Internet Explorer
Downloads
If the environment does not have restrictions on websites or downloads, try a few things:
Host a malicious file to download and execute
use exploit/multi/script/web_delivery
python3 -m http.server
python -m SimpleHTTPServer
Download PSAttack (https://github.com/jaredhaight/PSAttack/releases/)
Internet Explorer Options
Internet Options > Settings (Under Browsing History) > View Object (or View Files)
Accessibility > Check Format Documents box > click Browse > Right-click folder > open in new window (or drag to empty desktop area)
Privacy Tab > Import > Right-click folder > open in new window (or drag to empty desktop area)
Content Tab > Certificates or Publishers > Import > Right-click folder > open in new window (or drag to empty desktop area)
Programs Tab > Set programs (will pop open windows explorer)
URI
In Address bar type file:///c:/windows/system32/cmd.exe (or path to powershell, powershell_ise, etc)
Saving Files
File > Save As... > Right click a file and Open With... > Browse > navigate to c:\windows\system32 > right-click cmd.exe and click open
Right click page > View Source > File > Save > right-clickfolder > open in a new window (or drag to empty desktop area)
Last updated
Was this helpful?