Tactics Tuesday | DDE All The Things

Поделиться
HTML-код
  • Опубликовано: 15 дек 2024

Комментарии • 4

  • @sp3ct3r71
    @sp3ct3r71 Год назад

    im doing internal pentest meanwhile i found csv inject point in there.. but problem is if there are any payloads starts with = + - @ sign they append quotes to it.. is there any way I could execute formulas without = + - @ symbols??

  • @mayanktiwari8969
    @mayanktiwari8969 3 года назад

    This is inspiring. Makes me want to learn hacking to understand more about technology.

  • @zbgamesplay
    @zbgamesplay 2 года назад

    Do you think would be possible to DDE a JSON file?

    • @MatthewToussain
      @MatthewToussain  2 года назад

      Sort of. DDE is an Microsoft Office feature so it only works in file formats opened by those tools. Some of them like OneNote can support embedded file types. If JSON is supported like that then, theoretically, there might be some play there.