Hackers of India

Stegosploit – Drive-by Browser Exploits using only Images

 Saumil Shah 

2015/09/11


Presentation Material

Presentation

Keep Calm and Stegosploit - 44CON 2015 from Saumil Shah

Video


 

Abstract

“A good exploit is one that is delivered with style”.

Stegosploit creates a new way to encode “drive-by” browser exploits and deliver them through image files. These payloads are undetectable using current means. This paper discusses two broad underlying techniques used for image based exploit delivery – Steganography and Polyglots. Drive-by browser exploits are steganographically encoded into JPG and PNG images. The resultant image file is fused with HTML and Javascript decoder code, turning it into an HTML+Image polyglot. The polyglot looks and feels like an image, but is decoded and triggered in a victim’s browser when loaded.