Menu
Newbedev LogoNEWBEDEV Python Javascript Linux Cheat sheet
Newbedev LogoNEWBEDEV
  • Python 1
  • Javascript
  • Linux
  • Cheat sheet
  • Contact

Does "=cmd" CSV injection still exist in 2020?

Finally found the reason why the payload were not executing: DDE launch was disabled in Excel options.

If someone has the same issue, this setting can be found in

File → Options → Trust Center → Trust Center Settings → External Content → Enable Dynamic Data Exchange Server Launch

Reference https://docs.microsoft.com/en-us/office365/troubleshoot/security/security-settings

Tags:

Windows

Excel

Office

Injection

Related

Threema: Are received messages exposed, when sender's private key gets compromised? Can keylogger software exist solely on a keyboard PCB? Does Cloudflare masking my IP make my server more secure? Are files like favicon.ico, robots.txt, and sitemap.xml vulnerable to XSS? Is it bad to use special characters in passwords? Safely use old windows XP machine in business network Are XSS attacks possible if access to content generated by other users is restricted? Does Tor help us to prevent ISP tracking? How to remove quarantined virus securely? Is it considered bad practice to use company name as part of an SSID? Are all USB-based attacks dependent on being able to inject keystrokes? Can malicious code fit in 14 bytes?

Recent Posts

Pandas how to find column contains a certain value Recommended way to install multiple Python versions on Ubuntu 20.04 Build super fast web scraper with Python x100 than BeautifulSoup How to convert a SQL query result to a Pandas DataFrame in Python How to write a Pandas DataFrame to a .csv file in Python
© 2021 newbedevPrivacy Policy