logo

recreating known universal windows password backdoors with Frida

ID: 53508676-1760-5f12-bf1a-6b34dd2e744a

STIX ID: report--53508676-1760-5f12-bf1a-6b34dd2e744a

Feed Name: SensePost Blog

Threat Score
60/100

Date Published: 2019-04-23

Date Updated: 2026-04-29

...
...

This post demonstrates using Frida to dynamically instrument lsass.exe on Windows to prototype and implement local authentication backdoors: first by intercepting RtlCompareMemory to detect a specific backdoor password's MD4, and second by overriding MsvpPasswordValidate to accept any password. The author documents detection of relevant calls, backtraces, proof-of-concept Frida scripts, and building a standalone Frida-based executable to enable the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.