cldrn / cldrn/macphish

Implement latest sandbox escape

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
245
Forks
50
PR merge metrics
No merged PRs in 30d

Description

A nice bypass by Adam Chester was published this month:
https://www.mdsec.co.uk/2018/08/escaping-the-sandbox-microsoft-office-on-macos/

Label
com.xpnsec.escape
ProgramArguments

python
-c
payload

RunAtLoad

Contributor guide

No contributing guide indexed for this repository

Research direction

Read the linked Adam Chester write-up first, then locate the existing macOS Office macro payload generator entry point. Compare its output with the supplied launchd plist and Python payload structure. Done means the generator supports this sandbox-escape payload and its output can be validated on the intended macOS and Office versions.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, python
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.