COM OBJECT hijacking

CAccPropServicesClass and MMDeviceEnumerato

无需超管权限,无需重启
https://github.com/3gstudent/COM-Object-hijacking
将恶意DLLbase64编码写入ps脚本
image
image
image

Explorer

image

最后更新于

这有帮助吗?