
It rather involved being on the other side of this airtight hatchway: Planting files onto a custom PATH
For some reason, we get lots of reports about DLL planting that basically boil down to this: Program X is susceptible to a DLL planting attack because it loads the DLL TOTALLYSAFE.DLL without a full path. If I put a rogue TOTALLYSAFE.DLL on the system PATH ahead of its actual location, then the rogue copy is loaded into the service, and I h







