All About DLL Hijacking - My Favorite Persistence Method

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ม.ค. 2025

ความคิดเห็น • 74

  • @ismailarame3756
    @ismailarame3756 2 ปีที่แล้ว +34

    ippsec i am so amazed that your channel is so organized and consistent as well as putting timestamps in each video you release i do not know how thank you, you made it easy for us to learn i appreciate it too much 🖤🖤

  • @pbjandahighfive
    @pbjandahighfive 2 ปีที่แล้ว +4

    lul
    14:55 "Let's see... is there a process name?"
    >Proceeds to pass directly over "Process Name" no less than 3 times.
    Great video all the same. Subscribed.

  • @elevatecyber5031
    @elevatecyber5031 2 ปีที่แล้ว +20

    This is such good information. It's surprising that DLL hijacking isn't talked about more in this community. This is core education for any aspiring red teamer.

    • @trustedsecurity6039
      @trustedsecurity6039 2 ปีที่แล้ว +2

      It is talked a lot but you dont see it because you just look at channel where only basic stuff is teach

  • @cemkaaidarov2415
    @cemkaaidarov2415 ปีที่แล้ว

    Thank you for sharing another great video. I'm grateful for the knowledge you've shared. I've lived in this area for 10 years and I'm excited to share this with my team, especially with the "kids". Your video will help them understand the topic much faster than my long and sometimes boring lectures.

  • @allenxd
    @allenxd 2 ปีที่แล้ว

    OMG Nice timing ippsec! was doing a thick client test and actually trying some dll hijacking stuff. lol this is really helpful.

  • @shiverello6109
    @shiverello6109 2 ปีที่แล้ว +6

    Me at 8 in the morning after many hours of HTB "Im in a weird state" xD Love your videos, very organized and just full of information 👌

  • @atthaphonrattanarueanphet1362
    @atthaphonrattanarueanphet1362 2 ปีที่แล้ว

    So MANY of the episodes are bangers

  • @jmprcunha
    @jmprcunha 2 ปีที่แล้ว

    It is always a pleasure watching Your videos. Thank You Ippsec!

  • @thepianoaddict
    @thepianoaddict 2 ปีที่แล้ว +8

    Maybe these shortcuts don't work if you're in a vm, but on windows 10 if you hit win+x it will open a menu, if you then hit i, it will open powershell, if you do win+x and then a, it will open powershell as admin.
    These shortcuts work for the english version of windows, other languages sometimes have other keys once you're inside the menu.
    Very informative video!

  • @HishanShouketh
    @HishanShouketh 2 ปีที่แล้ว

    The right daily dose of cyber security, thank you so much for this awesome demo.so well explained.

  • @vectar
    @vectar 2 ปีที่แล้ว

    Thanks for the amazing content IppSec! Love your channel, keep em coming!

  • @ex6tenCe
    @ex6tenCe 2 ปีที่แล้ว

    wow this video showed a couple of cool ideas, which were unknown to me. got my sub

  • @mounir7320
    @mounir7320 2 ปีที่แล้ว +5

    thanks for the video...it would be great if you share some evasion techniques of (modern AV/EDR..) using DLL hijacking.

    • @ippsec
      @ippsec  2 ปีที่แล้ว +29

      That sounds like a very dangerous thing to share. I wouldn't do a video on something so weaponizable.

    • @damuffinman6895
      @damuffinman6895 2 ปีที่แล้ว +2

      Just use base64 encoding works all the time

    • @dadamnmayne
      @dadamnmayne 2 ปีที่แล้ว +4

      Offensive Security has entered the chat.

    • @maclie7078
      @maclie7078 2 ปีที่แล้ว

      @@ippsec if I'm not wrong your doing part of cybersecurity and penetration testing and of course they are part of it any thanks you help us every day😊

    • @AUBCodeII
      @AUBCodeII 2 ปีที่แล้ว

      pepsic is an anagram of ippsec.

  • @digitaldavid5633
    @digitaldavid5633 2 ปีที่แล้ว

    Very Helpful! Please do more like this. Thanks!

  • @securiti
    @securiti 2 ปีที่แล้ว

    Helpful videos! Love your content.
    Would love to catch a live stream some day on Twitch.

  • @R4z0r_arg
    @R4z0r_arg 11 หลายเดือนก่อน

    Amazing video IppSec, thanks

  • @khalilthebest7005
    @khalilthebest7005 2 ปีที่แล้ว +1

    😁wow that’s cool 👍the best part

  • @Badcitizenlgn
    @Badcitizenlgn ปีที่แล้ว

    Amazing content, thanks for sharing

  • @akazaka3578
    @akazaka3578 2 ปีที่แล้ว

    Oh didn't realize you are on Twitch now. I'll be sure to check out your streams.

  • @jumpstep7085
    @jumpstep7085 2 ปีที่แล้ว

    More persistence and slipping under the radar! :D

  • @Cod3rMax
    @Cod3rMax 2 ปีที่แล้ว

    But is is possible to write the code that you did in c++ with c#? Because when i do it and i try i'm getting error trying to access peotected memory

  • @kavishkagihan9495
    @kavishkagihan9495 2 ปีที่แล้ว

    Being new at DLL hijacking, I am having trouble understanding how DLL proxying works. Would love a dedicated video about that topic. Cheers!

    • @ippsec
      @ippsec  2 ปีที่แล้ว +3

      It’s not high on my priority list because it’s not valuable for defenders to understand that concept. I try to keep it at a basics level for red team stuff.

    • @kavishkagihan9495
      @kavishkagihan9495 2 ปีที่แล้ว

      If anyone is curious like myself about DLL proxying, check this out th-cam.com/video/tSdyfaJ7T50/w-d-xo.html

  • @romanxyz7248
    @romanxyz7248 2 ปีที่แล้ว

    Amazing video.Thank you ❤️

  • @AnkitSharma-cs6ez
    @AnkitSharma-cs6ez ปีที่แล้ว

    Hey ippsec, I am not able to cd or dir ..\.dotnet\ I tried different ways but it is not working. I am using Windows 11. is it the one causing issues or what is it ?

  • @callmekelvin
    @callmekelvin 2 ปีที่แล้ว

    Another great video...

  • @Novastuffnow
    @Novastuffnow 2 ปีที่แล้ว

    Great video!

  • @IBITZEE
    @IBITZEE 2 ปีที่แล้ว

    such good info...
    and doing it live helps a lot to avoid those 'natural' mistakes...
    ps: you site design seems just useful... no sh***... just all the juice...

  • @zedeleyici.1337
    @zedeleyici.1337 2 ปีที่แล้ว

    you are great, i love it

  • @jarsal_firahel
    @jarsal_firahel ปีที่แล้ว

    Pretty awesome !

  • @UmairAli
    @UmairAli 2 ปีที่แล้ว

    this is so awesome

  • @TracerPortable
    @TracerPortable 2 ปีที่แล้ว

    I fell like you are quite swifty with winapi, any tips? Maybe some video with basics? I don't know why but when I see MS documentation I just want to puke, I barely understand anything

  • @MrSerek
    @MrSerek 2 ปีที่แล้ว

    can you do priv esc with this? Find some app running as system with a missing dll and slap a fake dll into writeable path to run some commands would be my guess

    • @ippsec
      @ippsec  2 ปีที่แล้ว

      Yes, that is certainly possible.

    • @hexagon6290
      @hexagon6290 2 ปีที่แล้ว

      Some apps you can replace a DLL they load with your own and gain privs that way

    • @MrSerek
      @MrSerek 2 ปีที่แล้ว

      @@hexagon6290 yeah thats the goal, I need to find some weak (writeable and loading dlls that arent in KnownDlls) file running as NT Authority.

    • @trustedsecurity6039
      @trustedsecurity6039 2 ปีที่แล้ว

      @@hexagon6290 you dont need to replace an existing DLL for that... i didnt looked the video so idk if ippsec talks about it but im sure he did, you just see what DLL isnt found by known software installed in the victim workstation on a writable directory

  • @stanislavsmetanin1307
    @stanislavsmetanin1307 ปีที่แล้ว

    Wow)) It is fantastic

  • @peterw6583
    @peterw6583 2 ปีที่แล้ว

    If cscapi.dll is replaced by your customized one, won't it affect the normal behavior of explorer.exe?

    • @ippsec
      @ippsec  2 ปีที่แล้ว +1

      Normally if you don’t use a dll proxy technique yes. However, I think explorer just imports cscapi but doesn’t use it

  • @vincenttheriault3256
    @vincenttheriault3256 2 ปีที่แล้ว

    Amazing info

  • @itswellick9507
    @itswellick9507 2 ปีที่แล้ว

    hey ippsec. Is it possible to watch the twitch live stream history?

    • @ippsec
      @ippsec  2 ปีที่แล้ว

      Nope, think i said it at the start of the video but at this time, I don't plan on releasing VOD's for my streams.

    • @itswellick9507
      @itswellick9507 2 ปีที่แล้ว

      @@ippsec I'm sorry I missed it. By the way, thanks for everything you taught me.

    • @ippsec
      @ippsec  2 ปีที่แล้ว +3

      No worries, I plan on uploading raw clips or redoing them like this one for the YT. I’m just more comfortable in interacting with people live if there’s no record of it. I may setup the patreon again and post recordings there, just don’t want to do it before it’s a routine

  • @zedeleyici.1337
    @zedeleyici.1337 2 ปีที่แล้ว

    thnaks for content !

  • @epicvideos41
    @epicvideos41 2 ปีที่แล้ว

    sir you did not show how to fix it

  • @xternl_
    @xternl_ 2 ปีที่แล้ว

    Wonderful.

  • @ca7986
    @ca7986 2 ปีที่แล้ว

    ❤️

  • @JOJO-no8rb
    @JOJO-no8rb 2 ปีที่แล้ว

    Can you do more content about win api with c

  • @wyteedeng1874
    @wyteedeng1874 2 ปีที่แล้ว

    I got a cat ?

  • @AUBCodeII
    @AUBCodeII 2 ปีที่แล้ว

    ipp
    dll

  • @kezkya3683
    @kezkya3683 2 ปีที่แล้ว

    Waw, u r such a gem

  • @spear7916
    @spear7916 2 ปีที่แล้ว +1

    First

  • @itsme7570
    @itsme7570 2 ปีที่แล้ว

    Man oh man. More of this type of content please. Anyone know of a way to bypass cdn or cloud providers to find origin IP? My trusty python script that always works is failing on some of these cloud hosted sites or cloud firewall

  • @cipher4873
    @cipher4873 2 ปีที่แล้ว

    heeyyy

  • @yahyahassan3430
    @yahyahassan3430 2 ปีที่แล้ว

    The website needs a domain renewal. Anyway thanks for the content.

  • @JOJO-no8rb
    @JOJO-no8rb 2 ปีที่แล้ว

    Ippsec thank you very much