Elektrine lite

← Feed

@R41N3RZUF477@infosec.exchange

Post #4467158

2026-08-09 09:33 UTC

@tiraniddo@infosec.exchange PPL, but not PP suggests either because of Windows System DLLs that are not signed by file, but by catalog or because of a target program is signed for up to PPL-WinTCB. Now it needs to be hilariously trivial ... Maybe an oversight in loading catalog signed files? I haven't tried Windows redirection DLLs, but I'm sure they wouldn't load unless the DLL can be mapped from an outside process first. Maybe it has to do with loading an (old) vulnerable Windows System DLL that has no file signing? Maybe a COM DLL? Could it be a COM DLL loaded into WerFaultSecure.exe? At least I remember I have seen, that this program can load a COM DLL under certain circumstances. That would explain the wording. Sadly I'm not an expert in COM, so I don't know if there is an obvious "hey load this COM and you're pwned". 🤔 Hopefully I don't produce a duplicate. You jump scared me with PPL-WinTCB. I work on PPL bypass that can be run as system or as user, but as user only with SeBatchLogonRight. Hope that's not a duplicate.

Replies (1)