Learn about video file exfiltration using OpenPuff in this video.
- From the OpenPuff Graphical Interface,…we can select the Hide function and start the process.…The password screen allows to enter…three different passwords,…two for encryption and one for scrambling.…We can turn the second and third password off…and OpenPuff will just re-use…the first password for all three functions,…but that reduces the level of hiding we can achieve.…The passwords have to be at least eight characters.…OpenPuff checks the entropy of the passwords…and will display green when the passwords are satisfactory.…
I'll enter friendly,…laughing,…crocodiles.…Okay, we've got a green light…and we can move on to selecting our secret file.…It's called secret dot text.…We now need to choose a set of carrier files,…which can be any combination…of files supported by OpenPuff,…PDFs, pictures, video and audio files and so on.…
We'll just use the one carrier file,…song dot mp3.…We then need to choose the bits selection level,…which we can do until we get a green light,…I'll go for the medium.…At this point we could add a decoy file,…
- How tunneling works
- Running a local SSH tunnel
- Dynamic SSH tunneling
- Pivoting with Armitage and Metaspoit
- Exfiltrating using DET and DNS
- Covert exfiltration with Cachetalk
- Using PyExfil to exfiltrate over HTTPS
Skill Level Advanced
Ethical Hacking: Penetration Testingwith Lisa Bock1h 20m Intermediate
Penetration Testing Essential Trainingwith Malcolm Shore2h 29m Intermediate
Penetration Testing: Advanced Kali Linuxwith Malcolm Shore2h 22m Intermediate
1. Preparing the Lab
Next steps1m 38s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.