[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpBI4RtFfoOtHQ-BnlSDVgduCYN8TnZQosMl-DLSKbx8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},500,"How do you register a BHO DLL in Windows, and where is it stored in the registry?","To register a BHO, you use the command `regsvr32 helloworld.dll \u002Fs` with administrator privileges. This writes the BHO's CLSID to the registry under `HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID}` and `HKEY_CLASSES_ROOT\\CLSID\\{GUID}`. Unregistration is done with `regsvr32 helloworld.dll \u002Fs \u002Fu` or by deleting the registry keys. See the original article for the full development process: [Implementing IE Browser Hijacking Using BHO](\u002Fnews\u002Fimplementing-ie-browser-hijacking-using-bho).","\u003Cp>To register a BHO, you use the command `regsvr32 helloworld.dll \u002Fs` with administrator privileges. This writes the BHO&#39;s CLSID to the registry under `HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID}` and `HKEY_CLASSES_ROOT\\CLSID\\{GUID}`. Unregistration is done with `regsvr32 helloworld.dll \u002Fs \u002Fu` or by deleting the registry keys. See the original article for the full development process: [Implementing IE Browser Hijacking Using BHO](\u002Fnews\u002Fimplementing-ie-browser-hijacking-using-bho).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fimplementing-ie-browser-hijacking-using-bho\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-you-register-a-bho-dll-in-windows-and-where-is-it-stored-in-the-registry-1777483202309","regsvr32, DLL registration, registry, CLSID, BHO",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},124,"Implementing IE Browser Hijacking Using BHO","implementing-ie-browser-hijacking-using-bho","Learn how to implement IE browser hijacking using BHO for network connection simulation, bypassing security products. Includes development steps and exploitation approaches.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from a covert connection test that simulates IE browser initiating network connections, which can bypass certain security products that block third-party programs from initiating network connections\u003C\u002Fp>\u003Cp>There are many methods to simulate IE browser initiating network connections. Among them, using BHO to hijack IE browser has numerous advantages (open interface, simple and efficient, feature-rich, etc.). Therefore, this article will introduce the development of BHO and hijacking exploitation approaches\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to BHO\u003C\u002Fli>\u003Cli>Developing BHO\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to BHO\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>BHO, short for Browser Helper Object\u003C\u002Fp>\u003Cp>An industry standard introduced by Microsoft as an open interaction interface for third-party programmers with browsers\u003C\u002Fp>\u003Cp>Functions of BHO:\u003C\u002Fp>\u003Cul>\u003Cli>Capture browser behaviors, such as 'back', 'forward', 'current page', etc.\u003C\u002Fli>\u003Cli>Control browser behaviors, such as modifying or replacing browser toolbars, adding custom program buttons, etc.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>BHO relies on the main browser window and shares the same lifecycle as the browser instance, meaning the BHO object runs when the browser page opens and ends when the page closes\u003C\u002Fp>\u003Cp>Using BHO requires registration, which involves writing to the registry, located at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID} and HKEY_CLASSES_ROOT\\CLSID\\{GUID}\u003C\u002Fp>\u003Ch2>0x03 Developing BHO\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section provides only a brief introduction\u003C\u002Fp>\u003Cp>Development tools: VS2012\u003C\u002Fp>\u003Ch3>1. Generate DLL\u003C\u002Fh3>\u003Cp>New - Visual C++ - ATL\u003C\u002Fp>\u003Cp>Add - Class - ATL - ATL Simple Object, set the abbreviation as HelloWorldBHO, select IObjectWithSite (IE object support)\u003C\u002Fp>\u003Cp>Modify the following files:\u003C\u002Fp>\u003Cul>\u003Cli>HelloWorldBHO.h\u003C\u002Fli>\u003Cli>HelloWorldBHO.cpp\u003C\u002Fli>\u003Cli>dllmain.cpp\u003C\u002Fli>\u003Cli>HelloWorld.rgs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to http:\u002F\u002Fblog.csdn.net\u002Ffeier7501\u002Farticle\u002Fdetails\u002F11266345\u003C\u002Fp>\u003Cp>The GUID of the BHO is stored in helloworld.rgs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969365_0_f3b89df641.jpeg\">\u003C\u002Fp>\u003Cp>The name of the BHO is stored in HelloWorldBHO.rgs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975776_1_a07f51126c.jpeg\">\u003C\u002Fp>\u003Cp>In helloworld.rc, CompanyName represents the publisher, and PRODUCTVERSION represents the version, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986316_2_cd56f8a470.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The three figures above correspond to the display information of the add-on below\u003C\u002Fp>\u003Cp>HelloWorldBHO.cpp stores the operations corresponding to different events in the IE browser. Here, only an example code is introduced (for detailed code, refer to the open-source project), which implements displaying the current URL in a pop-up box when the page finishes loading. The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void STDMETHODCALLTYPE CHelloWorldBHO::OnDocumentComplete(IDispatch *pDisp, VARIANT *pvarURL)\u003Cbr>{\u003Cbr>    BSTR url = pvarURL-&gt;bstrVal;\u003Cbr>    CComBSTR u(url);\u003Cbr>    \u002F\u002F Retrieve the top-level window from the site.\u003Cbr>    HWND hwnd;\u003Cbr>    HRESULT hr = m_spWebBrowser-&gt;get_HWND((LONG_PTR*)&amp;hwnd);\u003Cbr>    if (SUCCEEDED(hr))\u003Cbr>    {\u003Cbr>        MessageBox(0, u, L\"the url is\", MB_OK);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate helloworld.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If VS2012 does not have administrator privileges, a registration failure prompt may appear during compilation. Manual registration can be performed subsequently.\u003C\u002Fp>\u003Ch3>2. Register DLL\u003C\u002Fh3>\u003Cp>Administrator privileges required, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32 helloworld.dll \u002Fs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fs parameter is used to suppress the success message box\u003C\u002Fp>\u003Cp>Equivalent to writing to registry, located at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID} and HKEY_CLASSES_ROOT\\CLSID\\{GUID}\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Uninstall DLL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32 helloworld.dll \u002Fs \u002Fu\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or delete corresponding registry keys\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win 7 x86 IE8\u003C\u002Fp>\u003Cp>Open IE browser, dialog box pops up displaying current URL, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990721_3_861eb84179.jpeg\">\u003C\u002Fp>\u003Cp>View IE's add-ons, located under Tools &gt; Manage Add-ons, to obtain add-on information, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017995179_4_b88b3b5bae.jpeg\">\u003C\u002Fp>\u003Cp>The name, publisher, and version can be specified via the previously mentioned helloworld.rgs, HelloWorldBHO.rgs, and helloworld.rc files, while the file date corresponds to the modification time of the dll\u003C\u002Fp>\u003Cp>Since our self-generated dll lacks a Microsoft signature, it shows as unverified\u003C\u002Fp>\u003Ch2>0x05 Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Forge Microsoft signature, hide BHO\u003C\u002Fh3>\u003Cp>Add a Microsoft Authenticode signature to helloworld.dll, modify the registry to hijack the system's signature verification function, making the signature effective\u003C\u002Fp>\u003Cp>Refer to the previous article: 'Authenticode Signature Forgery—Signature Forgery and Verification Hijacking for PE Files'\u003C\u002Fp>\u003Cp>Requires a signature from Microsoft Corporation, which can be obtained from Office files, available path: C:\\Program Files\\Microsoft Office\\Office14\\URLREDIR.DLL\u003C\u002Fp>\u003Cp>Use SigThief to add the signature, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Cp>Parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i \"C:\\Program Files\\Microsoft Office\\Office14\\URLREDIR.DLL\" -t helloworld.dll -o new.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate new.dll\u003C\u002Fp>\u003Cp>Modify registry to hijack signature verification function:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Register DLL, reopen IE, view add-ons, verification passed, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017998152_5_7e95d90d00.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying BHO information can further hide the BHO\u003C\u002Fp>\u003Ch3>2. Capture browser POST data to record plaintext passwords\u003C\u002Fh3>\u003Cp>Open-source code for capturing browser POST data is available on GitHub, reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fliigo\u002Fbho\u003C\u002Fp>\u003Cp>Capture browser POST data before the BeforeNavigate2 event\u003C\u002Fp>\u003Cp>In my own project, I directly referenced the key function: STDMETHODIMP CBhoApp::Invoke(DISPID dispidMember, REFIID riid, LCID lcid, WORD wFlags, DISPPARAMS *pDispParams, VARIANT *pvarResult, EXCEPINFO *pExcepInfo, UINT *puArgErr)\u003C\u002Fp>\u003Cp>Add function declaration to implement logging functionality\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GetTempPath retrieves the Temp directory of the current system; under IE permissions, the actual path is %Temp%\\Low\u003C\u002Fp>\u003Cp>The complete code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Capture browser POST data to obtain user-entered plaintext passwords, such as GitHub login credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018001645_6_e12e375ca6.jpeg\">\u003C\u002Fp>\u003Ch3>3. Download files\u003C\u002Fh3>\u003Cp>By downloading files in this manner, the firewall software's management interface shows the downloading program as the IE browser, achieving a certain level of concealment\u003C\u002Fp>\u003Ch3>4. Inject JavaScript into IE pages\u003C\u002Fh3>\u003Cp>Refer to the following open-source project for further modifications:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fxiyiaoo\u002FBHO\u003C\u002Fp>\u003Cp>This article will not elaborate further\u003C\u002Fp>\u003Ch3>5. Supplementary notes\u003C\u002Fh3>\u003Cp>By default, BHO permissions are low, which imposes certain operational limitations. If higher permissions are obtained through other means, more exploitation methods become available\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for BHO exploitation is obtaining system administrator privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Check the add-ons in the IE browser\u003C\u002Fli>\u003Cli>Check the DLLs loaded by the IE process\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the development method of IE Browser Helper Objects (BHO), analyzes the exploitation ideas after obtaining system administrator privileges, and touches upon some exploitation techniques without going into full detail\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article originates from a covert connection test that simulates IE browser initiating network connections, which can bypass certain security products that block third-party programs from initiating network connections\u003C\u002Fp>\u003Cp>There are many methods to simulate IE browser initiating network connections. Among them, using BHO to hijack IE browser has numerous advantages (open interface, simple and efficient, feature-rich, etc.). Therefore, this article will introduce the development of BHO and hijacking exploitation approaches\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to BHO\u003C\u002Fli>\u003Cli>Developing BHO\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003Cli>Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to BHO\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>BHO, short for Browser Helper Object\u003C\u002Fp>\u003Cp>An industry standard introduced by Microsoft as an open interaction interface for third-party programmers with browsers\u003C\u002Fp>\u003Cp>Functions of BHO:\u003C\u002Fp>\u003Cul>\u003Cli>Capture browser behaviors, such as 'back', 'forward', 'current page', etc.\u003C\u002Fli>\u003Cli>Control browser behaviors, such as modifying or replacing browser toolbars, adding custom program buttons, etc.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>BHO relies on the main browser window and shares the same lifecycle as the browser instance, meaning the BHO object runs when the browser page opens and ends when the page closes\u003C\u002Fp>\u003Cp>Using BHO requires registration, which involves writing to the registry, located at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID} and HKEY_CLASSES_ROOT\\CLSID\\{GUID}\u003C\u002Fp>\u003Ch2>0x03 Developing BHO\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section provides only a brief introduction\u003C\u002Fp>\u003Cp>Development tools: VS2012\u003C\u002Fp>\u003Ch3>1. Generate DLL\u003C\u002Fh3>\u003Cp>New - Visual C++ - ATL\u003C\u002Fp>\u003Cp>Add - Class - ATL - ATL Simple Object, set the abbreviation as HelloWorldBHO, select IObjectWithSite (IE object support)\u003C\u002Fp>\u003Cp>Modify the following files:\u003C\u002Fp>\u003Cul>\u003Cli>HelloWorldBHO.h\u003C\u002Fli>\u003Cli>HelloWorldBHO.cpp\u003C\u002Fli>\u003Cli>dllmain.cpp\u003C\u002Fli>\u003Cli>HelloWorld.rgs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to http:\u002F\u002Fblog.csdn.net\u002Ffeier7501\u002Farticle\u002Fdetails\u002F11266345\u003C\u002Fp>\u003Cp>The GUID of the BHO is stored in helloworld.rgs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969365_0_f3b89df641-1.jpeg\">\u003C\u002Fp>\u003Cp>The name of the BHO is stored in HelloWorldBHO.rgs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975776_1_a07f51126c-1.jpeg\">\u003C\u002Fp>\u003Cp>In helloworld.rc, CompanyName represents the publisher, and PRODUCTVERSION represents the version, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986316_2_cd56f8a470-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The three figures above correspond to the display information of the add-on below\u003C\u002Fp>\u003Cp>HelloWorldBHO.cpp stores the operations corresponding to different events in the IE browser. Here, only an example code is introduced (for detailed code, refer to the open-source project), which implements displaying the current URL in a pop-up box when the page finishes loading. The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void STDMETHODCALLTYPE CHelloWorldBHO::OnDocumentComplete(IDispatch *pDisp, VARIANT *pvarURL)\u003Cbr>{\u003Cbr>    BSTR url = pvarURL-&gt;bstrVal;\u003Cbr>    CComBSTR u(url);\u003Cbr>    \u002F\u002F Retrieve the top-level window from the site.\u003Cbr>    HWND hwnd;\u003Cbr>    HRESULT hr = m_spWebBrowser-&gt;get_HWND((LONG_PTR*)&amp;hwnd);\u003Cbr>    if (SUCCEEDED(hr))\u003Cbr>    {\u003Cbr>        MessageBox(0, u, L\"the url is\", MB_OK);\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate helloworld.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If VS2012 does not have administrator privileges, a registration failure prompt may appear during compilation. Manual registration can be performed subsequently.\u003C\u002Fp>\u003Ch3>2. Register DLL\u003C\u002Fh3>\u003Cp>Administrator privileges required, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32 helloworld.dll \u002Fs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u002Fs parameter is used to suppress the success message box\u003C\u002Fp>\u003Cp>Equivalent to writing to registry, located at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{GUID} and HKEY_CLASSES_ROOT\\CLSID\\{GUID}\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Uninstall DLL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32 helloworld.dll \u002Fs \u002Fu\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or delete corresponding registry keys\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win 7 x86 IE8\u003C\u002Fp>\u003Cp>Open IE browser, dialog box pops up displaying current URL, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990721_3_861eb84179-1.jpeg\">\u003C\u002Fp>\u003Cp>View IE's add-ons, located under Tools &gt; Manage Add-ons, to obtain add-on information, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017995179_4_b88b3b5bae-1.jpeg\">\u003C\u002Fp>\u003Cp>The name, publisher, and version can be specified via the previously mentioned helloworld.rgs, HelloWorldBHO.rgs, and helloworld.rc files, while the file date corresponds to the modification time of the dll\u003C\u002Fp>\u003Cp>Since our self-generated dll lacks a Microsoft signature, it shows as unverified\u003C\u002Fp>\u003Ch2>0x05 Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Forge Microsoft signature, hide BHO\u003C\u002Fh3>\u003Cp>Add a Microsoft Authenticode signature to helloworld.dll, modify the registry to hijack the system's signature verification function, making the signature effective\u003C\u002Fp>\u003Cp>Refer to the previous article: 'Authenticode Signature Forgery—Signature Forgery and Verification Hijacking for PE Files'\u003C\u002Fp>\u003Cp>Requires a signature from Microsoft Corporation, which can be obtained from Office files, available path: C:\\Program Files\\Microsoft Office\\Office14\\URLREDIR.DLL\u003C\u002Fp>\u003Cp>Use SigThief to add the signature, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Cp>Parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i \"C:\\Program Files\\Microsoft Office\\Office14\\URLREDIR.DLL\" -t helloworld.dll -o new.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate new.dll\u003C\u002Fp>\u003Cp>Modify registry to hijack signature verification function:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Register DLL, reopen IE, view add-ons, verification passed, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017998152_5_7e95d90d00-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying BHO information can further hide the BHO\u003C\u002Fp>\u003Ch3>2. Capture browser POST data to record plaintext passwords\u003C\u002Fh3>\u003Cp>Open-source code for capturing browser POST data is available on GitHub, reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fliigo\u002Fbho\u003C\u002Fp>\u003Cp>Capture browser POST data before the BeforeNavigate2 event\u003C\u002Fp>\u003Cp>In my own project, I directly referenced the key function: STDMETHODIMP CBhoApp::Invoke(DISPID dispidMember, REFIID riid, LCID lcid, WORD wFlags, DISPPARAMS *pDispParams, VARIANT *pvarResult, EXCEPINFO *pExcepInfo, UINT *puArgErr)\u003C\u002Fp>\u003Cp>Add function declaration to implement logging functionality\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GetTempPath retrieves the Temp directory of the current system; under IE permissions, the actual path is %Temp%\\Low\u003C\u002Fp>\u003Cp>The complete code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Capture browser POST data to obtain user-entered plaintext passwords, such as GitHub login credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018001645_6_e12e375ca6-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Download files\u003C\u002Fh3>\u003Cp>By downloading files in this manner, the firewall software's management interface shows the downloading program as the IE browser, achieving a certain level of concealment\u003C\u002Fp>\u003Ch3>4. Inject JavaScript into IE pages\u003C\u002Fh3>\u003Cp>Refer to the following open-source project for further modifications:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fxiyiaoo\u002FBHO\u003C\u002Fp>\u003Cp>This article will not elaborate further\u003C\u002Fp>\u003Ch3>5. Supplementary notes\u003C\u002Fh3>\u003Cp>By default, BHO permissions are low, which imposes certain operational limitations. If higher permissions are obtained through other means, more exploitation methods become available\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The prerequisite for BHO exploitation is obtaining system administrator privileges\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Check the add-ons in the IE browser\u003C\u002Fli>\u003Cli>Check the DLLs loaded by the IE process\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the development method of IE Browser Helper Objects (BHO), analyzes the exploitation ideas after obtaining system administrator privileges, and touches upon some exploitation techniques without going into full detail\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1093,"Onedaysec",5,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"IE Browser Hijacking with BHO: Development & Exploitation Guide","IE browser hijacking, BHO development, Browser Helper Object, security bypass, network connection simulation, exploit techniques, defense strategies",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],502,501,499,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.022Z","2026-07-23T16:01:40.073Z","draft","2026-07-23T16:12:46.377Z"]