Anti Incident Response - SANS Computer Forensics
Anti Incident Response - SANS Computer Forensics
Anti Incident Response - SANS Computer Forensics
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
20<br />
DLL Search Order Hijacking<br />
• Main Culprit: C:\Windows\explorer.exe<br />
• Recursive Problem:<br />
– Ws2_32.dll is protected by KnownDlls<br />
–It loads iphlpapi.dll, which is not<br />
© 2012 CrowdStrike, Inc. All rights reserved.