Thread: Juicy North Korean IIS Server - Tons of Vulns!
by PulseCipher - Wednesday June 19, 2024 at 06:02 PM
#1
Hey Breachers,

Stumbled upon a potential North Korean IIS server running on Windows 7 with some sweet vulnerabilities. Thought I’d drop the deets for anyone wanting to have a bit of fun. Check this out:

Target Info:
  • IP Address: 175.45.176.72

  • Server Type: Microsoft IIS

  •   Operating System: Windows 7 (Windows build 6.1.7600)

Vulnerabilities:

  1. MS15-034 (CVE-2015-1635) ->
    • Remote Code Execution via HTTP.sys.
    • Super critical. RCE just by sending a crafted HTTP request.

  2. CVE-2010-3972 ->
    • Remote Code Execution.
    • Mess with fonts and boom, you’re in.

  3. CVE-2010-2730 ->
    • Privilege Escalation.
    • Tweak those file and registry permissions.

  4. CVE-2010-1899 ->
    • Remote Code Execution.
    • Authenticode Signature Verification. Deliver a bad file and pwn the system.

Web Services:
  • Port 80: HTTP
  • Port 443: HTTPS

This box is practically begging for some action. Who's gonna be the first to dive in and see what goodies we can find?
Happy hunting, stay safe, and don’t forget to share any juicy finds. and also don't forget to add my name in the credits with yours!
Reply
#2
Hello,

Your Thread was moved to the "Other Leaks" category as it fits better there.

Please note that the "Databases" section is only for leaked databases. Scrapes, Consumer Data, Collections of data or any other types of data should be shared in the "Other Leaks" section. The Databases section is strictly for databases which were breached and nothing else.

Threads that are also too vague (I.e. stuff titled "USA DATABASE") will be moved to Other Leaks as you didn't provide the source where the information originated from.

This message is automatically posted when a thread is moved to the Other Leaks Section. If this message seems to be a mistake, please disregard.
Ban reason: Legend (Permanent)
Reply
#3
probably a honeypot
Ban reason: Self-Ban (Retired) | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you wish to be unbanned in the future. (Permanent)
Reply
#4
@ctf Dunno try yourself if you got balls
Reply
#5
(06-19-2024, 07:53 PM)PulseCipher Wrote: @ctf Dunno try yourself if you got balls

Cant attack my own nation
Ban reason: Self-Ban (Retired) | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you wish to be unbanned in the future. (Permanent)
Reply
#6
(06-19-2024, 08:14 PM)ctf Wrote:
(06-19-2024, 07:53 PM)PulseCipher Wrote: @ctf Dunno try yourself if you got balls

Cant attack my own nation

AYO
Reply
#7
I agree with Ctf, it's likely a honeypot. SSL cert was renewed in late 2023 so someone is aware that the server is in use.
Reply
#8
The north korean gov will find you XDD
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  FiveM Server: Reskate Roleplay - (Server Files, Web PCU, Player DB & Payment Logs ByteHunter 9 359 02-09-2026, 01:04 PM
Last Post: Pentesterog
  FiveM Server: El Bajo Roleplay | DISCORD ID, STEAM ID, LICENSE, IP, and more. ByteHunter 10 424 02-03-2026, 01:22 AM
Last Post: vexyHDD
  SOURCE CODE South Korean - Me2.to - Full source code + Github PAT hexvior 2 406 01-27-2026, 06:23 PM
Last Post: takana
  A bunch of French shit, can't read it, but tons of files OriginalCrazyOldFart 11 670 01-25-2026, 06:13 AM
Last Post: OriginalCrazyOldFart
  North Platte Natural Resources District QilinRansom 0 506 04-09-2025, 08:19 PM
Last Post: QilinRansom



 Users browsing this thread: 1 Guest(s)