Login
Register
Menu
Home
Help
Search
rejetto forum
PROBLEMS? QUESTIONS? CLICK HERE!
rejetto forum
»
Software
»
HFS ~ HTTP File Server
»
Bug reports
»
Unsafe DLL loading vulnerable in version 2.3k
Unsafe DLL loading vulnerable in version 2.3k
yeyint
·
6 ·
8135
« previous
next »
Print
Pages:
1
0 Members and 1 Guest are viewing this topic.
yeyint
Occasional poster
Posts:
1
Unsafe DLL loading vulnerable in version 2.3k
on:
July 29, 2017, 08:30:13 PM
The HSF Server application passes an insufficiently qualified path in loading an external library when a user launch the application.
Affected Library List
---------------------
# dwmapi.dll
# WindowsCodecs.dll
# apphelp.dll
# RICHED32.dll
# wsock32.dll
# DNSAPI.dll
# IPHLPAPI.dll
# rasadh1p.dll
Please find the following for demo. I rename the malicious dll file (which is execute calculator) as apphelp.dll in this demo.
https://www.youtube.com/watch?v=VGjRA-P0opM
Thanks
Ye
REFERENCES
https://support.microsoft.com/en-us/help/2389418/secure-loading-of-libraries-to-prevent-dll-preloading-attacks
https://cwe.mitre.org/data/definitions/427.html
http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx
Fysack
Tireless poster
Posts:
598
present picture
Re: Unsafe DLL loading vulnerable in version 2.3k
Reply #1 on:
September 30, 2017, 11:00:49 PM
it make no sense dude
GOD CAN READ YOUR MIND
rejetto
Administrator
Tireless poster
Posts:
13523
Re: Unsafe DLL loading vulnerable in version 2.3k
Reply #2 on:
November 21, 2017, 04:54:49 PM
i had missed this report, actually.
I'm not personally calling that DLL, and i'm not sure why it is called.
The results on google are quite confusing.
Would anyone have information, please share.
bmartino1
Tireless poster
Posts:
911
I'm only trying to help i mean no offense.
Re: Unsafe DLL loading vulnerable in version 2.3k
Reply #3 on:
November 23, 2017, 05:23:44 PM
rejjeto, i private messaged you about this....
what i have seen and what was shown was indeed dll hacking, but is not a probelm or a bug with your program, but a os system issues with a bad visual update. it was his pc casuing the issue..
this is not a bug that i have found.
Files I have snagged and share can be found on my google drive:
https://drive.google.com/drive/folders/1qb4INX2pzsjmMT06YEIQk9Nv5jMu33tC?usp=sharing
Fysack
Tireless poster
Posts:
598
present picture
Re: Unsafe DLL loading vulnerable in version 2.3k
Reply #4 on:
December 09, 2017, 12:19:53 AM
LOVE
GOD CAN READ YOUR MIND
Fysack
Tireless poster
Posts:
598
present picture
Re: Unsafe DLL loading vulnerable in version 2.3k
Reply #5 on:
October 12, 2019, 02:14:25 AM
Quote from: Fysack on September 30, 2017, 11:00:49 PM
it make no sense dude
GOD CAN READ YOUR MIND
Print
Pages:
1
rejetto forum
»
Software
»
HFS ~ HTTP File Server
»
Bug reports
»
Unsafe DLL loading vulnerable in version 2.3k
Search
Username
Password
Always stay logged in
Forgot your password?