
Ein Proof-of-Concept, das Cache Smuggling + Exif-Daten nutzt, um passiv ein Second-Stage-Payload herunterzuladen.
Eine Proof-of-Concept-Weiterentwicklung von Cache Smuggling. Dieser Angriff verbirgt eine ausführbare Nutzlast in den Exif-Daten eines JPGs. Dadurch kann das Zwischenspeichern von Bildern (z. B. in einem Webbrowser) genutzt werden, um die Nutzlast passiv herunterzuladen.
Folglich muss der Beispiel-Loader (chrome_poc.ps1) keine Internetanfragen stellen, um die zweite Stufe der Nutzlast abzurufen.
Stattdessen extrahiert er sie einfach aus dem Cache des Chrome-Browsers.
Für vollständige Details siehe: https://malwaretech.com/2025/10/exif-smuggling
python3 build_clickfix_cmd.py --input-file chrome_poc.ps1 --output-file encoded_command.txt --fake-path "C:\test\doc.txt"
python3 exif_smuggling.py --input-file image.jpg --output-file payload.jpg --payload hello_world.dll
www/index.html