Главная
Study mode:
on
1
Introduction
2
Exploit Development
3
History
4
What it is
5
Images are innocent
6
Exploits are not dangerous
7
Browser Exploit Delivery
8
Demo
9
Understanding Bit Layers
10
Image Analysis Tool
11
Image Layers
12
Exploits
13
Solution
14
Slow Motion
15
Overcome PNG
16
Read Pixel Values
17
JavaScript Decoder
18
Polyglot
19
Riddle
20
Images Toolkit
21
Bipolar File
22
Polyglot File
23
Images JPEG
24
Secret Sauce
25
PNG
26
CC
27
Delivery
28
Browser
29
Server
30
Meterpreter
31
Minicat
32
PNG Image
33
Colour Image
34
Green Channel
35
Task Manager
36
Heap Spray
37
Detection
38
Detection Rate
39
Package Delivery
40
Remove Extension
41
Content Sniffing
42
Clever Caching
43
Expires Tag
44
Time shifted payloads
45
Tools
46
Incident Response Nightmare
47
Outro
Description:
Explore the innovative technique of Stegosploit, which encodes browser exploits into image files for undetectable delivery. Learn about steganography and polyglots as underlying methods for creating HTML+Image polyglots that appear innocent but contain hidden exploits. Discover the process of encoding drive-by browser exploits into JPG and PNG images, fusing them with HTML and Javascript decoder code. Examine bit layers, image analysis tools, and JavaScript decoders used in this technique. Understand the challenges of detection and incident response for these sophisticated exploits. Gain insights into exploit development, browser exploit delivery, and the potential impact on cybersecurity through demonstrations and in-depth explanations of the Stegosploit toolkit.

Stegosploit - Drive by Browser Exploits Using Only Images

44CON Information Security Conference
Add to list
00:00
-01:36