Stego

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ด ์„น์…˜์€ ํŒŒ์ผ(์ด๋ฏธ์ง€/์˜ค๋””์˜ค/๋น„๋””์˜ค/๋ฌธ์„œ/์•„์นด์ด๋ธŒ)๊ณผ ํ…์ŠคํŠธ ๊ธฐ๋ฐ˜ steganography์—์„œ ์ˆจ๊ฒจ์ง„ ๋ฐ์ดํ„ฐ๋ฅผ ๋ฐœ๊ฒฌํ•˜๊ณ  ์ถ”์ถœํ•˜๋Š” ๊ฒƒ์— ์ค‘์ ์„ ๋‘ก๋‹ˆ๋‹ค.

์•”ํ˜ธํ•™ ๊ณต๊ฒฉ์„ ๋ณด๋Ÿฌ ์™”๋‹ค๋ฉด Crypto ์„น์…˜์œผ๋กœ ๊ฐ€์„ธ์š”.

์ง„์ž…์ 

steganography๋ฅผ ํฌ๋ Œ์‹ ๋ฌธ์ œ๋กœ ์ ‘๊ทผํ•˜์„ธ์š”: ์‹ค์ œ ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์‹๋ณ„ํ•˜๊ณ , ์ฃผ์š” ์‹ ํ˜ธ ์œ„์น˜(๋ฉ”ํƒ€๋ฐ์ดํ„ฐ, ์ถ”๊ฐ€๋œ ๋ฐ์ดํ„ฐ, ํฌํ•จ๋œ ํŒŒ์ผ)๋ฅผ ์—ด๊ฑฐํ•œ ๋‹ค์Œ์—์•ผ ์ฝ˜ํ…์ธ  ์ˆ˜์ค€์˜ ์ถ”์ถœ ๊ธฐ๋ฒ•์„ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค.

์›Œํฌํ”Œ๋กœ์šฐ ๋ฐ ๋ถ„๋ฅ˜

์ปจํ…Œ์ด๋„ˆ ์‹๋ณ„, ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ/๋ฌธ์ž์—ด ๊ฒ€์‚ฌ, carving, ํฌ๋งท๋ณ„ ๋ถ„๊ธฐ ๋“ฑ์„ ์šฐ์„ ์‹œํ•˜๋Š” ๊ตฌ์กฐํ™”๋œ ์›Œํฌํ”Œ๋กœ์šฐ์ž…๋‹ˆ๋‹ค. Stego Workflow

์ด๋ฏธ์ง€

๋Œ€๋ถ€๋ถ„์˜ CTF stego๊ฐ€ ์ฃผ๋กœ ๋“ฑ์žฅํ•˜๋Š” ๋ถ„์•ผ: LSB/bit-planes (PNG/BMP), chunk/file-format weirdness, JPEG tooling, ๋ฐ ๋‹ค์ค‘ ํ”„๋ ˆ์ž„ GIF ํŠธ๋ฆญ. Images

์˜ค๋””์˜ค

Spectrogram ๋ฉ”์‹œ์ง€, ์ƒ˜ํ”Œ LSB ์ž„๋ฒ ๋”ฉ, ๋ฐ ์ „ํ™” ํ‚คํŒจ๋“œ ํ†ค(DTMF)์ด ๋ฐ˜๋ณต๋˜๋Š” ํŒจํ„ด์ž…๋‹ˆ๋‹ค. Audio

ํ…์ŠคํŠธ

ํ…์ŠคํŠธ๊ฐ€ ์ •์ƒ์ ์œผ๋กœ ๋ Œ๋”๋ง๋˜์ง€๋งŒ ์˜ˆ์ƒ์น˜ ๋ชปํ•˜๊ฒŒ ๋™์ž‘ํ•œ๋‹ค๋ฉด, Unicode ๋™ํ˜•๋ฌธ์ž, ์ œ๋กœํญ ๋ฌธ์ž, ๋˜๋Š” ๊ณต๋ฐฑ ๊ธฐ๋ฐ˜ ์ธ์ฝ”๋”ฉ์„ ๊ณ ๋ คํ•˜์„ธ์š”. Text Stego

๋ฌธ์„œ

PDFs ๋ฐ Office ํŒŒ์ผ์€ ์šฐ์„  ์ปจํ…Œ์ด๋„ˆ์ž…๋‹ˆ๋‹ค; ๊ณต๊ฒฉ์€ ๋ณดํ†ต ํฌํ•จ๋œ ํŒŒ์ผ/์ŠคํŠธ๋ฆผ, ๊ฐ์ฒด/๊ด€๊ณ„ ๊ทธ๋ž˜ํ”„, ๊ทธ๋ฆฌ๊ณ  ZIP ์ถ”์ถœ์„ ์ค‘์‹ฌ์œผ๋กœ ์ „๊ฐœ๋ฉ๋‹ˆ๋‹ค. Documents

Malware ๋ฐ delivery-style steganography

Payload ์ „๋‹ฌ์€ ํ”ฝ์…€ ์ˆ˜์ค€์˜ ์€๋‹‰๋ณด๋‹ค, ๋งˆ์ปค๋กœ ๊ตฌ๋ถ„๋œ ํ…์ŠคํŠธ payload๋ฅผ ๋‹ด์€ ์œ ํšจํ•ด ๋ณด์ด๋Š” ํŒŒ์ผ(์˜ˆ: GIF/PNG)์„ ์ž์ฃผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. Malware & Network Stego

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ