Skip to content

Instantly share code, notes, and snippets.

View stempelo's full-sized avatar

Matteo Boffo aka stempelo stempelo

View GitHub Profile
@stempelo
stempelo / Various-Macro-Based-RCEs.md
Created December 27, 2018 15:02 — forked from mgeeky/Various-Macro-Based-RCEs.md
Various Visual Basic Macros-based Remote Code Execution techniques to get your meterpreter invoked on the infected machine.

This is a note for myself describing various Visual Basic macros construction strategies that could be used for remote code execution via malicious Document vector. Nothing new or fancy here, just a list of techniques, tools and scripts collected in one place for a quick glimpse of an eye before setting a payload.

All of the below examples had been generated for using as a remote address: 192.168.56.101.

List:

  1. Page substiution macro for luring user to click Enable Content
  2. The Unicorn Powershell based payload