How to Hack a Computer Using Just An Image [HTML 5 Canvas]

General discussion about Slimjet, or other issues related to web browser in general.
Locked
reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

How to Hack a Computer Using Just An Image [HTML 5 Canvas]

Post by reactorr »

Next time when someone sends you a photo of a cute cat or a hot chick than be careful before you click on the image to view — it might hack your machine.
Yes, the normal looking images could hack your computers — thanks to a technique discovered by security researcher Saumil Shah from India.
Dubbed "Stegosploit," the technique lets hackers hide malicious code inside the pixels of an image, hiding a malware exploit in plain sight to infect target victims.

Just look at the image and you are HACKED!

Shah demonstrated the technique during a talk titled, "Stegosploit: Hacking With Pictures," he gave on Thursday at the Amsterdam hacking conference Hack In The Box.
According to Shah, "a good exploit is one that is delivered in style."
Keeping this in mind, Shah discovered a way to hide malicious code directly into an image, rather than hiding it in email attachments, PDFs or other types of files that are typically used to deliver and spread malicious exploits.


Here's How to Hack digital pictures to send malicious exploits:
Until now Steganography is used to communicate secretly with each other by disguising a message in a way that anyone intercepting the communication will not realise it's true purpose.
Steganography is also being used by terrorist organisations to communicate securely with each other by sending messages to image and video files, due to which NSA officials are forced to watch Porn and much porn.
However in this case, instead of secret messages, the malicious code or exploit is encoded inside the image’s pixels, which is then decoded using an HTML 5 Canvas element that allows for dynamic, scriptable rendering of images.

Video Demonstration:
http://thehackernews.com/2015/06/Stegos ... lware.html

DISABLE READING FROM HTML5 CANVAS
slimjet://settings > Security > Disable reading from HTML5 Canvas

User avatar
paul1149
Posts: 304
Joined: Sat Aug 30, 2014 1:51 pm

Re: How to Hack a Computer Using Just An Image [HTML 5 Canva

Post by paul1149 »

html5 seems to have moved flash vulnerabilities to the browser. This is good, since now we have more control via SJ.

reactorr
Posts: 68
Joined: Sat Mar 21, 2015 2:45 pm

Re: How to Hack a Computer Using Just An Image [HTML 5 Canva

Post by reactorr »

paul1149 wrote:html5 seems to have moved flash vulnerabilities to the browser. This is good, since now we have more control via SJ.
you are right bro

Locked