EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard

A blue team analyst is investigating a compromised Windows server. They discover that the attacker used a technique to execute malicious code by manipulating the search order of DLLs that a legitimate, privileged application attempts to load. The attacker placed a malicious DLL in a directory that the application searches before its legitimate location. What is this attack technique called?

  1. ARootkit Installation
  2. BPass-the-Hash
  3. CDLL Side-Loading
  4. DProcess Hollowing
Show answer & explanation

Correct answer: C. DLL Side-Loading

DLL Side-Loading (or DLL Search Order Hijacking) specifically refers to placing a malicious DLL in a directory where a legitimate application will search for and load it, typically before finding the legitimate DLL, leading to the execution of the attacker's code within the context of the privileged application.

Why the other options are wrong

  • A. Rootkit Installation is a broader category of techniques used to hide malicious presence, but doesn't specifically describe the DLL search order manipulation.
  • B. Pass-the-Hash is a post-exploitation technique for authentication, not code execution via DLLs.
  • D. Process Hollowing involves injecting code into a legitimate process by creating it in a suspended state, unmapping its memory, and writing malicious code, which is different from manipulating DLL search order.

DLL Side-Loading (DLL Search Order Hijacking)

An attack technique where a malicious Dynamic Link Library (DLL) is placed in a specific directory so that a legitimate application loads it instead of the intended DLL, often due to vulnerabilities in the DLL search order.

  • Exploits the order in which Windows searches for DLLs.
  • Allows attackers to execute arbitrary code within a trusted process.
  • Often effective against applications with weak DLL loading practices or that are vulnerable to search order hijacking.

Memory trick: Code execution: DLL Side-Load for libraries, Process Hollowing for stealth, Injection for hooks, Shellcode for raw.

More System Hacking Phases and Attack Techniques questions