• We just launched and are currently in beta. Join us as we build and grow the community.

FaceDancer ¦ exploitation tool DLL

elyes123456789

Earnings Stream Designer
E Rep
0
0
0
Rep
0
E Vouches
0
0
0
Vouches
0
Posts
132
Likes
50
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 300 XP
FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs. FaceDancer performs two main functions:
  • Recon: Scans a given DLL to create the export definition file for proxying.
  • Attack: Creates a malicious DLL containing shellcode that can proxy valid function requests to the legitimate DLL.
FaceDancer contains numerous methods for performing DLL hijacking. These DLLs take advantage of either weak permissions on installation folders or COM-based system DLL image loading to load a malicious version of a legitimate DLL. Once loaded, the DLL executes the embedded shellcode while proxying valid requests for DLL functions to the legitimate DLL. This is done using a .def file to map the valid requests to the correct DLL, allowing a low-privilege user to proxy a legitimate DLL through a malicious one. This bypasses application whitelisting controls as FaceDancer targets native processes needed for standard operation, making it effective for initial access or persistence.
FaceDancer contains zero evasion techniques. FaceDancer’s sole focus is discovering and generating DLLs for proxying. It is important that the inputted DLL contains all the necessary evasion techniques.
You must upgrade your account or reply in the thread to view hidden text.
 

431,509

312,456

312,465

Top