logoalt Hacker News

eugenekolotoday at 2:24 PM1 replyview on HN

But is it running ShellExecute on URIs?


Replies

electrolytoday at 2:32 PM

I believe it is. Just tested it. You can make the link "C:\windows\system32\cmd.exe" and clicking it will launch the Command Prompt. I noticed you can't make it "C:\windows\system32\cmd.exe /c some-nefarious-thing"; it doesn't like the space. Exploiting may require you to ship both the malicious EXE and the MD, then trick the user into clicking the link inside the MD. But then you could have just tricked them into directly clicking the EXE.

show 2 replies