[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_8mBSWYnAQ8XTW9j3B9OtoYntpN2Vb_AjTxSpt64f6A":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},691,"How can an attacker modify IE browser settings to allow automatic clipboard access?","An attacker with system permissions can modify Internet Explorer's security zones to enable programmatic clipboard access. The registry key `HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3` with value `1407` set to `0` (allow) allows IE to read the clipboard without prompting. The command `REG ADD \"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\" \u002Fv 1407 \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff` enables this. After restarting IE, any webpage can silently retrieve clipboard data. This technique is explained in [Penetration Techniques - Exploitation of Clipboard in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-clipboard-in-windows).","\u003Cp>An attacker with system permissions can modify Internet Explorer&#39;s security zones to enable programmatic clipboard access. The registry key `HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3` with value `1407` set to `0` (allow) allows IE to read the clipboard without prompting. The command `REG ADD &quot;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3&quot; \u002Fv 1407 \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff` enables this. After restarting IE, any webpage can silently retrieve clipboard data. This technique is explained in [Penetration Techniques - Exploitation of Clipboard in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-clipboard-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-exploitation-of-clipboard-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-modify-ie-browser-settings-to-allow-automatic-clipboard-acce-1777482417301","IE clipboard access, registry modification, programmatic clipboard access, Internet Explorer security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},171,"Penetration Techniques - Exploitation of Clipboard in Windows","penetration-techniques-exploitation-of-clipboard-in-windows","Explore Windows clipboard exploitation techniques: writing\u002Freading methods, real-time monitoring for penetration testing, and pastejacking risks. Learn security implications.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, the clipboard is a common feature. What aspects of it can be exploited? This article will attempt to organize this content.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to write to the clipboard\u003C\u002Fli>\u003Cli>Methods to read from the clipboard\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Clipboard Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The clipboard refers to a module provided by the Windows operating system for temporarily storing and sharing data, which can be understood as a data transfer station.\u003C\u002Fp>\u003Cp>The content of the clipboard is stored in memory, so the saved data is lost after a system restart.\u003C\u002Fp>\u003Cp>The XP system supports the clipboard viewer clipbrd.exe (removed after Win7), which can be used to view clipboard content.\u003C\u002Fp>\u003Cp>The clipboard viewer clipbrd.exe does not require installation and can be used directly on other systems (e.g., Win7).\u003C\u002Fp>\u003Cp>After copying data, the copied content is displayed in real-time in the clipboard viewer clipbrd.exe, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017305522_0_09ced6f64e.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Methods for writing to the clipboard\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ctrl+C\u003C\u002Fh3>\u003Cp>Copy data, or use the shortcut Ctrl+C to save data to the clipboard.\u003C\u002Fp>\u003Ch3>2. Methods in cmd\u003C\u002Fh3>\u003Cp>Copy the output of whoami to the clipboard:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami|clip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017329260_1_5f4fccfaa4.jpeg\">\u003C\u002Fp>\u003Cp>Copy the content of 11.txt to the clipboard:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>clip&lt;11.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017380283_2_58493d0d75.jpeg\">\u003C\u002Fp>\u003Ch3>3. Program calls API to implement\u003C\u002Fh3>\u003Cp>C++ test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>BOOL CopyToClipboard(char* pszData)\u003Cbr>{\u003Cbr>    if(::OpenClipboard(NULL))\u003Cbr>    {\u003Cbr>        ::EmptyClipboard();\u003Cbr>        HGLOBAL clipbuffer;\u003Cbr>        char *buffer;\u003Cbr>        clipbuffer = ::GlobalAlloc(GMEM_DDESHARE, strlen(pszData)+1);\u003Cbr>        buffer = (char *)::GlobalLock(clipbuffer);\u003Cbr>        strcpy_s(buffer,strlen(pszData)+1, pszData);\u003Cbr>        ::GlobalUnlock(clipbuffer);\u003Cbr>        ::SetClipboardData(CF_TEXT, clipbuffer);\u003Cbr>        ::CloseClipboard();\u003Cbr>        return TRUE;\u003Cbr>    }\u003Cbr>    return FALSE;\u003Cbr>}\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tCopyToClipboard(\"clipcopydatatest\");\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017401105_3_5ed5776936.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Reading Clipboard Content\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ctrl+V\u003C\u002Fh3>\u003Cp>Paste data, or use the shortcut Ctrl+V to read data saved in the clipboard.\u003C\u002Fp>\u003Ch3>2. Read Tool\u003C\u002Fh3>\u003Cp>Clipboard Viewer clipbrd.exe\u003C\u002Fp>\u003Ch3>3. Program Calling API Implementation\u003C\u002Fh3>\u003Cp>C++ test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>BOOL GetTextFromClipboard()\u003Cbr>{\u003Cbr>    if(::OpenClipboard(NULL))\u003Cbr>    {\u003Cbr>        \u003Cbr>        HGLOBAL hMem = GetClipboardData(CF_TEXT);\u003Cbr>        if(NULL != hMem)\u003Cbr>        {\u003Cbr>            char* lpStr = (char*)::GlobalLock(hMem); \u003Cbr>            if(NULL != lpStr)\u003Cbr>            {\u003Cbr>                printf(\"%s\",lpStr);\u003Cbr>                ::GlobalUnlock(hMem);\u003Cbr>            }\u003Cbr>        }\u003Cbr>        ::CloseClipboard();\u003Cbr>        return TRUE;\u003Cbr>    }\u003Cbr>    return FALSE;\u003Cbr>}\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tGetTextFromClipboard();\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully read clipboard content, execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017447692_4_7a28632d91.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also simulate keyboard input Ctrl+V to obtain clipboard content\u003C\u002Fp>\u003Ch2>0x05 Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Real-time capture of clipboard content\u003C\u002Fh3>\u003Cp>During penetration testing, after gaining system control, attempts are made to read the user's clipboard content to obtain valuable information\u003C\u002Fp>\u003Cp>In practical exploitation, it is best to capture clipboard content in real-time, combined with keylogging, to comprehensively monitor the user's login input\u003C\u002Fp>\u003Cp>In program implementation, a loop check can be added; if the clipboard content changes, record it\u003C\u002Fp>\u003Ch4>(1) Using C++ to read the current system's clipboard information\u003C\u002Fh4>\u003Cp>Refer to the previous section for code, add loop checks and file writing functionality; code is omitted for now\u003C\u002Fp>\u003Ch4>(2) Using PowerShell to read the current system's clipboard information\u003C\u002Fh4>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcollection\u002FGet-ClipboardContents.ps1\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017469778_5_a78d6dba88.jpeg\">\u003C\u002Fp>\u003Ch3>2. Pastejacking\u003C\u002Fh3>\u003Cp>Used as a phishing site to deceive users into copying a segment of content from the URL, hijacking the copyTextToClipboard event, and adding malicious code to the copied content\u003C\u002Fp>\u003Cp>Copied content: echo \"not evil\", actual clipboard content obtained: echo \"evil\"\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017482557_6_b6214d5104.jpeg\">\u003C\u002Fp>\u003Ch3>3. Modify configuration to allow IE browser to read clipboard content\u003C\u002Fh3>\u003Cp>Page content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cscript type=\"text\u002Fjavascript\">\u003Cbr>var content = clipboardData.getData(\"Text\");\u003Cbr>if (content!=null) \u003Cbr>{\u003Cbr>\tdocument.write(content);\u003Cbr>}\u003Cbr>else \u003Cbr>{\u003Cbr>  \tdocument.write('No text found in clipboard.');\u003Cbr>}\u003Cbr>\u003C\u002Fscript>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When users access via Internet Explorer, a dialog box will pop up by default asking whether to allow the webpage to access the clipboard\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017493067_7_cf5e2f678c.jpeg\">\u003C\u002Fp>\u003Cp>After selecting 'Allow Access', the webpage obtains the clipboard content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017502200_8_1b34aff2f0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Chrome and Firefox browsers do not allow access to user clipboard content via getData\u003C\u002Fp>\u003Cp>If system permissions are obtained, IE configuration can be modified to allow web pages to access the clipboard\u003C\u002Fp>\u003Cp>The modification method is as follows:\u003C\u002Fp>\u003Cp>Internet Options -&gt; Security -&gt; Custom Level\u003C\u002Fp>\u003Cp>Settings -&gt; Scripting -&gt; Allow programmatic clipboard access -&gt; Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507656_9_6d93d090c5.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding registry key value 1407 under HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates allow\u003C\u002Fli>\u003Cli>1 indicates prompt\u003C\u002Fli>\u003Cli>3 indicates prohibit\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command to modify registry settings to allow clipboard access is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\" \u002Fv 1407 \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After restarting the IE browser, the configuration takes effect\u003C\u002Fp>\u003Cp>Accessing the webpage automatically obtains clipboard content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017512988_10_2ec281d12c.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation techniques related to the clipboard in penetration testing on Windows systems, demonstrating post-exploitation methods through examples.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, the clipboard is a common feature. What aspects of it can be exploited? This article will attempt to organize this content.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to write to the clipboard\u003C\u002Fli>\u003Cli>Methods to read from the clipboard\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Clipboard Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The clipboard refers to a module provided by the Windows operating system for temporarily storing and sharing data, which can be understood as a data transfer station.\u003C\u002Fp>\u003Cp>The content of the clipboard is stored in memory, so the saved data is lost after a system restart.\u003C\u002Fp>\u003Cp>The XP system supports the clipboard viewer clipbrd.exe (removed after Win7), which can be used to view clipboard content.\u003C\u002Fp>\u003Cp>The clipboard viewer clipbrd.exe does not require installation and can be used directly on other systems (e.g., Win7).\u003C\u002Fp>\u003Cp>After copying data, the copied content is displayed in real-time in the clipboard viewer clipbrd.exe, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017305522_0_09ced6f64e-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Methods for writing to the clipboard\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ctrl+C\u003C\u002Fh3>\u003Cp>Copy data, or use the shortcut Ctrl+C to save data to the clipboard.\u003C\u002Fp>\u003Ch3>2. Methods in cmd\u003C\u002Fh3>\u003Cp>Copy the output of whoami to the clipboard:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami|clip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017329260_1_5f4fccfaa4-1.jpeg\">\u003C\u002Fp>\u003Cp>Copy the content of 11.txt to the clipboard:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>clip&lt;11.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017380283_2_58493d0d75-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Program calls API to implement\u003C\u002Fh3>\u003Cp>C++ test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>BOOL CopyToClipboard(char* pszData)\u003Cbr>{\u003Cbr>    if(::OpenClipboard(NULL))\u003Cbr>    {\u003Cbr>        ::EmptyClipboard();\u003Cbr>        HGLOBAL clipbuffer;\u003Cbr>        char *buffer;\u003Cbr>        clipbuffer = ::GlobalAlloc(GMEM_DDESHARE, strlen(pszData)+1);\u003Cbr>        buffer = (char *)::GlobalLock(clipbuffer);\u003Cbr>        strcpy_s(buffer,strlen(pszData)+1, pszData);\u003Cbr>        ::GlobalUnlock(clipbuffer);\u003Cbr>        ::SetClipboardData(CF_TEXT, clipbuffer);\u003Cbr>        ::CloseClipboard();\u003Cbr>        return TRUE;\u003Cbr>    }\u003Cbr>    return FALSE;\u003Cbr>}\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tCopyToClipboard(\"clipcopydatatest\");\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017401105_3_5ed5776936-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Reading Clipboard Content\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ctrl+V\u003C\u002Fh3>\u003Cp>Paste data, or use the shortcut Ctrl+V to read data saved in the clipboard.\u003C\u002Fp>\u003Ch3>2. Read Tool\u003C\u002Fh3>\u003Cp>Clipboard Viewer clipbrd.exe\u003C\u002Fp>\u003Ch3>3. Program Calling API Implementation\u003C\u002Fh3>\u003Cp>C++ test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>BOOL GetTextFromClipboard()\u003Cbr>{\u003Cbr>    if(::OpenClipboard(NULL))\u003Cbr>    {\u003Cbr>        \u003Cbr>        HGLOBAL hMem = GetClipboardData(CF_TEXT);\u003Cbr>        if(NULL != hMem)\u003Cbr>        {\u003Cbr>            char* lpStr = (char*)::GlobalLock(hMem); \u003Cbr>            if(NULL != lpStr)\u003Cbr>            {\u003Cbr>                printf(\"%s\",lpStr);\u003Cbr>                ::GlobalUnlock(hMem);\u003Cbr>            }\u003Cbr>        }\u003Cbr>        ::CloseClipboard();\u003Cbr>        return TRUE;\u003Cbr>    }\u003Cbr>    return FALSE;\u003Cbr>}\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tGetTextFromClipboard();\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully read clipboard content, execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017447692_4_7a28632d91-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also simulate keyboard input Ctrl+V to obtain clipboard content\u003C\u002Fp>\u003Ch2>0x05 Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Real-time capture of clipboard content\u003C\u002Fh3>\u003Cp>During penetration testing, after gaining system control, attempts are made to read the user's clipboard content to obtain valuable information\u003C\u002Fp>\u003Cp>In practical exploitation, it is best to capture clipboard content in real-time, combined with keylogging, to comprehensively monitor the user's login input\u003C\u002Fp>\u003Cp>In program implementation, a loop check can be added; if the clipboard content changes, record it\u003C\u002Fp>\u003Ch4>(1) Using C++ to read the current system's clipboard information\u003C\u002Fh4>\u003Cp>Refer to the previous section for code, add loop checks and file writing functionality; code is omitted for now\u003C\u002Fp>\u003Ch4>(2) Using PowerShell to read the current system's clipboard information\u003C\u002Fh4>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcollection\u002FGet-ClipboardContents.ps1\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017469778_5_a78d6dba88-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Pastejacking\u003C\u002Fh3>\u003Cp>Used as a phishing site to deceive users into copying a segment of content from the URL, hijacking the copyTextToClipboard event, and adding malicious code to the copied content\u003C\u002Fp>\u003Cp>Copied content: echo \"not evil\", actual clipboard content obtained: echo \"evil\"\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017482557_6_b6214d5104-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Modify configuration to allow IE browser to read clipboard content\u003C\u002Fh3>\u003Cp>Page content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>\u003Cscript type=\"text\u002Fjavascript\">\u003Cbr>var content = clipboardData.getData(\"Text\");\u003Cbr>if (content!=null) \u003Cbr>{\u003Cbr>\tdocument.write(content);\u003Cbr>}\u003Cbr>else \u003Cbr>{\u003Cbr>  \tdocument.write('No text found in clipboard.');\u003Cbr>}\u003Cbr>\u003C\u002Fscript>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When users access via Internet Explorer, a dialog box will pop up by default asking whether to allow the webpage to access the clipboard\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017493067_7_cf5e2f678c-1.jpeg\">\u003C\u002Fp>\u003Cp>After selecting 'Allow Access', the webpage obtains the clipboard content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017502200_8_1b34aff2f0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Chrome and Firefox browsers do not allow access to user clipboard content via getData\u003C\u002Fp>\u003Cp>If system permissions are obtained, IE configuration can be modified to allow web pages to access the clipboard\u003C\u002Fp>\u003Cp>The modification method is as follows:\u003C\u002Fp>\u003Cp>Internet Options -&gt; Security -&gt; Custom Level\u003C\u002Fp>\u003Cp>Settings -&gt; Scripting -&gt; Allow programmatic clipboard access -&gt; Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507656_9_6d93d090c5-1.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding registry key value 1407 under HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates allow\u003C\u002Fli>\u003Cli>1 indicates prompt\u003C\u002Fli>\u003Cli>3 indicates prohibit\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The command to modify registry settings to allow clipboard access is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\" \u002Fv 1407 \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After restarting the IE browser, the configuration takes effect\u003C\u002Fp>\u003Cp>Accessing the webpage automatically obtains clipboard content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017512988_10_2ec281d12c-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation techniques related to the clipboard in penetration testing on Windows systems, demonstrating post-exploitation methods through examples.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",783,"Onedaysec",4,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Clipboard Exploitation: Penetration Techniques & Security Risks","Windows clipboard exploitation, penetration testing, clipboard security, pastejacking, real-time monitoring, C++ API, PowerShell, data theft, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],690,689,688,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.847Z","2026-07-23T16:01:57.564Z","draft","2026-07-23T16:14:12.755Z"]