im doing internal pentest meanwhile i found csv inject point in there.. but problem is if there are any payloads starts with = + - @ sign they append quotes to it.. is there any way I could execute formulas without = + - @ symbols??
Sort of. DDE is an Microsoft Office feature so it only works in file formats opened by those tools. Some of them like OneNote can support embedded file types. If JSON is supported like that then, theoretically, there might be some play there.
im doing internal pentest meanwhile i found csv inject point in there.. but problem is if there are any payloads starts with = + - @ sign they append quotes to it.. is there any way I could execute formulas without = + - @ symbols??
This is inspiring. Makes me want to learn hacking to understand more about technology.
Do you think would be possible to DDE a JSON file?
Sort of. DDE is an Microsoft Office feature so it only works in file formats opened by those tools. Some of them like OneNote can support embedded file types. If JSON is supported like that then, theoretically, there might be some play there.