3 ms·
I can imagine it would be possible to reverse engineer the service interfaces of DolbyDAX2API.exe ("exported functions"), write a wrapper which embeds the origi
by derFunk 11y ago
I can imagine it would be possible to reverse engineer the service interfaces of DolbyDAX2API.exe ("exported functions"), write a wrapper which embeds the original executable and forwards the service requests to the original implemententation. The wrapper could contain malicious code and intercept the service calls.
This could be even done generically. Maybe something like this exists already anyway.
This way nobody would notice that something is wrong - functionality wise. Perfect eavesdropping on Windows services.
- roddux 11y agoI was thinking this was where the article was going, but the solution ended up being a lot simpler. It leaves traces and notifies the user, though... I suppose yet another way would be to make a copy of the executable before the overwrite, then restore it after gaining a stable SYSTEM shell.