nccgroup / cve-2017-8759 Goto Github PK
View Code? Open in Web Editor NEWNCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements
NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements
I am trying to following your instructions using the "URL Moniker" case and I am having some issues. I downloaded the file, which contains CVE-2017-8759.ppsx, logo.png and w00t.hta. In the 'Embedding a link' section, it appears you opened the PowerPoint exploit file(i am assuming it is CVE-2017-8759) and link a file called 'hello.pptx.' So you're embedding hello.pptx: why? Does hello.pptx have anything special in particular? How do I modify the the path to include the moniker URL? Also, you mention adding a URL to the HTA file: the HTA file you provided does not appear to take a URL. The png file, on the other hand does appear to take in the attacker specified URL.
Regards.
Hey man really great work you've done. Just wanted to know how to edit the ppsx file to point to another url?
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.