# SandboxEscaper Windows 0-Day Exploit payload Weaponised: Tribute

This is a tribute post to a researcher named “sandboxescaper” – who used to find zero days for breakfast in Windows – PE was her expertise and much more. I heard she went to work for MS after dropping tons of zero days on Windows some 5-6 years ago. I was quite fascinated an intrigued by her. She was mentioned in quite a few articles and new posts at the time – here is one such example [here](https://www.theregister.com/2018/08/28/windows_zero_day_lpe/) – so at the time I decided to weaponise one of her exploits to do:  [CVE-2018-8440](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8440)

* A bindshell
    
* And a Reverse TCP
    

%[https://youtu.be/mV5I5Syc4rU] 

Bind Shell Payload Modification

%[https://youtu.be/epqsMWUyT60] 

Reverse TCP Payload Modification

* Run Exploit as shown in original video or for weaponization from my video downloaded from this gdrive.
    
* The existing ALPC DLL is modified with weaponized payload located here -&gt;&gt;&gt; Weaponized Dll’s
    

1. Reverse TCP (192.168.5.21:4444 connects back from victim to our meterpreter)
    
2. Bind TCP Shell (4444 on victim)
    

Weaponised DLL’s

[sandboxescaper-zeroday-demo-with-weaponized-payloadDownload](https://autohackin.wordpress.com/wp-content/uploads/2023/07/sandboxescaper-zeroday-demo-with-weaponized-payload.zip)

[weaponized-dllsDownload](https://autohackin.wordpress.com/wp-content/uploads/2023/07/weaponized-dlls.zip)

This is just a demo. Do not really weaponize in real world.
