Hide a photo inside another photo
avestura.dev
avestura.dev
Example: you have duck.jpg (21500 bytes) and you want to hide flower.jpg (37733 bytes). Do this to create a larger file (59233 bytes):
cat duck.jpeg flower.jpeg > bigger-duck-file.jpg
Anyone looking at bigger-duck-file.jpg will see the duck. Every image viewing program I tried displays the duck and none of them complain about the extra bytes (the hidden image) at the end of the file.The recipient can extract the hidden file as follows:
tail -c 37733 bigger-duck-file.jpg > flower.jpg
You would have to tell the recipient the size of the hidden file by some other means. But there might be a simple command-line way to determine where the image data for duck.jpg really ends in the bigger file, so maybe you wouldn't need that step.So, if you just append a ZIP file to another file, it will screw up all the internal pointers in the ZIP file. If you overlay a file on the beginning of the ZIP, most of it should be recoverable, though.
Another clever hack is that you can put a batch file in the beginning of the ZIP with the compression level set to "none", rename it to .CMD or .BAT, and run it like a batch file. If said batch file locates and unzips itself, you've got a self-extracting archive.
Now, it can break if your "other" file happens to include the magic bytes. But that's rare enough that you only have to be aware that it can happen.
A 4-byte sequence has 2^32 possible values. For the file not to contain the zip magic, all N-3 positions would have to have one of the 2^32-1 non-zip magic values. The probability that it doesn't contain a zip magic is then
P(nonzip) = ((2^32-1)/(2^32)) ^ (N-3)
And the probability that it does have a zip magic is P(zip) = 1-P(nonzip).
A 1 gigabyte file has about a 20% chance to contain a zip header. A 10 gigabyte file has about a 90% chance.
(Maybe?)
A robust zip decoder can beat those odds.
It can bail on a nominal start position by considering a bit more than the local file header signature magic word.
The next two bytes is a minimum version needed to extract and its legal values are sparse. A bit further comes 2 bytes giving the compression method which also has sparse values. I'd guess sparse values (small integers) are more likely to be found in a "random" non-zip stream but would still reduce the collision probability.
Then there are CRCs. These can greatly reduce the collision probability at the cost of the decoder doing speculative work which gets thrown away if a CRC fails to replicate.
$ file some.*
some.jpg: JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 64x736, components 1
some.zip: Zip archive data, at least v1.0 to extract
$ cat some.* > new.jpg
$ file new.jpg
new.jpg: JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 64x736, components 1
$ unzip -l new.jpg
Archive: new.jpg
warning [new.jpg]: 1557 extra bytes at beginning or within zipfile
(attempting to process anyway)
Length Date Time Name
--------- ---------- ----- ----
0 2022-04-28 21:53 stuff/
5 2022-04-28 21:53 stuff/a
5 2022-04-28 21:53 stuff/c
5 2022-04-28 21:53 stuff/b
--------- -------
15 4 files
$However Gmail now rebuilds images to protect against malicious code and it completely strips the appended files from the image.
Edit: he told me it was because his boss had journalling turned on and saw every email sent and received in the company and he thought it was funny to bypass the boss for personal stuff.
I’ve done something similar in the past and embedded Merkle tree nodes in an image to allow partial integrity validation. It was a fun little project:
I've always wondered if there was some way that hidden information inside videos could be designed to survive the re-encoding that youtube does when you upload a video.
Has anyone investigated this?
Where is the link? Well, I don't give 100%, I like to only point people in the right direction, rest is left as an exercise for the reader.
So combined with Apple's CSAM scanner, you can put CSAM inside a cat photo... And then anonymously leak the cat photo and tool to show it's CSAM. And then the CSAM scanner will flag the hash and alert the police of the user.
And the target victim would never know.
But nothing prevents us from putting 0s in the Quantization table. And any pixel put in those values wouldn't contributed to the rasterized image. So we can cut off some of the high frequency bins entirely and then store whatever in them.
The main pitfall is that it doesn't work very well if the output is saved as a JPEG because of the compression.
I think OP's idea of encoding all of the bits of the hidden image, by using a cover image with more pixels, is a good improvement: you get no loss of quality in the hidden image, and you vastly reduce the loss of quality in the cover image.
No? Is there any use for this besides people sharing Child Sexual Abuse imagery without being detected?
That's like inventing a "remote roadside detonation device" and claiming it will only be used for parades to activate confetti payloads. It's naive.
You could do something like Eurion and hide a pattern that only copiers can identify. Or do the same as color printers and encode hardware and user information as a pattern.
DOOM 2016 hid satanic images in its sound files instead of other images, of course that was only an easter egg and not really useful outside of confirming that computer games are evil.
Hiding one thing inside another doesn't necessarily require secrecy as part of the intent.
Besides complaining about the potential use for child pornography is bizarre. If someone wanted to secretly send child porn to someone else, they could just encrypt it. It would be far more effective than this image packing method.
You're making a case against steganography?
Or without leaving the country you might want to hide pictures of animal abuse if you took them without permission from the owner, in some places documenting animal abuse is even more illegal than committing it. Look at all those funny cat pictures, no cows rotting in their own shit to see officer.
Or does this technique rely on having access to the original digital image, and too much information is lost over the analog gap?
Bokode: Imperceptible Visual Tags for Camera Based Interaction from a Distance
https://www.researchgate.net/publication/215457339_Bokode_Im...
This is mildly related: [PDF] Surmounting the Effects of Lossy Compression on Steganography
https://csrc.nist.gov/csrc/media/publications/conference-pap...
Btw this is fascinating!