TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How Hackers Are Hiding Content and Links via PNG Files

73 pointsby squiggy22over 7 years ago

6 comments

herodotusover 7 years ago
I wonder how many file formats are subject to injection attacks? You could embed the entire universe in PDF, for example, and it would not change the file’s visual appearance at all.
评论 #16233232 未加载
评论 #16233469 未加载
评论 #16233407 未加载
peterburkimsherover 7 years ago
I&#x27;m interested in encoding data into image files.<p>The Cemetech TI-84+ calculator emulator uses image files to load the ROM from a phone.<p><a href="https:&#x2F;&#x2F;www.cemetech.net&#x2F;projects&#x2F;jstified&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cemetech.net&#x2F;projects&#x2F;jstified&#x2F;</a><p>I couldn&#x27;t load the ROM for some reason, until I synced the photo to my iPhone via iTunes over USB.<p>The image gets recompressed when doing a &quot;Save to Camera Roll&quot; or uploading to Facebook.<p>I did some more investigation with a checkerboard pattern, and was shocked at how quickly the image data was lost.<p>If there&#x27;s a way to have error-correcting codes to recover data from an image, please let me know!<p>(the application for this is to load 9.9 MB of lyrics data into LocalStorage so a user can search songs with Pingtype, and I wouldn&#x27;t need to host it on my own server where the lyrics are vulnerable to DMCA takedowns)
fenwick67over 7 years ago
Is this a typical Wordpress attack goal? To just get more links and improve your Google PageRank?<p>What a world.
评论 #16233022 未加载
stephen82over 7 years ago
I have shared my story in the article&#x27;s comments how a virus affected our hosting company&#x27;s server and had to move us on a newer one.<p>All of this from inside a .ico file...complete madness!
GrumpyNlover 7 years ago
Ahhh, the good old days, inject javascript in gifs and see it run.
_pdp_over 7 years ago
There are many non-printable characters that can be used to hide whatever you want in plain sight.