Watch how whitelisting stops Microsoft DLL hijacking attack

  • Email This Post
This entry was posted in endpoint security, Featured, whitelisting and tagged , , , , . Bookmark the permalink.


Recently, “MUTTS” at Offensive Security Training did an excellent video demonstrating the Metasploit exploit module for the “new” Insecure Library Loading vulnerability (2269637). Part of the title was “We can’t fix this one”. While I assume he meant we can’t fix the vulnerability, I wanted to show that we can prevent the attack itself.

I just posted my new video on the DLL hijacking attack and how the exploit gets loaded and executed on a victim’s machine. Check out how the malicious DLL uploads on endpoint systems when end-users open up legitimate Powerpoint files:

The video demonstrates how the base operating system is susceptible to the DLL hijack vulnerability and how organizations using application whitelisting such as BOUNCER by CoreTrace are protected from this particular DLL attack. Through the BOUNCER interface, our customers see how our application whitelisting solution successfully blocks all attempts Powerpoint makes to run the corrupt DLL files.

Check it out and let me know what you think or if you have any questions.

Greg Valentine

About Greg Valentine

Director of Technical Sales & Services: A great technology and security pro, and an even better dad. Security/Anti-malware/Whitelisting. @gvalentine
This entry was posted in endpoint security, Featured, whitelisting and tagged , , , , . Bookmark the permalink.

2 Responses to Watch how whitelisting stops Microsoft DLL hijacking attack

  1. Pingback: Fallout for DLL exploits increases… but it doesn’t have to be the case — CoreTrace WhiteSpace

  2. Pingback: Top Endpoint Security Stories for November 2010 — If malware is a top security concern, then why does it take so long to fix known vulnerabilities?

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>