![]() |
|
Siofra Automated DLL Hijacking Tool - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools) +--- Thread: Siofra Automated DLL Hijacking Tool (/Thread-Siofra-Automated-DLL-Hijacking-Tool) |
Siofra Automated DLL Hijacking Tool - S3xySmurf - 10-05-2017 Siofra
## Infection mode
When in infection mode, the tool is capable of generating infected copies of both 32 and 64-bit DLL files. These infected files are able to hijack the execution flow of a target application when they are loaded during process initialization, causing either a payload DLL to be loaded or a payload executable to be launched prior to the execution of the target application entry point. ## File scanning mode When in file scanning mode, the tool may be given either an executable file path or a folder (which will be searched for executable files, optionally with recursion) which will recursively have its PE imports, delay load imports, API sets, assembly dependencies, and explicitly loaded libraries enumerated and processed to determine the path at which each will be loaded during runtime process initialization. With this information, the tool is able to identify modules which are vulnerable to hijacking. During PE processing and loader simulation, the tool is capable of handling: 1. Modules imported using the primary PE imports section. 2. Modules imported via delay load. 3. WinSxS assembly dependency resolution (the PE manifest resource is parsed, assembly dependency IDs are extracted, and the WinSxS module path is identified using a custom implementation). 4. Explicitly loaded modules, imported via LoadLibrary at runtime. 5. API set resolution of all of the above import types. This is achieved via a custom implementation of a parser for the undocumented data structures found in ApiSetSchema.dll (note that only versions 2, 4 and 6 have been tested). 6. Searching for specific imported modules by name. 7. Identifying Windows components which can be leveraged for UAC bypass attacks (the UAC auto-elevation criteria are applied to a specified target PE in an automated way, then used in conjunction with a hijacking attack if one is present). 8. Automatically detect and filter module dependencies which are not vulnerable on the basis of: * KnownDLLs * Exempt ("Base") DLL status. Kernelbase.dll, ntdll.dll, etc. * Manifest override security mechanism (used by Microsoft in sysprep.exe) ## Memory scanning mode When in memory scanning mode, the tool can either enumerate local process names/IDs or it can be given a process ID to scan. Rather than parsing the image file corresponding to the given PID on disk, the tool will enumerate the modules currently loaded into the process and identify which of them may be vulnerable to hijacking. This is useful in instances where an executable on disk is packed/obfuscated and its imports cannot be identified through parsing the PE header. RE: Siofra Automated DLL Hijacking Tool - polarvoid - 10-06-2017 This seems cool. Just to clarify my understanding, this tool can be used to infect DLL files so that they can launch an executable file when they are loaded by an application? |