Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add wow64log.yml #98

Merged
merged 5 commits into from
Jan 23, 2025
Merged

Add wow64log.yml #98

merged 5 commits into from
Jan 23, 2025

Conversation

ice-wzl
Copy link
Contributor

@ice-wzl ice-wzl commented Jan 2, 2025

Summary

  • This PR adds wow64log.dll and the vulnerable executable cmder.exe that loads the library. The Phantom DLL Hijacking was recently discovered while digging into some Windows internals

@ice-wzl ice-wzl requested a review from wietze as a code owner January 2, 2025 04:01
Copy link
Owner

@wietze wietze left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @ice-wzl , great find! Since the DLL likely originally was written by Microsoft (but no longer ships with Windows since at least Windows 7), I have moved the entry to the Microsoft folder. Let me know if you agree with the change and if so, I'll merge it to the main repo. Thanks!

@ice-wzl
Copy link
Contributor Author

ice-wzl commented Jan 23, 2025

@wietze Thank you for the kind words! That is a good point, and upon realization, I agree 100%. Based upon what you just mentioned, I suspect there are many more applications that look for this DLL outside of just cmder.

@wietze wietze merged commit 4f26674 into wietze:main Jan 23, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants