A file that's both an acceptable HTML page and a JPEG (view source on it)
lcamtuf.coredump.cx
lcamtuf.coredump.cx
A PNG that's interpreted as HTML and loads itself as compressed JavaScript!
Edit: It also won a much-deserved first place in the DemoJS 1k compo.
EDIT: Oh, okay. It's not a valid PNG. That would have been all sorts of incredible. Still great, though.
By the way, the for loop seems to be irrelevant to the invocation, (1,eval) just returns eval. (1,console.log)("hi") looks like it should work, except it raises an error. (1,2)+3 returns 5, however, and (1,console.log) returns the log function.
http://cs.unm.edu/~eschulte/data/webpage.html
download webpage.html and it should run on any 64-bit linux machine as an executable printing out the same text shown on the web page. Here's the C file used to compile the original executable, nothing exciting...
Step 1: upload the "image" to the site. Let the site do whatever it does to ensure it has received a valid image. Nine validators out of ten will happily accept the file; the case that is likeliest to shoot you down is if the site modifies the image by cropping, resizing, or watermarking it.
Step 2: point your victim back to the uploaded "image" as though it's actually a page, and presto!, it's a page -- a page with malicious javascript in it.
Step 3: profit!
If you are inspecting binary data for validity, and not checking the parameter (filename) that affects how Apache serves your file, you are doing something wrong.
Also that's completely different than what you originally said.
Here is a link to a variation of the "image" file which is the subject of this post: https://dl.dropbox.com/u/131649/squirrel.html
I have embedded harmless (-- honest! --) script in the file to demonstrate that your browser will execute the script in the context of the site where the file is hosted.
So, click the link. (Again I promise that no harm will come to your computer.) Now imagine that dl.dropbox.com is, instead, some hypothetical site where users are expected to upload images, but not HTML documents containing arbitrary script, and the security implications should be fairly obvious.
The source is just the image, and you can embed the image, but there's an ad under the image. Also, right click -> view image or copy image location point to the same URL.
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Embedding the URL as a <img> element in a HTML file: Accept:*/*If your browser requests a html page, it will respond with a html page... and vice versa.
I think a similar exploit was used recently with .svg images - they can contain javascript (being XML) which will be executed by the browser. Not sure about the details however.
However, the JavaScript shouldn't execute if the image is embedded via <img>.
body { visibility: hidden; } .n { visibility: visible; position: absolute; padding: 0 1ex 0 1ex; margin: 0; top: 0; left: 0; }
the html portion comments the remaining part of the data with <!--
Apparently, the jpeg format allows this.
Neat hack.
What is surprising is that web browsers just ignore the 24 bytes of binary data between the start of the file and the start of the HTML.
Edit: Misread your comment...the bytes at the beginning of the file are hidden by CSS (as pointed out by others).
The browser actually picks that "text" up and shows it on page. It's just the html content itself contains some css rule to make that text not visible.
The first part probably isn't too hard, since most web browsers go to great lengths to render non-standard html in a sensible way, I'm not too sure about the second part. I'm guessing the jpeg spec has some variable length space in some kind of file header that the html for the page can be put in to.
I read something similar a while back (I think it was called a Jafar attack) where a clever person worked out how to create a file that was both a valid .gif image and .jar java executable.
Would have been smarter to put a bitcoin address :)
ps. you have two uncommented slashes at the top of your <body> tag
JS and PHP is also possible http://tantek.pbworks.com/w/page/19402872/CassisProject
JS and HTML http://project.mahemoff.com/josh/ (also demonstrated by Tantek Çelik earlier on in a project that eentually led him to Cassis.)
My problem is that i want to publish a series of JPEG images as a Kindle book, but i can't, since the reader slices some of my images and puts padding around them. I would prefer that the images render like the cover page, in full screen, but this is impossible to achieve despite saving the images in 600 * 800 like the cover page.
How can i use this great wisdom to create an .epub file that then becomes a Kindle book.
PS; The scans are a business book that is made up entirely of mindmaps, which are like spatial roadmaps on paper. The book has been written to teach newbies in business the most important things and all the trade-offs involved in this important things.
I think that that sort of thing would do very well on the Kindle platform but i am unable to do it.
I don't know why they remove the watermarks, but that step alone invalidates your suggestion.
However I can download the file, rename it to .jpg, and view the image just fine.
Well, the JPEG file doesn't have the correct mime-type. Chrome warns, "Resource interpreted as Image but transferred with MIME type text/html" in the console. Apparently in the context of an <img src=""> URL it figures it out though.
$ gm convert http://lcamtuf.coredump.cx/squirrel/ -comment '' x.jpg
…and… $ gm identify -format '%c' http://lcamtuf.coredump.cx/squirrel/http://www.reddit.com/comments/arc79/reddit_i_got_the_best_p...
http://lcamtuf.coredump.cx/squirrel/404.html
:)
http://zbyszek.posterous.com - the theme for this, did you create it? It's neat. There are a pair of forward slashes at the beginning of the page though. In Chrome at least.
http://naugtur.pl - Love the categorization and of course the animation. What are you using to do the animation?
Thanks~
As for animations - It's just a CSS transition definition and a single rule to rotate and scale an element. I created a hack that makes the CSS rule apply recursively. fun.js has some code that converts the simple html into a deeper structure.
I think someone else got the idea of _recursive CSS_ first, but it was used for drawing shapes as far as I remember.
enter in you jpeg comment field: "<html>...your page...</html><!--"
then the "image" will look like:
@^PJFIF^@^A^A^A^A,^A,^@^@000^Cr<html>...your page...</html><!-- rest of garbage
to the browser this is just the same as: \n
\n
\n
<html>...your page...</html>Remember there is no file system. In fact, there are no files.
We hid them so they do not exist. Out of sight, out of mind.
There's no such thing as binary. That only existed when you were younger. Now it no longer exists. The numbers are gone. They do not exist.
What's really important is how good fonts look. The javascript, the CSS, the browser!
No user cares about content like text, audio and video, they care about window dressing: html and browsers. They care about what you can do with javascript. What can you do? Show me some tricks.
Content alone is not enough. Who wants to read a story or download a video clip? You have to present it; you must entertain and you must persuade, by trickery if necessary. It's not the content, silly. It's the webpage. No javascript, no dice. Don't just deliver the content, entertain me for a few minutes first. Tell me about something else.
No one cares about TV programming. They care about the TV's setup screens and onscreen channel guide. They want these menus to come to life. They want their TV's to become "intelligent".
A webpage without javascript is like a lifeless onscreen TV channel guide that does not track what you watch and report it to marketers, or make automatic suggestions on what you should watch, or display animations while you sit and wait for seconds while the TV's software is "Loading..." in response to your last button push. Boring.
Users want books, newspapers, radios and TV's that have "artificial intelligence". They want others to know what they are reading and watching and they want advertisers to address them by name. Let's get with it. Bring us the future.
Don't worry, there's lots of people who are trying to keep the web worth your attention :)
No one needs to cater to my attention. Apparently I'm not today's end user. I'm for all intents and purposes a blind user. The web is not for me. I don't even start X11 if it's not necessary. I work with text. Graphics and multimedia are for recreation.
One of my favorite recent HN comments/stories was from Diego Basch. He described what happened at Inktomi, an early search engine that eventually was made all but obsolescent by Google.
In his story, he stated what he saw as one of the sure signs that Inktomi was being overtaken by Google. He said he saw that Inktomi engineers did not use Inktomi's search. They used Google.
Are complex browsers the way of the future? I find it easier to work on _operating systems_ than I do to work on today's "modern browsers". That is how complex (and therby insecure) the code has gotten. I would rather try to understand the code for ffmpeg or mplayer than I would for Chrome or Mozilla. But as I said, I'm not the "end user" to focus on.
Developers/engineers gotta eat. Do what works today. Focus on what you think "end users" are doing. Try to anticpate what they "want".
When I'm pondering "the next big thing" and what may work tomorrow to pay the bills, I will always remember Diego's story of the Inktomi engineers.