Sunday, September 8, 2013

[Tool] DLL Hijack Helper


https://code.google.com/p/yehg-core-lab-misc/source/browse/#svn%2Ftrunk%2Fdll-hijack-helper

This tool will aid you in your manual DLL Hijacking vulnerability hunting when automatic approach does not smoothly work.


How-to
++++++++++++++++++++++++++++++

1. Run ProcMon
2. Set filter rule with result "NAME NOT FOUND"
3. Run your target application
4. Save ProcMon output as CSV
5. Run dll-hijack-helper.py