Koppeling is a demonstration of advanced DLL hijack techniques. It was released in conjunction with the “Adaptive DLL Hijacking” blog post. I recommend you start there to contextualize this code.
This project is comprised of the following elements:
The VS solution itself supports 4 build configurations which map to 4 different methods of proxying functionality. This should provide a nice scalable way of demonstrating more techniques in the future.
The goal of each technique is to successfully capture code execution while proxying functionality to the legitimate DLL. Each technique is tested to ensure static and dynamic sink situations are handled. This is by far not every primitive or technique variation. The post above goes into more detail.
Example
Prepare a hijack scenario with an obviously incorrect DLL
copy C:\windows\system32\whoami.exe .\whoami.exe
1 file(s) copied.
copy C:\windows\system32\kernel32.dll .\wkscli.dll
1 file(s) copied.
Executing in the current configuration should result in an error
whoami.exe
“Entry Point Not Found”
Convert kernel32 to proxy functionality for wkscli
NetClone.exe –target C:\windows\system32\kernel32.dll –reference C:\windows\system32\wkscli.dll –output wkscli.dll
[+] Done.
whoami.exe
COMPUTER\User
The cp command, short for "copy," is the main Linux utility for duplicating files and directories. Whether…
Introduction In digital investigations, images often hold more information than meets the eye. With the…
The cat command short for concatenate, It is a fast and versatile tool for viewing and merging…
What is a Port? A port in networking acts like a gateway that directs data…
The ls command is fundamental for anyone working with Linux. It’s used to display the files and…
The pwd (Print Working Directory) command is essential for navigating the Linux filesystem. It instantly shows your…