TGViewer
P.F.K 0Day P.F.K 0Day @pfk_0day · 1.12K subscribers
Post #40 1.1K
​​Save the Environment

Many applications appear to rely on Environment Variables such as %SYSTEMROOT% to load DLLs from protected locations.

By changing these variables on process level, it is possible to let a legitimate program load arbitrary DLLs.

https://github.com/wietze/windows-dll-env-hijacking

Research:
https://www.wietzebeukema.nl/blog/save-the-environment-variables

#maldev #dll #hijacking #environment
@pfk_0day
GitHub GitHub - wietze/windows-dll-env-hijacking: Project for identifying executables and DLLs vulnerable to environment-variable based… Project for identifying executables and DLLs vulnerable to environment-variable based DLL hijacking. - wietze/windows-dll-env-hijacking
More from @pfk_0day
  1. Oct 4, 2026🔥 جشن شهریورگان / ۳۰ امرداد 💠 شهریورگان، جشنی به پاس شهریور امشاسپند است. شهریور، فروزه‌…
  2. Oct 4, 2026⁨ به یاد مردی که نامش با آزادی، خرد، دادگری و بزرگواری در تاریخ ایران جاودانه شد؛ مردی که…
  3. Nov 6, 2025🎓 مرجع تخصصی آموزش تست نفوذ و رد تیم TryHackBox و Ai Security 📌 در اینجا، آموزش‌ های خود…
  4. Sep 30, 2025ADKAVEH — PowerShell tool for AD enumeration & attack simulation ADKAVEH is a PowerShell s…
  5. Apr 19, 2023https://github.com/oldboy21/CGPL
  6. Apr 17, 2023​​pdtm ProjectDiscovery's Open Source Tool Manager A simple and easy-to-use golang based t…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →