr>  Easybee                1.0.1\u003Cbr>  Easypi                 3.1.0\u003Cbr>  Eclipsedwing           1.5.2\u003Cbr>  Educatedscholar        1.0.0\u003Cbr>  Emeraldthread          3.0.0\u003Cbr>  Emphasismine           3.4.0\u003Cbr>  Englishmansdentist     1.2.0\u003Cbr>  Erraticgopher          1.0.1\u003Cbr>  Eskimoroll             1.1.1\u003Cbr>  Esteemaudit            2.1.0\u003Cbr>  Eternalromance         1.4.0\u003Cbr>  Eternalsynergy         1.0.1\u003Cbr>  Ewokfrenzy             2.0.0\u003Cbr>  Explodingcan           2.0.2\u003Cbr>  Zippybeer              1.0.2\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Payload\u003Cbr>========================\u003Cbr>\u003Cbr>  Name              Version\u003Cbr>  ----              -------\u003Cbr>  Doublepulsar      1.3.1\u003Cbr>  Jobadd            1.1.1\u003Cbr>  Jobdelete         1.1.1\u003Cbr>  Joblist           1.1.1\u003Cbr>  Pcdlllauncher     2.3.1\u003Cbr>  Processlist       1.1.1\u003Cbr>  Regdelete         1.1.1\u003Cbr>  Regenum           1.1.1\u003Cbr>  Regread           1.1.1\u003Cbr>  Regwrite          1.1.1\u003Cbr>  Rpcproxy          1.0.1\u003Cbr>  Smbdelete         1.1.1\u003Cbr>  Smblist           1.1.1\u003Cbr>  Smbread           1.1.1\u003Cbr>  Smbwrite          1.1.1\u003Cbr>\u003Cbr>\u003Cbr>Plugin Category: Special\u003Cbr>========================\u003Cbr>\u003Cbr>  Name                Version\u003Cbr>  ----                -------\u003Cbr>Eternalblue 2.2.0\u003Cbr>Eternalchampion 2.0.0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Plugins are divided into five major categories:\u003C\u002Fp>\u003Cul>\u003Cli>Touch - Information detection, vulnerability testing\u003C\u002Fli>\u003Cli>ImplantConfig - Implant tools\u003C\u002Fli>\u003Cli>Exploit - Vulnerability exploitation\u003C\u002Fli>\u003Cli>Payload - Payload\u003C\u002Fli>\u003Cli>Special - Specialized\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Each plugin corresponds to three files in the folder:\u003C\u002Fp>\u003Cul>\u003Cli>.exe\u003C\u002Fli>\u003Cli>.fb\u003C\u002Fli>\u003Cli>.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For example, Eternalblue-2.2.0 under Special corresponds to:\u003C\u002Fp>\u003Cul>\u003Cli>Eternalblue-2.2.0.exe\u003C\u002Fli>\u003Cli>Eternalblue-2.2.0.fb\u003C\u002Fli>\u003Cli>Eternalblue-2.2.0.0.xml\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Viewing the file content reveals:\u003C\u002Fp>\u003Cul>\u003Cli>The exe can run independently (provided the required dll files are found)\u003C\u002Fli>\u003Cli>The exe reads configuration parameters saved in the xml file (requires secondary modification)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>That is to say, only the standalone exe and xml configuration file, along with necessary support files, are needed to execute the corresponding plugin, without fully installing the FuzzBunch framework\u003C\u002Fp>\u003Ch2>0x03 Smbtouch\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Located under the Touch class, the file is in \u002Fwindows\u002Ftouches\u002F, used to detect whether the target host contains SMB and NBT remote privilege escalation vulnerabilities, mainly testing the following four vulnerabilities:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALBLUE\u003C\u002Fli>\u003Cli>ETERNALCHAMPION\u003C\u002Fli>\u003Cli>ETERNALROMANCE\u003C\u002Fli>\u003Cli>ETERNALSYNERGY\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Command line testing\u003C\u002Fh3>\u003Cp>Execute fb.py to enter command line operation mode\u003C\u002Fp>\u003Cp>Set the scanning parameters and execute in sequence:\u003C\u002Fp>\u003Cp>use Smbtouch\u003C\u002Fp>\u003Cp>execute\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019827857_2_334d6762ef-1.jpeg\">\u003C\u002Fp>\u003Cp>then execute the plugin, the echo is as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019838797_3_7a235cf5a5-1.jpeg\">\u003C\u002Fp>\u003Cp>detection successful, obtained the following information:\u003C\u002Fp>\u003Cp>System: Windows Server 2003 3790 Service Pack 2 x86\u003C\u002Fp>\u003Cp>Available vulnerabilities:\u003C\u002Fp>\u003Cul>\u003Cli>ETERNALROMANCE - FB\u003C\u002Fli>\u003Cli>ETERNALCHAMPION - DANE\u002FFB\u003C\u002Fli>\u003C\u002Ful>\u003Cp>then use specific vulnerability attacks\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The target host needs to have port 445 open; for testing environments, you can choose to disable the firewall or manually open port 445\u003C\u002Fp>\u003Cp>The command line code to open port 445 is as follows:\u003C\u002Fp>\u003Cp>netsh advfirewall firewall add rule name=\"445\" protocol=TCP dir=in localport=445 action=allow\u003C\u002Fp>\u003Ch3>2. Execute the exe directly\u003C\u002Fh3>\u003Cp>Enter the folder shadowbroker-master\\windows\\touches and directly execute Smbtouch-1.1.1.exe\u003C\u002Fp>\u003Cp>Prompt indicates missing dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860192_4_cc5d93c82c-1.jpeg\">\u003C\u002Fp>\u003Cp>Find the missing dll in the folder shadowbroker-master\\windows\\lib\\x86-Windows and complete it\u003C\u002Fp>\u003Cp>Directly execute Smbtouch-1.1.1.exe, echo prompt:\u003C\u002Fp>\u003Cp>TargetIp must have a value assigned.\u003C\u002Fp>\u003Cp>So next, need to edit the Smbtouch-1.1.1.0.xml file\u003C\u002Fp>\u003Cp>Need to add the following parameters:\u003C\u002Fp>\u003Cul>\u003Cli>NetworkTimeout: 60\u003C\u002Fli>\u003Cli>TargetIp: 127.0.0.1\u003C\u002Fli>\u003Cli>TargetPort: 445\u003C\u002Fli>\u003Cli>Protocol: SMB\u003C\u002Fli>\u003Cli>Credentials: Anonymous\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Refer to the XML file format, add the code \u003Cvalue>data\u003C\u002Fvalue>, and rename it to Smbtouch-1.1.1.xml\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The file name is not the original Smbtouch-1.1.1.0.xml\u003C\u002Fp>\u003Cp>The modified XML file can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Execute Smbtouch-1.1.1.exe again\u003C\u002Fp>\u003Cp>The echo is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019865933_5_ad2f03b3ad-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019869834_6_9cbdf11992-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully executed, and the XML file content is echoed\u003C\u002Fp>\u003Ch2>0x04 Smbtouch Scanner\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above content, if you want to attempt scanning a specified network segment, you need to repeatedly modify the XML configuration file, then execute Smbtouch-1.1.1.exe for detection\u003C\u002Fp>\u003Cp>Using Python to automatically implement the above operations, the following issues need to be considered:\u003C\u002Fp>\u003Cul>\u003Cli>Execute Smbtouch-1.1.1.exe and obtain the echo\u003C\u002Fli>\u003Cli>Parse the echo content and remove redundant parts\u003C\u002Fli>\u003Cli>Parse range IP addresses\u003C\u002Fli>\u003Cli>Automatically read and write XML files\u003C\u002Fli>\u003Cli>Generate log files\u003C\u002Fli>\u003Cli>Improve efficiency with multithreading\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Complete code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Actual testing:\u003C\u002Fh3>\u003Ch3>1. Set the scanning IP segment\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874380_7_c40435e213-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute SmbtouchScanner.py\u003C\u002Fh3>\u003Cp>Wait for the scan to complete, echo displays brief information\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019877997_8_79b23f3ae5-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate log files in the same directory, displaying detailed information\u003C\u002Fh3>\u003Cp>Includes specific existing vulnerabilities, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881427_9_eb8d1722f6-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Supplement\u003C\u002Fh3>\u003Cp>Due to security reasons, this open-source code does not yet support multithreading\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For NSA's SMB and NBT remote privilege escalation vulnerabilities, it is recommended to upgrade system patches, enable the firewall, and restrict port 445\u003C\u002Fp>\u003Cp>The command-line code to restrict port 445 is as follows:\u003C\u002Fp>\u003Cp>netsh advfirewall firewall add rule name=\"445\" protocol=TCP dir=in localport=445 action=block\u003C\u002Fp>\u003Cp>At the same time, to ensure intranet security, SmbtouchScanner.py can be used to scan and detect the intranet\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Currently, Smbtouch-1.1.1.exe has been detected and removed by antivirus software\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to use Python to automatically detect vulnerabilities in internal networks that can be exploited via SMB and NBT protocols. Of course, the disclosed vulnerabilities are not limited to the four mentioned above, and the Touch plugin is not limited to Smbtouch.\u003C\u002Fp>\u003Cp>Subsequent updates will be synchronized to GitHub: an open-source project.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1625,"Onedaysec",5,"published","2026-02-02T08:19:47.663Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"NSA Smbtouch Intranet Security: Batch Detection for SMB Vulnerabilities","intranet security, NSA Smbtouch, SMB vulnerabilities, batch detection, EternalBlue, FuzzBunch, penetration testing, network security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],148,147,146,145,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.135Z","2026-07-23T16:01:04.609Z","draft","2026-07-23T16:03:58.812Z"]