[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqyYGH5P7xFeJQDLJPrNzWEQWM-rBvuG0UhyXkaEAyd4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},683,"What are the limitations of using Long UNC filenames for catalog signature forgery?","The main limitations include: (1) the spoofed file cannot be executed via double-click or a standard path that includes a trailing space; (2) it requires write access to the target directory (e.g., `C:\\Windows\\System32`); (3) tools like `certutil.exe` and hash verifiers see the real file content, not the forged signature; (4) on 64-bit systems, file system redirection may interfere; (5) only files with catalog signatures (not Authenticode) can be spoofed this way. The article also contrasts this with [Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking](\u002Fnews\u002Fauthenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking).","\u003Cp>The main limitations include: (1) the spoofed file cannot be executed via double-click or a standard path that includes a trailing space; (2) it requires write access to the target directory (e.g., `C:\\Windows\\System32`); (3) tools like `certutil.exe` and hash verifiers see the real file content, not the forged signature; (4) on 64-bit systems, file system redirection may interfere; (5) only files with catalog signatures (not Authenticode) can be spoofed this way. The article also contrasts this with [Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking](\u002Fnews\u002Fauthenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fcatalog-signature-forgery-long-unc-filename-spoofing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-limitations-of-using-long-unc-filenames-for-catalog-signature-forge-1777482376747","limitations, system redirection, Authenticode vs catalog, execution constraints, hash verification",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},169,"Catalog Signature Forgery - Long UNC Filename Spoofing","catalog-signature-forgery-long-unc-filename-spoofing","Exploit Long UNC filenames to forge catalog signatures, copying attributes from system files to bypass security checks and deceive Windows.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles 'Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking' and 'Authenticode Signature Forgery - Signature Forgery for File Types' introduced methods for Authenticode signature forgery. This article will present a method for Catalog signature forgery, exploiting Long UNC filenames to deceive the system and obtain built-in Catalog signatures.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The techniques discussed in this article are based on publicly available materials by Matt Graeber (@mattifestation). This article combines personal experience, organizes relevant content, and adds personal insights.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2013\u002F02\u002FWindowsFileConfusion.html?m=1\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Long UNC Basics\u003C\u002Fli>\u003Cli>Methods for Long UNC Filename Spoofing\u003C\u002Fli>\u003Cli>Analysis of Advantages and Disadvantages of Long UNC Filename Spoofing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Long UNC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>UNC (Universal Naming Convention)\u003C\u002Fh3>\u003Cp>Universal Naming Convention, used to represent file locations in Windows systems\u003C\u002Fp>\u003Cp>For detailed information, please refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPath_(computing)\u003C\u002Fp>\u003Ch3>Long UNC\u003C\u002Fh3>\u003Cp>The maximum length supported by normal UNC is 260 characters\u003C\u002Fp>\u003Cp>To support longer characters, Long UNC was introduced, supporting a maximum length of 32767\u003C\u002Fp>\u003Cp>Format example: \\\\?\\C:\\test\\a.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\test\\longUNC.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, files using Long UNC are no different from ordinary files\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017368642_0_fedad74093.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Special usage:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a space is added after the Long UNC filename, the system's judgment of the filename will be incorrect\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\test\\mimikatz.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017393585_1_53c43aa279.jpeg\">\u003C\u002Fp>\u003Cp>Rename putty.exe to \"\\\\?\\C:\\test\\mimikatz.exe \", right-click to view the file properties of \"\\\\?\\C:\\test\\mimikatz.exe \"\u003C\u002Fp>\u003Cp>A strange discovery:\u003Cstrong>The properties show that this file has the attributes of the sample file mimikatz.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Intuitive understanding: Special Long UNC files can deceive the system into recognizing them as another file\u003C\u002Fp>\u003Ch2>0x03 Method of Long UNC filename spoofing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the previous section's test, we know that using Long UNC can copy file attributes\u003C\u002Fp>\u003Cp>So, if system files, or even files with catalog signatures, are copied, can catalog signature forgery be achieved?\u003C\u002Fp>\u003Ch3>Test 1: Forge the catalog signature of calc.exe\u003C\u002Fh3>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>Use sigcheck.exe to view the catalog signature of calc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017436371_2_e3551826f7.jpeg\">\u003C\u002Fp>\u003Cp>Long UNC File Forgery:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Output to c:\\windows\\system32 requires administrator privileges\u003C\u002Fp>\u003Cp>Special filenames must be placed in the same directory as the target, i.e., C:\\Windows\\System32, otherwise startup fails\u003C\u002Fp>\u003Cp>As shown below, verifying the conclusion that special Long UNC can copy file attributes\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017465696_3_7c1143cec5.jpeg\">\u003C\u002Fp>\u003Cp>In a previous article 'Advanced Techniques for Utilizing Hidden Alternative Data Streams', it was mentioned that special filenames can be replaced with short filenames\u003C\u002Fp>\u003Cp>Obtain short filename:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \u002Fx calc*.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480423_4_f9e20364e8.jpeg\">\u003C\u002Fp>\u003Cp>\"\\\\?\\C:\\Windows\\System32\\calc.exe \" can be replaced with the short filename CALC~1.EXE\u003C\u002Fp>\u003Cp>Use sigcheck.exe to view the catalog signature of this file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i C:\\Windows\\System32\\CALC~1.EXE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017489596_5_fb45e1d79c.jpeg\">\u003C\u002Fp>\u003Cp>successfully forged catalog signature\u003C\u002Fp>\u003Ch3>Test 2: Execute special Long UNC file\u003C\u002Fh3>\u003Cp>1. Cannot double-click to execute\u003C\u002Fp>\u003Cp>2. Via command line\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>system cannot find the specified path\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\CALC~1.EXE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>launch normal calc.exe\u003C\u002Fp>\u003Cp>3. Via WMIC\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create C:\\Windows\\System32\\CALC~1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Via VBS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set objShell = CreateObject(\"Wscript.Shell\")\u003Cbr>objShell.Run \"c:\\windows\\system32\\calc~1.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Via JS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>var wsh=new ActiveXObject(\"wscript.shell\");\u003Cbr>wsh.run(\"c:\\\\windows\\\\system32\\\\calc~1.exe\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After launch, the process name is calc~1.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Notable point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Verifying process signature via Process Explorer identifies it as the default Microsoft certificate for calc.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017500609_6_5616545519.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>File descriptions, such as \"SSH, Telnet and Rlogin client\" in the screenshot, can be forged by modifying program resources; the method is omitted here\u003C\u002Fp>\u003Cp>Conclusion:\u003Cstrong>Executing special Long UNC files can deceive Process Explorer's process signature verification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can deceive some log monitoring functions of Sysmon, such as Process creation\u003C\u002Fp>\u003Ch3>Test 3: Tools that cannot be deceived\u003C\u002Fh3>\u003Cp>1. Use certutil.exe to calculate MD5\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certutil.exe -hashfile C:\\Windows\\System32\\calc.exe MD5\u003Cbr>\u003Cbr>certutil.exe -hashfile C:\\Windows\\System32\\calc~1.exe MD5\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certutil.exe -hashfile \"\\\\?\\C:\\Windows\\System32\\calc.exe \" MD5\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error message indicates the system cannot find the file\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507279_7_dc3e4958b6.jpeg\">\u003C\u002Fp>\u003Ch3>Test 4: Generation of multiple folders with the same name\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003Cbr>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe  \"\u003Cbr>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe   \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017512939_8_a46406818f.jpeg\">\u003C\u002Fp>\u003Ch3>Test 5: Deletion of special Long UNC files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del C:\\Windows\\System32\\CALC~1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Test 6: Other system tests\u003C\u002Fh3>\u003Cp>Supports Win7-Win10\u003C\u002Fp>\u003Cp>64-bit systems need to pay attention to redirection issues\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Utilize special Long UNC filenames to deceive the system's judgment of file paths, achieving forged catalog signatures\u003C\u002Fp>\u003Cp>\u003Cstrong>Characteristics:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deceive the system's filename checks, disguise files as system files, forge catalog signatures\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Permission Control\u003C\u002Fp>\u003Cp>To spoof system files, writable permission to system folders is required\u003C\u002Fp>\u003Cp>2. File Identification\u003C\u002Fp>\u003Cp>Files with the same name in the same directory\u003C\u002Fp>\u003Cp>3. Process Name Judgment\u003C\u002Fp>\u003Cp>Special process names, formatted as short filenames, e.g., CALC~1.EXE\u003C\u002Fp>\u003Cp>4. Tool Detection\u003C\u002Fp>\u003Cp>Using certutil.exe to verify file hash\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for spoofing the system and obtaining Catalog signatures using special Long UNC filenames, analyzes exploitation methods, and shares defense strategies\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles 'Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking' and 'Authenticode Signature Forgery - Signature Forgery for File Types' introduced methods for Authenticode signature forgery. This article will present a method for Catalog signature forgery, exploiting Long UNC filenames to deceive the system and obtain built-in Catalog signatures.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The techniques discussed in this article are based on publicly available materials by Matt Graeber (@mattifestation). This article combines personal experience, organizes relevant content, and adds personal insights.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2013\u002F02\u002FWindowsFileConfusion.html?m=1\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Long UNC Basics\u003C\u002Fli>\u003Cli>Methods for Long UNC Filename Spoofing\u003C\u002Fli>\u003Cli>Analysis of Advantages and Disadvantages of Long UNC Filename Spoofing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Long UNC\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>UNC (Universal Naming Convention)\u003C\u002Fh3>\u003Cp>Universal Naming Convention, used to represent file locations in Windows systems\u003C\u002Fp>\u003Cp>For detailed information, please refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPath_(computing)\u003C\u002Fp>\u003Ch3>Long UNC\u003C\u002Fh3>\u003Cp>The maximum length supported by normal UNC is 260 characters\u003C\u002Fp>\u003Cp>To support longer characters, Long UNC was introduced, supporting a maximum length of 32767\u003C\u002Fp>\u003Cp>Format example: \\\\?\\C:\\test\\a.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\test\\longUNC.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, files using Long UNC are no different from ordinary files\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017368642_0_fedad74093-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Special usage:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a space is added after the Long UNC filename, the system's judgment of the filename will be incorrect\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\test\\mimikatz.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017393585_1_53c43aa279-1.jpeg\">\u003C\u002Fp>\u003Cp>Rename putty.exe to \"\\\\?\\C:\\test\\mimikatz.exe \", right-click to view the file properties of \"\\\\?\\C:\\test\\mimikatz.exe \"\u003C\u002Fp>\u003Cp>A strange discovery:\u003Cstrong>The properties show that this file has the attributes of the sample file mimikatz.exe\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Intuitive understanding: Special Long UNC files can deceive the system into recognizing them as another file\u003C\u002Fp>\u003Ch2>0x03 Method of Long UNC filename spoofing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the previous section's test, we know that using Long UNC can copy file attributes\u003C\u002Fp>\u003Cp>So, if system files, or even files with catalog signatures, are copied, can catalog signature forgery be achieved?\u003C\u002Fp>\u003Ch3>Test 1: Forge the catalog signature of calc.exe\u003C\u002Fh3>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Cp>Use sigcheck.exe to view the catalog signature of calc.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i c:\\windows\\system32\\calc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017436371_2_e3551826f7-1.jpeg\">\u003C\u002Fp>\u003Cp>Long UNC File Forgery:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Output to c:\\windows\\system32 requires administrator privileges\u003C\u002Fp>\u003Cp>Special filenames must be placed in the same directory as the target, i.e., C:\\Windows\\System32, otherwise startup fails\u003C\u002Fp>\u003Cp>As shown below, verifying the conclusion that special Long UNC can copy file attributes\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017465696_3_7c1143cec5-1.jpeg\">\u003C\u002Fp>\u003Cp>In a previous article 'Advanced Techniques for Utilizing Hidden Alternative Data Streams', it was mentioned that special filenames can be replaced with short filenames\u003C\u002Fp>\u003Cp>Obtain short filename:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir \u002Fx calc*.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480423_4_f9e20364e8-1.jpeg\">\u003C\u002Fp>\u003Cp>\"\\\\?\\C:\\Windows\\System32\\calc.exe \" can be replaced with the short filename CALC~1.EXE\u003C\u002Fp>\u003Cp>Use sigcheck.exe to view the catalog signature of this file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -i C:\\Windows\\System32\\CALC~1.EXE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017489596_5_fb45e1d79c-1.jpeg\">\u003C\u002Fp>\u003Cp>successfully forged catalog signature\u003C\u002Fp>\u003Ch3>Test 2: Execute special Long UNC file\u003C\u002Fh3>\u003Cp>1. Cannot double-click to execute\u003C\u002Fp>\u003Cp>2. Via command line\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>system cannot find the specified path\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\CALC~1.EXE\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>launch normal calc.exe\u003C\u002Fp>\u003Cp>3. Via WMIC\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create C:\\Windows\\System32\\CALC~1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Via VBS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set objShell = CreateObject(\"Wscript.Shell\")\u003Cbr>objShell.Run \"c:\\windows\\system32\\calc~1.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>5. Via JS\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>var wsh=new ActiveXObject(\"wscript.shell\");\u003Cbr>wsh.run(\"c:\\\\windows\\\\system32\\\\calc~1.exe\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After launch, the process name is calc~1.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Notable point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Verifying process signature via Process Explorer identifies it as the default Microsoft certificate for calc.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017500609_6_5616545519-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>File descriptions, such as \"SSH, Telnet and Rlogin client\" in the screenshot, can be forged by modifying program resources; the method is omitted here\u003C\u002Fp>\u003Cp>Conclusion:\u003Cstrong>Executing special Long UNC files can deceive Process Explorer's process signature verification\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can deceive some log monitoring functions of Sysmon, such as Process creation\u003C\u002Fp>\u003Ch3>Test 3: Tools that cannot be deceived\u003C\u002Fh3>\u003Cp>1. Use certutil.exe to calculate MD5\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certutil.exe -hashfile C:\\Windows\\System32\\calc.exe MD5\u003Cbr>\u003Cbr>certutil.exe -hashfile C:\\Windows\\System32\\calc~1.exe MD5\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certutil.exe -hashfile \"\\\\?\\C:\\Windows\\System32\\calc.exe \" MD5\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error message indicates the system cannot find the file\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507279_7_dc3e4958b6-1.jpeg\">\u003C\u002Fp>\u003Ch3>Test 4: Generation of multiple folders with the same name\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003Cbr>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe  \"\u003Cbr>type putty.exe &gt; \"\\\\?\\C:\\Windows\\System32\\calc.exe   \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017512939_8_a46406818f-1.jpeg\">\u003C\u002Fp>\u003Ch3>Test 5: Deletion of special Long UNC files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del \"\\\\?\\C:\\Windows\\System32\\calc.exe \"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del C:\\Windows\\System32\\CALC~1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Test 6: Other system tests\u003C\u002Fh3>\u003Cp>Supports Win7-Win10\u003C\u002Fp>\u003Cp>64-bit systems need to pay attention to redirection issues\u003C\u002Fp>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Utilize special Long UNC filenames to deceive the system's judgment of file paths, achieving forged catalog signatures\u003C\u002Fp>\u003Cp>\u003Cstrong>Characteristics:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deceive the system's filename checks, disguise files as system files, forge catalog signatures\u003C\u002Fp>\u003Cp>\u003Cstrong>Defense detection:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. Permission Control\u003C\u002Fp>\u003Cp>To spoof system files, writable permission to system folders is required\u003C\u002Fp>\u003Cp>2. File Identification\u003C\u002Fp>\u003Cp>Files with the same name in the same directory\u003C\u002Fp>\u003Cp>3. Process Name Judgment\u003C\u002Fp>\u003Cp>Special process names, formatted as short filenames, e.g., CALC~1.EXE\u003C\u002Fp>\u003Cp>4. Tool Detection\u003C\u002Fp>\u003Cp>Using certutil.exe to verify file hash\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for spoofing the system and obtaining Catalog signatures using special Long UNC filenames, analyzes exploitation methods, and shares defense strategies\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",802,"Onedaysec",4,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Catalog Signature Forgery via Long UNC Filename Spoofing","catalog signature forgery, long UNC spoofing, Windows security, file attribute copying, signature hijacking",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],682,681,680,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.899Z","2026-07-23T16:01:57.247Z","draft","2026-07-23T16:14:11.123Z"]