INNER CODE UNIT · C#

GetForwardModuleBase

ghostvectoracademy/DLLHijackHunter · src/DLLHijackHunter/Canary/CanaryDllBuilder.cs:133

    public static string GetForwardModuleBase(string deployPath) =>
        // PE forwarder strings are split at the FIRST dot by the Windows loader.
        // Using ".hhorig" produces "foo.hhorig.Export" which the loader misparses as
        // module="foo" (the canary itself) with export="hhorig.Export" — not found,
        // so the import snap fails before DllMain runs. Using "_hhorig" (underscore)
        // produces "foo_hhorig.Export" — one dot, unambiguous, resolves to sidecar.
        Path.GetFileNameWithoutExtension(deployPath) + "_hhorig";

    /// <summary>
    /// The sidecar path (the runtime proxy's forward target) for a canary deployed to
    /// <paramref name="deployPath"/>: a copy of the original DLL under a distinct name in the
    /// same directory, so forwarders point at real code rather than at the canary itself.
    /// </summary>
    public static string GetSidecarPath(string deployPath)
    {
        string dir = Path.GetDirectoryName(deployPath) ?? "";
        return Path.Combine(dir, GetForwardModuleBase(deployPath) + ".dll");
    }

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…