Get a Pentest and security assessment of your IT network.

News

New iFrame Injections Leverage PNG Image Metadata

Iframe injection is a new way to embed malicious code from another site into your own. Attackers use the iframe tag to embed content in a PNG image. They place the payload out of view via the elm.style.position.left and.top elements, positioning the image at -1000px.position. The payload is embedded in the meta of the image, and just like that we have a new distribution mechanism. The attacker obfuscated the payload inside a PNG file. This is unique in the level of level of effort being taken to obfuscate the payload.”]

Source: https://blog.sucuri.net/2014/02/new-iframe-injections-leverage-png-image-metadata.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

RasGas, The Second Victim!

News

Technical analysis of the Locker virus on mobile phones