Viewing 8 posts - 1 through 8 (of 8 total)
  • Author
    Posts
  • #40487
    Kayoh
    Participant

    Hey all, I’ve used a Right-to-Left-Override on a file in Kali and successfully changed the name from a .bat to look like a .jpg but when my target downloads the file from my apache2 server it shows on my windows machine as a .bat file still?

    #40507
    Diego PérezDiego Pérez
    Participant

    Hi!
    Can you try to zip the file first? The download and uncompres it in your victim’s machine.

    Let me know how it goes!
    Diego

    #40555
    Kayoh
    Participant

    when extracting the file it shows a folder as _gpj for some reason. The file its self does show as a .jpg once its all extracted though so that does help thanks.

    #40579
    Diego PérezDiego Pérez
    Participant

    Hi!
    Can you share a screenshot of what are you compressing in kali?
    Also the result in windows please.

    Thanks!
    Diego

    #40631
    Kayoh
    Participant

    I’m compressing this and here is the output shown to the Windows machine:

    View post on imgur.com

    #40642
    Diego PérezDiego Pérez
    Participant

    Hi Tcale!
    As I can see the file in windows shows a proper spoofed extension.
    The othe issues are because you left the right-to-left character when compressing the file, to avoid this just clear the suggested name by the compressing tool and write a new one.

    Hope it helps!
    Diego

    #40659
    Kayoh
    Participant

    Il give it a try awesome thanks

    #40712
    Diego PérezDiego Pérez
    Participant

    Hi!
    Let me know how it goes!
    Diego

Viewing 8 posts - 1 through 8 (of 8 total)
  • You must be logged in to reply to this topic.
Privacy Overview
ZSecurity logo featuring a stylized red letter Z

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics and Linkedin to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.