PowerShell, C-Sharp and DDE The Power Within
ID: 4cfbff62-aaaf-5b04-b30e-42173a1b7e34
STIX ID: report--4cfbff62-aaaf-5b04-b30e-42173a1b7e34
Feed Name: SensePost Blog
Threat Score
**Executive summary:** This blog post demonstrates how to combine a PowerShell exploit for MS16-032 (using embedded C# and DllImport calls) with Microsoft Excel DDE command execution to remotely load and run code and obtain a SYSTEM reverse shell; it provides code snippets, DDE formulas, and details on adding Winsock functions and STARTUPINFO handle redirection to spawn a socket-backed CMD process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
