See how to install the OpenPuff video exfiltration tool in this video.
- [Instructor] A novel approach to exfiltration…is the use of video files to hide data,…a form of steganography.…These files can then be uploaded into a video sharing site…for later recovery.…In 2011 the German Federal Criminal Police…arrested a suspected Al-Qaeda member…and on forensic search of his laptop found a video,…which contained hidden data.…They discovered 141 separate files,…reportedly containing documents detailing…the Al-Qaeda operations and plans for future operations.…
Among them three untitled future works,…lessons learned, and report on operations.…Let's take a look at exfiltrating data using a video file.…To do this we need to install…a video steganography tool called OpenPuff.…This isn't obeying one of the rules of exfiltration,…but nevertheless it can sometimes be a viable option.…We can download the OpenPuff zip file…from the .net site shown.…
I load the zip file for the tool…into my usr share directory.…I can now unzip this into the folder OpenPuff.…I'll start the OpenPuff shell script and let it initialize.…
- How tunneling works
- Running a local SSH tunnel
- Dynamic SSH tunneling
- Pivoting with Armitage and Metaspoit
- Exfiltrating using DET and DNS
- Covert exfiltration with Cachetalk
- Using PyExfil to exfiltrate over HTTPS
Skill Level Advanced
Ethical Hacking: Penetration Testingwith Lisa Bock1h 29m Intermediate
Penetration Testing Essential Trainingwith Malcolm Shore2h 29m Intermediate
Penetration Testing: Advanced Kali Linuxwith Malcolm Shore2h 22m Intermediate
1. Preparing the Lab
Next steps1m 38s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.