-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added lolbas iediagcmd.exe as discovered by Adam @hexacorn #199
Added lolbas iediagcmd.exe as discovered by Adam @hexacorn #199
Conversation
Apologies for a delayed reply. We are working through some backlog. Undoubtedly, this has likely worked before but I am unable to duplicate on Windows 10 22H2. Can you see if you have similar results? |
@manasmbellani Reminder, please check the above message. |
Also, worth noting that this is a command prompt and requires "&" or "&&" between commands, not ";". This will need to be fixed in the example. |
Made corrections
Removing trailing spaces
removing empty fields
@wietze if you could review this, I think we can merge and close this out. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@wietze, it fires several times but the processes do not persist. You would have to use an app that spawns a new process to visually see this work or, watch the task manager very carefully for netsh.exe to appear briefly. I used a simple C EXE that launches calc via shellcode (metasploit) and wind up poping calc without issue on Windows 10 22H1 and 22H2: |
AH-HA! problem is the space before the first "&". |
Removing space before first "&". When setting the Environment variable, it's picking up the space so the path seemed to be "c:\test \", which is why tests are failing.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No description provided.