Executable and DLL planting

Some writable shares host programs that users launch or that services run on a schedule. Replacing or adding an executable there runs attacker code when it is next used. More subtly, planting a DLL next to an executable on the share, one it loads by search order or sideloading, runs code in that program's context without modifying the executable itself.

bash
# Replace or add a binary users run from the share (smbclient from Linux)
smbclient //<target>/share -U user%pass -c 'cd Tools; put payload.exe update.exe'
# Or sideload a DLL the share's EXE loads from its own directory
smbclient //<target>/share -U user%pass -c 'cd App; put evil.dll version.dll'   # loaded by App.exe via search order

Exploitation notes#

  • Target programs that run with higher privilege than the planter: a service that executes from the share, or an admin's tool.
  • DLL sideloading is stealthier than replacing the EXE, since the signed executable is untouched; identify which DLLs the share's binaries resolve relatively.
  • Scheduled tasks and logon scripts that point at a writable share path are reliable execution triggers.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more