Steganography In the modern Attacksciber.sejalivre.org/steganography.pdf · WTF is Steganography?...

Post on 23-Sep-2020

51 views 2 download

Transcript of Steganography In the modern Attacksciber.sejalivre.org/steganography.pdf · WTF is Steganography?...

SteganographyIn the modern

Attacks

▪Professor e Coordenador FIAP

▪Pentester | Cyber Security Specialist

▪Guerra Cibernética (Exército)

▪C|EH, DCPT, LPIC-2, CCNA Sec, CASP, ISO 27001

▪WTF is Steganography?

▪Types & Evolution

▪Divide to Conquer

▪Stego Attack Techniques

▪Conclusion

A esteganografia é a prática de enviar dados em um formato oculto, para que o próprio fato de enviá-los

seja disfarçado. A palavra esteganografia é uma combinação das palavras gregas στεγανός (steganos), que significa “coberto, oculto ou protegido” e γράφειν

(graphein) que significa “escrita”.

WTF is Steganography?

Types of Steganography

WTF is Steganography?

Types of Steganography

link do vídeo: https://bit.ly/33GBCIC

Steganography Implementations

Steganography Implementations

Evolution

▪Military

▪Spyonage

▪Crime

▪Malwares

▪Data Leak

▪Fun (CTF, Academic...)

Evolution

Divide to Conquer

▪Payload

▪Carrier

▪Stego System

▪Channel

▪Key or Not

XSS Stego

XSS Stego

Video

Data Exfiltration

Data Exfiltration

Data Exfiltration

Video

Image based Malware

Image based Malware

Video

Polymorphic File

Polymorphic File

Video

E-mail: profvinicius.vieira@fiap.com.br

Telegram: @V1n1v131r4

Wiki: vinicius.sejalivre.org

https://about.me/viniciusvieira

PoC how-to: https://bit.ly/2R5YkHD