Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
أدوات/GitHubGitHub/conscioushacker/wfh
التحليل الديناميكي (عزل)الاستغلالالاختبار العشوائيتحليل الملفات الثنائية
GitHubconscioushacker/wfh

WFH

أداة تحليل ديناميكي قائمة على Frida تحدد تلقائيًا نقاط ضعف تحميل DLL الجانبي واختطاف COM في تنفيذيات ويندوز من خلال الإعداد الآلي أثناء التشغيل وتحليل IAT.

عرض المستودع
43672منذ 4 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

متصيد ميزات ويندوز (WFH)

متصيد ميزات ويندوز (WFH) هو سكربت إثبات مفهوم بلغة بايثون يستخدم Frida، وهي مجموعة أدوات تحليل ديناميكي، للمساعدة في التعرف المحتمل على "الثغرات" أو "الميزات" الشائعة داخل برامج ويندوز التنفيذية. يمتلك WFH حاليًا القدرة على التعرف التلقائي على فرص تحميل المكتبات الديناميكية (DLL) الجانبية واختطاف نموذج كائن المكون (COM) على نطاق واسع.

يستخدم تحميل DLL الجانبي تجميع ويندوز جنبًا إلى جنب (WinSXS) لتحميل DLL ضار من قائمة SXS. يسمح اختطاف COM للمهاجم بإدخال كود ضار يمكن تنفيذه بدلاً من البرنامج الشرعي من خلال اختطاف مراجع وعلاقات COM. سيقوم WFH بطباعة الثغرات المحتملة وكتابة ملف CSV يحتوي على الثغرات المحتملة في برامج ويندوز التنفيذية المستهدفة.

جدول المحتويات

  • متصيد ميزات ويندوز (WFH)
    • تثبيت WFH
    • مساعدة WFH
    • استخدام WFH
      • تحديد تحميل DLL الجانبي بواسطة WFH
      • تحديد اختطاف COM بواسطة WFH
    • حالات استخدام WFH
      • برامج ويندوز التنفيذية الموقعة الأصلية
  • متصيد ميزات ويندوز درايدكس (WFH Dridex)
    • تثبيت WFH Dridex
    • تبعيات WFH Dridex
    • استخدام WFH Dridex
      • تحديد تحميل DLL الجانبي بواسطة WFH Dridex
    • تحميلات DLL الجانبية بواسطة WFH Dridex من System32
      • نتائج مقارنة WFH و WFH Dridex
  • مساهمة HijackLibs

تثبيت WFH

root@kitploit:~
pip install -r requirements.txt

مساعدة WFH

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -h
usage: wfh.py [-h] -t T [T ...] -m {dll,com} [-v] [-timeout TIMEOUT]

Windows Feature Hunter

optional arguments:
  -h, --help            show this help message and exit
  -t T [T ...], -targets T [T ...]
                        list of target windows executables
  -m {dll,com}, -mode {dll,com}
                        vulnerabilities to potentially identify
  -v, -verbose          verbose output from Frida instrumentation
  -timeout TIMEOUT      timeout value for Frida instrumentation

EXAMPLE USAGE
    NOTE: It is recommended to copy target binaries to the same directory as wfh for identifying DLL Sideloading

    DLL Sideloading Identification (Single):        python wfh.py -t .\mspaint.exe -m dll
    DLL Sideloading Identification (Verbose):       python wfh.py -t .\mspaint.exe -m dll -v
    DLL Sideloading Identification (Timeout 30s):   python wfh.py -t .\mspaint.exe -m dll -timeout 30
    DLL Sideloading Identification (Wildcard):      python wfh.py -t * -m dll
    DLL Sideloading Identification (List):          python wfh.py -t .\mspaint.exe .\charmap.exe -m dll

    COM Hijacking Identification (Single):          python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
    COM Hijacking Identification (Verbose):         python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -v
    COM Hijacking Identification (Timeout 60s):     python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -timeout 60
    COM Hijacking Identification (Wildcard):        python wfh.py -t * -m com -v
    COM Hijacking Identification (List):            python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Windows\System32\notepad.exe" -m com -v

استخدام WFH

تحديد تحميل DLL الجانبي بواسطة WFH

أولاً، تحتاج إلى نسخ البرامج التنفيذية التي تريد تحليلها إلى نفس دليل WFH

root@kitploit:~
PS C:\Tools\WFH > copy C:\Windows\System32\mspaint.exe .
PS C:\Tools\WFH > copy C:\Windows\System32\charmap.exe .
PS C:\Tools\WFH > dir


    Directory: C:\Tools\WFH


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         5/14/2021   2:12 PM                .vscode
-a----          5/6/2021   2:39 PM           1928 .gitignore
-a----         12/7/2019   2:09 AM         198656 charmap.exe
-a----         5/18/2021   7:39 AM           6603 loadlibrary.js
-a----          4/7/2021  12:48 PM         988160 mspaint.exe
-a----         5/18/2021   7:53 AM           8705 README.md
-a----         5/17/2021  11:27 AM           5948 registry.js
-a----          5/6/2021   2:41 PM             11 requirements.txt
-a----         5/18/2021   8:35 AM          10623 wfh.py

الآن يمكنك تشغيل wfh ضد البرامج التنفيذية لتحديد فرص تحميل DLL الجانبي

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t * -m dll
==================================================
Running Frida against charmap.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

PS C:\Tools\WFH > type .\dll_results.csv
Executable,WinAPI,DLL,EntryPoint / WinAPI Args
charmap.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
charmap.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
mspaint.exe,LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
mspaint.exe,GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
mspaint.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
mspaint.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

إذا كنت تفضل إخراجًا أكثر تفصيلاً، يمكنك استخدام "-v" لرؤية كل رسالة من Frida أثناء تنصيب استدعاءات واجهة برمجة تطبيقات ويندوز. يمكنك أيضًا عرض هذا الإخراج في ملف السجل الخام.

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t * -m dll -v
==================================================
Running Frida against charmap.exe
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE'}
{'type': 'send', 'payload': 'GetProcAddress,hModule : C:\\WINDOWS\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\\gdiplus.dll, LPCSTR: GdiplusStartup'}
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

تحديد اختطاف COM بواسطة WFH

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
==================================================
Running Frida against C:\Program Files\Internet Explorer\iexplore.exe
--------------------------------------------------
        [+] Potential COM Hijack: Path : HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32,lpValueName : null,Type : REG_EXPAND_SZ, Value : %SystemRoot%\system32\Windows.Storage.dll
        [+] Potential COM Hijack: Path : HKEY_CLASSES_ROOT\CLSID\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}\InProcServer32,lpValueName : null,Type : REG_SZ, Value : C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.62\BHO\ie_to_edge_bho_64.dll

[*] Writing raw Frida instrumentation to .\iexplore.exe-raw.log
[*] Writing Potential COM Hijack to .\iexplore.exe-comhijack.log
--------------------------------------------------
==================================================
[*] Writing dll results to comhijack_results.csv

حالات استخدام WFH

برامج ويندوز التنفيذية الموقعة الأصلية

انسخ جميع برامج ويندوز التنفيذية الموقعة الأصلية إلى دليل wfh

root@kitploit:~
Get-ChildItem c:\ -File | ForEach-Object { if($_ -match '.+?exe$') {Get-AuthenticodeSignature $_.fullname} } | where {$_.IsOSBinary} | ForEach-Object {Copy-Item $_.path . }

ابحث عن فرص تحميل DLL الجانبي

root@kitploit:~
python wfh.py -t * -m dll

ابحث عن فرص اختطاف COM

root@kitploit:~
python wfh.py -t * -m com

متصيد ميزات ويندوز درايدكس (WFH Dridex)

متصيد ميزات ويندوز درايدكس (WFH Dridex) هو سكربت إثبات مفهوم بلغة بايثون مستوحى من مُحمّل Dridex. يحلل WFH Dridex جدول عناوين الاستيراد (IAT) للبرامج التنفيذية المستهدفة، ويُجمّع DLL لكل إدخال في IAT الخاص بالبرامج التنفيذية، ويتحقق مما إذا تم تحديد تحميل DLL جانبي.

حدد الإصدار الأصلي من WFH ما يقرب من 96 فرصة محتملة لتحميل DLL الجانبي. حدد WFH Dridex ما يقرب من 966 فرصة محققة لتحميل DLL الجانبي.

تثبيت WFH Dridex

root@kitploit:~
pip install -r requirements.txt

تبعيات WFH Dridex

MingW G++ (64 bit)

g++.exe يجب إضافة g++.exe إلى متغير بيئة PATH بعد التثبيت لكي يعمل WFH Dridex بشكل صحيح.

استخدام WFH Dridex

تحديد تحميل DLL الجانبي بواسطة WFH Dridex

أولاً، تحتاج إلى نسخ البرامج التنفيذية التي تريد تحليلها إلى نفس دليل WFH Dridex

root@kitploit:~
❯ cp C:\Windows\System32\mspaint.exe .
❯ cp C:\Windows\System32\charmap.exe .
root@kitploit:~
❯ python .\wfh_dridex.py
[*] Creating a payload for charmap.exe with GetUName.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oGetUName.dll dllmain.c
    |_ Testing charmap.exe with GetUName.dll for DLL sideloading opportunity
    |_ PID: 8936
[>] Listing working DLL sideloads
    |_ charmap.exe GetUName.dll
[*] Creating a payload for mspaint.exe with MFC42u.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive testaroo.def -oMFC42u.dll dllmain.c
    |_ Testing mspaint.exe with MFC42u.dll for DLL sideloading opportunity
    |_ PID: 9472
[*] Creating a payload for mspaint.exe with PROPSYS.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oPROPSYS.dll dllmain.c
    |_ Testing mspaint.exe with PROPSYS.dll for DLL sideloading opportunity
    |_ PID: 11308
[*] Creating a payload for mspaint.exe with WINMM.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oWINMM.dll dllmain.c
    |_ Testing mspaint.exe with WINMM.dll for DLL sideloading opportunity
    |_ PID: 180
[>] Listing working DLL sideloads
    |_ mspaint.exe MFC42u.dll
    |_ mspaint.exe PROPSYS.dll
    |_ mspaint.exe WINMM.dll

الآن يمكنك تشغيل WFH Dridex ضد البرامج التنفيذية لتحديد فرص تحميل DLL الجانبي

root@kitploit:~
❯ gc .\results.csv
Executable,DllName
charmap.exe,GetUName.dll
mspaint.exe,MFC42u.dll
mspaint.exe,PROPSYS.dll
mspaint.exe,WINMM.dll

تحميلات DLL الجانبية بواسطة WFH Dridex من System32

يمكن الاطلاع على نموذج إخراج CSV من تشغيل WFH Dridex ضد C:\Windows\System32 هنا.

نتائج مقارنة WFH و WFH Dridex

حدد الإصدار الأصلي من WFH ما يقرب من 96 فرصة محتملة لتحميل DLL الجانبي. حدد WFH Dridex ما يقرب من 966 فرصة محققة لتحميل DLL الجانبي.

مساهمة HijackLibs

كجزء من إصدار WFH Dridex، تم تقديم طلب سحب إلى مشروع HijackLibs الخاص بـ Wietze والذي تضمن 507 إدخالات جديدة للمشروع.

تنزيل الأداة