Sinisterly
Siofra Automated DLL Hijacking Tool - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: Siofra Automated DLL Hijacking Tool (/Thread-Siofra-Automated-DLL-Hijacking-Tool)



Siofra Automated DLL Hijacking Tool - S3xySmurf - 10-05-2017

Siofra


## Infection mode
 
 When in infection mode, the tool is capable of generating infected copies of both
 32 and 64-bit DLL files. These infected files are able to hijack the execution flow
 of a target application when they are loaded during process initialization, causing
 either a payload DLL to be loaded or a payload executable to be launched prior to
 the execution of the target application entry point.
 
 ## File scanning mode
 
 When in file scanning mode, the tool may be given either an executable file path
 or a folder (which will be searched for executable files, optionally with recursion)
 which will recursively have its PE imports, delay load imports, API sets, assembly
 dependencies, and explicitly loaded libraries enumerated and processed to determine
 the path at which each will be loaded during runtime process initialization. With
 this information, the tool is able to identify modules which are vulnerable to hijacking.
 During PE processing and loader simulation, the tool is capable of handling:
   1. Modules imported using the primary PE imports section.
   2. Modules imported via delay load.
   3. WinSxS assembly dependency resolution (the PE manifest resource is parsed, assembly
      dependency IDs are extracted, and the WinSxS module path is identified using
      a custom implementation).
   4. Explicitly loaded modules, imported via LoadLibrary at runtime.
   5. API set resolution of all of the above import types. This is achieved via a
      custom implementation of a parser for the undocumented data structures found in
      ApiSetSchema.dll (note that only versions 2, 4 and 6 have been tested).
   6. Searching for specific imported modules by name.
   7. Identifying Windows components which can be leveraged for UAC bypass attacks
      (the UAC auto-elevation criteria are applied to a specified target PE in an
      automated way, then used in conjunction with a hijacking attack if one is present).
   8. Automatically detect and filter module dependencies which are not
      vulnerable on the basis of:
        * KnownDLLs
        * Exempt ("Base") DLL status. Kernelbase.dll, ntdll.dll, etc.
        * Manifest override security mechanism (used by Microsoft in sysprep.exe)
 
 ## Memory scanning mode
 
 When in memory scanning mode, the tool can either enumerate local process names/IDs
 or it can be given a process ID to scan. Rather than parsing the image file corresponding
 to the given PID on disk, the tool will enumerate the modules currently loaded into
 the process and identify which of them may be vulnerable to hijacking. This is useful
 in instances where an executable on disk is packed/obfuscated and its imports cannot
 be identified through parsing the PE header.




RE: Siofra Automated DLL Hijacking Tool - polarvoid - 10-06-2017

This seems cool. Just to clarify my understanding, this tool can be used to infect DLL files so that they can launch an executable file when they are loaded by an application?