{"id":311,"date":"2015-05-11T14:15:33","date_gmt":"2015-05-11T14:15:33","guid":{"rendered":"http:\/\/www.adlice.com\/?p=311"},"modified":"2022-12-21T10:39:05","modified_gmt":"2022-12-21T10:39:05","slug":"bho-a-spy-in-your-browser","status":"publish","type":"post","link":"https:\/\/www.adlice.com\/de\/bho-a-spy-in-your-browser\/","title":{"rendered":"Internet Explorer BHO: A spy in your browser"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">How Internet Explorer BHO can turn into a Spy<\/h2>\n\n\n\n<p>What is a BHO? <strong>A BHO (for Browser Helper Object)<\/strong> is a module (often a DLL) that acts as a <strong>plugin for either explorer.exe or Internet Explorer<\/strong>. Most of the time (as its name suggests) it&#8217;s used to extend Web Browser features with some customization. If you&#8217;re familiar with Internet Explorer, you probably use some extensions, or toolbars. They are BHOs.<\/p>\n\n\n\n<p>Like any web browser extension, a BHO <strong>runs in the context of the web browser<\/strong>, using provided APIs. Knowing that, it&#8217;s easy to understand that an extension can have <strong>access to pretty much everything you&#8217;re doing on the web<\/strong>, including <strong>passwords, bank information, credentials<\/strong>, and so on, no matter if encryption is used (SSL). And this is what I&#8217;ll try to demonstrate.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">What is a BHO ?<\/h4>\n\n\n\n<p>To be able to start within the web browser, a Internet Explorer BHO needs to be <strong>registered first<\/strong>. This is usually done with the command <strong>regsvr32.exe myBHO.dll<\/strong>.<\/p>\n\n\n\n<p>This will call the registration routine (that you have to code, see later), that will add a registry key to <strong>globally register the DLL in the system under a guid name<\/strong>:<\/p>\n\n\n\n<p><span style=\"color: #6699ff;\">(x86) HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Classes\\CLSID\\{guid}<br>(x64) HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{guid}<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/hex-1.png\"><img decoding=\"async\" width=\"986\" height=\"238\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/hex-1.png\" alt=\"internet explorer BHO\" class=\"wp-image-317\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/hex-1.png 986w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/hex-1-300x72.png 300w\" sizes=\"(max-width: 986px) 100vw, 986px\" \/><\/a><\/figure>\n\n\n\n<p>And the registry key that will <strong>add a new BHO<\/strong> using the defined guid above:<\/p>\n\n\n\n<p><span style=\"color: #6699ff;\">(x86) HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\Browser Helper Objects\\{guid}<br>(x64) HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\explorer\\Browser Helper Objects\\{guid}<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture2-2.png\"><img decoding=\"async\" width=\"968\" height=\"340\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture2-2.png\" alt=\"internet explorer BHO\" class=\"wp-image-312\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture2-2.png 968w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture2-2-300x105.png 300w\" sizes=\"(max-width: 968px) 100vw, 968px\" \/><\/a><\/figure>\n\n\n\n<p>That registry key is responsible for loading the DLL into Internet Explorer.<br>To unregister a DLL, use <strong>regsvr32.exe \/u myBHO.dll<\/strong>.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">How to make a BHO ?<\/h4>\n\n\n\n<p>First, we need to learn how to <strong>code a BHO<\/strong>. Microsoft gives us <a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/bb250489%28v=vs.85%29.aspx\"><strong>a tutorial to get on rails<\/strong><\/a>, let&#8217;s follow it to <strong>create the project and have some working code<\/strong>. Once done, let&#8217;s customize it.<\/p>\n\n\n\n<p>Our main goal is to <strong>intercept data from forms that are <strong>posted back to a web server<\/strong><\/strong>. This includes <strong>login and passwords, even encrypted with SSL, and even visually obfuscated (with dots or stars)<\/strong>.<\/p>\n\n\n\n<p>We are using the <a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/aa768326%28v=vs.85%29.aspx\"><strong>BeforeNavigate2 event<\/strong><\/a> because it&#8217;s fired when clicking on a link, or submitting a form.<\/p>\n\n\n\n<p><strong>.h file<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>class ATL_NO_VTABLE CmyBHO :\n\tpublic CComObjectRootEx,\n\tpublic CComCoClass&lt;cmybho, &amp;clsid_mybho=\"\"&gt;,\n\tpublic IObjectWithSiteImpl,\n\tpublic IDispatchImpl&lt;imybho, &amp;iid_imybho,=\"\" &amp;libid_bholib,=\"\" *wmajor=\"*\/\" 1,=\"\" *wminor=\"*\/\" 0=\"\"&gt;,\n    public IDispEventImpl&lt;1, CmyBHO, &amp;DIID_DWebBrowserEvents2, &amp;LIBID_SHDocVw, 1, 1&gt;\n{\n...\n\npublic:\n    STDMETHOD(SetSite)(IUnknown *pUnkSite);\n    void STDMETHODCALLTYPE OnBeforeNavigate( IDispatch *pDisp, VARIANT *pvarURL, VARIANT* pFlags, VARIANT* pTargetFrameName, VARIANT* pPostData, VARIANT* pHeaders, VARIANT* pCancel );\n\n...\n\n};<\/code><\/pre>\n\n\n\n<p><strong>.cpp file<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>void STDMETHODCALLTYPE CmyBHO::OnBeforeNavigate( IDispatch *pDisp, VARIANT *pvarURL, VARIANT* pFlags, VARIANT* pTargetFrameName, VARIANT* pPostData, VARIANT* pHeaders, VARIANT* pCancel )\n{\n    HRESULT hr = S_OK;\n\n    \/\/ Query for the IWebBrowser2 interface.\n    CComQIPtr spTempWebBrowser = pDisp;\n\n    \/\/ Is this event associated with the top-level browser?\n    if (spTempWebBrowser &amp;&amp; m_spWebBrowser &amp;&amp; m_spWebBrowser.IsEqualObject(spTempWebBrowser))\n    {\n        VARIANT* post = pPostData-&gt;pvarVal;\n        if ( post &amp;&amp; post-&gt;vt == (VT_ARRAY|VT_UI1) )\n        {\n            ULONG size      = post-&gt;parray-&gt;rgsabound&#91;0].cElements;\n\n            \/\/Obtain safe pointer to the array\n            void * pArrayData;\n            SafeArrayAccessData( post-&gt;parray, &amp;pArrayData );\n\n            \/\/Copy the bitmap into our buffer\n            BYTE* buff = (BYTE*) malloc(size);\n            memcpy( buff, pArrayData, size );\n\n            \/\/Unlock the variant data\n            SafeArrayUnaccessData( post-&gt;parray );\n\n            MessageBoxA( NULL, (char*)buff, \"posted\", MB_OK );\n            free( buff );\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p>The code is very basic. We only <strong>read pPostData value, and output its text in a MessageBox<\/strong>. Let&#8217;s take a look at the resuts.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">BHO Analysis<\/h4>\n\n\n\n<p>The DLL is indeed <strong>loaded in Internet Explorer<\/strong>:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture6-1.png\"><img decoding=\"async\" width=\"1052\" height=\"357\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture6-1.png\" alt=\"internet explorer BHO\" class=\"wp-image-316\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture6-1.png 1052w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture6-1-300x102.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture6-1-1024x347.png 1024w\" sizes=\"(max-width: 1052px) 100vw, 1052px\" \/><\/a><\/figure>\n\n\n\n<p><strong>Credit Mutuel<\/strong> (French Bank), with SSL turned on:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture3-2.png\"><img decoding=\"async\" width=\"1225\" height=\"405\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture3-2.png\" alt=\"internet explorer BHO credit mutuel\" class=\"wp-image-313\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture3-2.png 1225w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture3-2-300x99.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture3-2-1024x339.png 1024w\" sizes=\"(max-width: 1225px) 100vw, 1225px\" \/><\/a><\/figure>\n\n\n\n<p><strong>Some custom form in HTML<\/strong>, containing a hidden &#8220;magic field&#8221;:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture4-1.png\"><img decoding=\"async\" width=\"813\" height=\"416\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture4-1.png\" alt=\"Capture4\" class=\"wp-image-314\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture4-1.png 813w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture4-1-300x154.png 300w\" sizes=\"(max-width: 813px) 100vw, 813px\" \/><\/a><\/figure>\n\n\n\n<p><strong>Facebook<\/strong>:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\"><img decoding=\"async\" width=\"1213\" height=\"518\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\" alt=\"Capture5\" class=\"wp-image-315\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png 1213w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5-300x128.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5-1024x437.png 1024w\" sizes=\"(max-width: 1213px) 100vw, 1213px\" \/><\/a><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">Conclusion<\/h4>\n\n\n\n<p>I&#8217;ve tried a <strong>few secure login pages, from some banks, and social networks<\/strong>. I found only one that was able to bypass this: <strong>Paypal<\/strong>, because they probably use a ajax login (?). Anyway it didn&#8217;t hit the BeforeNavigate2 routine. For the others, <strong>even with SSL turned on, we are able to see the clear text that is posted back to the web server<\/strong>.<\/p>\n\n\n\n<p>All of this was to demonstrate that <strong>any random web browser extension can access your personal data, and very classified credentials<\/strong>. So please, pay attention to what you install (in general) but especially in your web browser. <strong>And don&#8217;t think you&#8217;re safe because you&#8217;re seeing the &#8220;encryption symbol&#8221;<\/strong>. Malicious extensions have been found to be <strong>redirecting users, stealing credentials, modifying web pages on-the-fly to request credentials (HTML injection), opening ads<\/strong>, &#8230; There&#8217;s no limit.<\/p>\n\n\n\n<p><strong>Don&#8217;t feel safe, you&#8217;re not.<\/strong><\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">Links<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/bb250489%28v=vs.85%29.aspx\">https:\/\/msdn.microsoft.com\/en-us\/library\/bb250489%28v=vs.85%29.aspx<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/aa768326%28v=vs.85%29.aspx\">https:\/\/msdn.microsoft.com\/en-us\/library\/aa768326%28v=vs.85%29.aspx<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser. Learn how it works to better prevent further infections.<\/p>\n","protected":false},"author":1,"featured_media":315,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,84],"tags":[7,298,301,8,299,300,85],"class_list":["post-311","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-tutorial","tag-analysis","tag-bho","tag-browser","tag-malware","tag-spy","tag-spyware","tag-tutorial","category-36","category-84","description-off"],"views":3682,"yoast_score":80,"yoast_readable":60,"featured_image_src":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","author_info":{"display_name":"tigzy","author_link":"https:\/\/www.adlice.com\/de\/author\/tigzy\/"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software<\/title>\n<meta name=\"description\" content=\"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software\" \/>\n<meta property=\"og:description\" content=\"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\" \/>\n<meta property=\"og:site_name\" content=\"Adlice Software\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RogueKiller\" \/>\n<meta property=\"article:published_time\" content=\"2015-05-11T14:15:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-21T10:39:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1213\" \/>\n\t<meta property=\"og:image:height\" content=\"518\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"tigzy\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:site\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"tigzy\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"5\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\"},\"author\":{\"name\":\"tigzy\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\"},\"headline\":\"Internet Explorer BHO: A spy in your browser\",\"datePublished\":\"2015-05-11T14:15:33+00:00\",\"dateModified\":\"2022-12-21T10:39:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\"},\"wordCount\":617,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\",\"keywords\":[\"analysis\",\"bho\",\"browser\",\"malware\",\"spy\",\"spyware\",\"tutorial\"],\"articleSection\":[\"Analysis\",\"Tutorial\"],\"inLanguage\":\"de\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\",\"url\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\",\"name\":\"Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\",\"datePublished\":\"2015-05-11T14:15:33+00:00\",\"dateModified\":\"2022-12-21T10:39:05+00:00\",\"description\":\"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png\",\"width\":1213,\"height\":518},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.adlice.com\/de\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Internet Explorer BHO: A spy in your browser\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.adlice.com\/#website\",\"url\":\"https:\/\/www.adlice.com\/\",\"name\":\"Adlice Software\",\"description\":\"Anti-malware and analysis tools\",\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.adlice.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.adlice.com\/#organization\",\"name\":\"Adlice Software\",\"url\":\"https:\/\/www.adlice.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"width\":276,\"height\":276,\"caption\":\"Adlice Software\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/RogueKiller\",\"https:\/\/x.com\/AdliceSoftware\",\"https:\/\/fr.linkedin.com\/company\/adlice-software\",\"https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\",\"name\":\"tigzy\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"caption\":\"tigzy\"},\"description\":\"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.\",\"url\":\"https:\/\/www.adlice.com\/de\/author\/tigzy\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software","description":"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/","og_locale":"de_DE","og_type":"article","og_title":"Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software","og_description":"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.","og_url":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/","og_site_name":"Adlice Software","article_publisher":"https:\/\/www.facebook.com\/RogueKiller","article_published_time":"2015-05-11T14:15:33+00:00","article_modified_time":"2022-12-21T10:39:05+00:00","og_image":[{"width":1213,"height":518,"url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","type":"image\/png"}],"author":"tigzy","twitter_card":"summary_large_image","twitter_creator":"@AdliceSoftware","twitter_site":"@AdliceSoftware","twitter_misc":{"Verfasst von":"tigzy","Gesch\u00e4tzte Lesezeit":"5\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#article","isPartOf":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/"},"author":{"name":"tigzy","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d"},"headline":"Internet Explorer BHO: A spy in your browser","datePublished":"2015-05-11T14:15:33+00:00","dateModified":"2022-12-21T10:39:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/"},"wordCount":617,"commentCount":1,"publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"image":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","keywords":["analysis","bho","browser","malware","spy","spyware","tutorial"],"articleSection":["Analysis","Tutorial"],"inLanguage":"de"},{"@type":"WebPage","@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/","url":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/","name":"Internet Explorer BHO: A Spy in your Browser \u2022 Adlice Software","isPartOf":{"@id":"https:\/\/www.adlice.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage"},"image":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","datePublished":"2015-05-11T14:15:33+00:00","dateModified":"2022-12-21T10:39:05+00:00","description":"Internet Explorer extensions (BHO) are a very stealth way to inject code in a web browser to spy users. Learn how it works.","breadcrumb":{"@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/"]}]},{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#primaryimage","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/Capture5.png","width":1213,"height":518},{"@type":"BreadcrumbList","@id":"https:\/\/www.adlice.com\/bho-a-spy-in-your-browser\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.adlice.com\/de\/"},{"@type":"ListItem","position":2,"name":"Internet Explorer BHO: A spy in your browser"}]},{"@type":"WebSite","@id":"https:\/\/www.adlice.com\/#website","url":"https:\/\/www.adlice.com\/","name":"Adlice Software","description":"Anti-malware and analysis tools","publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.adlice.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Organization","@id":"https:\/\/www.adlice.com\/#organization","name":"Adlice Software","url":"https:\/\/www.adlice.com\/","logo":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","width":276,"height":276,"caption":"Adlice Software"},"image":{"@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RogueKiller","https:\/\/x.com\/AdliceSoftware","https:\/\/fr.linkedin.com\/company\/adlice-software","https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ"]},{"@type":"Person","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d","name":"tigzy","image":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","caption":"tigzy"},"description":"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.","url":"https:\/\/www.adlice.com\/de\/author\/tigzy\/"}]}},"_links":{"self":[{"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/posts\/311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/comments?post=311"}],"version-history":[{"count":0,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/posts\/311\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/media\/315"}],"wp:attachment":[{"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/media?parent=311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/categories?post=311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.adlice.com\/de\/wp-json\/wp\/v2\/tags?post=311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}