[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fULlQoPFTmZ3rjIAT2GRQpGRSiB3wvWEnvA4ENjgVVWI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1065,"What is Windows Attachment Manager and how does it mark downloaded files as untrusted?","Windows Attachment Manager is a security feature introduced in Windows XP SP2 that blocks or warns before executing files from untrusted sources like the internet or email. It tags such files with an Alternate Data Stream (ADS) named `Zone.Identifier:$DATA`, which contains `[ZoneTransfer] ZoneId=3`. When you try to open a file with this ADS, a confirmation dialog appears. For more details, see [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager).","\u003Cp>Windows Attachment Manager is a security feature introduced in Windows XP SP2 that blocks or warns before executing files from untrusted sources like the internet or email. It tags such files with an Alternate Data Stream (ADS) named `Zone.Identifier:$DATA`, which contains `[ZoneTransfer] ZoneId=3`. When you try to open a file with this ADS, a confirmation dialog appears. For more details, see [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-windows-attachment-manager-and-how-does-it-mark-downloaded-files-as-untr-1777480865560","Windows Attachment Manager, ADS, Zone.Identifier, ZoneId, untrusted files",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},260,"An interesting way of bypassing Windows Attachment Manager","an-interesting-way-of-bypassing-windows-attachment-manager","Learn how to bypass Windows Attachment Manager using ADS removal and LNK file techniques. Exploit Zone.Identifier:$DATA to avoid untrusted file prompts.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently I came across an article titled 'Bypassing Windows Attachment Manager' by rvrsh3ll@424f424f, which introduced his approach to bypassing Windows Attachment Manager in a very interesting way.\u003C\u002Fp>\u003Cp>Coincidentally, I have conducted research on the utilization of ADS and lnk files mentioned in the article. Therefore, this article will combine some of my insights to provide an extended introduction to this bypass method and share an interesting issue I discovered during actual testing.\u003C\u002Fp>\u003Cp>The related article addresses are as follows:\u003C\u002Fp>\u003Cp>'Bypassing Windows Attachment Manager':\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.rvrsh3ll.net\u002Fblog\u002Finformational\u002Fbypassing-windows-attachment-manager\u002F\u003C\u002Fp>\u003Cp>Some of my previous research insights:\u003C\u002Fp>\u003Cp>'Penetration Techniques – Parameter Hiding Techniques in Shortcut Files'\u003C\u002Fp>\u003Cp>'Advanced Exploitation Techniques for Hidden Alternative Data Streams'\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The role of Windows Attachment Manager\u003C\u002Fli>\u003Cli>Implementation of Windows Attachment Manager\u003C\u002Fli>\u003Cli>Bypass Techniques for Windows Attachment Manager\u003C\u002Fli>\u003Cli>Construction of Special Files\u003C\u002Fli>\u003Cli>Interesting Issues Discovered During Actual Testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Windows Attachment Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cul>\u003Cli>A new feature introduced by Microsoft since Windows XP SP2\u003C\u002Fli>\u003Cli>Designed to prevent files downloaded from untrusted sources from being executed directly\u003C\u002Fli>\u003Cli>Untrusted sources include email and internet downloads\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If a file is found to originate from an untrusted source, a dialog box will prompt the user upon opening, requiring user confirmation before execution, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015593496_0_6ecd2d34c5.jpeg\">\u003C\u002Fp>\u003Cp>File formats marked as High-risk are as follows:\u003C\u002Fp>\u003Cp>.ade, .adp, .app, .asp, .bas, .bat, .cer, .chm, .cmd, .com, .cpl, .crt, .csh, .exe, .fxp, .hlp, .hta, .inf, .ins, .isp, .its, .js, .jse, .ksh, .lnk, .mad, .maf, .mag, .mam, .maq, .mar, .mas, .mat, .mau, .mav, .maw, .mda, .mdb, .mde, .mdt, .mdw, .mdz, .msc, .msi, .msp, .mst, .ops, .pcd, .pif, .prf, .prg, .pst, .reg, .scf, .scr, .sct, .shb, .shs, .tmp, .url, .vb, .vbe, .vbs, .vsmacros, .vss, .vst, .vsw, .ws, .wsc, .wsf, .wsh\u003C\u002Fp>\u003Cp>For detailed information, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F883260\u002Finformation-about-the-attachment-manager-in-microsoft-windows\u003C\u002Fp>\u003Ch3>Implementation Method\u003C\u002Fh3>\u003Cp>Untrusted files are tagged with ADS:Zone.Identifier:$DATA upon download\u003C\u002Fp>\u003Cp>Detailed content of ADS is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[ZoneTransfer]\u003Cbr>ZoneId=3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>That is, as long as a file contains ADS:Zone.Identifier:$DATA, a prompt will appear when opening it, requiring user confirmation to proceed\u003C\u002Fp>\u003Ch3>Bypass Approach\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Remove the file's ADS, so no prompt will appear when opening the file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For small files, you can use the default Windows command 'more'\u003C\u002Fp>\u003Cp>For large files, you can use the tool 'Streams'\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to 'Advanced Techniques for Utilizing Hidden Alternative Data Streams'\u003C\u002Fp>\u003Cp>Alternatively, you can perform the operation via the interface, as shown in the figure below, select 'Unblock'\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015596267_1_7bfe7b67de.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Changing the Transmission Path\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a file is copied to another operating system, the original file's ADS will not be preserved.\u003C\u002Fp>\u003Cp>That is to say, if a previously downloaded untrusted file is copied to another operating system via a trusted method, the file will not be marked as \"untrusted\" in the new system.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>A file downloaded from the internet, python-2.7.12.msi, is by default added with ADS:Zone.Identifier:$DATA, and a prompt will appear when opening it.\u003C\u002Fp>\u003Cp>Now, drag this file into a virtual machine (this operation is considered a trusted method and will not add ADS), and the original ADS will not be preserved, so no prompt will appear when opening the file.\u003C\u002Fp>\u003Ch2>0x03 Construction of Special Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since untrusted files are added with ADS:Zone.Identifier:$DATA upon download, what about compressed files? Will they still contain ADS after decompression?\u003C\u002Fp>\u003Cp>Test system: Win10x64\u003C\u002Fp>\u003Cp>HTTP server: Kali Linux\u003C\u002Fp>\u003Cp>Enable HTTP server functionality:\u003C\u002Fp>\u003Cp>python -m SimpleHTTPServer 80\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Attempt .exe + .rar\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use WinRAR to compress putty.exe into putty.rar, then upload it to the HTTP server.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows 10 systems cannot decompress .rar files by default; WinRAR must be manually installed.\u003C\u002Fp>\u003Cp>The test system downloads putty.rar via Chrome, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015598578_2_e8b17e1fbb.jpeg\">\u003C\u002Fp>\u003Cp>Decompress and open the file using WinRAR, no dialog box pops up.\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>.rar compressed files will not have ADS added.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Attempt .lnk + .rar\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When compressing .lnk files, the source file pointed to by the .lnk is compressed directly; the .lnk file itself cannot be compressed. Test failed.\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Attempt .exe + zip\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use WinRAR to compress putty.exe into putty.zip and upload it to the HTTP server.\u003C\u002Fp>\u003Cp>The test system downloads putty.zip via Chrome.\u003C\u002Fp>\u003Cp>Open the zip file via Windows Explorer, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015600851_3_1afc04b7a4.jpeg\">\u003C\u002Fp>\u003Cp>After opening, a dialog box pops up, prompting the user, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015603722_4_132b196fb0.jpeg\">\u003C\u002Fp>\u003Cp>When using WinRAR to decompress and open the file, no dialog box appeared\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 2:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Attachment Manager does not support third-party software like WinRAR\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Attempt .exe+cab\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There is no need to test compression formats that require third-party software; we should continue searching for formats natively supported by the Windows system\u003C\u002Fp>\u003Cp>For example, .cab files\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CAB files can be generated using makecab.exe, which is included by default in the system\u003C\u002Fp>\u003Cp>Compression types include: none, mszip, lzx\u003C\u002Fp>\u003Cp>Use makecab to compress putty.exe into putty.cab, selecting lzx as the compression type, with the following command:\u003C\u002Fp>\u003Cp>makecab \u002Fd compressiontype=lzx putty.exe putty.cab\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015606277_5_932234ef33.jpeg\">\u003C\u002Fp>\u003Cp>Upload to HTTP server\u003C\u002Fp>\u003Cp>Test system downloads via Chrome\u003C\u002Fp>\u003Cp>Unzip, save file, open, dialog box pops up\u003C\u002Fp>\u003Cp>Drag file to any path, open, no dialog box\u003C\u002Fp>\u003Cp>Complete testing process as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015607746_6_00ce401210.png\">\u003C\u002Fp>\u003Cp>GIF online address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.gif\u003C\u002Fp>\u003Cp>Monitor both operations using Procmon, differences shown below, further research and more testing required here\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015610901_7_72d6e0a099.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This issue exists in Win10 Build 14393(1607) and earlier versions, fixed in Win10 Build 15063(1703)\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 3:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using cab compressed files, then dragging and saving files can bypass Windows Attachment Manager\u003C\u002Fp>\u003Cp>\u003Cstrong>5、Try .lnk+cab\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method originates from rvrsh3ll@424f424f's article, but I discovered another interesting issue during testing.\u003C\u002Fp>\u003Cp>Use makecab to compress test.lnk into test.cab, selecting lzx compression type, with the following command:\u003C\u002Fp>\u003Cp>makecab \u002Fd compressiontype=lzx test.lnk test.cab\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The cab file can compress the lnk file itself. To increase obfuscation, you can use the following test code:\u003C\u002Fp>\u003Cp>Write the following content in test.txt:\u003C\u002Fp>\u003Cp>\u002Fc start calc.exe\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$file = Get-Content \"c:\\test\\test.txt\"\u003Cbr>$WshShell = New-Object -comObject WScript.Shell\u003Cbr>$Shortcut = $WshShell.CreateShortcut(\"c:\\test\\test.lnk\")\u003Cbr>$Shortcut.TargetPath = \"%SystemRoot%\\system32\\cmd.exe\"\u003Cbr>$Shortcut.IconLocation = \"%SystemRoot%\\System32\\Shell32.dll,3\"\u003Cbr>$Shortcut.Arguments = $file\u003Cbr>$Shortcut.Save()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameters of the generated lnk file are padded with space characters, and the actual payload is hidden, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015613021_8_493a2edb09.jpeg\">\u003C\u002Fp>\u003Cp>For more details, refer to:\u003C\u002Fp>\u003Cp>《Penetration Techniques – Parameter Hiding Techniques in Shortcut Files》\u003C\u002Fp>\u003Cp>Upload test.cab to the HTTP server\u003C\u002Fp>\u003Cp>The test system downloads it via Chrome\u003C\u002Fp>\u003Cp>Extract, save the file, open it, and a dialog box appears (same as test 4)\u003C\u002Fp>\u003Cp>Drag the file to any path, open it, no dialog box appears (same as test 4)\u003C\u002Fp>\u003Cp>\u003Cstrong>An interesting question:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Extract the lnk file, save the file, open it, and a dialog box appears\u003C\u002Fp>\u003Cp>Then right-click to view the properties of the lnk file, open the lnk file again, no dialog box appears, and ADS is cleared\u003C\u002Fp>\u003Cp>The complete testing process is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015614343_9_2f0da74cc9.png\">\u003C\u002Fp>\u003Cp>GIF online address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.gif\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 4:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under certain special circumstances (versions before Win10 Build 14393 (1607)), ADS will be cleared, allowing bypass of Windows Attachment Manager\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win10 Build 10586 has this issue, Win10 Build 14393 (1607) fixed this issue\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Win7 systems do not have the above issues, reason:\u003C\u002Fp>\u003Cp>After opening a cab file, a prompt box will appear when saving the file (this feature does not exist in Win10)\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616370_10_3ce0db6c62.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Untrusted files will have ADS:Zone.Identifier:$DATA added during download\u003C\u002Fli>\u003Cli>If the file is copied to another operating system, the original file's ADS will not be preserved\u003C\u002Fli>\u003Cli>Compared to rar and zip formats, using cab format to compress lnk files is more appropriate\u003C\u002Fli>\u003Cli>lnk files are more deceptive\u003C\u002Fli>\u003Cli>Win10 Build 15063 (1703) has fixed the above bugs\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently I came across an article titled 'Bypassing Windows Attachment Manager' by rvrsh3ll@424f424f, which introduced his approach to bypassing Windows Attachment Manager in a very interesting way.\u003C\u002Fp>\u003Cp>Coincidentally, I have conducted research on the utilization of ADS and lnk files mentioned in the article. Therefore, this article will combine some of my insights to provide an extended introduction to this bypass method and share an interesting issue I discovered during actual testing.\u003C\u002Fp>\u003Cp>The related article addresses are as follows:\u003C\u002Fp>\u003Cp>'Bypassing Windows Attachment Manager':\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.rvrsh3ll.net\u002Fblog\u002Finformational\u002Fbypassing-windows-attachment-manager\u002F\u003C\u002Fp>\u003Cp>Some of my previous research insights:\u003C\u002Fp>\u003Cp>'Penetration Techniques – Parameter Hiding Techniques in Shortcut Files'\u003C\u002Fp>\u003Cp>'Advanced Exploitation Techniques for Hidden Alternative Data Streams'\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The role of Windows Attachment Manager\u003C\u002Fli>\u003Cli>Implementation of Windows Attachment Manager\u003C\u002Fli>\u003Cli>Bypass Techniques for Windows Attachment Manager\u003C\u002Fli>\u003Cli>Construction of Special Files\u003C\u002Fli>\u003Cli>Interesting Issues Discovered During Actual Testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Windows Attachment Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Introduction\u003C\u002Fh3>\u003Cul>\u003Cli>A new feature introduced by Microsoft since Windows XP SP2\u003C\u002Fli>\u003Cli>Designed to prevent files downloaded from untrusted sources from being executed directly\u003C\u002Fli>\u003Cli>Untrusted sources include email and internet downloads\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If a file is found to originate from an untrusted source, a dialog box will prompt the user upon opening, requiring user confirmation before execution, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015593496_0_6ecd2d34c5-1.jpeg\">\u003C\u002Fp>\u003Cp>File formats marked as High-risk are as follows:\u003C\u002Fp>\u003Cp>.ade, .adp, .app, .asp, .bas, .bat, .cer, .chm, .cmd, .com, .cpl, .crt, .csh, .exe, .fxp, .hlp, .hta, .inf, .ins, .isp, .its, .js, .jse, .ksh, .lnk, .mad, .maf, .mag, .mam, .maq, .mar, .mas, .mat, .mau, .mav, .maw, .mda, .mdb, .mde, .mdt, .mdw, .mdz, .msc, .msi, .msp, .mst, .ops, .pcd, .pif, .prf, .prg, .pst, .reg, .scf, .scr, .sct, .shb, .shs, .tmp, .url, .vb, .vbe, .vbs, .vsmacros, .vss, .vst, .vsw, .ws, .wsc, .wsf, .wsh\u003C\u002Fp>\u003Cp>For detailed information, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F883260\u002Finformation-about-the-attachment-manager-in-microsoft-windows\u003C\u002Fp>\u003Ch3>Implementation Method\u003C\u002Fh3>\u003Cp>Untrusted files are tagged with ADS:Zone.Identifier:$DATA upon download\u003C\u002Fp>\u003Cp>Detailed content of ADS is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[ZoneTransfer]\u003Cbr>ZoneId=3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>That is, as long as a file contains ADS:Zone.Identifier:$DATA, a prompt will appear when opening it, requiring user confirmation to proceed\u003C\u002Fp>\u003Ch3>Bypass Approach\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. Remove the file's ADS, so no prompt will appear when opening the file\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For small files, you can use the default Windows command 'more'\u003C\u002Fp>\u003Cp>For large files, you can use the tool 'Streams'\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to 'Advanced Techniques for Utilizing Hidden Alternative Data Streams'\u003C\u002Fp>\u003Cp>Alternatively, you can perform the operation via the interface, as shown in the figure below, select 'Unblock'\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015596267_1_7bfe7b67de-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Changing the Transmission Path\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a file is copied to another operating system, the original file's ADS will not be preserved.\u003C\u002Fp>\u003Cp>That is to say, if a previously downloaded untrusted file is copied to another operating system via a trusted method, the file will not be marked as \"untrusted\" in the new system.\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>A file downloaded from the internet, python-2.7.12.msi, is by default added with ADS:Zone.Identifier:$DATA, and a prompt will appear when opening it.\u003C\u002Fp>\u003Cp>Now, drag this file into a virtual machine (this operation is considered a trusted method and will not add ADS), and the original ADS will not be preserved, so no prompt will appear when opening the file.\u003C\u002Fp>\u003Ch2>0x03 Construction of Special Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since untrusted files are added with ADS:Zone.Identifier:$DATA upon download, what about compressed files? Will they still contain ADS after decompression?\u003C\u002Fp>\u003Cp>Test system: Win10x64\u003C\u002Fp>\u003Cp>HTTP server: Kali Linux\u003C\u002Fp>\u003Cp>Enable HTTP server functionality:\u003C\u002Fp>\u003Cp>python -m SimpleHTTPServer 80\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Attempt .exe + .rar\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use WinRAR to compress putty.exe into putty.rar, then upload it to the HTTP server.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows 10 systems cannot decompress .rar files by default; WinRAR must be manually installed.\u003C\u002Fp>\u003Cp>The test system downloads putty.rar via Chrome, as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015598578_2_e8b17e1fbb-1.jpeg\">\u003C\u002Fp>\u003Cp>Decompress and open the file using WinRAR, no dialog box pops up.\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>.rar compressed files will not have ADS added.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Attempt .lnk + .rar\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When compressing .lnk files, the source file pointed to by the .lnk is compressed directly; the .lnk file itself cannot be compressed. Test failed.\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Attempt .exe + zip\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use WinRAR to compress putty.exe into putty.zip and upload it to the HTTP server.\u003C\u002Fp>\u003Cp>The test system downloads putty.zip via Chrome.\u003C\u002Fp>\u003Cp>Open the zip file via Windows Explorer, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015600851_3_1afc04b7a4-1.jpeg\">\u003C\u002Fp>\u003Cp>After opening, a dialog box pops up, prompting the user, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015603722_4_132b196fb0-1.jpeg\">\u003C\u002Fp>\u003Cp>When using WinRAR to decompress and open the file, no dialog box appeared\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 2:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Attachment Manager does not support third-party software like WinRAR\u003C\u002Fp>\u003Cp>\u003Cstrong>4. Attempt .exe+cab\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There is no need to test compression formats that require third-party software; we should continue searching for formats natively supported by the Windows system\u003C\u002Fp>\u003Cp>For example, .cab files\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>CAB files can be generated using makecab.exe, which is included by default in the system\u003C\u002Fp>\u003Cp>Compression types include: none, mszip, lzx\u003C\u002Fp>\u003Cp>Use makecab to compress putty.exe into putty.cab, selecting lzx as the compression type, with the following command:\u003C\u002Fp>\u003Cp>makecab \u002Fd compressiontype=lzx putty.exe putty.cab\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015606277_5_932234ef33-1.jpeg\">\u003C\u002Fp>\u003Cp>Upload to HTTP server\u003C\u002Fp>\u003Cp>Test system downloads via Chrome\u003C\u002Fp>\u003Cp>Unzip, save file, open, dialog box pops up\u003C\u002Fp>\u003Cp>Drag file to any path, open, no dialog box\u003C\u002Fp>\u003Cp>Complete testing process as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015607746_6_00ce401210-1.png\">\u003C\u002Fp>\u003Cp>GIF online address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.gif\u003C\u002Fp>\u003Cp>Monitor both operations using Procmon, differences shown below, further research and more testing required here\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015610901_7_72d6e0a099-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This issue exists in Win10 Build 14393(1607) and earlier versions, fixed in Win10 Build 15063(1703)\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 3:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using cab compressed files, then dragging and saving files can bypass Windows Attachment Manager\u003C\u002Fp>\u003Cp>\u003Cstrong>5、Try .lnk+cab\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method originates from rvrsh3ll@424f424f's article, but I discovered another interesting issue during testing.\u003C\u002Fp>\u003Cp>Use makecab to compress test.lnk into test.cab, selecting lzx compression type, with the following command:\u003C\u002Fp>\u003Cp>makecab \u002Fd compressiontype=lzx test.lnk test.cab\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The cab file can compress the lnk file itself. To increase obfuscation, you can use the following test code:\u003C\u002Fp>\u003Cp>Write the following content in test.txt:\u003C\u002Fp>\u003Cp>\u002Fc start calc.exe\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$file = Get-Content \"c:\\test\\test.txt\"\u003Cbr>$WshShell = New-Object -comObject WScript.Shell\u003Cbr>$Shortcut = $WshShell.CreateShortcut(\"c:\\test\\test.lnk\")\u003Cbr>$Shortcut.TargetPath = \"%SystemRoot%\\system32\\cmd.exe\"\u003Cbr>$Shortcut.IconLocation = \"%SystemRoot%\\System32\\Shell32.dll,3\"\u003Cbr>$Shortcut.Arguments = $file\u003Cbr>$Shortcut.Save()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The parameters of the generated lnk file are padded with space characters, and the actual payload is hidden, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015613021_8_493a2edb09-1.jpeg\">\u003C\u002Fp>\u003Cp>For more details, refer to:\u003C\u002Fp>\u003Cp>《Penetration Techniques – Parameter Hiding Techniques in Shortcut Files》\u003C\u002Fp>\u003Cp>Upload test.cab to the HTTP server\u003C\u002Fp>\u003Cp>The test system downloads it via Chrome\u003C\u002Fp>\u003Cp>Extract, save the file, open it, and a dialog box appears (same as test 4)\u003C\u002Fp>\u003Cp>Drag the file to any path, open it, no dialog box appears (same as test 4)\u003C\u002Fp>\u003Cp>\u003Cstrong>An interesting question:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Extract the lnk file, save the file, open it, and a dialog box appears\u003C\u002Fp>\u003Cp>Then right-click to view the properties of the lnk file, open the lnk file again, no dialog box appears, and ADS is cleared\u003C\u002Fp>\u003Cp>The complete testing process is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015614343_9_2f0da74cc9-1.png\">\u003C\u002Fp>\u003Cp>GIF online address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.gif\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion 4:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under certain special circumstances (versions before Win10 Build 14393 (1607)), ADS will be cleared, allowing bypass of Windows Attachment Manager\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win10 Build 10586 has this issue, Win10 Build 14393 (1607) fixed this issue\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Win7 systems do not have the above issues, reason:\u003C\u002Fp>\u003Cp>After opening a cab file, a prompt box will appear when saving the file (this feature does not exist in Win10)\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616370_10_3ce0db6c62-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Untrusted files will have ADS:Zone.Identifier:$DATA added during download\u003C\u002Fli>\u003Cli>If the file is copied to another operating system, the original file's ADS will not be preserved\u003C\u002Fli>\u003Cli>Compared to rar and zip formats, using cab format to compress lnk files is more appropriate\u003C\u002Fli>\u003Cli>lnk files are more deceptive\u003C\u002Fli>\u003Cli>Win10 Build 15063 (1703) has fixed the above bugs\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>",303,"Onedaysec",6,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass Windows Attachment Manager: ADS & LNK Exploitation","Windows Attachment Manager bypass, ADS Zone.Identifier, alternative data streams, LNK files, security bypass, untrusted file execution, ZoneId=3, attachment manager exploit",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1068,1067,1066,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.886Z","2026-07-23T16:02:29.360Z","draft","2026-07-23T16:16:26.542Z"]