How To Create A Simple PHP Virus Carried By A JPEG 03-06-2013, 01:41 AM
#1
How to exploit this error?
The list of available attacks, of course, depends on the security level of the script.
The easiest way is to send a PHP code in plain text file and save it under the extension of the target image/movie/file (eg virus.jpg).
Unfortunately many web applications validate not only the file extension but also an internal structure of the uploaded file (eg by checking the dimensions of an image file using getimagesize() function)
In that case you can not simply change the file extension of the virus (eg from virus.php to virus.jpg), because the PHP script will detect bad file format during the upload processs.
Fortunately, most binary files may carry the PHP code without losing compatibility with the standard in which they were created.
A simple virus PHP step by step
While the described mechanism can be used in many different file formats, in the example here
I will describe an attack on the poorly-protected PHP gallery.
To perform the code injection you just need a JPEG picture, EXIF tag editor and little knowledge of PHP.
I chosed the PHP logo as a virus carrier and this program as an EXIF editor.
![[Image: s1.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s1.png)
To create a virus, open the image with EXIF editor:
Then add a new tag (by pressing the plus button in the green circle), the new editing window will pop up:
![[Image: s2.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s2.png)
From the drop-down list choose DocumentName as a type of the tag and copy-paste the code below as the tag value:
Click “Commit change (s)” to save the file:
![[Image: s3.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s3.png)
Here is the result of my work, a JPG file with a hidden PHP code (you can download and try it yourself):
![[Image: php-logo-virus.jpg]](http://php.webtutor.pl/wp-content/uploads/2011/04/php-logo-virus.jpg)
From now on, the PHP logo carries a PHP code which is invisible to most picture viewers. You can quickly test the virus by uploading it to a badly-written gallery and displaying it in a browser:
![[Image: s4.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s4.png)
Most PHP scripts on the Internet use the binary-safe functions to read the files.
The above example shows, however, the importance of validating input data, and that existing security mechanisms (such as built-in PHP getimagesize() function) can be easily deceived by an appropriately crafted files.
Ofcourse an image created in this article is not a real virus (because it’s unable to propagate itself or infect other files), but it may serve as a precursor to such a program.
Also, this mechanism can be used as an unusual obfuscator, hiding the PHP code in binary files.
The list of available attacks, of course, depends on the security level of the script.
The easiest way is to send a PHP code in plain text file and save it under the extension of the target image/movie/file (eg virus.jpg).
Unfortunately many web applications validate not only the file extension but also an internal structure of the uploaded file (eg by checking the dimensions of an image file using getimagesize() function)
In that case you can not simply change the file extension of the virus (eg from virus.php to virus.jpg), because the PHP script will detect bad file format during the upload processs.
Fortunately, most binary files may carry the PHP code without losing compatibility with the standard in which they were created.
A simple virus PHP step by step
While the described mechanism can be used in many different file formats, in the example here
I will describe an attack on the poorly-protected PHP gallery.
To perform the code injection you just need a JPEG picture, EXIF tag editor and little knowledge of PHP.
I chosed the PHP logo as a virus carrier and this program as an EXIF editor.
![[Image: s1.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s1.png)
To create a virus, open the image with EXIF editor:
Then add a new tag (by pressing the plus button in the green circle), the new editing window will pop up:
![[Image: s2.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s2.png)
From the drop-down list choose DocumentName as a type of the tag and copy-paste the code below as the tag value:
PHP Code:
<style>body{font-size: 0;} h1{font-size: 12px !important;}</style><h1><?php echo "<hr />THIS IMAGE COULD ERASE YOUR WWW ACCOUNT, it shows you the PHP info instead...<hr />"; phpinfo(); __halt_compiler(); ?></h1>
Click “Commit change (s)” to save the file:
![[Image: s3.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s3.png)
Here is the result of my work, a JPG file with a hidden PHP code (you can download and try it yourself):
![[Image: php-logo-virus.jpg]](http://php.webtutor.pl/wp-content/uploads/2011/04/php-logo-virus.jpg)
From now on, the PHP logo carries a PHP code which is invisible to most picture viewers. You can quickly test the virus by uploading it to a badly-written gallery and displaying it in a browser:
![[Image: s4.png]](http://php.webtutor.pl/wp-content/uploads/2011/04/s4.png)
Most PHP scripts on the Internet use the binary-safe functions to read the files.
The above example shows, however, the importance of validating input data, and that existing security mechanisms (such as built-in PHP getimagesize() function) can be easily deceived by an appropriately crafted files.
Ofcourse an image created in this article is not a real virus (because it’s unable to propagate itself or infect other files), but it may serve as a precursor to such a program.
Also, this mechanism can be used as an unusual obfuscator, hiding the PHP code in binary files.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


![[Image: cat-breading-funny-animated-signatures_2...253481.gif]](http://i1309.photobucket.com/albums/s640/FunnyStash/04b_Signatures/cat-breading-funny-animated-signatures_20121114_1210253481.gif)