From ed66f00f16363ba197ea0b67a5eea5ca9ea2e200 Mon Sep 17 00:00:00 2001 From: Nick Landers Date: Wed, 19 Feb 2020 11:44:40 -0700 Subject: [PATCH] Add example to README --- README.md | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/README.md b/README.md index 0d18a51..a73ab54 100644 --- a/README.md +++ b/README.md @@ -16,3 +16,30 @@ The VS solution itself supports 4 build configurations which map to 4 different The goal of each technique is to successfully capture code execution while proxying functionality to the legitimate DLL. Each technique is tested to ensure static and dynamic sink situations are handled. This is by far not every primitive or technique variation. The post above goes into more detail. +## Example + +Prepare a hijack scenario with an obviously incorrect DLL +``` +> copy C:\windows\system32\whoami.exe .\whoami.exe + 1 file(s) copied. + +> copy C:\windows\system32\kernel32.dll .\wkscli.dll + 1 file(s) copied. + +``` + +Executing in the current configuration should result in an error +``` +> whoami.exe + +"Entry Point Not Found" +``` + +Convert kernel32 to proxy functionality for wkscli +``` +> NetClone.exe --target C:\windows\system32\kernel32.dll --reference C:\windows\system32\wkscli.dll --output wkscli.dll +[+] Done. + +> whoami.exe +COMPUTER\User +``` \ No newline at end of file