3 ms·
> DLL injection API DLL "injection"? What API is that?
by hypervis0r 9y ago
> DLL injection API
DLL "injection"? What API is that?
- Animats 9y agoThere are ways in Windows to start a new thread in another process.[1] Most of these involve the OpenProcess function.[2] This gives one process access to the state of another process. Once a handle to another process has been obtained, it can be used for starting a new thread in that process, which can load code into the process's address space. There are security checks, but they suffer from the usual problem of assuming that the security entity is the user, not the application. This is mostly a debug facility, but it has other misuses. [1] https://www.codeproject.com/Articles/4610/Three-Ways-to-Inject-Your-Code-into-Another-Proces https://www.codeproject.com/Articles/4610/Three-Ways-to-Inje... [2] https://msdn.microsoft.com/en-us/library/windows/desktop/ms684320(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/ms6...
- hypervis0r 9y agoI know what DLL injection is. I was challenging the "DLL injection API" expression, because there's no such thing as an API that allows you to arbitrarily inject a DLL into a target process. Put it this way: InjectDllIntoProcessEx() does not exist. > (one of Windows' stranger features) It is not a feature by any means. It's hackery and, by the time you've got a handle to the process with PROCESS_CREATE_THREAD (you don't even need PROCESS_VM_WRITE), it's game over. Use ACLs to disallow getting a handle with the necessary permissions if you want to avoid code injection. This post, however, makes no sense. Running an infected Word document with admin permissions is, like somebody else said on this thread, running 'rm -rf /' as root.