Skip to content

Latest commit

 

History

History
58 lines (33 loc) · 1.22 KB

README.md

File metadata and controls

58 lines (33 loc) · 1.22 KB

Vulnerable Windows Application

Vulnerable Windows Application for Pentesters.

Disclaimer

Warning! You are about to install DarkRelay's Vulnerable Windows Application! Purpose of the application is to educate students on Windows Thick Client Pentesting. If you use this application for malicious means or if your server is compromised via an installation of this application,DarkRelay does not hold any responsibility! If you have more questions, please write to us https://www.darkrelay.com/get-started

Write-ups

https://www.darkrelay.com/post/thick-client-penetration-testing

Vulnerabilities

DLL Hijacking

EXE Hijacking

Symlink Attacks

IFEO Injection

Unquoted Service Paths

Man In the Middle Attack

Weak Named Pipes

Weak Memory Protection

Stack Overflow

Absence of Digital Signatures

COM Hijacking

Process Injection

Heap Overflow

Installation

Install the msi as an Administrator

Platorms Supported

Windows 10 x64, Windows 2016 and 2019 x64

Recommended pentest tools

Microsoft Sysinternal Tools

Immunity Debugger

Symboliclink-testing-tools from Google

Echo Mirage

Regshot

Windows Attack Surface Analyzer

mingw compiler c++