tothi/dll-hijack-by-proxying

Still viable?

Opened this issue · 1 comments

Awesome project that thought me a quite a bit about dll sideloading. However, I'm reading your post here https://reposhub.com/cpp/miscellaneous/tothi-dll-hijack-by-proxying.html and I was wondering if this method is still viable? Been following the post but for some reason my calc.exe never runs. When I build a simple dll in C++ that also runs calc.exe (without any proxying) it works, but as soon as I try to enable proxying, it stops working. Any idea?

tothi commented

yes, this still should work. (used it recently for something.)