<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; DLL</title>
	<atom:link href="http://www.megapanzer.com/tag/dll/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Things to do for the next days &#8230;</title>
		<link>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/</link>
		<comments>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/#comments</comments>
		<pubDate>Fri, 01 Oct 2010 11:27:33 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[DLL]]></category>
		<category><![CDATA[DLL injection]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[skypetap]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4166</guid>
		<description><![CDATA[I&#8217;m still struggling to make SkypeTap (skype interception module) work on Win7. This week things just don&#8217;t go as smoothly as expected :/ As soon as I have a result (may it be positive or negative) I&#8217;ll let you know. If it works I think a further post would be appropriate that shows in detail [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="" title="trojanhorse" width="100" height="96" class="alignright size-full wp-image-2132" />I&#8217;m still struggling to make <strong>SkypeTap </strong>(skype interception module) work on Win7. This week things just don&#8217;t go as smoothly as expected :/ As soon as I have a result (may it be positive or negative) I&#8217;ll let you know.</p>
<p>If it works I think a further post would be appropriate that shows in detail how to inject <strong>*something*</strong> into a process and what different approches exist to do that.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/10/01/things-to-do-for-the-next-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watching encrypted Skype traffic with SkypeDLLInjector</title>
		<link>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/</link>
		<comments>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 12:30:22 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[DLL]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[Skype]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2471</guid>
		<description><![CDATA[Tool name : SkypeDLLInjector version 0.1 &#160; Description : SkypeDLLInjector is a tool to demonstrate how DLL injection works. In this proof of concept it is applied to the Skype application. It consists of a loader application which remains running in the background and a DLL which will be injected into every newly started program [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%"></td>
<td width="70%"></td>
</tr>
<tr valign="top">
<td><strong>Tool name</strong> :</td>
<td>SkypeDLLInjector version 0.1</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td>SkypeDLLInjector is a tool to demonstrate how DLL injection works. In this proof of concept it is applied to the Skype application. It consists of a loader application which remains running in the background and a DLL which will be injected into every newly started program via a system wide Windows hook.<br />
All what this tool does is interception the function calls recv() and send() to inspect the network data skype is sending and receiving. Because Skype traffic is encrypted only a small portion of the traffic is readable. But it could inspire you to create your own tools which eavesdrop other calls to intercept sensitive data (as the username and password for example).
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Tested on</strong> :</td>
<td>Windows XP</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr>
<td><strong>Feedback</strong> :</td>
<td>In case you encounter any problems with the tool, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong> :</td>
<td><a href="http://www.megapanzer.com/wp-content/uploads/skypedllinjector_binary.zip">Binary</a> | <a href="http://www.megapanzer.com/wp-content/uploads/skypedllinjector_source.zip" target="_blank">Source</a></td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/08/04/watching-encrypted-skype-traffic-with-skypedllinjector/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DLL injection by modifying an executable file.</title>
		<link>http://www.megapanzer.com/2009/07/03/dll-injection-by/</link>
		<comments>http://www.megapanzer.com/2009/07/03/dll-injection-by/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 16:43:53 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Reading material]]></category>
		<category><![CDATA[DLL]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[PE]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2236</guid>
		<description><![CDATA[This is a newer document from 2009 that explains DLL injection. Instead of using the often used Windows hooking method to inject a DLL into a running process in this example the author modifies the binary itself and loads the DLL when starting the executable file. Download it here.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/books-150x150.jpg" width="75" height="75" class="alignright size-thumbnail wp-image-2238" />This is a newer document from 2009 that explains DLL injection. Instead of using the often used Windows hooking method to inject a DLL into a running process in this example the author modifies the binary itself and loads the DLL when starting the executable file.<br />
<br />
Download it <a href="http://www.megapanzer.com/wp-content/uploads/pe-infection_by_dll_injection.pdf" target="_blank">here</a>.<br />
<br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/07/03/dll-injection-by/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

