rejetto forum

Software => HFS ~ HTTP File Server => Bug reports => Topic started by: yeyint on July 29, 2017, 08:30:13 PM

Title: Unsafe DLL loading vulnerable in version 2.3k
Post by: yeyint on July 29, 2017, 08:30:13 PM
The HSF Server application passes an insufficiently qualified path in loading an external library when a user launch the application.

Affected Library List
---------------------
# dwmapi.dll
# WindowsCodecs.dll
# apphelp.dll
# RICHED32.dll
# wsock32.dll
# DNSAPI.dll
# IPHLPAPI.dll
# rasadh1p.dll

Please find the following for demo. I rename the malicious dll file (which is execute calculator) as apphelp.dll in this demo.

https://www.youtube.com/watch?v=VGjRA-P0opM

Thanks
Ye


REFERENCES
https://support.microsoft.com/en-us/help/2389418/secure-loading-of-libraries-to-prevent-dll-preloading-attacks
https://cwe.mitre.org/data/definitions/427.html
http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx
Title: Re: Unsafe DLL loading vulnerable in version 2.3k
Post by: Fysack on September 30, 2017, 11:00:49 PM
it make no sense dude
Title: Re: Unsafe DLL loading vulnerable in version 2.3k
Post by: rejetto on November 21, 2017, 04:54:49 PM
i had missed this report, actually.
I'm not personally calling that DLL, and i'm not sure why it is called.
The results on google are quite confusing.
Would anyone have information, please share.

Title: Re: Unsafe DLL loading vulnerable in version 2.3k
Post by: bmartino1 on November 23, 2017, 05:23:44 PM
rejjeto, i private messaged you about this....

what i have seen and what was shown was indeed dll hacking, but is not a probelm or a bug with your program, but a os system issues with a bad visual update. it was his pc casuing the issue..

this is not a bug that i have found.
Title: Re: Unsafe DLL loading vulnerable in version 2.3k
Post by: Fysack on December 09, 2017, 12:19:53 AM
 ;D ;D ;D LOVE
Title: Re: Unsafe DLL loading vulnerable in version 2.3k
Post by: Fysack on October 12, 2019, 02:14:25 AM
it make no sense dude
  ;D ;D ;D