EvilZone

Other => Found it on the Webs => Topic started by: techb on November 06, 2015, 11:43:03 PM

Title: single image browser exploit
Post by: techb on November 06, 2015, 11:43:03 PM
Found this on hackaday.

http://hackaday.com/2015/11/06/stegosploit-owned-by-a-jpg/ (http://hackaday.com/2015/11/06/stegosploit-owned-by-a-jpg/)
Title: Re: single image browser exploit
Post by: Insanity on November 07, 2015, 12:17:43 AM
Yeah,
I've heard of that,
it's been around for a while.
http://www.pcworld.com/article/2105408/3/watch-out-for-photos-containing-malware.html
That's from last year.
I'm not sure whether or not antivirus software looks out for that now though,
I'm guessing no.
Title: Re: single image browser exploit
Post by: techb on November 07, 2015, 02:26:00 AM
I don't think antivirus software can see it since it dynamically puts the exploit together.
Title: Re: single image browser exploit
Post by: Insanity on November 07, 2015, 02:40:14 AM
I don't think antivirus software can see it since it dynamically puts the exploit together.

Yeah,
so I doubt they'd be able to to catch that.
Then again, I'm thinking that they could try and write an array to compare the actual code,
then try and piece together different parts. Probably wouldn't work though.
I know nothing, so it's probably best to ignore what I just said!
Title: Re: single image browser exploit
Post by: techb on November 07, 2015, 06:10:38 AM
Yeah,
so I doubt they'd be able to to catch that.
Then again, I'm thinking that they could try and write an array to compare the actual code,
then try and piece together different parts. Probably wouldn't work though.
I know nothing, so it's probably best to ignore what I just said!

Unless they sandbox everything this will work, just the same BeeF works.
Title: Re: single image browser exploit
Post by: Insanity on November 07, 2015, 07:11:01 AM
Unless they sandbox everything this will work, just the same BeeF works.

Hmm, never heard of BeeF.
Interesting though!