4.9 • 696 Ratings
🗓️ 23 March 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, March 23rd, 2023 edition of the Sansonet Storms Center's Stormcast. |
0:09.1 | My name is Johannes Ulrich and today I'm recording from Augusta, Georgia. |
0:15.5 | Still a lot of questions about, well, cropping tools that don't crop images, right? |
0:21.2 | Or at least leave some remainder of the original image behind. |
0:27.0 | We had last week this issue with the Android sniping tool. |
0:32.1 | And, well, yesterday I talked about the same problem with Windows 11. |
0:37.3 | DDA now took a little bit of closer look at this problem and how to identify affected images. |
0:44.3 | First of all, the Windows 10 Snipping tool is not an issue here because it can't open existing files, |
0:51.3 | and this problem only shows up if you are reducing or cropping existing files. |
0:57.1 | And the DDA's PNG dump tool always was able to actually identify data after the I-end chunk, |
1:05.6 | which usually marks the end of a PNG image. |
1:10.1 | This technique, aside from all these cropping issues, was useful because sometimes |
1:16.2 | miscreants are adding data like binaries and such at the end of images just sort of to |
1:23.8 | obfuscate their presence. |
1:26.3 | So that's why PNGD dump, I believe, originally had this feature. |
1:30.8 | Now, Did he did add a new option to this feature, dash F or find that will scan any file that you give it |
1:40.7 | and then basically report on known PNG chunks and also well on unexpected data. |
1:48.7 | The nice thing about this particular option is that now you can actually just send a bunch of |
1:55.2 | images to the tool and then basically have it report on what particular chunks it finds and if there was any |
2:02.9 | uninspected data. So this should make it relatively easy to scan larger numbers of files for any |
2:10.8 | problems. Probably not a bad idea to sort of look at some of the PNGs that you have sitting |
2:15.5 | around. And given that we had this in two different sniffing tools already, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.