![]() |
#17
|
|||
|
|||
ok
we can not load dll from %systemroot%\system32 in some situations. the behavor is change if used the registry data for "SafeDllSearchMode" is set 1 in [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] or "DevOverrideEnable" is set 1 in [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] with .local for the executable file extension |
The Following User Says Thank You to FoxB For This Useful Post: | ||
niculaita (08-27-2022) |
Tags |
dll, hijacking |
Thread Tools | |
Display Modes | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Windows Handle Hijacking | TechLord | General Discussion | 2 | 05-15-2017 20:11 |