[Hacking on Linux] How to extract & remove metadata 07-06-2014, 09:46 PM
#1
What is metadata ?
Spoiler:
Metadata is data about data. The metadata usually stores various informations like Author name and surname of the created file, program name and version in which such file was created, date and time when it was created also it contains time zone.
In some cases it could be different for example when we take a photo using modern smartphone then the metadata will contain such juicy info as smartphone make and model, date and time of taken picture and sometimes when we have some options turned on it even can store geo location when it was taken.
Coming back to original topic, that data is assigned to every file every time when we create such documents like PDF, Word document, PowerPoint Presentation etc.
In some cases it could be different for example when we take a photo using modern smartphone then the metadata will contain such juicy info as smartphone make and model, date and time of taken picture and sometimes when we have some options turned on it even can store geo location when it was taken.
Coming back to original topic, that data is assigned to every file every time when we create such documents like PDF, Word document, PowerPoint Presentation etc.
Why do I would want to extract metadata ?
Spoiler:
The reason is simple for Doxing to find out more information about someone or this could be useful when we doing information gathering for example about websites etc. The reasons are many as people on this planet really.
Why do I would want to remove metadata ?
Spoiler:
The reason is simple to Anti-Dox as well as prevent someone from gathering information about yourself. Metadata is very important in computer forensics as some group member of anonymous even get arrested for releasing PDF without removing metadata from it and in the result as you know is getting arrested and his website was completely taken offline. If you want to read more about it, read this article as it's very interesting tho.
How to install Exiftool :
Finding terminal in Ubuntu
Spoiler:
We firstly need to open terminal in ubuntu with old gnome to find it in ubuntu go to applications → Accessories and click on Terminal.
![[Image: tumblr_lcl53wB1Vv1qc11np.png]](http://media.tumblr.com/tumblr_lcl53wB1Vv1qc11np.png)
(Image borrowed from Tumbrl)
To open terminal in the latest ubuntu (14.04) with Unity go to left top corner and click on Unity Icon then type terminal in search bar and by double clicking on terminal icon it will run the terminal emulator.
![[Image: Menu_020.png]](http://180016988.r.cdn77.net/wp-content/uploads/2014/04/Menu_020.png)
(Image borrowed from unixmen)
![[Image: tumblr_lcl53wB1Vv1qc11np.png]](http://media.tumblr.com/tumblr_lcl53wB1Vv1qc11np.png)
(Image borrowed from Tumbrl)
To open terminal in the latest ubuntu (14.04) with Unity go to left top corner and click on Unity Icon then type terminal in search bar and by double clicking on terminal icon it will run the terminal emulator.
![[Image: Menu_020.png]](http://180016988.r.cdn77.net/wp-content/uploads/2014/04/Menu_020.png)
(Image borrowed from unixmen)
Installing git-core
Spoiler:
Now when we have terminal up and runing we need to install Git with Apt-Get. That will allow us to download and install Exiftool from Git Repositories. So run the terminal if you didn't run it yet (your termianl can look different than mine but the commands are the same if you are using Ubuntu/Debian based distro like Mint etc) and type the following command to install git-core:
sudo apt-get install git-core
![[Image: YRbvZMM.png]](http://i.imgur.com/YRbvZMM.png)
Type the following command and press enter.
![[Image: 13OLdYh.png]](http://i.imgur.com/13OLdYh.png)
As we need to install it as root (Administrator privileges are needed) so we will need to provide our password, don't be surprised while typing the password it will be invisible for human eye but in fact the password is there being said that it's just another security layer just like asterisks when entering passwords in various websites but in here it's just invisible. So enter the password and press enter.
![[Image: fyZNRC0.png]](http://i.imgur.com/fyZNRC0.png)
As I already have it installed I don't need to install it again but if you don't have it installed the installer will ask you if you want to install git-core listing all dependencies etc just type Y and press enter. After a while it should be installed.
sudo apt-get install git-core
![[Image: YRbvZMM.png]](http://i.imgur.com/YRbvZMM.png)
Type the following command and press enter.
![[Image: 13OLdYh.png]](http://i.imgur.com/13OLdYh.png)
As we need to install it as root (Administrator privileges are needed) so we will need to provide our password, don't be surprised while typing the password it will be invisible for human eye but in fact the password is there being said that it's just another security layer just like asterisks when entering passwords in various websites but in here it's just invisible. So enter the password and press enter.
![[Image: fyZNRC0.png]](http://i.imgur.com/fyZNRC0.png)
As I already have it installed I don't need to install it again but if you don't have it installed the installer will ask you if you want to install git-core listing all dependencies etc just type Y and press enter. After a while it should be installed.
Installing Exiftool
![[Image: XpqHAqL.png]](http://i.imgur.com/XpqHAqL.png)
Now to install Exiftool just type in terminal and press enter:
git clone https://github.com/pandastream/libimage-...l-9.27.git exiftool
![[Image: CMGBTnI.png]](http://i.imgur.com/CMGBTnI.png)
Now after we pressed enter the exiftool will automatically be installed (without any prompt for acceptance) in our home directory in folder called exiftool. (Home directory is different partition which has it's own space and it's separate from where Linux is installed, you can say it's like Documents folder from Windows assigned to different partition so it stores Documents at different place than our Windows is installed). The picture above represents how does exiftool is being installed.
![[Image: v8JVWK5.png]](http://i.imgur.com/v8JVWK5.png)
After we have done installing git core and exiftool it's time to install needed dependencies. Just type:
sudo apt-get install libarchive-zip-perl
press enter, provide password and wait until it will be installed. Now after all that installations we will be able to successfully run and use tool called exiftool.
Spoiler:
![[Image: XpqHAqL.png]](http://i.imgur.com/XpqHAqL.png)
Now to install Exiftool just type in terminal and press enter:
git clone https://github.com/pandastream/libimage-...l-9.27.git exiftool
![[Image: CMGBTnI.png]](http://i.imgur.com/CMGBTnI.png)
Now after we pressed enter the exiftool will automatically be installed (without any prompt for acceptance) in our home directory in folder called exiftool. (Home directory is different partition which has it's own space and it's separate from where Linux is installed, you can say it's like Documents folder from Windows assigned to different partition so it stores Documents at different place than our Windows is installed). The picture above represents how does exiftool is being installed.
![[Image: v8JVWK5.png]](http://i.imgur.com/v8JVWK5.png)
After we have done installing git core and exiftool it's time to install needed dependencies. Just type:
sudo apt-get install libarchive-zip-perl
press enter, provide password and wait until it will be installed. Now after all that installations we will be able to successfully run and use tool called exiftool.
Locating home directory and running Exiftool
Locating home directory
![[Image: UKEgs9p.png]](http://i.imgur.com/UKEgs9p.png)
To distinguish if we are in home directory just type ls (list command which shows all the content of the current folder in which are in) and press Enter and if there are folders like Desktop, tmp, documents, videos, downloadas etc then it's our home directory. Please note that my home directory will be different than yours as you can create different folders and files in there. However every time when you run terminal the default directory which terminal will place us always will be Home directory.
![[Image: oV2hexB.png]](http://i.imgur.com/oV2hexB.png)
However if you are lost and don't know where your home directory is I will help you to locate it as it's easy. To go to your home directory just type in termianl the following command: cd /home/your username and press enter. (cd command stands for change directory and moves us around different directories.) To see if you are in your home directory just type ls to see which folders and files are there.
Locating home directory
Spoiler:
![[Image: UKEgs9p.png]](http://i.imgur.com/UKEgs9p.png)
To distinguish if we are in home directory just type ls (list command which shows all the content of the current folder in which are in) and press Enter and if there are folders like Desktop, tmp, documents, videos, downloadas etc then it's our home directory. Please note that my home directory will be different than yours as you can create different folders and files in there. However every time when you run terminal the default directory which terminal will place us always will be Home directory.
![[Image: oV2hexB.png]](http://i.imgur.com/oV2hexB.png)
However if you are lost and don't know where your home directory is I will help you to locate it as it's easy. To go to your home directory just type in termianl the following command: cd /home/your username and press enter. (cd command stands for change directory and moves us around different directories.) To see if you are in your home directory just type ls to see which folders and files are there.
Running Exiftool
![[Image: 7hd4OQz.png]](http://i.imgur.com/7hd4OQz.png)
As we can see that there is a folder named exiftool in our home directory. That is because we have installed it there and from this folder we will need to run the exiftool. So just type cd exiftool then ls command to list the directory content.
![[Image: q111ets.png]](http://i.imgur.com/q111ets.png)
This is all the content of exiftool folder. Every time when you want to run this program we need to navigate to this folder and execute it from here. (Yeah sure you can create shortucts for it but I won't be covering that in this tutorial). What we are interested in is file called exiftool. However if the file is not green bold for some reason (that is if you have downloaded it from their website) you need to make it exectuable. If you have installed exiftool as it's in this tutorial you just skip this part. To make it executable you just need to type chmod +x exiftool, press enter, provide password and the file should be executable from now on. This command giving us various file permissions for example if we use +r instead of +x it will make the permission to only view the content of the folder (it will be read only).
![[Image: N03FvEY.png]](http://i.imgur.com/N03FvEY.png)
Let's try to run it and see if it's working without any problems. So type ./exiftool and press enter. The command ./ execute specific selected program in this case it's exiftool. If the output is the same as on the picture above then we have done everything correctly and you can continue if not please return to previous steps, read it carefully and return to this step when everything is done correctly.
Spoiler:
![[Image: 7hd4OQz.png]](http://i.imgur.com/7hd4OQz.png)
As we can see that there is a folder named exiftool in our home directory. That is because we have installed it there and from this folder we will need to run the exiftool. So just type cd exiftool then ls command to list the directory content.
![[Image: q111ets.png]](http://i.imgur.com/q111ets.png)
This is all the content of exiftool folder. Every time when you want to run this program we need to navigate to this folder and execute it from here. (Yeah sure you can create shortucts for it but I won't be covering that in this tutorial). What we are interested in is file called exiftool. However if the file is not green bold for some reason (that is if you have downloaded it from their website) you need to make it exectuable. If you have installed exiftool as it's in this tutorial you just skip this part. To make it executable you just need to type chmod +x exiftool, press enter, provide password and the file should be executable from now on. This command giving us various file permissions for example if we use +r instead of +x it will make the permission to only view the content of the folder (it will be read only).
![[Image: N03FvEY.png]](http://i.imgur.com/N03FvEY.png)
Let's try to run it and see if it's working without any problems. So type ./exiftool and press enter. The command ./ execute specific selected program in this case it's exiftool. If the output is the same as on the picture above then we have done everything correctly and you can continue if not please return to previous steps, read it carefully and return to this step when everything is done correctly.
Before we begin
Spoiler:
I want to say that before I even begin showing how to use exiftool that I just randomly grab some random PDF file from internet and use it for this example, of course you can use any file which you like to check metadata on (Word Document, PowerPoint Presentation, Txt file etc).
How to Extract Metadata
![[Image: dAp1HQL.png]](http://i.imgur.com/dAp1HQL.png)
The process of extracting Meatadata is very easy as it's require one single command to execute and perform that action. So let's begin. Please note that this to work we need to be in the same folder where we have installed exiftool. Type the following command: ./exiftool directory to file in my case it was /home/myusername/Test.pdf as I store that file in my main home directory. Then press enter and if the directory was correct you should receive similar output as mine on the picture (it can be different in details as different files has different data saved).
Now we done here, easy right ? Let's move to removing the metadata from the PDF file.
Spoiler:
![[Image: dAp1HQL.png]](http://i.imgur.com/dAp1HQL.png)
The process of extracting Meatadata is very easy as it's require one single command to execute and perform that action. So let's begin. Please note that this to work we need to be in the same folder where we have installed exiftool. Type the following command: ./exiftool directory to file in my case it was /home/myusername/Test.pdf as I store that file in my main home directory. Then press enter and if the directory was correct you should receive similar output as mine on the picture (it can be different in details as different files has different data saved).
Now we done here, easy right ? Let's move to removing the metadata from the PDF file.
How to Remove Metadata
![[Image: LpWsOCm.png]](http://i.imgur.com/LpWsOCm.png)
Now to remove all metadata from this PDF file we need to type the following command: ./exiftool -all= /home/yourusername/Test.pdf and press enter. Please be patient as the process will take from few seconds to few minutes depending on the size of the file. My one is around 6.6 MB and took about 15 – 20 seconds to remove all metadata. If everything went perfectly you should see the same output as on my picture above. That means the metadata was successfully removed from the PDF file.
![[Image: SipusDr.png]](http://i.imgur.com/SipusDr.png)
Now let's navigate to the directory when we have placed our PDF file from which we wanted to remove all metadata. Now we can see not one but two of the PDF files because the first one named Test.pdf is the one without metadata and the other one called Test.pdf_original is the original file which contains all the details in metadata. If you want to see difference between original and removed metadata please continue to comparison section below.
Spoiler:
![[Image: LpWsOCm.png]](http://i.imgur.com/LpWsOCm.png)
Now to remove all metadata from this PDF file we need to type the following command: ./exiftool -all= /home/yourusername/Test.pdf and press enter. Please be patient as the process will take from few seconds to few minutes depending on the size of the file. My one is around 6.6 MB and took about 15 – 20 seconds to remove all metadata. If everything went perfectly you should see the same output as on my picture above. That means the metadata was successfully removed from the PDF file.
![[Image: SipusDr.png]](http://i.imgur.com/SipusDr.png)
Now let's navigate to the directory when we have placed our PDF file from which we wanted to remove all metadata. Now we can see not one but two of the PDF files because the first one named Test.pdf is the one without metadata and the other one called Test.pdf_original is the original file which contains all the details in metadata. If you want to see difference between original and removed metadata please continue to comparison section below.
Comparison [Original vs Removed Metadata]
![[Image: PXPckCZ.png]](http://i.imgur.com/PXPckCZ.png)
As we can see from the comparison above that the following data was removed: author name & surname, creation and modify date and finally Producer which is name of the program in which PDF file was created in. As you can see that tool has removed all the important data which could get you into trouble or just reveal more information about yourself to the public prying eyes.
Spoiler:
![[Image: PXPckCZ.png]](http://i.imgur.com/PXPckCZ.png)
As we can see from the comparison above that the following data was removed: author name & surname, creation and modify date and finally Producer which is name of the program in which PDF file was created in. As you can see that tool has removed all the important data which could get you into trouble or just reveal more information about yourself to the public prying eyes.
Also for collectors which store such Hacking materials on their Hard Drives I had compiled PDF file + added original comparison picture in original resolution all together packed in zip file. The pack was uploaded on file sharing hosting which doesn't have any surveys or download limitations just simply click & download :Smile:
Download Link
Jotti Scan
VirusTotal Scan
Hashesh:
Download Link
Code:
http://www48.zippyshare.com/v/93934682/file.htmlJotti Scan
Code:
http://virusscan.jotti.org/en/scanresult/801ab8be08216c35aafd44dbcd4ae3b5eb8dc0e3VirusTotal Scan
Code:
https://www.virustotal.com/uk/file/d7ea3467b3f5a89e69a32d7100d74e427c1d52d5bda690a843c29f4615b91e15/analysis/1404678375Hashesh:
Code:
MD5: 9a1559ed98e0bf52d972363b5e30470c
SHA1: 8f81ee7a736a0a302339d613f2f8f33b9d27fbf3Don't trust ? Don't download ! Simple as that.
MISCELLANEOUS:
This tutorial was made for EDUCATIONAL PURPOSES ONLY and either I or HC community doesn't take any resposibility of how you use it so play it clean and ethical boy 

I hope this tutorial will be useful to you and at least to new comers here on HC.
Please comment if you have any problems, questions or just have idea how to improve my tutorial. Also big thanks to @Maxx who has helped me around the forum and took me out from my confusion.
Want to share it ? Yeah it's cool you can share it as long as you put me in the credits and say what's the source (website address) of this tutorial.
More HQ tutorials coming soon
Enjoy reading
BroZix (Tutorial King)
Please comment if you have any problems, questions or just have idea how to improve my tutorial. Also big thanks to @Maxx who has helped me around the forum and took me out from my confusion.
Want to share it ? Yeah it's cool you can share it as long as you put me in the credits and say what's the source (website address) of this tutorial.
More HQ tutorials coming soon

Enjoy reading
BroZix (Tutorial King)



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
