Showing posts with label hidden. Show all posts
Showing posts with label hidden. Show all posts

Saturday, January 10, 2009

The Coded Camel - Cool Linux And Unix Perl Art

Hey There,

Bon Saturday! (That's my best Ameri-French ;)

This week, while I was tripping all over the web (which is kind of like stumbling except different and, possibly, not as much fun as it sounds like ;) I came across this piece of Perl art. It's a picture of the O'Reilly Perl Camel. This, in and of itself, was pretty cool. But, just for yucks, I threw it into a script, fired it up and (what do you know?) it spit out the name of the guy whom I can only presume is the author. Since I found this on some dead-end somewhere (like a message board that people contribute stuff to; sometimes secondhand), I have no idea how to give "Raul S Dias" his proper attribution.

Raul, if you're out there reading this and want some free link-love, shoot me an email (via the "Send Me A Comment" link at the top right of every page) and I'll be happy to give you full credit. Unfortunately, your name is Raul, which is almost as bad as my name: Mike (That's not even brand-name Mike. Just generic Mike ;) It took me years to develop the inner fortitude to not respond to everyone who screamed out my name in crowded public areas. At one point in my life, when my neck had become permanently craned and I could wear no expression other than a sheepish look of unexpected embarassment and humiliation, I had to stop reacting to shouts of "Hey Mike!," "What's up, Mike?" and "Where's my money, Mike?" It took my family a while to get used to it, but now they're all well acclimated to calling me by my code name. When someone shouts out "Hey, you self-serving son of a b####," they almost always want to talk to me :)

Here's hoping you've gotten plenty of rest after staying out way too late last night ;) Check out the picture below; after which I've attached the original picture in script form.

Cheers,

Note: Clicking on the picture below will only make you feel smaller than you already do ;)



#!/usr/bin/perl
$==$';
$;||$.| $|;$_
='*$ ( ^@(%_+&~~;# ~~/.~~
;_);;.);;#) ;~~~~;_,.~~,.* +,./|~
~;_);@-, .;.); ~ ~,./@@-__);@-);~~,.*+,.
/|);;;~~@-~~~~;.~~,. /.);;.,./@~~@-;.;#~~@-;;
;;,.*+,./.);;#;./@,./ |~~~~;#-(@-__@-__&$#%^';$__
='`'&'&';$___="````" |"$[`$["|'`%",';$~=("$___$__-$[``$__"|
"$___"| ("$___$__-$[.%")).("'`"|"'$["|"'#").
'/.*?&([^&]*)&.*/$'.++$=.("/``"|"/$[`"|"/#'").(";`/[\\`\\`$__]//`;"
|";$[/[\\$[\\`$__]//`;"|";#/[\\\$\\.$__]//'").'@:=("@-","/.",
"~~",";#",";;",";.",",.",");","()","*+","__","-(","/@",".%","/|",
";_");@:{@:}=$%..$#:;'.('`'|"$["|'#')."/(..)(..)/".("```"|"``$["|
'#("').'(($:{$'.$=.'}<<'.(++$=+$=).')|($:{$'.$=.'}))/'.("```;"|
"``$[;"|"%'#;").("````'$__"|"%$[``"|"%&!,").${$[};`$~$__>&$=`;$_=
'*$(^@(%_+&@-__~~;#~~@-;.;;,.(),./.,./|,.-();;#~~@-);;;,.;_~~@-,./.,
./@,./@~~@-);;;,.(),.;.~~@-,.,.,.;_,./@,.-();;#~~@-,.;_,./|~~@-,.
,.);););@-@-__~~;#~~@-,.,.,.;_);~~~~@-);;;,.(),.*+);;# ~~@-,
./|,.*+,.,.);;;);*+~~@-,.*+,.;;,.;.,./.~~@-,.,.,.;_) ;~~~
~@-,.;;,.;.,./@,./.);*+,.;.,.;;@-__~~;#~~@-,.;;,.* +);;
#);@-,./@,./.);*+~~@-~~.%~~.%~~@-;;__,. /.);;#@- __@-
__ ~~;;);/@;#.%;#/.;#-(@-__~~;;;.;_ ;#.%~~~~ ;;()
,.;.,./@,. /@,.;_~~@- ););,.;_ );~~,./ @,.
;;;./@,./| ~~~~;#-(@- __,.,.,. ;_);~~~ ~@
-~~());; #);@-,./@, .*+);;; ~~@-~~
);~~);~~ *+~~@-);-( ~~@-@-_ _~~@-
~~@-);; #,./@,.;., .;.);@ -~~@-;
#/.;#-( ~~@-@-__ ~~@-~~ @-);@
-);~~, .*+,./ |);;;~ ~@-~~
;;;.; _~~@-@ -__);. %;#-(
@-__@ -__~~;# ~~@-;; ;#,.
;_,.. %);@-,./@, .*+,
..%, .;.,./|) ;;;)
;;#~ ~@-,.*+,. ,.~~
@-); *+,.;_);;.~ ~););
~~,.; .~~@-);~~,.;., ./.,.;
;,.*+ ,./|,.); ~~@- );;;,.(
),.*+); ;#~~/|@-
__~~;#~~ $';$;;


, Mike




Discover the ClickBank affiliate program that pays 100% commission!



Please note that this blog accepts comments via email only. See our Mission And Policy Statement for further details.

Tuesday, November 4, 2008

Really Simple Keyless Steganography For Linux And Unix

IMPORTANT NOTE: A reader has noted that Blogspot elected to change all my bitmap images to jpg format without renaming them, which, of course, removes the hidden message just as surely as resizing does. Apologies for any confusion. I will refrain from posting bitmaps in the future. At least when their actually "remaining" bitmaps is of importance!

Hey again,

Today we're going to take a look at a topic that most people are probably familiar with to one degree or another. To use the dictionary definition, steganography is the art of "hiding a secret message within a larger one in such a way that others can not discern the presence or contents of the hidden message."

I'm sure the title of today's post probably put off more than a few purists who subscribe to the more exact definition that steganography is "the art of writing in cipher, or in characters which are not intelligible except to persons who have the key." If you define steganography that strictly, there can be no such thing as keyless steganography, except in the land where the oxymoron is king ;)

Later in the week, we'll be looking at "really" hiding a message inside another message (or PDF, or picture, etc, as the case may be) so that it can't be encoded or decoded without a key. For now, we're going to look at just how easily one can pass a message along (inside a bitmap image) without using a key. The beauty of this method is that it's incredibly easy to implement and hard to notice if one isn't looking for it.

For our example today, we'll take a standard Windows bitmap tile: The cute, pouting little kitten. Knowing that the little kitty on the right (below) is actually an agent for the delivery of a blatant hidden message, it probably looks a lot more menacing now, right?

innocent kitty stealth kitty


Okay, it doesn't look all that different than the original picture. However, if you blow up the top left section of the bitmap, you can see the difference (Remember; this is a hackish way of hiding a message that is just begging to be found out, so we can make a point ;)

innocent kitty blowup stealth kitty blowup


Now, you should be fairly confident that the kitten on the right is a bit more vicious than the kitten on the left (in the original pictures). We should note that the blown-up sections of the pictures, and even resizing the original bitmap (below), will completely erase our message (This is generally true of most steganographic methods).

stealth kitty large

So what's the secret to lame steganography? It's exactly that: completely lame ;) We could have actually taken some time and spaced the message out somewhat and made it much harder to see the difference in the altered image, but, again, we're trying to make the difference obvious (although not totally).

The secret to doing this sort of "lame steganography" is simple (raw) editing of the binary file. Using "vi" (available on virtually every distro of Linux and Unix imaginable) is one simple way to accomplish this. If you use "vi" to "read" the second kitty (the rightmost in the first set of pictures), you'll notice the message near the end:

<J"?ÅOY?'BiâXÅqdaeY/¤I>O¬¬>->O¬êSl"I>I>O>c,/¤ñÄI>o'_¼ì£,¼,_lIc£(",¼IOH<%>m"i£ª£òíl¼&ja fb` ?%jD,E3Öÿ²_O_II^£+zâ@á8åafri>¦zÆY("frSöÆ'é»jO-YO_#Y
¼I>OIIOÆ,£acIÄY?Ah>NíoåNåkO.åI"¥YCAÅYåqHr OE"&j?'IIE3Nåìä+IçIIJ$!A( THIS CAT WANTS TO EAT YOU ALIVE<I>ê,O"E,`'O>E,l"Ez^r%zE,I>ò¼`'ÑÄo'_Ä'åôåé»?'c£
Y/Oê»<ê3i>L¼ª£I"
å+,§,BA#AEjçSE«-ídQñoÄa¤Y,¼Äqi£?Y±_0Y?I+¼IOOIkIH"A0+r£Qfr<OOåíÜIO-I¬O+z?9dQÅigr+¼?¬Ç'f,É,II3_Ñås_"_S_


Another, more elegant way to do it, is with any hex editor (for instance, Ultra Edit). Just like with vi, you can add the message and read it very simply (in the ASCII conversion column). This is how the output looks in Ultra Edit in the original file:

¡ ‹ì›¼ÏÄRÕ¯´+´¦Š"aYåy&z„qâH+‹


and with the hidden message (hidden in the kitty on the right):

THIS CAT WANTS TO EAT YOU ALIVE‹


You see what I'm saying? That cat is just downright mean ;)

As promised, later this week, we'll take a look at some more advanced forms of steganography. In the meantime, the odds are that no one (except the person you tell) will notice this sort of secret-message-passing. And the best part is that you don't need to invest in any extra software to get the job done :)

Cheers,

, Mike




Iker Landajuela had this suggestion as an alternate solution to getting at information hidden in hex files!


To watch for string inside a BMP picture we can execute:

$ hexdump -C hiddenimage.bmp | grep "hidden message"


Please note that this blog accepts comments via email only. See our Mission And Policy Statement for further details.

Sunday, February 24, 2008

Creating Your Own Secret Webserver Log With CGI

Howdy,

This is a little trick I like to use every once in a while, if I need to debug visits and don't want to mess with the "official" log files that everyone else looks at and/or may depend upon to do their jobs correctly. The last thing I want to do is cause problems for other people. ...Well, it's pretty close to the end of my list ;) This script (Both the HTML and CGI) should run on any Linux or Unix system. The HTML portion should also run on pretty much any webserver.

The Perl CGI script is very simple, so I've included both the HTML (which you should nest or include in the page you want to track) and the backend CGI script that will record the information for you. The only important things to note are that, in your HTML, you want to set the form variable type to "hidden" (You'll only be passing one variable, which will be bogus, since, in this case, you're just interested in getting environment variables that are normally passed by the POST method). Your CGI output should also be somewhere secure enough that not just anyone can get to it, but unsecure enough so that the user your webserver runs as can actually write to it.

In a worst case scenario here, a malicious user can write bogus data to your file. Putting the file in a separate location is my way of hedging my bets in case there's something else a malicious user can do that I haven't thought of. If they destroy my personal file, I won't have to hear about it from anyone else :)

Without further ado, the HTML and the CGI march on!

Cheers,


Creative Commons License


This work is licensed under a
Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License

HTML PORTION

<form name="form" method="post" action="loggen.pl">
<input type="hidden" name="bogus" value="0">
</form>


CGI SCRIPT

#!/usr/bin/perl

#
# loggen.pl
# generate your own secret log file
#
# 2008 - Mike Golvach - eggi@comcast.net
#
# Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License
#

print "Content-type: text/plain\n\n";
$logfile = "/wherever/you/want/to/put/your/log_file";
chomp($date = `date +%m%d%y`);
open (LOG, ">>$logfile");
print LOG "$date|";
print LOG "$ENV{'REMOTE_HOST'}|";
print LOG "$ENV{'HTTP_USER_AGENT'}|";
print LOG "$ENV{'DOCUMENT_URI'}|";
print LOG "$ENV{'HTTP_REFERER'}\n";
close (LOG);
exit;


, Mike