[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8V3CEwMlpPWGWmmJJV35DwJGRWJ3ptiJpzf41sd7Y8A":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1019,"How does the LNK file's attribute flags field indicate the presence of a command-line arguments segment?","The attribute flags field at offset 0x14 is a 4-byte value where individual bits mark which optional segments are present. Bit 5 (value 0x20) corresponds to 'Command-line arguments exist'. In the example, the flag 0x000000F5 (binary 11110101) has bits 0, 2, 4, 5, and 6 set, meaning the LNK includes a shell item ID list, description string, working directory, command-line arguments, and custom icon. These flags guide the parser to locate and read each segment sequentially, as detailed in the article's LNK format breakdown.","\u003Cp>The attribute flags field at offset 0x14 is a 4-byte value where individual bits mark which optional segments are present. Bit 5 (value 0x20) corresponds to &#39;Command-line arguments exist&#39;. In the example, the flag 0x000000F5 (binary 11110101) has bits 0, 2, 4, 5, and 6 set, meaning the LNK includes a shell item ID list, description string, working directory, command-line arguments, and custom icon. These flags guide the parser to locate and read each segment sequentially, as detailed in the article&#39;s LNK format breakdown.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-parameter-hiding-techniques-in-shortcut-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-lnk-files-attribute-flags-field-indicate-the-presence-of-a-command--1777480680390","attribute flags, bit 5, command-line arguments segment, LNK format offsets, file structure",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},249,"Penetration Techniques - Parameter Hiding Techniques in Shortcut Files","penetration-techniques-parameter-hiding-techniques-in-shortcut-files","Explore parameter hiding techniques in shortcut files, including lnk format analysis, Delphi\u002FPowerShell POCs, and exploitation methods for bypassing 260-char limits.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, phrozensoft introduced exploitation techniques for shortcuts in a blog post, demonstrating how to embed applications within shortcut files. When users open the shortcut, a VBS script extracts and executes the application.\u003C\u002Fp>\u003Cp>I found this particularly interesting because shortcut parameters have a default length limit of 260 characters, a constraint I also encountered while researching jsrat (ultimately resolved by invoking an sct file to bypass the length restriction).\u003C\u002Fp>\u003Cp>phrozensoft shared POC code in Delphi format. This article will test it, study the lnk file format, develop corresponding POC code implemented in PowerShell, and briefly analyze the exploitation and defense methods of this technique.\u003C\u002Fp>\u003Cp>phrozensoft's blog address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.phrozensoft.com\u002F2016\u002F12\u002Fshortcuts-as-entry-points-for-malware-poc-part-2-19\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Delphi\u003C\u002Fh3>\u003Cp>A renowned rapid application development tool for the Windows platform\u003C\u002Fp>\u003Cp>Developed by Borland\u003C\u002Fp>\u003Cp>It can also be used to develop applications on the LINUX platform, with its counterpart product on LINUX being Kylix\u003C\u002Fp>\u003Cp>Common versions:\u003C\u002Fp>\u003Cul>\u003Cli>Borland Delphi 7\u003C\u002Fli>\u003Cli>Delphi 2010\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Delphi POC Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Phrozensoft's blog also shares POCs for other functionalities, such as a Python script for generating LNK files. This article will not cover those, focusing only on testing the Delphi POC.\u003C\u002Fp>\u003Cp>\u003Cstrong>Environment Setup:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test System: Win7 x86\u003C\u002Fp>\u003Cp>Delphi Version: Delphi 2010\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Delphi 7 results in a compilation error: 'File not found System.sysutils.dcu'\u003C\u002Fp>\u003Cp>After switching to Delphi 2010, the POC was slightly modified and compiled successfully.\u003C\u002Fp>\u003Ch3>1. Create a New Project\u003C\u002Fh3>\u003Cp>Open Delphi 2010\u003C\u002Fp>\u003Cp>Select File-New-Other-Console Application\u003C\u002Fp>\u003Cp>Directly pasting the POC code results in an error, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014876974_0_7b016839ac.png\">\u003C\u002Fp>\u003Ch3>2. Modify POC\u003C\u002Fh3>\u003Cp>After testing, System.SysUtils needs to be changed to SysUtils\u003C\u002Fp>\u003Cp>Compilation passed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014879203_1_1bf90950f0.png\">\u003C\u002Fp>\u003Ch3>3. Compile\u003C\u002Fh3>\u003Cp>Select Project-Build All Projects\u003C\u002Fp>\u003Cp>As shown, compilation succeeded, generating Project1.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014880331_2_4f29842fb9.png\">\u003C\u002Fp>\u003Ch3>4. Test\u003C\u002Fh3>\u003Cp>Create a new test.txt, fill it with data exceeding 260 characters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Execute the following command in cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate test.lnk\u003C\u002Fp>\u003Cp>View command-line parameters, only a string of length 260 can be seen, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014881915_3_b3b3be9ea3.png\">\u003C\u002Fp>\u003Cp>However, the size of the lnk file is 2.45kb, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014882524_4_c29a5edb5d.png\">\u003C\u002Fp>\u003Cp>(Looks like we've found something interesting)\u003C\u002Fp>\u003Cp>Opening test.lnk in cmd, the parameters of the lnk file execute normally, displaying characters exceeding 260 without truncation, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014883109_5_800c715b9a.png\">\u003C\u002Fp>\u003Cp>Using the hexadecimal editor Hex Editor to view the lnk file format, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014884014_6_f0593bfae9.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Unable to use UltraEdit, as UltraEdit opens lnk files by default to open the file pointed to by the lnk\u003C\u002Fp>\u003Cp>For example, as shown in the figure, pointing to cmd.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014885377_7_9aa5ac90b5.png\">\u003C\u002Fp>\u003Ch2>0x03 Introduction to Lnk File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Overall Structure\u003C\u002Fh3>\u003Cul>\u003Cli>File Header\u003C\u002Fli>\u003Cli>Shell Item Id List Segment\u003C\u002Fli>\u003Cli>File Location Information Segment\u003C\u002Fli>\u003Cli>Description Character Segment\u003C\u002Fli>\u003Cli>Relative Path Segment\u003C\u002Fli>\u003Cli>Working Directory Segment\u003C\u002Fli>\u003Cli>Command Line Segment\u003C\u002Fli>\u003Cli>Icon File Segment\u003C\u002Fli>\u003Cli>Additional Information Segment\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. File Header Structure\u003C\u002Fh3>\u003Cp>1.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0h | 4 bytes | Fixed value, character is L |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886127_8_914d1cfe83.jpeg\">\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 4h | 4 bytes | GUID |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886475_9_7d98d0e732.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 14h | 4 bytes | Attribute flags |\u003C\u002Fp>\u003Cp>Represent these four bytes in binary; if bits 0-6 are set to 1, they respectively indicate that the lnk file contains the following attributes:\u003C\u002Fp>\u003Cp>Bit 0: Has shell item ID list\u003C\u002Fp>\u003Cp>Bit 1: Points to a file or folder\u003C\u002Fp>\u003Cp>Bit 2: Contains a description string\u003C\u002Fp>\u003Cp>Bit 3: Contains a relative path\u003C\u002Fp>\u003Cp>Bit 4: Working directory exists\u003C\u002Fp>\u003Cp>Bit 5: Command-line arguments exist\u003C\u002Fp>\u003Cp>Bit 6: Custom icon exists\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886846_10_2a4ab050f1.jpeg\">\u003C\u002Fp>\u003Cp>Offset 14h, take 4 bytes as 000000f5, binary representation is 11110101\u003C\u002Fp>\u003Cp>Bits 0, 2, 4, 5, 6 are 1, corresponding to the following attributes:\u003C\u002Fp>\u003Cul>\u003Cli>Has shell item ID list\u003C\u002Fli>\u003Cli>Description string exists\u003C\u002Fli>\u003Cli>Working directory exists\u003C\u002Fli>\u003Cli>Command-line arguments exist\u003C\u002Fli>\u003Cli>Custom icon exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>4.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 18h | 4 bytes | Target file attributes\u003C\u002Fp>\u003Cp>| 1ch | 8 bytes | File creation time\u003C\u002Fp>\u003Cp>| 24h | 8 bytes | File modification time\u003C\u002Fp>\u003Cp>| 2ch | 8 bytes | File last access time\u003C\u002Fp>\u003Cp>| 34h | 4 bytes | Target file length\u003C\u002Fp>\u003Cp>| 38h | 4 bytes | Number of custom icons\u003C\u002Fp>\u003Cp>| 3ch | 4 bytes | Window execution mode: 1.Normal 2.Minimized 3.Maximized\u003C\u002Fp>\u003Cp>| 40h | 4 bytes | Hotkey\u003C\u002Fp>\u003Ch3>3. Shell Item ID List\u003C\u002Fh3>\u003Cp>The presence of a Shell Item ID List for test.lnk is determined from position 14h, so the first segment starting from 4ch is the Shell Item ID List\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 4ch | 2 bytes | Total length of Shell Item ID List |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887303_11_56258670fa.jpeg\">\u003C\u002Fp>\u003Cp>Total length of shell item id list is 0129\u003C\u002Fp>\u003Cp>Starting address of next segment (description string) is 004e+0129=0177h\u003C\u002Fp>\u003Ch3>4. Description String\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 004e+0129=0177h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887843_12_63181fd0c5.jpeg\">\u003C\u002Fp>\u003Cp>Description string length is 000c (Unicode)\u003C\u002Fp>\u003Cp>Starting address of next segment (working path) is 0177+2+000c×2=0191h\u003C\u002Fp>\u003Ch3>5. Working Path\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0177+2+000c×2=0191h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014888488_13_921ad13511.jpeg\">\u003C\u002Fp>\u003Cp>Working path length is 0012 (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (command line arguments) is 0191+2+0012×2=01b7h\u003C\u002Fp>\u003Ch3>6. Command line arguments\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0191+2+0012×2=01b7h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014889105_14_f5cdbdca34.jpeg\">\u003C\u002Fp>\u003Cp>Command line arguments length is 039f (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (custom icon) is 01b7+2+039f×2=08f7h\u003C\u002Fp>\u003Ch3>7. Custom icon\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 01b7+2+039f×2=08f7h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014889800_15_d1dfb84b63.jpeg\">\u003C\u002Fp>\u003Cp>Custom icon length is 000bf (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (custom icon) is 08f7+2+000b×2=090fh\u003C\u002Fp>\u003Ch2>0x04 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By comparing the differences between normal lnk files and POC files using Delphi POC code and Lnk file format, it was found that only the command-line parameter length differs\u003C\u002Fp>\u003Cp>Hence the principle is inferred:\u003C\u002Fp>\u003Cp>As long as the command-line parameter length exceeds 260!\u003C\u002Fp>\u003Cp>Test PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$file = Get-Content \"c:\\test\\test.txt\"\u003Cbr>$WshShell = New-Object -comObject WScript.Shell\u003Cbr>$Shortcut = $WshShell.CreateShortcut(\"c:\\test\\test.lnk\")\u003Cbr>$Shortcut.TargetPath = \"%SystemRoot%\\system32\\cmd.exe\"\u003Cbr>$Shortcut.IconLocation = \"%SystemRoot%\\System32\\Shell32.dll,21\"\u003Cbr>$Shortcut.Arguments = '                                                                                                                                                                                                                                      '+ $file\u003Cbr>$Shortcut.Save()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Write the following content into test.txt:\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, phrozensoft introduced exploitation techniques for shortcuts in a blog post, demonstrating how to embed applications within shortcut files. When users open the shortcut, a VBS script extracts and executes the application.\u003C\u002Fp>\u003Cp>I found this particularly interesting because shortcut parameters have a default length limit of 260 characters, a constraint I also encountered while researching jsrat (ultimately resolved by invoking an sct file to bypass the length restriction).\u003C\u002Fp>\u003Cp>phrozensoft shared POC code in Delphi format. This article will test it, study the lnk file format, develop corresponding POC code implemented in PowerShell, and briefly analyze the exploitation and defense methods of this technique.\u003C\u002Fp>\u003Cp>phrozensoft's blog address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.phrozensoft.com\u002F2016\u002F12\u002Fshortcuts-as-entry-points-for-malware-poc-part-2-19\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Delphi\u003C\u002Fh3>\u003Cp>A renowned rapid application development tool for the Windows platform\u003C\u002Fp>\u003Cp>Developed by Borland\u003C\u002Fp>\u003Cp>It can also be used to develop applications on the LINUX platform, with its counterpart product on LINUX being Kylix\u003C\u002Fp>\u003Cp>Common versions:\u003C\u002Fp>\u003Cul>\u003Cli>Borland Delphi 7\u003C\u002Fli>\u003Cli>Delphi 2010\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Delphi POC Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Phrozensoft's blog also shares POCs for other functionalities, such as a Python script for generating LNK files. This article will not cover those, focusing only on testing the Delphi POC.\u003C\u002Fp>\u003Cp>\u003Cstrong>Environment Setup:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test System: Win7 x86\u003C\u002Fp>\u003Cp>Delphi Version: Delphi 2010\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Delphi 7 results in a compilation error: 'File not found System.sysutils.dcu'\u003C\u002Fp>\u003Cp>After switching to Delphi 2010, the POC was slightly modified and compiled successfully.\u003C\u002Fp>\u003Ch3>1. Create a New Project\u003C\u002Fh3>\u003Cp>Open Delphi 2010\u003C\u002Fp>\u003Cp>Select File-New-Other-Console Application\u003C\u002Fp>\u003Cp>Directly pasting the POC code results in an error, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014876974_0_7b016839ac-1.png\">\u003C\u002Fp>\u003Ch3>2. Modify POC\u003C\u002Fh3>\u003Cp>After testing, System.SysUtils needs to be changed to SysUtils\u003C\u002Fp>\u003Cp>Compilation passed, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014879203_1_1bf90950f0-1.png\">\u003C\u002Fp>\u003Ch3>3. Compile\u003C\u002Fh3>\u003Cp>Select Project-Build All Projects\u003C\u002Fp>\u003Cp>As shown, compilation succeeded, generating Project1.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014880331_2_4f29842fb9-1.png\">\u003C\u002Fp>\u003Ch3>4. Test\u003C\u002Fh3>\u003Cp>Create a new test.txt, fill it with data exceeding 260 characters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>Execute the following command in cmd:\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate test.lnk\u003C\u002Fp>\u003Cp>View command-line parameters, only a string of length 260 can be seen, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014881915_3_b3b3be9ea3-1.png\">\u003C\u002Fp>\u003Cp>However, the size of the lnk file is 2.45kb, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014882524_4_c29a5edb5d-1.png\">\u003C\u002Fp>\u003Cp>(Looks like we've found something interesting)\u003C\u002Fp>\u003Cp>Opening test.lnk in cmd, the parameters of the lnk file execute normally, displaying characters exceeding 260 without truncation, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014883109_5_800c715b9a-1.png\">\u003C\u002Fp>\u003Cp>Using the hexadecimal editor Hex Editor to view the lnk file format, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014884014_6_f0593bfae9-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Unable to use UltraEdit, as UltraEdit opens lnk files by default to open the file pointed to by the lnk\u003C\u002Fp>\u003Cp>For example, as shown in the figure, pointing to cmd.exe\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014885377_7_9aa5ac90b5-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Introduction to Lnk File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Overall Structure\u003C\u002Fh3>\u003Cul>\u003Cli>File Header\u003C\u002Fli>\u003Cli>Shell Item Id List Segment\u003C\u002Fli>\u003Cli>File Location Information Segment\u003C\u002Fli>\u003Cli>Description Character Segment\u003C\u002Fli>\u003Cli>Relative Path Segment\u003C\u002Fli>\u003Cli>Working Directory Segment\u003C\u002Fli>\u003Cli>Command Line Segment\u003C\u002Fli>\u003Cli>Icon File Segment\u003C\u002Fli>\u003Cli>Additional Information Segment\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. File Header Structure\u003C\u002Fh3>\u003Cp>1.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0h | 4 bytes | Fixed value, character is L |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886127_8_914d1cfe83-1.jpeg\">\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 4h | 4 bytes | GUID |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886475_9_7d98d0e732-1.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 14h | 4 bytes | Attribute flags |\u003C\u002Fp>\u003Cp>Represent these four bytes in binary; if bits 0-6 are set to 1, they respectively indicate that the lnk file contains the following attributes:\u003C\u002Fp>\u003Cp>Bit 0: Has shell item ID list\u003C\u002Fp>\u003Cp>Bit 1: Points to a file or folder\u003C\u002Fp>\u003Cp>Bit 2: Contains a description string\u003C\u002Fp>\u003Cp>Bit 3: Contains a relative path\u003C\u002Fp>\u003Cp>Bit 4: Working directory exists\u003C\u002Fp>\u003Cp>Bit 5: Command-line arguments exist\u003C\u002Fp>\u003Cp>Bit 6: Custom icon exists\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886846_10_2a4ab050f1-1.jpeg\">\u003C\u002Fp>\u003Cp>Offset 14h, take 4 bytes as 000000f5, binary representation is 11110101\u003C\u002Fp>\u003Cp>Bits 0, 2, 4, 5, 6 are 1, corresponding to the following attributes:\u003C\u002Fp>\u003Cul>\u003Cli>Has shell item ID list\u003C\u002Fli>\u003Cli>Description string exists\u003C\u002Fli>\u003Cli>Working directory exists\u003C\u002Fli>\u003Cli>Command-line arguments exist\u003C\u002Fli>\u003Cli>Custom icon exists\u003C\u002Fli>\u003C\u002Ful>\u003Cp>4.\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 18h | 4 bytes | Target file attributes\u003C\u002Fp>\u003Cp>| 1ch | 8 bytes | File creation time\u003C\u002Fp>\u003Cp>| 24h | 8 bytes | File modification time\u003C\u002Fp>\u003Cp>| 2ch | 8 bytes | File last access time\u003C\u002Fp>\u003Cp>| 34h | 4 bytes | Target file length\u003C\u002Fp>\u003Cp>| 38h | 4 bytes | Number of custom icons\u003C\u002Fp>\u003Cp>| 3ch | 4 bytes | Window execution mode: 1.Normal 2.Minimized 3.Maximized\u003C\u002Fp>\u003Cp>| 40h | 4 bytes | Hotkey\u003C\u002Fp>\u003Ch3>3. Shell Item ID List\u003C\u002Fh3>\u003Cp>The presence of a Shell Item ID List for test.lnk is determined from position 14h, so the first segment starting from 4ch is the Shell Item ID List\u003C\u002Fp>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 4ch | 2 bytes | Total length of Shell Item ID List |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887303_11_56258670fa-1.jpeg\">\u003C\u002Fp>\u003Cp>Total length of shell item id list is 0129\u003C\u002Fp>\u003Cp>Starting address of next segment (description string) is 004e+0129=0177h\u003C\u002Fp>\u003Ch3>4. Description String\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 004e+0129=0177h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887843_12_63181fd0c5-1.jpeg\">\u003C\u002Fp>\u003Cp>Description string length is 000c (Unicode)\u003C\u002Fp>\u003Cp>Starting address of next segment (working path) is 0177+2+000c×2=0191h\u003C\u002Fp>\u003Ch3>5. Working Path\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0177+2+000c×2=0191h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014888488_13_921ad13511-1.jpeg\">\u003C\u002Fp>\u003Cp>Working path length is 0012 (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (command line arguments) is 0191+2+0012×2=01b7h\u003C\u002Fp>\u003Ch3>6. Command line arguments\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 0191+2+0012×2=01b7h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014889105_14_f5cdbdca34-1.jpeg\">\u003C\u002Fp>\u003Cp>Command line arguments length is 039f (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (custom icon) is 01b7+2+039f×2=08f7h\u003C\u002Fp>\u003Ch3>7. Custom icon\u003C\u002Fh3>\u003Cp>| Offset | Length | Description |\u003C\u002Fp>\u003Cp>|:--:|:--:|:--:|\u003C\u002Fp>\u003Cp>| 01b7+2+039f×2=08f7h | 2 bytes | Length (Unicode), actual length should be multiplied by 2 |\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014889800_15_d1dfb84b63-1.jpeg\">\u003C\u002Fp>\u003Cp>Custom icon length is 000bf (Unicode)\u003C\u002Fp>\u003Cp>The starting address of the next segment (custom icon) is 08f7+2+000b×2=090fh\u003C\u002Fp>\u003Ch2>0x04 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By comparing the differences between normal lnk files and POC files using Delphi POC code and Lnk file format, it was found that only the command-line parameter length differs\u003C\u002Fp>\u003Cp>Hence the principle is inferred:\u003C\u002Fp>\u003Cp>As long as the command-line parameter length exceeds 260!\u003C\u002Fp>\u003Cp>Test PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$file = Get-Content \"c:\\test\\test.txt\"\u003Cbr>$WshShell = New-Object -comObject WScript.Shell\u003Cbr>$Shortcut = $WshShell.CreateShortcut(\"c:\\test\\test.lnk\")\u003Cbr>$Shortcut.TargetPath = \"%SystemRoot%\\system32\\cmd.exe\"\u003Cbr>$Shortcut.IconLocation = \"%SystemRoot%\\System32\\Shell32.dll,21\"\u003Cbr>$Shortcut.Arguments = '                                                                                                                                                                                                                                      '+ $file\u003Cbr>$Shortcut.Save()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Write the following content into test.txt:\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",419,"Onedaysec",5,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Parameter Hiding in Shortcut Files: Penetration Techniques & POC","shortcut exploitation, lnk file format, parameter hiding, penetration techniques, PowerShell POC, malware entry points, Delphi POC, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],1020,1018,1017,1016,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.187Z","2026-07-23T16:02:26.191Z","draft","2026-07-23T16:16:09.798Z"]