Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Alternatives for msdt, rft no click, and some possible improvements #1

Open
hastalamuerte opened this issue Apr 27, 2023 · 0 comments

Comments

@hastalamuerte
Copy link

hastalamuerte commented Apr 27, 2023

Is it possible to use a ps1 file as a command , or txt will ps payload , raw ps payload . Or maybe read payload from dns records with netstat. https://github.com/rtfmkiesel/goldig (extra cool)

what if use not msdt , can Ms word spawn something that can execute pwsh ?
Here is a bit of em what have bypass and execute options
nandisec/mshta@909383b
https://lolbas-project.github.io/#

And I know that some rft formats is work on older versions plz add them too, no click version is nice too
https://github.com/chvancooten/follina.py
https://github.com/JMousqueton/PoC-CVE-2022-30190

@komomon thanks for your version , use of real file is a usefull

@hastalamuerte hastalamuerte changed the title ps injector and more obf Alternatives for msdt, rft no click, and some possible improvements Apr 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant