{"id":6760,"date":"2019-09-13T23:03:14","date_gmt":"2019-09-13T23:03:14","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=6760"},"modified":"2019-09-13T23:03:16","modified_gmt":"2019-09-13T23:03:16","slug":"beyond-good-ol-run-key-part-115","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2019\/09\/13\/beyond-good-ol-run-key-part-115\/","title":{"rendered":"Beyond good ol\u2019 Run key, Part 115"},"content":{"rendered":"\n<p>This is yet another episode of &#8220;I think I am right, but I have not tested it&#8221;. I don&#8217;t have the hardware to do it, but I do have information that suggests it should work.<\/p>\n\n\n\n<p>It&#8217;s nearly Saturday, so we should talk about cats. And one cat in particular has a potential meaning in the persistence universe: a cougar.<\/p>\n\n\n\n<p>The following Registry entries point to a <em>settings.dll<\/em> library. I suspect that if you have Cougar software installed, these entries exist and are utilized by the supporting software. Aka if you point these settings to a different DLL, you may achieve a man-in-the-middle persistence.<\/p>\n\n\n\n<ul><li>HKLM\\SOFTWARE\\Cougar\\GamingDevice\\250M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\300M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\400M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\450K\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\450M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\500K\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\500M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\530M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\550M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\600M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\700K\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\700M\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\AttackX3\\Dll\\String=setting.dll<\/li><li> HKLM\\SOFTWARE\\Cougar\\GamingDevice\\Revenger\\Dll\\String=setting.dll<\/li><\/ul>\n\n\n\n<p>I would appreciate if you could test it, if you have the aforementioned software installed. Thank you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is yet another episode of &#8220;I think I am right, but I have not tested it&#8221;. I don&#8217;t have the hardware to do it, but I do have information that suggests it should work. It&#8217;s nearly Saturday, so we &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2019\/09\/13\/beyond-good-ol-run-key-part-115\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[13,35],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6760"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=6760"}],"version-history":[{"count":1,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6760\/revisions"}],"predecessor-version":[{"id":6761,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6760\/revisions\/6761"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=6760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=6760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=6760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}