P4wnP1 icon indicating copy to clipboard operation
P4wnP1 copied to clipboard

FireStage1 works only with nohide

Open Spycial opened this issue 6 years ago • 3 comments

When i try to use FireStage1 the powershell just disappears randomly but with nohide it works?? EDIT: I think the problem is that because when the window gets resized it disappears 100% so the payload cannot type anymore there.

Spycial avatar Feb 01 '19 05:02 Spycial

P4wnP1 prepends a stager that moves the powershell window off the screen so it can type the long payload with anybody noticing instantly by just looking at the screen. Even though the windows isn't visible anymore, it should still be focused. It probably fails either because the window looses focus for some reason and the keystrokes just "disappear", or because some security measure (eg AV) notices that the window was moved off screen and terminates the process... I'm just speculating though. Are you sure that the injection actually fails without nohide?

Swiftb0y avatar Feb 02 '19 18:02 Swiftb0y

so yeah you can just use nexmon additions, you'll find it on github

On Sat, Feb 2, 2019 at 8:35 PM Swiftb0y [email protected] wrote:

P4wnP1 prepends a stager that moves the powershell window off the screen so it can type the long payload with anybody noticing instantly by just looking at the screen. Even though the windows isn't visible anymore, it should still be focused. It probably fails either because the window looses focus for some reason and the keystrokes just "disappear", or because some security measure (eg AV) notices that the window was moved off screen and terminates the process... I'm just speculating though. Are you sure that the injection actually fails without nohide?

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/mame82/P4wnP1/issues/284#issuecomment-459988369, or mute the thread https://github.com/notifications/unsubscribe-auth/AsuZxqdGAzzLOliDfcKAORzg-9JGdN_uks5vJdp_gaJpZM4adsIL .

ghost avatar Feb 05 '19 10:02 ghost

I am facing the same problem. I run the Firestage1 with nohide parameter and it works just fine. How do i use the nexmon additions?

r41nm4k3r avatar Feb 15 '19 22:02 r41nm4k3r