Re: Portable steg?
[email protected] Wed, 16 May 2007 11:54:16 -0700
| Newsgroups | gmane.comp.security.forensics |
|---|---|
| Message-ID | <OFC1DBDF6F.B41512FA-ON072572DD.0067C300-072572DD.0067D548@londen-insurance.com> |
Check out DIIT (Digital Invisible Ink Toolkit). It's a Java application that is run from an executable jar file, so it is as portable as they come (as long as you have a JRE installed). It supports several different steg algorithms and is very easy to use. http://diit.sourceforge.net/ HTH, Skyler Bingham [email protected] (602) 957-1650 x1139 ph1atka5t <ph1atka5t@no-log .org> To Sent by: evb <[email protected]> listbounce@securi cc tyfocus.com [email protected] Subject Re: Portable steg? 05/11/2007 03:56 PM Please respond to ph1atka5t@no-log. org > Can anyone reference a portable steganography application? By this, I mean > can you point to a specific steg app that has been designed/modified to run > from an .exe, without installation? I'm not aware of such stego executable (that should be considered any safe), but the well-known (and one of the best) algorithm M5 from Andreas Westfeld comes in the fashion of a Java package -- I guess it should be considered portable, maybe more than an exe file? http://wwwrn.inf.tu-dresden.de/~westfeld/f5.html See also Neil Johnson page for starters: http://www.jjtc.com/Security/stegtools.htm Some more googling yields Hide-in-Picture for a 'portable' exe: http://sourceforge.net/project/showfiles.php?group_id=42816&package_id=34960&release_id=67439 To some extent, you might also consider this project aiming at developping a live CD (is that portable enough?) with built-in anonymizing tools (which is definitely to be considered a form of steganography IMO): http://kaos.to/cms/projects/releases/anonym.os-livecd.html Final thoughts: - current media-oriented stego tools only deal with first-order statistics of the media. Powerful classifiers like SVM do help a lot in distinguishing modifications in higher-order statistics that are caused by stego tools. See works by Jessica Fridrich et al. - by 'portable' don't you mean 'ready to work out of the box'? If so, just consider building a static executable and distribute it freely! As a reasonably secure public-key stego tool (at least for first-order statistics), I would use PubliMark -- not yet broken: http://perso.orange.fr/gleguelv/soft/publimark/index.html HTH, François. This e-mail and files transmitted with it are confidential, and are intended solely for the use of the individual or entity to whom this e-mail is addressed. If you are not the intended recipient, or the employee or agent responsible to deliver it to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you are not one of the named recipient(s) or otherwise have reason to believe that you received this message in error, please immediately notify [email protected] by e-mail, and destroy the original message. Thank You.