[00:05.580 --> 00:10.300] While I get this set up, there is not going to be any actual explosives. [00:10.300 --> 00:12.380] It's all software, so not to disappoint. [00:21.820 --> 00:22.300] Yay. [00:26.240 --> 00:28.400] My presentation software, wing it. [00:29.800 --> 00:31.140] It's a Grand Theft Auto joke. [00:35.110 --> 00:38.570] All right, the code, it will be released in about 50 minutes. [00:38.670 --> 00:40.230] I have a cron at home that will upload it. [00:41.510 --> 00:42.910] So, I'll get into it. [00:44.790 --> 00:48.510] What I plan to go over is just a quick intro to steganography. [00:48.990 --> 00:51.510] How many people are familiar or understand steganography? [00:52.370 --> 00:53.610] Cool, so you'll be bored. [00:55.750 --> 00:57.950] And then I'm going to get even more off-topic. [00:58.390 --> 01:01.870] And then I'll finally talk about what is explosive steganography. [01:02.150 --> 01:03.410] Something I kind of made up. [01:04.510 --> 01:08.250] And I'll go over all my tools and summarize it after that. [01:10.310 --> 01:15.050] So, for those few of you that are not familiar with steganography, I'm going to go over a really old example. [01:16.050 --> 01:17.390] It's based on a true story. [01:17.510 --> 01:18.790] The method, not the story. [01:18.950 --> 01:20.050] This story is completely fake. [01:20.250 --> 01:22.970] But imagine a time, a long time ago, B.C. [01:22.990 --> 01:26.530] times, we have a tyrannical settlement over on the east. [01:26.530 --> 01:30.450] And we also infiltrated spies in there. [01:30.830 --> 01:33.730] They're serving the actual tyrant. [01:34.550 --> 01:36.730] And we also have poison over there. [01:36.870 --> 01:38.290] But the spies don't know where the poison is. [01:38.370 --> 01:44.230] So, we've got to send a diplomat into the country or the settlement to tell the spies where the poison is. [01:47.950 --> 01:53.310] So, we have our guy, our diplomat, with his message that says the poison is under the blue vase. [01:54.150 --> 01:58.690] So, when he goes through into the settlement, the problem is the guards, they see that message. [01:59.610 --> 02:00.690] And then that happens. [02:03.990 --> 02:10.410] So, not only does the messenger get killed, but then the actual soldiers, they know where the poison is, too. [02:10.410 --> 02:13.010] So, you can't just even send in another messenger. [02:13.350 --> 02:14.610] So, tries again. [02:15.110 --> 02:16.610] Comes in with a cipher message. [02:16.770 --> 02:18.050] And this is kind of like a Caesar cipher. [02:18.210 --> 02:18.710] It's really old. [02:18.730 --> 02:19.850] So, no good encryption. [02:20.870 --> 02:22.310] This still doesn't work. [02:23.670 --> 02:27.810] Because the guards see this encrypted message and they're still like, I don't know what it is. [02:27.890 --> 02:28.730] So, I'm not going to let you through. [02:29.030 --> 02:30.110] It's still suspicious. [02:30.810 --> 02:37.170] I guess the benefit is they can send in another diplomat that has a message that says that. [02:39.310 --> 02:41.190] So, this is kind of steganography. [02:41.350 --> 02:42.710] This is hidden in plain sight. [02:42.810 --> 02:45.490] There is a real message, but it's not what it looks like. [02:46.390 --> 02:49.350] So, when he goes into the village, the diplomat doesn't know anything. [02:49.570 --> 02:52.610] I mean, he had a little bit of pain in the back of his head, but he doesn't know what's going on. [02:52.810 --> 02:54.950] When he goes in, the spies know what to do. [02:56.010 --> 02:56.570] Well, okay. [02:56.730 --> 02:57.630] So, first off, he gets through. [02:58.390 --> 02:59.330] Now, the spies know what to do. [02:59.390 --> 03:02.110] They shave the back of his head and it says the poison is under the blue vase. [03:03.270 --> 03:04.590] And I didn't draw these. [03:05.090 --> 03:06.190] Props to my friend, Nack. [03:07.130 --> 03:10.230] If any of you know, meatspin.com, he's the creator of that. [03:15.070 --> 03:16.630] Don't go to it right now. [03:18.550 --> 03:19.030] So, yeah. [03:19.130 --> 03:19.750] Hidden in plain sight. [03:19.950 --> 03:20.610] That's steganography. [03:21.250 --> 03:25.930] So, as I go into steganography, I'm going to kind of go over my impression of steganography. [03:26.090 --> 03:28.610] I know there's a lot to it, and I'm just going to go over my impression of it. [03:29.090 --> 03:31.030] And I'm going to try to go through this as quickly as possible. [03:31.030 --> 03:31.770] There's a lot of stuff here. [03:32.110 --> 03:34.030] So, modern steganography, common stuff. [03:34.230 --> 03:35.270] Usually, it's image-based. [03:35.790 --> 03:37.110] Those of you that are familiar with it. [03:37.570 --> 03:40.850] I'm going to do the least significant bit method. [03:40.970 --> 03:41.770] That's what I'm going to go over. [03:42.610 --> 03:43.250] And for... [03:43.250 --> 03:44.230] There's a lot of tools out there. [03:44.450 --> 03:45.570] Outguess, steghide, and all that. [03:45.810 --> 03:49.570] Nack, that same guy, he also wrote something called node-stego. [03:50.690 --> 03:51.930] This is all going to be on my GitHub. [03:52.270 --> 03:53.530] So, these are actually links. [03:53.650 --> 03:54.430] This is all web-based. [03:54.830 --> 03:57.010] So, that node-stego, you can actually get to the tool that way. [03:57.970 --> 04:00.330] So, you've got this really low resolution picture here. [04:00.330 --> 04:03.610] This is supposed to be a 4x4 pixel image. [04:03.770 --> 04:06.050] With some red, some other red, and some green. [04:07.270 --> 04:09.290] Now, those are the values. [04:10.150 --> 04:14.710] So, you got 0 through 255 for your shades of red, green, and blue. [04:14.950 --> 04:19.650] So, you notice the mid, or the kind of darker red, that's 127 for the red and all those. [04:19.770 --> 04:21.430] And they don't have anything for green or blue. [04:22.250 --> 04:24.090] For the green, that's also half turned on. [04:24.290 --> 04:26.390] So, those green pixels, you have 127 for that. [04:26.670 --> 04:29.690] And for your bright red, it's all the way turned on to 255 for each. [04:30.310 --> 04:34.090] So, what would happen if I, say, took the green down a couple notches? [04:34.210 --> 04:35.510] Say, I took it down to like 65. [04:35.830 --> 04:37.510] It's going to be a much darker shade. [04:37.710 --> 04:39.130] But say, I only took it down to... [04:39.130 --> 04:41.010] Instead of 127, I took it down to 126. [04:41.810 --> 04:43.230] Visually, it's not going to look that much different. [04:43.330 --> 04:44.070] And that's the secret. [04:44.470 --> 04:53.470] So, if we wanted to hide some information in there, binary information, we could say something like, all the even numbers are going to be ones, and all the odd... [04:53.470 --> 04:56.030] Or the even numbers, we'll say, are going to be zeros, and odd numbers are going to be ones. [04:56.450 --> 04:58.990] So, that's three different colors per pixel. [04:59.250 --> 05:01.390] If you multiply that out, that's 48 bits. [05:01.590 --> 05:03.130] It's not a lot, but it's still something. [05:03.370 --> 05:04.490] And visually, you won't notice it. [05:04.770 --> 05:06.170] So, let's try to put a message in there. [05:06.930 --> 05:08.670] In binary, those are all the ones and zeros. [05:08.830 --> 05:10.550] Those are 48 ones and zeros. [05:10.750 --> 05:12.110] In ASCII, that's HOPE Number Nine. [05:13.930 --> 05:16.490] So, those are the ones and zeros that we can fit into each pixel. [05:17.330 --> 05:18.590] This is the new image. [05:18.990 --> 05:25.290] You can tell in the first pixel up here, we cranked up red by one, and we even added one for green. [05:25.670 --> 05:28.770] And if I go back, so that would be a zero, one, zero. [05:29.550 --> 05:30.590] It's a zero, one, zero. [05:30.810 --> 05:31.730] That's what we're doing right there. [05:32.230 --> 05:33.550] And we do it throughout that whole thing. [05:33.650 --> 05:37.990] So, we actually embedded HOPE Number Nine in our four by four pixel image. [05:39.110 --> 05:40.170] And that's the new image. [05:40.810 --> 05:41.790] There's not much of a difference. [05:41.790 --> 05:43.390] It's almost that simple. [05:44.030 --> 05:47.610] There's more complicated methods, but that's, in my opinion, the simple one to understand. [05:48.910 --> 05:50.570] Here's another favorite method of mine. [05:50.690 --> 05:58.070] This isn't really typical for steganography, but I like this example, because it's really illustrating out-of-band context. [05:58.810 --> 06:04.750] So, the book cipher, the message itself, we're not actually even inserting anything in there to obscure it or anything. [06:05.270 --> 06:07.770] The original message is still the original message. [06:07.890 --> 06:09.210] The secret is in the context. [06:09.610 --> 06:14.050] So, at the book cipher, we have our context, which is the blue up at the top there. [06:14.950 --> 06:17.890] It's referring to the first letter of what word. [06:18.810 --> 06:21.570] So, for like the 45th word in there, it would be a G. [06:21.950 --> 06:27.770] But an easier example to scan if you're looking at it is, say, for that second chunk, we got 14, nine, six. [06:27.990 --> 06:29.970] So, the six, we go to the six words. [06:30.110 --> 06:31.390] So, one, two, three, four, five, six. [06:31.390 --> 06:32.030] It's respecting. [06:32.950 --> 06:36.530] So, that's the R in the word for, go for smaller parts. [06:36.690 --> 06:37.610] That's the secret message. [06:39.470 --> 06:44.550] And I'm gonna get more detailed on the whole idea of meaning and context. [06:45.050 --> 06:48.870] Data doesn't have meaning unless there's context to go with it. [06:49.170 --> 06:53.310] So, these ones and zeros here are meaningless without the right context. [06:53.310 --> 06:59.230] And for those that have memorized the ASCII chart, you're probably trying to decode that right now, thinking what that means. [06:59.590 --> 07:00.430] But that's the thing. [07:00.570 --> 07:02.310] The ASCII chart is the context. [07:02.350 --> 07:05.290] So, the data is still meaningless unless you interpret it with ASCII. [07:05.450 --> 07:06.330] So, we'll do that. [07:06.610 --> 07:10.230] We have ASCII, which in hex would be the 4F4444. [07:10.690 --> 07:13.030] And in printable, that would be the word odd. [07:14.470 --> 07:17.010] So, let's take a look at it in a different context. [07:17.830 --> 07:18.710] Same message. [07:19.950 --> 07:23.290] Base 64, another coding scheme that we have. [07:23.290 --> 07:24.530] that a lot of you are probably aware of. [07:24.990 --> 07:26.350] It's an indexing scheme. [07:26.570 --> 07:34.990] So, it goes from like A through Z, capital A through Z, lowercase, and zero through nine, and a couple, two special characters. [07:35.190 --> 07:36.330] I think I have that right. [07:37.150 --> 07:40.990] So, what this would translate to is the word Tor. [07:42.430 --> 07:45.190] Leetspeak though, because the O is actually a zero. [07:45.730 --> 07:49.490] But my point is, the data itself, it's all about interpretation. [07:49.490 --> 07:53.390] So, it's a really tough game with steganography. [07:53.730 --> 08:01.270] Yeah, if you know about outguess and stake hide, you can use some other anti-steganography tools to recover it. [08:01.350 --> 08:03.290] But if you don't know the context, it's really difficult. [08:04.150 --> 08:06.550] Even though I would say that nothing is in a vacuum. [08:07.310 --> 08:09.150] You can eventually arrive at it. [08:10.410 --> 08:13.110] So, another idea that confuses it even more. [08:13.210 --> 08:14.150] And this is me getting off track. [08:15.510 --> 08:16.270] It's apophenia. [08:16.430 --> 08:18.970] It's the idea of finding meaning and meaningless data. [08:19.250 --> 08:21.370] So, this image here, we got a few cars here. [08:21.390 --> 08:22.210] You can kind of see that. [08:23.210 --> 08:24.790] And I'll read the license plates. [08:25.110 --> 08:27.110] For the first one, you have PDF 225. [08:27.390 --> 08:28.790] You have 512 256. [08:29.610 --> 08:32.130] And then you have 337 CCG. [08:32.850 --> 08:33.830] It doesn't mean anything. [08:34.090 --> 08:34.410] Next slide. [08:37.170 --> 08:38.750] So, this, more art by neck. [08:39.250 --> 08:41.250] We have this guy studying a street sign. [08:41.470 --> 08:43.350] This is kind of apophenia, but kind of not. [08:43.490 --> 08:45.390] I mean, we got apophenia avenue he's looking at here. [08:45.490 --> 08:47.990] But he's studying the timings of the red and green lights. [08:48.170 --> 08:50.330] He wants to see if there's any pattern in that. [08:50.530 --> 08:52.030] So, you know, he has a table here. [08:52.230 --> 08:53.690] We have a bunch of different times. [08:53.750 --> 08:57.270] We're marking when it was red, when it was green, the time frames. [08:57.270 --> 08:58.650] And how long. [08:58.890 --> 09:02.590] We can go from the times to figuring out how long each one was red and green. [09:02.830 --> 09:04.470] And I have kind of highlighted there. [09:05.290 --> 09:11.990] The one time, the red light wasn't on as long as it usually is. [09:12.090 --> 09:12.790] It's an anomaly. [09:13.670 --> 09:14.710] So, what does that mean? [09:15.070 --> 09:16.250] He sees this anomaly. [09:16.490 --> 09:18.410] He tracks how many other times this happens. [09:18.710 --> 09:23.090] So, spread out through time, like about half a year, it happened six times. [09:23.430 --> 09:25.690] That exact same anomaly happened six more times. [09:25.690 --> 09:26.610] And he recorded the times. [09:26.610 --> 09:28.750] And he's still wondering, what does this mean? [09:29.250 --> 09:32.910] And again, part of my point is, the context can be out of band. [09:33.130 --> 09:35.570] It might not mean anything unless you're looking at the right context. [09:36.330 --> 09:39.210] So, what if we cross-reference it with the weather that day? [09:39.530 --> 09:45.190] We have 72 degrees, 79, 80, as it gets to get closer to winter, 69, 35, 57. [09:45.910 --> 09:51.930] Well, if you convert that to decimal ASCII, again, we get HOPE Number Nine. [09:56.860 --> 10:07.920] And this is just obscurely illustrating that when you have a lot of data and you don't know the context exactly, meaning is a really significant idea. [10:12.170 --> 10:14.030] So, I hope that was quick enough. [10:14.220 --> 10:15.050] Hopefully I have time here. [10:16.170 --> 10:16.960] Explosive steganography. [10:18.030 --> 10:21.210] These tools... This term might not even be correct. [10:21.330 --> 10:21.810] I made it up. [10:22.140 --> 10:27.960] It's not steganography in the general sense of the term of you want it to be not noticeable. [10:28.790 --> 10:30.910] This is very noisy steganography. [10:31.170 --> 10:32.860] So, it's almost like not steganography. [10:33.480 --> 10:34.950] But I don't know what else to call this. [10:35.670 --> 10:37.530] So, a pictorial analogy. [10:38.620 --> 10:39.340] Where's Waldo? [10:40.910 --> 10:42.580] Steganography to me, where's Waldo? [10:42.880 --> 10:44.190] Waldo would be the steganography. [10:44.910 --> 10:46.600] He's hidden, but in plain sight. [10:46.760 --> 10:47.530] Like, you can kind of find him. [10:47.620 --> 10:49.030] You know what he looks like, but it might take a while. [10:49.260 --> 10:52.860] So, the explosive steganography is kind of more like that. [10:55.030 --> 10:56.360] You want to avoid that. [10:56.720 --> 10:59.290] And the secret message is in there. [11:04.080 --> 11:05.480] So, I'll go to the first tool. [11:05.900 --> 11:08.800] And each one of my tools, they're all written in Perl. [11:09.560 --> 11:13.420] I was mostly just learning the language and playing around. [11:13.700 --> 11:15.060] Don't take any of this seriously. [11:15.240 --> 11:18.260] I'm not trying to make these real awesome tools or anything. [11:18.400 --> 11:23.280] I just did all this with kind of an evil set of mind, I guess. [11:24.640 --> 11:25.040] So... [11:25.460 --> 11:29.600] With Archive Bombs, I'll talk about my first tool, which is eZipload. [11:29.700 --> 11:31.640] Like, you know, zip, but eZipload. [11:32.820 --> 11:35.880] And before I talk about the tool, though, I'll go into a little bit of history of Archive Bombs. [11:35.920 --> 11:37.100] This isn't something that I made up. [11:37.580 --> 11:40.360] I think the most well-known one is 42.zip. [11:40.500 --> 11:43.300] And I think it's called that because the actual zip file is 42K. [11:43.920 --> 11:44.960] So, 42.zip. [11:45.680 --> 11:48.680] It's a zip file that, when you open it up, it has 16 more zip files. [11:49.280 --> 11:50.320] lib0, lib1, lib2. [11:50.520 --> 11:55.480] You open up any one of those, and you have book 0, book 1, book 2, and so on. [11:55.560 --> 11:57.160] You go in there, you've got 16 more zip files. [11:57.320 --> 11:59.120] Chapter 0, chapter 1, chapter 2, and so on. [11:59.120 --> 12:01.820] You go into any of those, you've got 16 more zip files. [12:02.080 --> 12:03.140] Doc 0, doc 1, doc 2. [12:03.620 --> 12:06.080] You go into there, you've got 16 more zip files. [12:06.260 --> 12:07.760] Page 0, page 1, page 2, and on. [12:08.080 --> 12:12.840] You go into any one of those, and you've got a 16-gigabyte file. [12:14.300 --> 12:15.360] I didn't make this tool. [12:18.420 --> 12:20.460] While I like the tool, there's a couple of limitations. [12:20.880 --> 12:30.160] Being that inside they're all zip files, and you've got a hierarchy of zip files, it's not going to, typically most archive tools aren't going to recursively extract it. [12:30.280 --> 12:36.640] So if you extract all, you're just going to get the first 16 zip files, and they're all only like about 30k, so it's not really going to do a whole lot. [12:39.540 --> 12:43.480] And, not that this other thing's a limitation, but I want it to be more configurable, so I wrote my own tool. [12:44.520 --> 12:48.400] I used just a normal vanilla 32-bit, so it has some limitations. [12:48.400 --> 12:57.360] 4.3 gigs is the most any file inside can be, and you can only have 65,535 files, which limits you to a mere 256 terabytes inside. [13:01.180 --> 13:06.160] This is just kind of a loose example of how a file might look on a file system. [13:06.280 --> 13:13.340] You've got your data in the blue, but you also have metadata, which isn't part of the actual file itself, depending on how your file system handles it, but it's separate from the file. [13:13.440 --> 13:15.200] It's metadata of data. [13:15.440 --> 13:18.740] So, you know, describing the file size, the name, date, permissions, and all that. [13:19.160 --> 13:25.220] The zip structure is kind of complicated, and I had to kind of reverse engineer it, and Wikipedia helped a little bit of the way, but not all the way. [13:25.380 --> 13:28.400] I had to do a lot of hex, lots of hex. [13:28.880 --> 13:33.540] I had to, like, copy it in hex and then change bytes at a time to figure out what was doing what. [13:33.700 --> 13:34.080] It was horrible. [13:34.960 --> 13:41.860] But, so this is an example of a zip file that has two files inside of it, and that's the two blue parts there. [13:41.900 --> 13:42.840] It's the compressed data. [13:44.280 --> 13:53.780] And it's kind of redundant on purpose, but you have a couple headers in the beginning, and you have some other headers and metadata in the middle, and you have a footer. [13:54.120 --> 13:59.280] So, for a header, the typical kind of stuff it has is, like, the PK label from, you know, PK zip. [13:59.500 --> 14:00.520] It's still there. [14:01.560 --> 14:06.800] What kind of archive software it's compatible with, what kind of compression method it used. [14:07.000 --> 14:14.800] You got your UNIX timecodes, CRC, the checksum, the compressed file size, uncompressed file size, which is just reporting to the archiver. [14:14.940 --> 14:17.720] It can be faked, which I did, and the file names. [14:19.080 --> 14:21.720] And then you got your kind of middle metadata. [14:22.040 --> 14:30.140] It's kind of the same, but you also have, like, a pointer to the internal memory location that the files start at, and some attributes. [14:32.900 --> 14:36.700] And, yeah, for that other smaller mid metadata, like, I don't really know what it does. [14:36.820 --> 14:37.960] I don't really care, because I didn't need to. [14:37.960 --> 14:38.940] I just faked it all anyway. [14:39.560 --> 14:43.620] And the footer is also kind of complicated mathematically if you're reverse engineering it. [14:44.140 --> 14:51.920] It also has a pointer to internal memory where the mid metadata starts, and also the total file size of all the mid metadata. [14:52.300 --> 15:08.260] So your structure for all those pointers and offsets, you have your mid metadata, this first red line refers to that first file up there, so it points to where that starts data-wise, and your second part points to the second file, and then your footer points to the beginning of the mid metadata, [15:08.580 --> 15:09.980] and also to the total size. [15:10.940 --> 15:18.460] So the problem with this for me, doing it standard was, if I have a 4.3 gig file compressed, it's about a 4 megabyte file zipped. [15:19.220 --> 15:32.660] And if I have to keep repeating that over, and over, and over, and over, and over again, I'm going to have a pretty large zip file for, I mean, it's still going to explode quite a bit, but still, if I want 256 terabytes, and I'm going to have like a zip file that's a few gigs, [15:32.700 --> 15:33.820] that still wasn't good enough for me. [15:33.920 --> 15:34.680] So I had to trick it. [15:36.540 --> 15:46.020] So what I actually did was, dynamically, for however many files you want inside, I had all the mid metadata pointing to that same file over, and over, and over, and over, and over again. [15:47.180 --> 15:49.860] Typical archive software will not make a file like that for you. [15:52.200 --> 15:53.000] So I'll do a demo. [15:59.150 --> 16:00.650] And I'll try to make this big. [16:04.420 --> 16:05.640] That's as big as I'm going to get it. [16:17.100 --> 16:22.740] Try to make extensive use of auto key here, so I don't have to type out huge commands, but I have to turn auto key on. [16:23.780 --> 16:24.140] There we go. [16:26.900 --> 16:28.600] So, I'm going to run ease upload. [16:29.800 --> 16:30.640] Actually, I take that back. [16:30.780 --> 16:32.180] Let's go into my directory that I want to be in. [16:34.300 --> 16:34.700] Okay. [16:39.700 --> 16:40.520] I'm going to run it. [16:40.720 --> 16:41.440] Don't want the help. [16:42.100 --> 16:44.540] I'm going to save the total amount of files I can do. [16:45.960 --> 16:46.760] 65,535. [16:47.600 --> 16:49.820] File names, I'm going to have the convention of DCIM. [16:50.080 --> 16:52.380] Kind of like pictures that a camera would take. [16:52.560 --> 16:53.980] File extensions will be JPEG. [16:54.660 --> 16:56.500] And the out file will be pictures.zip. [16:56.500 --> 16:57.380] So, I'm running it. [16:58.280 --> 16:59.000] It ran. [17:03.010 --> 17:03.460] And... [17:03.980 --> 17:05.700] I'll go into that folder real quick. [17:06.580 --> 17:08.100] We got stick demo. [17:08.960 --> 17:10.620] There is our pictures.zip. [17:10.840 --> 17:11.640] I'll open it up. [17:12.900 --> 17:14.820] It's going to take maybe 10 seconds. [17:17.100 --> 17:17.840] There we are. [17:23.460 --> 17:24.840] I'm not going to extract all. [17:25.160 --> 17:26.360] It would take a while anyway. [17:26.480 --> 17:27.420] It's not good for presentations. [17:27.720 --> 17:29.400] But you can see at the bottom here... [17:29.400 --> 17:30.840] Well, I actually probably can't. [17:30.840 --> 17:34.240] It says 281.5 terabytes. [17:36.300 --> 17:39.240] And the date is... [17:39.840 --> 17:40.180] Oops. [17:40.560 --> 17:40.720] No. [17:41.300 --> 17:41.940] Default day. [17:43.140 --> 17:45.780] So, it's November 11th of 2011. [17:50.600 --> 17:52.680] So, that's the Prankster version of it. [17:57.910 --> 17:59.210] And actually, yeah. [17:59.330 --> 17:59.890] All these tools. [18:00.070 --> 18:02.790] I would use the Prankster version and the Steganography version. [18:02.990 --> 18:08.830] Like, kind of as Benny said, one of the good things to do to throw people off is to give them more work. [18:09.090 --> 18:10.530] This stuff isn't going to be perfect. [18:11.890 --> 18:13.390] So, you can't hide it forever. [18:13.550 --> 18:17.970] But if you give them a lot of stuff that doesn't even have a secret message in it, it's going to give them more work. [18:18.510 --> 18:21.510] So, I would use all these tools in combination with the actual Steganography. [18:22.130 --> 18:23.690] But my other tool... [18:24.930 --> 18:29.450] And actually, also, if you download this presentation, I have screenshots offline too. [18:30.130 --> 18:31.350] I'm not going to go into them. [18:34.090 --> 18:37.250] So, ZipMouth, that's the other tool that goes along with EZipload. [18:37.350 --> 18:38.010] It's kind of the same thing. [18:38.210 --> 18:43.370] But it actually makes a fake PK header and puts secret information in there. [18:43.430 --> 18:44.910] And it's AES encrypted. [18:45.190 --> 18:49.550] So, the file structure is kind of the same, but at the bottom we have a fake PK signature in Steganography. [18:51.710 --> 18:53.050] So, we'll run that one. [18:57.250 --> 19:00.170] Actually, before I do that, we've got all of our files in there. [19:00.390 --> 19:01.470] We've got a plain text file. [19:03.070 --> 19:03.690] There it is. [19:03.930 --> 19:06.350] A secret message with two lines of text, just so you see that first. [19:08.770 --> 19:10.090] So, I'm going to run ZipMouth. [19:10.230 --> 19:12.050] I'm going to inject plain text. [19:12.570 --> 19:14.770] And that file will be compressed.zip. [19:15.390 --> 19:17.730] And the host file is 42.zip. [19:17.750 --> 19:21.070] So, I'm going to piggyback off of that so it's not a destructive process. [19:22.390 --> 19:23.410] So, I ran it. [19:25.050 --> 19:26.370] We have compressed.zip. [19:30.200 --> 19:32.140] And actually, I'll show you compressed.zip. [19:35.210 --> 19:35.860] There it is. [19:35.970 --> 19:36.360] Lib 0. [19:37.520 --> 19:38.180] Book 0. [19:39.100 --> 19:39.800] Chapter 0. [19:40.340 --> 19:41.240] Yeah, I won't waste your time. [19:52.290 --> 19:53.700] So, I'm just going to look at the... [19:53.700 --> 19:56.030] kind of a specific hex stump of what I have in there. [19:56.120 --> 19:57.290] I didn't use encryption this time. [19:57.560 --> 20:01.560] The only reason I added the feature of not using encryption was just for demonstration purposes. [20:01.730 --> 20:02.920] Otherwise, I'd recommend always using it. [20:02.920 --> 20:04.100] I've got to shrink this... [20:07.380 --> 20:08.360] a little more. [20:11.120 --> 20:11.600] Okay. [20:12.300 --> 20:16.740] So, over there in the lower end, you'll see a secret message with two lines of text. [20:23.850 --> 20:25.210] So, now I'm going to extract it. [20:28.900 --> 20:30.060] So, I use extract. [20:31.000 --> 20:32.840] I'm going to use compressed.zip. [20:32.920 --> 20:33.920] That's what I want to grab out of. [20:34.340 --> 20:36.520] And it'll go to decrypted.text. [20:37.560 --> 20:39.360] So, we have decrypted.text in there. [20:40.280 --> 20:40.680] Yep. [20:43.340 --> 20:44.860] A secret message with two lines of text. [20:47.480 --> 20:49.100] Just to show that I'm not lying. [20:50.640 --> 20:52.980] I will do this with encryption this time. [20:53.220 --> 20:54.860] The password will be lol. [20:56.960 --> 20:57.500] Yarp. [20:58.680 --> 20:59.060] Okay. [21:01.820 --> 21:05.270] You can... anything that starts with the letter Y works. [21:11.500 --> 21:14.800] So, same... same thing, but I used a password this time. [21:14.800 --> 21:17.040] So, in that same location there, it looks like garbage. [21:17.040 --> 21:18.260] Because it's AES encrypted. [21:22.080 --> 21:23.920] And to show that I can rip it back out. [21:28.380 --> 21:29.100] There it is. [21:33.710 --> 21:35.950] So, now I'll move to the next interesting tool. [21:38.370 --> 21:39.710] Hiding an illness. [21:40.350 --> 21:42.450] So, hiding secret messages and illness. [21:43.070 --> 21:45.730] Things that look like viruses, but aren't really. [21:45.910 --> 21:46.930] They're actually pretty benign. [21:47.430 --> 21:49.510] So, the first tool, the prankster version of the tool. [21:49.850 --> 21:50.210] Hivsneeze. [21:52.870 --> 21:54.990] It generates a user-defined amount of viruses. [21:55.730 --> 21:56.130] Viruses. [21:56.910 --> 21:58.090] They're all false positives. [21:58.310 --> 22:00.410] I just grabbed them out of ClamAV's dictionary. [22:00.670 --> 22:03.350] But I removed all the ones that are actually ClamAV specific. [22:04.490 --> 22:09.270] And the thing that took a little bit of work on my end was, I made all the files kind of look or act real. [22:09.470 --> 22:10.750] So, executables will execute. [22:10.990 --> 22:12.030] PDFs will open as a PDF. [22:12.310 --> 22:14.550] Zip files will resemble r.zip. [22:14.710 --> 22:17.250] And r.zip, I don't know if anybody's heard of that, but that's amazing. [22:17.410 --> 22:18.630] It's a recursive zip file. [22:18.850 --> 22:22.450] So, when you open it, what's inside is a folder called r. [22:22.610 --> 22:25.310] And if you open the folder, r.zip is inside of it. [22:25.410 --> 22:27.990] If you open up r.zip, on and on and on. [22:28.190 --> 22:28.870] It's amazing. [22:32.750 --> 22:34.930] I'll go over a few features, but you'll see it. [22:35.470 --> 22:38.250] One of the cool ones that I added later was a feature called spread. [22:38.430 --> 22:41.130] So, if you have a whole bunch of files, it will just randomly pick the file types. [22:41.210 --> 22:42.050] You don't have to define it. [22:42.530 --> 22:43.530] You can have... [22:43.530 --> 22:46.350] Each file could have more than one signatures in it. [22:46.450 --> 22:49.330] Just so, like, if you ran it against virus total, you get a little bit more fidelity. [22:49.990 --> 22:52.670] You could add random padding to make it look a little bit more real. [22:52.970 --> 23:09.030] And then another tool, or another switch you can add to it, is sucker punch, which is actually not random, but it adds, like, a carefully crafted concoction of signatures that will raise the fidelity and virus total by around 30 out of 42 or so. [23:09.390 --> 23:15.010] Sucker punch was actually a name that my friend at work, Ruben, thought would be funny. [23:15.130 --> 23:15.990] So, that's what I use. [23:16.410 --> 23:17.230] Why use it? [23:17.330 --> 23:18.310] Well, the funny stuff. [23:18.530 --> 23:23.910] But also, you can kind of use it as a more powerful EI car, which I wouldn't do it in an actual job environment. [23:24.110 --> 23:25.550] But for personal use, it's fun. [23:25.770 --> 23:28.370] I did a one million hip sneeze, and that was kind of funny. [23:30.150 --> 23:33.530] And, again, for the forensic saturation, like, make them work. [23:37.050 --> 23:44.450] And before I show you the tool, just not related to the explosive steganography, but something interesting I noticed when it's combining virus definitions. [23:45.770 --> 23:49.690] At the end, I wanted to get 42 out of 42 on virus total, but I couldn't quite make it. [23:49.790 --> 23:51.610] So, I was like, well, what happens if I throw the EI car in there? [23:52.010 --> 23:54.750] You know, every virus vendor should pick that up. [23:55.270 --> 23:56.770] ByteHero didn't, but they're kind of different. [23:56.890 --> 23:58.110] They're kind of heuristic only. [23:58.270 --> 23:59.330] But it worked. [24:00.210 --> 24:07.230] But what I noticed is for the ones before that were showing the real Trojans and viruses, EICar seemed to kind of override that. [24:08.130 --> 24:10.270] Which, okay, whatever, I put EICar in front. [24:10.470 --> 24:13.250] What happens if I put EICar in the back of my whole file? [24:14.370 --> 24:19.110] Well, all the vendors still kind of see EICar before they see real Trojans and viruses. [24:20.050 --> 24:20.870] I don't know why. [24:21.230 --> 24:23.670] It's probably not a big deal, but it is still kind of interesting. [24:26.350 --> 24:27.350] So, I'll show you this tool. [24:29.970 --> 24:31.510] Is this too small? [24:31.870 --> 24:33.410] It might be for people back there. [24:33.450 --> 24:33.790] I don't know. [24:48.580 --> 24:49.080] Okay. [24:49.600 --> 24:51.560] I'm running the hip sneeze tool. [24:52.800 --> 24:55.200] Saliva is the switch for how many you want. [24:55.860 --> 24:58.800] So, we're going to do a sneeze of 30 files. [24:59.540 --> 25:02.980] The app name, they're all just going to have a file name of totally legit program. [25:03.940 --> 25:05.420] And we're going to run spread. [25:07.280 --> 25:07.920] There we go. [25:08.960 --> 25:11.200] There is all of our totally legit programs. [25:15.260 --> 25:15.780] And... [25:17.240 --> 25:17.760] Great. [25:18.120 --> 25:20.700] I had the folder for my shared folder on my desktop. [25:21.300 --> 25:22.920] But it got cut off, so... [25:31.320 --> 25:33.400] And I'll go back into the file system here. [25:33.960 --> 25:34.460] Stick demo. [25:35.400 --> 25:35.920] Sneezes. [25:36.860 --> 25:38.180] There's all of our sneezes. [25:38.980 --> 25:39.500] Spoiler. [25:43.620 --> 25:44.640] They're all in. [25:50.960 --> 25:51.900] So, share. [25:52.400 --> 25:52.500] Okay. [25:52.720 --> 25:53.700] So, totally legit program. [25:53.860 --> 25:54.240] One. [25:54.560 --> 25:55.880] It's an executable. [25:56.460 --> 25:57.060] Double click it. [25:57.460 --> 25:57.780] Run. [25:59.060 --> 25:59.700] Calc. [26:01.720 --> 26:03.280] Totally legit program two. [26:03.440 --> 26:04.060] And this is all random. [26:04.320 --> 26:07.200] But that is a VBS script. [26:08.080 --> 26:08.460] Run. [26:10.320 --> 26:10.960] Calc. [26:13.400 --> 26:13.880] Screensaver. [26:14.780 --> 26:15.260] Run. [26:15.500 --> 26:16.480] It just doesn't do anything. [26:17.120 --> 26:18.160] But it does an error. [26:18.340 --> 26:18.800] So, that's cool. [26:20.460 --> 26:20.940] PDF. [26:23.460 --> 26:23.940] Yeah. [26:26.760 --> 26:27.940] And then there's one more. [26:28.020 --> 26:28.160] Yeah. [26:28.260 --> 26:28.680] Zip files. [26:29.560 --> 26:31.460] So, we got r.zip. [26:32.920 --> 26:33.880] r.zip. [26:38.980 --> 26:39.760] And, yeah. [26:40.080 --> 26:41.600] I didn't show the most important part. [26:42.140 --> 26:42.620] ClamScan. [26:48.530 --> 26:49.950] So, scan files, 30. [26:50.510 --> 26:51.750] Infected files, 30. [26:52.490 --> 26:59.850] But, yeah, if you really know what you're doing, or you're a good malware analyst, that's not really current stuff. [26:59.990 --> 27:01.050] It's old history. [27:01.650 --> 27:03.110] But, it's still kind of funny. [27:09.130 --> 27:11.750] So, the other tool, the Stego part, hivsaur. [27:13.690 --> 27:16.790] It does the same thing hivsneeze does, but you can put Stego in it. [27:18.650 --> 27:19.530] So, let's do that. [27:26.740 --> 27:27.930] It's supposed to save me time. [27:29.220 --> 27:30.100] Alright, so hivsaur. [27:30.260 --> 27:35.430] We're going to share needle, which means encrypt, or inject, because we're not going to do encryption this time, just so you can see it. [27:35.960 --> 27:37.160] And, let's see how we do it on time. [27:37.380 --> 27:41.800] I might skip the actual encryption parts, just so you... I don't know. [27:42.460 --> 27:44.600] You guys trust me, right, that it actually encrypts stuff now? [27:45.590 --> 27:47.460] I just don't want to go over on time. [27:48.600 --> 27:50.930] And I want you guys to see where it's putting it or hiding it. [27:51.020 --> 27:53.000] So, we're going to do the plaintext.txt file. [27:53.000 --> 27:56.140] The out file will be monster, and it will be .exe. [27:58.780 --> 27:59.430] Oh, wait. [27:59.860 --> 28:00.720] Let's back out. [28:01.740 --> 28:02.460] Run that again. [28:04.320 --> 28:04.720] Okay. [28:06.600 --> 28:08.960] So, we have monster.exe in there. [28:09.740 --> 28:10.980] And we'll clamscan it. [28:24.550 --> 28:25.230] That's awesome. [28:25.670 --> 28:26.190] Just a second. [28:26.210 --> 28:27.230] Let me delete those zip files. [28:28.330 --> 28:31.970] Awesome side effect of a 256 terabyte zip file. [28:32.490 --> 28:33.910] Virus scans take a while. [28:42.010 --> 28:42.290] Clamscan. [28:46.840 --> 28:47.400] See? [28:47.620 --> 28:48.320] A lot quicker. [28:49.900 --> 28:52.140] So, it was monster.exe. [28:52.740 --> 28:57.220] It's all random, so this time it was trivial-177, whatever that is. [28:57.220 --> 28:59.120] I don't know what I'm doing, so whatever. [29:00.700 --> 29:03.760] I'm actually, yeah, I should say that I'm not a forensics expert. [29:03.940 --> 29:05.500] I'm not even a steganography expert. [29:06.460 --> 29:07.340] I don't know what I'm doing. [29:12.470 --> 29:13.030] All right. [29:13.210 --> 29:13.370] So, [29:16.470 --> 29:19.530] I'll show you what that looks like. [29:20.470 --> 29:22.010] That was an executable. [29:22.830 --> 29:24.950] I'm running .exe editor. [29:25.190 --> 29:27.870] I'm only telling the last 16 lines of it. [29:28.010 --> 29:29.170] It's actually a pretty big file. [29:29.170 --> 29:34.850] But, what I noticed, the executable, the template I used for it, I made it in C++. [29:35.430 --> 29:41.090] And I realized that after a bunch of, if you add a bunch of null at the end of it, you can put arbitrary stuff at the end. [29:41.270 --> 29:41.890] So, that's what I did. [29:42.050 --> 29:43.830] It's actually really unsophisticated. [29:44.490 --> 29:50.810] And just to save time, just imagine that that part at the bottom there is encrypted. [29:53.030 --> 29:54.390] And then I got to extract it. [30:07.700 --> 30:09.520] And I put it into out.txt. [30:10.220 --> 30:11.840] So, secret message with two lines of text. [30:16.020 --> 30:17.500] This next one is my favorite. [30:19.040 --> 30:20.720] Because, I don't know if it's really been done. [30:21.660 --> 30:24.640] I tried to research it afterwards, and I just couldn't find anything. [30:24.820 --> 30:25.960] So, if it's out there, it's hidden. [30:25.960 --> 30:28.940] But, I was abusing Scalpel. [30:29.880 --> 30:33.600] The tool I wrote is called MagicBomb, the non-stigo version of it. [30:34.320 --> 30:36.520] So, I'll talk about Scalpel and how it works a little bit. [30:37.020 --> 30:43.380] Scalpel is something you do when you may not be able to rely on the file system or the metadata to tell you what you're looking at. [30:43.440 --> 30:44.220] All you have is data. [30:44.360 --> 30:48.040] So, you have to kind of look at the headers and footers and kind of signatures of what the file looks like. [30:48.400 --> 30:50.920] The simplest example would be HTML. [30:51.100 --> 30:52.420] I'm sure a lot of people are familiar with that. [30:52.560 --> 30:58.400] If you're just looking through a bunch of raw data and you see the beginning HTML tag and the ending HTML tag, it's probably an HTML file. [30:59.020 --> 31:03.280] So, a file carver will carve out of the middle and save it as a .html. [31:03.580 --> 31:08.220] And that's a really simplistic version of how Scalpel works. [31:08.960 --> 31:11.240] And that's a Scalpel configuration file. [31:12.460 --> 31:17.620] I kind of highlighted the HTML definition for it. [31:17.700 --> 31:20.860] So, in red, you have the HTML and then the end tag for it. [31:20.980 --> 31:29.280] And that 50,000, if I understand right, basically says, if you have more than 50K of data, just cut it off at the end there. [31:29.980 --> 31:35.600] That comes in handy when you have signatures that don't have a footer, like the Macromedia Flash definition up there. [31:35.800 --> 31:37.880] This one says, stop after four megs. [31:38.760 --> 31:41.800] So, the question is, what happens when you get data that looks like that? [31:42.220 --> 31:43.800] You have an HTML file in there. [31:43.900 --> 31:47.640] You also have another header in there for the shockwave. [31:48.340 --> 31:50.620] But you don't have a footer. [31:51.420 --> 31:52.700] What does Scalpel do? [31:52.920 --> 31:55.440] Well, what it does is it will carve out that HTML file. [31:55.720 --> 31:58.580] But it also will carve out that Flash file. [31:59.120 --> 32:02.260] So, you kind of get a false positive in this case. [32:02.480 --> 32:06.360] Because as you can see in this HTML file, we're not really intending to carve out a Flash file. [32:06.480 --> 32:07.340] It's not a Flash file. [32:07.780 --> 32:09.140] But it still will carve it out. [32:09.440 --> 32:11.220] So, what happens when your file looks like that? [32:11.760 --> 32:14.380] It's a file that's only headers and only footers. [32:14.380 --> 32:15.420] There's no actual content. [32:16.320 --> 32:18.040] The answer is you get a lot of false positives. [32:20.560 --> 32:22.200] And it's actually really bad. [32:22.340 --> 32:23.700] It's worse than the archive bomb. [32:25.000 --> 32:33.520] So, the tool, you give it an actual scalpel.com file to tell it what kind of files you want to give headers and footers. [32:34.320 --> 32:36.960] And you tell it how many times you want it to repeat. [32:37.440 --> 32:38.340] And you let it go. [32:38.500 --> 32:41.740] And you can also add random padding to make it look more convincing. [32:41.780 --> 32:43.660] But it does lower the fidelity a little bit. [32:44.100 --> 32:47.680] So, to give some practical examples, say we have a mp3.com file. [32:48.560 --> 32:51.120] And the configuration would look like above there. [32:51.260 --> 32:52.620] It's just the MP3 is the extension. [32:53.260 --> 32:55.680] Don't carve more than 8 megs. [32:56.100 --> 32:58.240] Which is kind of reasonable for an MP3. [32:58.540 --> 33:00.960] And the tag or the header is ID3. [33:01.080 --> 33:05.560] You'll notice that on MP3s, if you look at it in hex header, they almost all start with ID3. [33:06.800 --> 33:09.240] So, running the tool, the command looks like that. [33:10.060 --> 33:11.220] You use magic bomb. [33:11.220 --> 33:17.800] I'm going to do it 10 times and use mp3.conf and put it to out.dd and have it on my hard drive. [33:18.020 --> 33:20.560] So, the point for this is to kind of target it. [33:20.620 --> 33:29.360] Instead of using just a default scuple.conf, we're targeting this MP3 bomb for an investigator that might see a box or a computer that looks like that. [33:30.920 --> 33:32.420] But, so, how it really works. [33:32.960 --> 33:34.900] We got this, we did it 10 times. [33:35.040 --> 33:36.880] And we got this file that's 30 bytes. [33:37.080 --> 33:38.700] Because it's just ID3, ID3, ID3. [33:38.900 --> 33:40.120] 3 times 10, 30 bytes. [33:40.660 --> 33:42.800] Well, it looks at this first ID3. [33:43.060 --> 33:45.500] And it carves out all the rest of it as an MP3. [33:45.640 --> 33:47.180] It's a 30 byte MP3 file. [33:47.460 --> 33:50.420] It comes to the next ID3, carves out all the rest again. [33:50.680 --> 33:52.720] And we got a 27 byte MP3 file. [33:52.720 --> 33:55.620] And on and on and on and on until we hit the last ID3. [33:56.140 --> 34:01.140] So, 30 bytes of a magic bomb is 165 bytes total. [34:02.000 --> 34:03.740] And it gets worse and worse and worse. [34:03.840 --> 34:04.880] It's actually exponential. [34:06.300 --> 34:13.240] So, another funny example as far as targeting goes is you got a scuple conf and you got images and movies. [34:13.680 --> 34:16.060] And, you know, that's what you're targeting it for. [34:16.140 --> 34:17.880] A guy that's going to find your computer looking like that. [34:21.590 --> 34:22.770] So, I'll show you this tool. [34:24.350 --> 34:25.910] For this one, I might actually show you screenshots. [34:25.910 --> 34:27.890] I had to do that because this is a long process. [34:28.050 --> 34:30.290] When you're, you know, filling up the hard drive, it takes a while. [34:33.910 --> 34:35.550] But I'll show you a small scale example. [34:42.400 --> 34:43.700] Again, this is supposed to save me time. [34:43.820 --> 34:44.440] I type out too much. [34:44.600 --> 34:45.240] Same command here. [34:45.980 --> 34:46.360] Ran it. [34:55.890 --> 34:56.210] Dash. [34:58.170 --> 35:00.750] So, we have a 3k file is what that output. [35:01.610 --> 35:03.330] With the standard scuple.conf. [35:05.110 --> 35:07.150] So, let's run scalpel against it. [35:08.830 --> 35:09.990] 10 files of each, right? [35:10.130 --> 35:10.710] That's what you expect. [35:11.130 --> 35:12.130] It's all garbage though. [35:12.210 --> 35:12.510] It's nothing. [35:12.990 --> 35:15.350] And to show you the output folder, [35:19.290 --> 35:21.670] it's 2.3 megs. [35:22.050 --> 35:22.810] It's garbage. [35:23.030 --> 35:23.470] It's trash. [35:23.750 --> 35:25.450] That's a small example. [35:25.650 --> 35:26.290] Just 10 files. [35:26.790 --> 35:28.530] I mean, what if we did a lot more than that? [35:30.310 --> 35:32.170] So, this time I'll do the screenshots. [35:32.490 --> 35:33.450] Just because it's quick. [35:35.250 --> 35:36.630] So, we're gonna do it with 6,000. [35:37.250 --> 35:39.190] Multiplier, 6,000 over there. [35:40.170 --> 35:41.250] Finishes in 10 seconds. [35:41.410 --> 35:41.730] Pretty quick. [35:42.950 --> 35:44.470] Gonna run scalpel against it. [35:44.650 --> 35:45.170] That's the command. [35:47.090 --> 35:47.970] We ran scalpel. [35:48.090 --> 35:49.170] 6,000 files of each. [35:49.470 --> 35:51.810] At the bottom I ran DU on that as well. [35:51.890 --> 35:52.330] On the folder. [35:53.330 --> 35:55.810] And this is a 2 megabyte magic bomb. [35:56.030 --> 35:56.670] 2 megabytes. [35:56.930 --> 35:57.530] The folder? [35:58.550 --> 35:59.350] 175 gigs. [36:00.990 --> 36:02.250] And that's a small sample. [36:02.530 --> 36:04.590] And that's all I can really test on this laptop here. [36:04.990 --> 36:06.810] I mean, it can get much bigger than that. [36:10.680 --> 36:11.900] A little bit far. [36:12.040 --> 36:12.100] Okay. [36:13.200 --> 36:14.000] Magic Bombasaur. [36:14.180 --> 36:15.400] Same concept as all the rest. [36:15.500 --> 36:17.420] It's a prank, but we're gonna stego it too. [36:28.250 --> 36:29.910] So, we'll do 6,000 this time. [36:30.030 --> 36:32.050] Because I'm not actually gonna run scalpel against it. [36:32.050 --> 36:33.130] It takes a long time. [36:33.250 --> 36:34.210] Again, give people work. [36:35.410 --> 36:37.890] And you can give your own custom header or footer. [36:37.950 --> 36:38.970] If you don't, it'll use a default. [36:39.130 --> 36:44.150] But in this case, I used a STE for the header and a GEO for the footer, stego. [36:44.390 --> 36:45.690] Use scalpel.conf. [36:45.850 --> 36:46.770] Goes to output.dd. [36:47.030 --> 36:49.910] And I'm using plaintext.txt again as an input file to stego. [37:01.760 --> 37:02.420] Alright, it's done. [37:07.220 --> 37:07.800] Wasn't lying. [37:07.920 --> 37:08.660] It's about 2 megs. [37:14.700 --> 37:16.820] We're gonna look at a hex output of it. [37:17.040 --> 37:19.020] This time I did just the first 21 lines. [37:19.020 --> 37:20.000] Hex-wise. [37:20.400 --> 37:21.360] It's head, 21. [37:22.400 --> 37:24.180] You'll see it towards the bottom of this one as well. [37:24.400 --> 37:28.760] You'll see the STE in capitals around the fourth to last line. [37:29.260 --> 37:32.620] And then right after it, a secret message with 2 lines of text. [37:32.820 --> 37:33.360] And then go. [37:33.900 --> 37:34.340] Or stego. [37:34.960 --> 37:36.440] And you can encrypt it too. [37:37.840 --> 37:39.440] So, we'll extract it as well. [37:43.160 --> 37:44.700] And you gotta tell it... [37:44.700 --> 37:46.840] If you use a password, obviously you gotta use the same password. [37:46.840 --> 37:49.900] But you also have to tell it what header and footer was used as well. [37:50.180 --> 37:51.900] So, it's 3 lines of context there. [37:52.380 --> 37:53.960] And we're gonna look at out.dd. [37:54.080 --> 37:56.360] And we're gonna put it into decrypted.txt. [38:03.270 --> 38:04.850] Secret message with 2 lines of text. [38:09.910 --> 38:11.530] Alright, I'm almost done here actually. [38:12.630 --> 38:12.850] Cool. [38:15.810 --> 38:17.810] This one, this is not my tool. [38:18.030 --> 38:20.870] But when I came across it, I thought I had to include it. [38:21.290 --> 38:22.510] I went to their site. [38:22.610 --> 38:25.950] And I couldn't really find the real authors or get in contact with them. [38:26.210 --> 38:28.910] But it's a site called Spam Mimic. [38:28.970 --> 38:30.610] And it's steganography. [38:31.050 --> 38:33.250] But it's still another one of those things that you avoid. [38:33.390 --> 38:35.230] So, it's something you can email to somebody. [38:35.750 --> 38:37.770] And the message looks like spam. [38:38.890 --> 38:41.870] Let me get Internet connection real quick here. [38:57.000 --> 38:58.040] Sure, whatever. [39:02.840 --> 39:03.900] Or not, whatever. [39:05.300 --> 39:08.120] If I copy and paste this, and you guys can do it later too. [39:08.340 --> 39:09.400] When this is all uploaded. [39:09.900 --> 39:14.940] But you copy and paste this into the SpamMimic.com and click decode and paste it in. [39:15.140 --> 39:16.800] And it'll decode to HOPE Number Nine. [39:17.180 --> 39:21.540] And the cool thing is that HOPE Number Nine isn't anywhere in the message. [39:21.540 --> 39:22.560] It's just kind of cool. [39:25.320 --> 39:26.180] Wait, do I have... [39:26.740 --> 39:27.060] No, I... [39:27.060 --> 39:27.660] Okay, let me show you. [39:28.160 --> 39:28.720] Let's do it now. [39:39.780 --> 39:40.180] Okay. [39:42.180 --> 39:42.580] Decode. [39:43.180 --> 39:43.740] Paste it. [39:47.230 --> 39:47.990] HOPE Number 9. [39:54.670 --> 39:55.210] All right. [39:55.450 --> 39:57.390] So, this is pretty much the... [39:57.390 --> 39:58.030] Almost the end here. [39:58.310 --> 40:02.550] I'm just gonna say that the most fun thing to do is to combine all three tools. [40:02.870 --> 40:05.070] To chain them one after another inside of each other. [40:05.250 --> 40:07.190] So, say you're an investigator. [40:07.190 --> 40:08.490] And you know about my tools. [40:09.250 --> 40:11.310] So, you have this whole file system. [40:11.490 --> 40:14.170] It's like a graphical representation of a file system. [40:14.510 --> 40:16.130] And you're carving files. [40:16.190 --> 40:16.810] That's your first step. [40:16.870 --> 40:17.490] You carve files. [40:18.050 --> 40:19.710] And you get a magic bomb. [40:19.910 --> 40:22.810] And the size after scalpel is 530 terabytes. [40:23.910 --> 40:26.150] And really, that magic bomb isn't that big. [40:26.710 --> 40:27.850] It's in the megabytes. [40:28.090 --> 40:30.650] But after you use scalpel against it, it's 530 terabytes. [40:31.730 --> 40:37.050] So, if you know my tools, you use magic bombasor to extract whatever is in there. [40:37.350 --> 40:39.990] And what you get is lol.exe. [40:40.110 --> 40:41.550] And that's 19 megabytes. [40:41.710 --> 40:42.730] It's picked up as a virus. [40:44.470 --> 40:45.430] Lol.exe. [40:45.570 --> 40:46.530] Not actually a virus. [40:47.850 --> 40:51.270] It looks like a virus as far as the virus signature goes, but it's not a virus. [40:51.930 --> 40:57.170] So, again, if you know my tool, or my toolset, what you want to use is hivasor against that. [40:57.450 --> 41:00.270] And if you do, you get a file called pictures.zip. [41:00.470 --> 41:01.350] It's 9 megabytes. [41:01.490 --> 41:04.590] If you extract all, it's 256 terabytes of JPEGs. [41:04.910 --> 41:06.850] And there's nothing meaningful in any of them. [41:07.770 --> 41:12.190] Because, as you saw with the file structure, it's in the file system, not the files in it. [41:13.430 --> 41:14.310] It's pictures.zip. [41:14.510 --> 41:15.290] It's an archive bomb. [41:16.190 --> 41:18.310] If you know the tools, extract it with zip mouth. [41:18.310 --> 41:21.230] And it's a text file that says, the princess is in another castle. [41:22.710 --> 41:25.030] And that's symbolic of making them work. [41:25.210 --> 41:26.030] That's meaningless. [41:26.330 --> 41:27.730] It's saying, look somewhere else. [41:27.990 --> 41:29.030] You went through all that work. [41:29.230 --> 41:30.350] You found something. [41:30.670 --> 41:31.090] No. [41:33.790 --> 41:36.530] That's the command to generate that. [41:36.990 --> 41:38.030] So, I will. [41:42.790 --> 41:43.590] There's a command. [41:44.050 --> 41:49.350] I echo the princess is in another castle to plaintext.2, or plaintext2.txt. [41:49.350 --> 41:52.030] And you'll just see I run it through a chain all the way through. [41:52.270 --> 41:52.850] So, I'll run it. [42:07.990 --> 42:08.590] All right. [42:09.850 --> 42:11.650] So, it's out.dd that it output. [42:14.550 --> 42:15.210] Let's see. [42:15.470 --> 42:16.930] For 256 terabytes. [42:18.050 --> 42:19.270] How big was out.dd? [42:22.110 --> 42:23.330] Looks like 11 megs. [42:24.090 --> 42:24.850] Not much. [42:28.330 --> 42:32.450] So, let me, yeah, as opposed to running a compound command here. [42:32.690 --> 42:35.010] I'm gonna just start deleting some of these files one by one. [42:37.110 --> 42:38.350] Plaintext2, we don't want that. [42:38.650 --> 42:40.670] We don't want, yeah, we'll keep plaintext, whatever. [42:41.110 --> 42:41.890] Now, we'll delete that too. [42:42.090 --> 42:44.550] Here's pictures, pictured, out. [42:45.290 --> 42:46.550] We need to keep out.dd. [42:46.650 --> 42:47.370] That was our payload. [42:47.530 --> 42:49.750] Monster, lol, decrypted. [42:51.590 --> 42:52.050] Okay. [42:55.920 --> 43:01.820] Just to show, we're starting with out.dd, or out.dd, and we'll get our secret message out of that with our other command. [43:05.180 --> 43:10.580] So, that's the command to extract all of that, another compound command to extract all of that out of out.dd. [43:10.920 --> 43:11.560] We'll run it. [43:14.100 --> 43:17.260] We now have decrypted2.txt. [43:19.860 --> 43:20.560] And there it is. [43:31.180 --> 43:32.580] So, this is where I'll take questions. [43:33.360 --> 43:35.260] I don't know what kind of questions you've had for this. [43:36.360 --> 43:37.800] But, thanks, credits, shouts. [43:38.660 --> 43:41.960] My friend, MedicineStorm, he was actually supposed to present with me, but things came up. [43:42.100 --> 43:45.300] But he had the same mindset as me, so we had some good conversations. [43:45.720 --> 43:46.740] Knack for the crayon art. [43:47.860 --> 43:48.960] Phoenix2600, that's my crew. [43:49.900 --> 43:50.920] They're great people. [43:52.000 --> 43:52.660] 10 minutes, okay. [43:53.040 --> 43:55.460] HeatSync Labs for letting me use their space. [43:55.460 --> 43:57.880] I mostly code there and sometimes print weird 3D stuff. [43:59.180 --> 44:01.540] PSSH, it's the Phoenix Secret Society of Hackers. [44:01.660 --> 44:02.480] It's kind of based on AHA. [44:03.600 --> 44:08.200] Just for all the feedback I gave, I kind of went over some ideas with them on it and they gave me some good feedback. [44:08.800 --> 44:10.480] And Press.js, it's not PowerPoint. [44:10.660 --> 44:11.280] It's what I used. [44:12.440 --> 44:15.260] And then OpenClipArt for stealing some of their clip art. [44:19.730 --> 44:20.980] It's not really a question. [44:21.120 --> 44:21.820] It's more of an anecdote. [44:21.820 --> 44:30.680] I've seen an unintentional situation, very similar to some of these intentional situations that I thought you might find abusing. [44:31.000 --> 44:31.960] It was... [44:31.960 --> 44:36.280] I was working with a file sharing service that did a lot of transcoding on the back end. [44:36.280 --> 44:46.480] And someone uploaded a 15,000 by 12,000 pixel one-bit architectural drawing that was... [44:46.480 --> 44:47.500] that compressed down. [44:47.660 --> 44:50.740] It was like LZW GIF file. [44:50.840 --> 44:52.280] And it compressed down to like 200K. [44:53.160 --> 44:59.620] And our back-end transcoders were running ImageMagic, which in order to transcode it, decompressed it to RAM. [44:59.620 --> 45:02.940] There wasn't enough RAM for it to decompress, so it started swapping. [45:03.860 --> 45:05.420] And then that crashed. [45:05.620 --> 45:06.380] And then it was like... [45:06.380 --> 45:08.140] And then the transcoders were like, oh, that failed. [45:08.240 --> 45:08.720] Try it again. [45:08.940 --> 45:13.600] So they got into this loop where a 200K file took down our entire transcoding farm. [45:13.780 --> 45:14.640] And it was sweet. [45:16.040 --> 45:18.340] Yeah, it's funny how unintended things can happen with that. [45:18.420 --> 45:19.280] Actually, I like that. [45:19.320 --> 45:22.220] Because if I had more time, I would have done something like that as well. [45:22.340 --> 45:24.720] I was thinking about the Image Exploders. [45:24.720 --> 45:25.940] I wasn't going to do it as a separate tool. [45:26.060 --> 45:29.280] But I was actually going to use that for the virus one. [45:29.300 --> 45:33.220] Because it actually can do real files like the XEs and PDFs and all that. [45:33.300 --> 45:37.540] I wanted to have its prototype for the image, which I didn't do yet. [45:37.620 --> 45:39.720] But for the image to be something like that. [45:39.820 --> 45:41.760] Like a purple picture. [45:42.060 --> 45:43.660] You know, like purple.com kind of thing. [45:44.800 --> 45:45.160] But... [45:46.020 --> 45:46.740] Yeah, so... [45:48.640 --> 45:50.040] I thought that would have been funny too. [45:53.050 --> 45:53.510] Is that all? [45:55.770 --> 45:56.490] I'll go back. [46:01.200 --> 46:01.660] And... [46:03.040 --> 46:04.730] Should be uploaded in four minutes. [46:05.280 --> 46:07.230] If I know my time zones right and all that. [46:07.800 --> 46:08.400] Is it? [46:08.920 --> 46:09.380] Cool. [46:10.700 --> 46:11.300] All right. [46:11.900 --> 46:12.760] Any other questions? [46:15.640 --> 46:16.100] Okay. [46:16.360 --> 46:17.080] I'll start shutting down.