[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

How do I figure out what's imbedded in a file?

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 16
Thread images: 2

File: 3495.gif (1003KB, 245x160px) Image search: [Google]
3495.gif
1003KB, 245x160px
I have a version of this image with something embedded in it. How do I get it out or whatever?
>>
>>59749498
If it's a simple lsb scheme,xor the stego image with the empty image to find the altered bytes,take the lsb's from the altered bytes and start analyzing.

If it's a more complex scheme,like the one used by openpuff,you're fucked.
>>
I fucking love that movie, do you remember what program you used to write the information in the first place?
>>
>>59749823
It's that swedish vampire movie where the die at pool or smth right? I think I saw it when a swedistan pleb can to get some freedom. Wasn't bad.
>>
>>59749559
sorry I don't know these technical terms, what am I supposed to do?

>>59749823
idk how it has something embedded
>>
ok
>>
>>59749498
Open it with winrar
>>
>>59751676
If the info is hidden in the least significant bit, just xor the original image and the image with the hidden message and analyze the result. If it is more complicated than that then you are fucked
>>
>>59749498
If you have one with it and one without just get the difference between the two using rsync
>>
>>59749498
three choices:

1. its just a file copied in windows to be an image and probably a zip with the same name. try renaming the image.jpg or whatever to image.zip or other possible file extension types.

2. He used a standard steganography or image hiding tool. google those keywords and try everything you find (keep an original of the image, always try on new copies)

3. He used something custom. you're fucked
>>
>>59749498
Post it?
>>
>>59757869
I can try

>>59758152
like this? http://i.imgur.com/un3Lhdm.gif
>>
>>59749498
$ file 3495.gif 
3495.gif: GIF image data, version 89a, 245 x 160
$


I dunno.
>>
use foremost on it
>>
>>59749498
If it was embedded with Veracrypt you'll need the password(s). The same if it was embedded with that program Eliot Alderson used in Mr. Robot to hide his hacks as music files.
>>
>>59749498
If you use Windows photo viewer or something like that to crop the image Windows saves the data inside of the picture. Just open the pic in paint or something similar and export it under a different name
Thread posts: 16
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.