-
Notifications
You must be signed in to change notification settings - Fork 17
SIP Hijacking
Windows does not verify every signed file the same way. It looks up a handler for the file type, then asks that handler whether the signature is good. SIP hijacking swaps that handler in the registry, so Windows asks the wrong function and gets a success answer.
- SIP means Subject Interface Package.
- Each supported file type maps to a GUID.
- Windows reads the verification handler from:
HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{GUID}
- TrustMeBro redirects:
-
Dll->C:\Windows\System32\ntdll.dll -
FuncName->DbgUiContinue
-
-
DbgUiContinuealways returnsTRUEin this trust path.
TrustMeBro supports 19 GUIDs. The default set targets PE, PowerShell, and MSI. Use --sip-types to pick a different set.
After a hijack, log out and log back in before testing. SIP DLLs stay cached per-process.
SIP hijack flips the embedded hash verdict. It does not grant chain trust. A self-signed PE still fails WinVerifyTrust with 0x800B0109 (CERT_E_UNTRUSTEDROOT) while the hijack is active. Full trust needs a FinalPolicy hijack or enrollment of the signing cert into both Root and TrustedPublisher.
Catalog-signed PEs follow the catalog path when the file has no WIN_CERTIFICATE entry. That path does not reach SIP dispatch for the PE itself. The SIP hijack affects embedded signatures only.
ReactOS wintrust source shows a per-process provider_cache that stores resolved provider function pointers. A registry change does not update processes that already cached the old SIP DLL. This matches the log out, log in requirement after installation.
Win11 24H2 exposes more SIP surfaces than the default TrustMeBro target set.
| Surface | Example types | Provider note |
|---|---|---|
| JScript |
.js, .jse
|
wshext.dll via IsFileSupportedName
|
| VBScript |
.vbs, .vbe
|
built-in script SIP |
| WSF | .wsf |
built-in script SIP |
| AppX and MSIX |
.appx, .msix
|
AppxSip.dll |
| AppX Bundle |
.appxbundle, .msixbundle
|
AppxSip.dll |
| Encrypted AppX | encrypted package formats | AppxSip.dll |
| P7X | .p7x |
AppxSip.dll |
| CTL | CTL blobs | built-in CTL SIP |
| ESD and WIM |
.esd, .wim
|
EsdSip.dll |
| Flat | fallback path | built-in flat SIP |
| Catalog | .cat |
built-in catalog SIP |
The same DbgUiContinue gadget works across the set.
Get-AuthenticodeSignature reports Valid under the hijack. PSAuthorizationManager.CheckPolicy applies a second gate and requires the signer in the TrustedPublisher store. SIP hijack alone does not give silent AllSigned execution.