Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Marcus Hutchins :verified:
@malwaretech@infosec.exchange  ·  activity timestamp 2 months ago

Did you know that you can passively download malicious payloads onto target systems?

Lots of software caches images locally to save bandwidth, often without stripping metadata.

You can leverage this functionality to download payloads.

Simply store your payload inside a valid image, then just have the target's web browser or email client download it for you.

No more web requests to obtain follow-up payloads!

https://malwaretech.com/2025/10/exif-smuggling.html?a=1

  • Copy link
  • Flag this post
  • Block
SpaceLifeForm
@SpaceLifeForm@infosec.exchange replied  ·  activity timestamp 2 months ago

@malwaretech

Who knew that tracking pixels could be 64KB in size?

You would not notice just by looking at them.

"To my surprise, the size limit of the Exif header was much larger than expected. An entire 64-KB worth of metadata can be stored in the image. But better yet, a single Exif field can use up the entire 64-KB of space."

#Exif

  • Copy link
  • Flag this comment
  • Block
Jernej Simončič �
@jernej__s@infosec.exchange replied  ·  activity timestamp 2 months ago

@malwaretech Instead of using EXIF in JPEG, how about using tEXt chunk in a PNG? It can be much larger (up to 2 GB IIRC), and a conveniently-placed nul byte will similarly hide the content from normal viewers.

  • Copy link
  • Flag this comment
  • Block
Marcus Hutchins :verified:
@malwaretech@infosec.exchange replied  ·  activity timestamp 2 months ago

@jernej__s Gonna look into this, thanks

  • Copy link
  • Flag this comment
  • Block
Reed Mideke
@reedmideke@mastodon.social replied  ·  activity timestamp 2 months ago

@malwaretech @jernej__s RIFF used by webp also looks like it should be easy to stuff in large chunks that will be ignored by standard conforming viewers/browsers https://developers.google.com/speed/webp/docs/riff_container

Google for Developers

WebP Container Specification  |  Google for Developers

  • Copy link
  • Flag this comment
  • Block
kas (she/her)
@1casie@mas.to replied  ·  activity timestamp 2 months ago

@malwaretech thank you, malwaretech from infosec dot exchange

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login