Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How To Create A Simple PHP Virus Carried By A JPEG filter_list
Author
Message
How To Create A Simple PHP Virus Carried By A JPEG #1
How to exploit this error?
The list of available attacks, of course, depends on the security level of the script.
The easiest way is to send a PHP code in plain text file and save it under the extension of the target image/movie/file (eg virus.jpg).
Unfortunately many web applications validate not only the file extension but also an internal structure of the uploaded file (eg by checking the dimensions of an image file using getimagesize() function)
In that case you can not simply change the file extension of the virus (eg from virus.php to virus.jpg), because the PHP script will detect bad file format during the upload processs.
Fortunately, most binary files may carry the PHP code without losing compatibility with the standard in which they were created.
A simple virus PHP step by step
While the described mechanism can be used in many different file formats, in the example here
I will describe an attack on the poorly-protected PHP gallery.
To perform the code injection you just need a JPEG picture, EXIF tag editor and little knowledge of PHP.
I chosed the PHP logo as a virus carrier and this program as an EXIF editor.

[Image: s1.png]
To create a virus, open the image with EXIF editor:
Then add a new tag (by pressing the plus button in the green circle), the new editing window will pop up:
[Image: s2.png]
From the drop-down list choose DocumentName as a type of the tag and copy-paste the code below as the tag value:

PHP Code:
<style>body{font-size: 0;} h1{font-size: 12px !important;}</style><h1><?php echo "<hr />THIS IMAGE COULD ERASE YOUR WWW ACCOUNT, it shows you the PHP info instead...<hr />"; phpinfo(); __halt_compiler(); ?></h1>

Click “Commit change (s)” to save the file:
[Image: s3.png]
Here is the result of my work, a JPG file with a hidden PHP code (you can download and try it yourself):
[Image: php-logo-virus.jpg]
From now on, the PHP logo carries a PHP code which is invisible to most picture viewers. You can quickly test the virus by uploading it to a badly-written gallery and displaying it in a browser:
[Image: s4.png]

Most PHP scripts on the Internet use the binary-safe functions to read the files.
The above example shows, however, the importance of validating input data, and that existing security mechanisms (such as built-in PHP getimagesize() function) can be easily deceived by an appropriately crafted files.
Ofcourse an image created in this article is not a real virus (because it’s unable to propagate itself or infect other files), but it may serve as a precursor to such a program.
Also, this mechanism can be used as an unusual obfuscator, hiding the PHP code in binary files.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

Reply

How To Create A Simple PHP Virus Carried By A JPEG #2
How to exploit this error?
The list of available attacks, of course, depends on the security level of the script.
The easiest way is to send a PHP code in plain text file and save it under the extension of the target image/movie/file (eg virus.jpg).
Unfortunately many web applications validate not only the file extension but also an internal structure of the uploaded file (eg by checking the dimensions of an image file using getimagesize() function)
In that case you can not simply change the file extension of the virus (eg from virus.php to virus.jpg), because the PHP script will detect bad file format during the upload processs.
Fortunately, most binary files may carry the PHP code without losing compatibility with the standard in which they were created.
A simple virus PHP step by step
While the described mechanism can be used in many different file formats, in the example here
I will describe an attack on the poorly-protected PHP gallery.
To perform the code injection you just need a JPEG picture, EXIF tag editor and little knowledge of PHP.
I chosed the PHP logo as a virus carrier and this program as an EXIF editor.

[Image: s1.png]
To create a virus, open the image with EXIF editor:
Then add a new tag (by pressing the plus button in the green circle), the new editing window will pop up:
[Image: s2.png]
From the drop-down list choose DocumentName as a type of the tag and copy-paste the code below as the tag value:

PHP Code:
<style>body{font-size: 0;} h1{font-size: 12px !important;}</style><h1><?php echo "<hr />THIS IMAGE COULD ERASE YOUR WWW ACCOUNT, it shows you the PHP info instead...<hr />"; phpinfo(); __halt_compiler(); ?></h1>

Click “Commit change (s)” to save the file:
[Image: s3.png]
Here is the result of my work, a JPG file with a hidden PHP code (you can download and try it yourself):
[Image: php-logo-virus.jpg]
From now on, the PHP logo carries a PHP code which is invisible to most picture viewers. You can quickly test the virus by uploading it to a badly-written gallery and displaying it in a browser:
[Image: s4.png]

Most PHP scripts on the Internet use the binary-safe functions to read the files.
The above example shows, however, the importance of validating input data, and that existing security mechanisms (such as built-in PHP getimagesize() function) can be easily deceived by an appropriately crafted files.
Ofcourse an image created in this article is not a real virus (because it’s unable to propagate itself or infect other files), but it may serve as a precursor to such a program.
Also, this mechanism can be used as an unusual obfuscator, hiding the PHP code in binary files.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #3
Wrap the text toward the left a lot of it is scrolling off the page for me to the right and is not visible.
[Image: cat-breading-funny-animated-signatures_2...253481.gif]

Champion Cat Breader!

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #4
Wrap the text toward the left a lot of it is scrolling off the page for me to the right and is not visible.
[Image: cat-breading-funny-animated-signatures_2...253481.gif]

Champion Cat Breader!

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #5
Thanks for the tip. I'll fix it right now.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #6
Thanks for the tip. I'll fix it right now.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #7
In which situations does this work? What's the code needed on the server side to display the PHP code?

A simple image uploader will just output an
Code:
<img src="path"/>

thanks

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #8
In which situations does this work? What's the code needed on the server side to display the PHP code?

A simple image uploader will just output an
Code:
<img src="path"/>

thanks

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #9
This works only on PHP-Enabled servers. If your website is running a simple HTML code, it will now work.
A computer is a stupid machine with the ability to do incredibly smart things,
while computer programmers are smart people with the ability to do incredibly stupid things.
They are, in short, a perfect match. - Bill Bryson

Reply

RE: How To Create A Simple PHP Virus Carried By A JPEG #10
Could you do the same but then with an .exe file instead of a .php file?

Reply