Sunday, 23 November 2014

PDF

$pdfextract filename.pdf
- All of the components will be extracted to filename.dump folder
- Do a "grep javascript" here

PDF Stream Dumper
- "Scan malicious"

http://hiddenillusion.blogspot.co.uk/2012/06/getting-what-you-want-out-of-pdf-with.html

$shellcode2exe

$base64 -d

c:\>convertshellcode.exe

$js-beatify

$js -f filename.js
document = {
write:print
};

$unicode2hex-escaped

No comments:

Post a Comment