{"id":2534,"date":"2021-04-27T21:08:57","date_gmt":"2021-04-28T02:08:57","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2534"},"modified":"2021-04-27T21:09:13","modified_gmt":"2021-04-28T02:09:13","slug":"eternalromance-a-very-dangerous-vulnerability","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/","title":{"rendered":"EternalRomance, a very dangerous vulnerability"},"content":{"rendered":"\n<p>The SMB EternalRomance exploit from the list of leaked vulnerabilities used by the NSA \/ FuzzBunch that targets Windows XP \/ Vista \/ 7, also Windows Server 2003\/2008, its main feature is that it attacks through SMB (Port 445), having as a result the control of the target machine. In Sheila Berta&#8217;s paper it was demonstrated how an unauthenticated attack can exploit a Windows 7\/2008 target vulnerable to EternalBlue, DoublePulsar and Empire. This guide will show how to exploit a Windows Server 2003 SP1 x86 using FuzzBunch&#8217;s EternalRomance exploit. It should be considered that the exploitation process is quite similar to that of EternalBlue, except that DoublePulsar will be used to generate a shellcode that will be used by EternalRomance.<\/p>\n\n\n\n<p>Some time ago an exploit was published that takes advantage of the ETERNALROMANCE \/ SYNERGY bug, with improvements in the exploitation method, to make it more stable when attacking systems with Windows Server 2012 and 2016. But the truth is that, in the true style of Its author (Sleepya), if you want to use this exploit you need to figure out a bit, understand how it works and modify some small things to achieve that, when hitting a target, whatever we want happens.<\/p>\n\n\n\n<p>Recent ransomware incidents have been attributed in part to NSA hacking tools, in particular the EternalBlue exploit. In most cases, these tools could only be used against &#8220;old&#8221; versions of the Windows operating system. However, a modified version of the EternalSynergy exploit has been used against newer versions of Windows.<\/p>\n\n\n\n<p>The new version of EternalSynergy affects a long list of Windows versions, including Windows 8.1, Windows Server 2012 and 2016. Wang says that, for now, Windows 10 users are protected, but that &#8220;this could change.&#8221; As a result, around 75% of all Windows-operated computers worldwide are vulnerable to the new version of EternalSynergy.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/crlf-injection-a-vulnerability-that-attacks-servers\/\">CRLF Injection \u2013 A Vulnerability that attacks servers<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/arduino-vulnerability-that-appeared-over-time\/\">Arduino Vulnerability that appeared over time<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The SMB EternalRomance exploit from the list of leaked vulnerabilities used by the NSA \/ FuzzBunch that targets Windows XP \/ Vista \/ 7, also Windows Server 2003\/2008, its main feature is that it attacks through SMB (Port 445), having as a result the control of the target machine. In Sheila Berta&#8217;s paper it was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2535,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2534","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>EternalRomance, a very dangerous vulnerability - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"EternalRomance is a vulnerability that attacks Windows XP \/ Vista \/ 7 in addition to many others which we will see and analyze today....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EternalRomance, a very dangerous vulnerability - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"EternalRomance is a vulnerability that attacks Windows XP \/ Vista \/ 7 in addition to many others which we will see and analyze today....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-28T02:08:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-28T02:09:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"EternalRomance, a very dangerous vulnerability\",\"datePublished\":\"2021-04-28T02:08:57+00:00\",\"dateModified\":\"2021-04-28T02:09:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/\"},\"wordCount\":312,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Ciberataque.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/\",\"name\":\"EternalRomance, a very dangerous vulnerability - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Ciberataque.jpg\",\"datePublished\":\"2021-04-28T02:08:57+00:00\",\"dateModified\":\"2021-04-28T02:09:13+00:00\",\"description\":\"EternalRomance is a vulnerability that attacks Windows XP \\\/ Vista \\\/ 7 in addition to many others which we will see and analyze today....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Ciberataque.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Ciberataque.jpg\",\"width\":1024,\"height\":512},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/eternalromance-a-very-dangerous-vulnerability\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"EternalRomance, a very dangerous vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"EternalRomance, a very dangerous vulnerability - Truxgo Server Blog","description":"EternalRomance is a vulnerability that attacks Windows XP \/ Vista \/ 7 in addition to many others which we will see and analyze today....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/","og_locale":"es_MX","og_type":"article","og_title":"EternalRomance, a very dangerous vulnerability - Truxgo Server Blog","og_description":"EternalRomance is a vulnerability that attacks Windows XP \/ Vista \/ 7 in addition to many others which we will see and analyze today....","og_url":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-04-28T02:08:57+00:00","article_modified_time":"2021-04-28T02:09:13+00:00","og_image":[{"width":1024,"height":512,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"EternalRomance, a very dangerous vulnerability","datePublished":"2021-04-28T02:08:57+00:00","dateModified":"2021-04-28T02:09:13+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/"},"wordCount":312,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/","url":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/","name":"EternalRomance, a very dangerous vulnerability - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg","datePublished":"2021-04-28T02:08:57+00:00","dateModified":"2021-04-28T02:09:13+00:00","description":"EternalRomance is a vulnerability that attacks Windows XP \/ Vista \/ 7 in addition to many others which we will see and analyze today....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/Ciberataque.jpg","width":1024,"height":512},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/eternalromance-a-very-dangerous-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"EternalRomance, a very dangerous vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2534"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2534\/revisions"}],"predecessor-version":[{"id":2549,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2534\/revisions\/2549"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2535"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}