Text Steganography

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ฐพ์•„๋ณผ ํ•ญ๋ชฉ:

  • Unicode homoglyphs
  • Zero-width characters
  • Whitespace patterns (spaces vs tabs)

์‹ค์šฉ์  ์ ˆ์ฐจ

ํ‰๋ฌธ(plain text)์ด ์˜ˆ๊ธฐ์น˜ ์•Š๊ฒŒ ๋™์ž‘ํ•˜๋ฉด ์ฝ”๋“œํฌ์ธํŠธ๋ฅผ ๊ฒ€์‚ฌํ•˜๊ณ  ์‹ ์ค‘ํžˆ ์ •๊ทœํ™”ํ•˜์„ธ์š”(์ฆ๊ฑฐ๋ฅผ ํ›ผ์†ํ•˜์ง€ ๋งˆ์„ธ์š”).

๊ธฐ๋ฒ•

Text stego๋Š” ๋™์ผํ•˜๊ฒŒ(๋˜๋Š” ๋ณด์ด์ง€ ์•Š๊ฒŒ) ๋ Œ๋”๋ง๋˜๋Š” ๋ฌธ์ž์— ์ž์ฃผ ์˜์กดํ•ฉ๋‹ˆ๋‹ค:

  • Homoglyphs: ์„œ๋กœ ๊ฐ™์•„ ๋ณด์ด๋Š” ๋‹ค๋ฅธ Unicode codepoints (Latin a vs Cyrillic ะฐ)
  • Zero-width characters: joiners, non-joiners, zero-width spaces
  • Whitespace encodings: spaces vs tabs, trailing spaces, line-length patterns

์ถ”๊ฐ€๋กœ ์‹ ํ˜ธ๊ฐ€ ๋†’์€ ์‚ฌ๋ก€:

  • Bidirectional override/control characters (ํ…์ŠคํŠธ๋ฅผ ์‹œ๊ฐ์ ์œผ๋กœ ์žฌ์ •๋ ฌํ•  ์ˆ˜ ์žˆ์Œ)
  • Variation selectors and combining characters used as a covert channel

๋””์ฝ”๋”ฉ ๋„๊ตฌ

  • Unicode homoglyph/zero-width playground: https://www.irongeek.com/i.php?page=security/unicode-steganography-homoglyph-encoder

์ฝ”๋“œํฌ์ธํŠธ ๊ฒ€์‚ฌ

python3 - <<'PY'
import sys
s=sys.stdin.read()
for i,ch in enumerate(s):
if ord(ch) > 127 or ch.isspace():
print(i, hex(ord(ch)), repr(ch))
PY

CSS unicode-range ์ฑ„๋„

@font-face ๊ทœ์น™์€ unicode-range: U+.. ํ•ญ๋ชฉ์— ๋ฐ”์ดํŠธ๋ฅผ ์ธ์ฝ”๋”ฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฝ”๋“œํฌ์ธํŠธ๋ฅผ ์ถ”์ถœํ•˜์—ฌ 16์ง„์ˆ˜๋ฅผ ์ด์–ด๋ถ™์ด๊ณ  ๋””์ฝ”๋“œํ•˜์„ธ์š”:

grep -o "U+[0-9A-Fa-f]\+" styles.css | tr -d 'U+\n' | xxd -r -p

ranges์— ์„ ์–ธ๋‹น ์—ฌ๋Ÿฌ bytes๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฉด, ๋จผ์ € ์‰ผํ‘œ๋กœ ๋ถ„๋ฆฌํ•˜๊ณ  ์ •๊ทœํ™”ํ•˜์„ธ์š” (tr ',+' '\n'). ํฌ๋งท์ด ์ผ๊ด€๋˜์ง€ ์•Š์œผ๋ฉด bytes๋ฅผ ํŒŒ์‹ฑํ•˜๊ณ  ์ถœ๋ ฅํ•˜๋Š” ์ž‘์—…์€ Python์œผ๋กœ ์‰ฝ๊ฒŒ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฐธ์กฐ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ