Author Topic: Encoding Web Shells in PNG IDAT chunks  (Read 1085 times)

0 Members and 1 Guest are viewing this topic.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Encoding Web Shells in PNG IDAT chunks
« on: August 11, 2013, 03:46:08 pm »
If you carefully encode a web shell in an image you can bypass server-side filters and seemingly make shells materialize out of nowhere(and I'm not talking about encoding data in comments or metadata) - this post will show you how it's possible to write PHP shells into PNG IDAT chunks using only GD.

Its worth a check out.https://www.idontplaydarts.com/2012/06/encoding-web-shells-in-png-idat-chunks/
« Last Edit: August 11, 2013, 03:47:13 pm by kenjoe41 »
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: Encoding Web Shells in PNG IDAT chunks
« Reply #1 on: August 11, 2013, 05:19:10 pm »
The technique itself isn't new at all, and it's noted by most security advisories nowadays, but I really like the technical detail and crafty approach here. The blog is good in general.

Another much simpler variant is to use GIMP's scripting engine to embed malicious code into images.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: Encoding Web Shells in PNG IDAT chunks
« Reply #2 on: August 12, 2013, 05:37:31 pm »
Come to think of it. Am gonna try that Gimp thing sometime. Thanks for the heads up.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]