[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSWnqq_qKj6xX-JWVxCCXTu2oqNH0cOf5moLjKLp9Y10":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1037,"How does the YCrCb color model used in JPEG files aid in compression and steganography?","JPEG uses YCrCb (luminance and chrominance) because the human eye is more sensitive to changes in luminance (Y) than chrominance (Cr, Cb). This allows compression by storing one CrCb value per 2x2 pixel block, reducing data size. For steganography, manipulating chrominance data can hide payloads with less visual impact compared to the RGB model. Further details on color space conversion are in the article, while [LSB steganography in PNG files](\u002Fnews\u002Fsteganography-techniques-lsb-steganography-in-png-files) provides a contrasting approach for lossless formats.","\u003Cp>JPEG uses YCrCb (luminance and chrominance) because the human eye is more sensitive to changes in luminance (Y) than chrominance (Cr, Cb). This allows compression by storing one CrCb value per 2x2 pixel block, reducing data size. For steganography, manipulating chrominance data can hide payloads with less visual impact compared to the RGB model. Further details on color space conversion are in the article, while [LSB steganography in PNG files](\u002Fnews\u002Fsteganography-techniques-lsb-steganography-in-png-files) provides a contrasting approach for lossless formats.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsteganography-techniques-hiding-payloads-using-jpeg-file-format\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-ycrcb-color-model-used-in-jpeg-files-aid-in-compression-and-stegano-1777480741248","YCrCb, luminance, chrominance, JPEG compression, steganography color model",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},253,"Steganography Techniques - Hiding Payloads Using JPEG File Format","steganography-techniques-hiding-payloads-using-jpeg-file-format","Learn JPEG steganography techniques for hiding payloads, including DCT and LSB encryption, Exif manipulation, and tools like stegdetect and JPEGsnoop.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Continuing the study of image steganography techniques, this time focusing on learning and understanding the JPEG file format. Compared to PNG file formats, JPEG files are relatively simpler. The methods for extracting hidden payloads are largely similar, with the main difference lying in the file formats themselves, leading to variations in exploitable details.\u003C\u002Fp>\u003Ch3>Tools mentioned in this article:\u003C\u002Fh3>\u003Cul>\u003Cli>Hex Editor: Hex Editor\u003C\u002Fli>\u003Cli>Steganography Detection: Stegdetect\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fabeluck\u002Fstegdetect\u003C\u002Fp>\u003Cul>\u003Cli>Edit EXIF Information: MagicEXIF\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.magicexif.com\u002F\u003C\u002Fp>\u003Cul>\u003Cli>Analyze JPEG Image Format: JPEGsnoop\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.impulseadventure.com\u002Fphoto\u002Fjpeg-snoop.html\u003C\u002Fp>\u003Ch2>0x01 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>JPEG File\u003C\u002Fh3>\u003Cp>JPEG stands for Joint Photographic Experts Group\u003C\u002Fp>\u003Cp>Supports lossy compression\u003C\u002Fp>\u003Cp>Does not support transparency\u003C\u002Fp>\u003Cp>Does not support animation\u003C\u002Fp>\u003Cp>Non-vector\u003C\u002Fp>\u003Cp>\u003Cstrong>Difference between JPEG and JPG\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>JPEG can serve as both a file extension and represent the file format\u003C\u002Fp>\u003Cp>JPG is an abbreviation of JPEG, representing the file extension\u003C\u002Fp>\u003Cp>JPEG and JPG are essentially the same, and their formats are interchangeable\u003C\u002Fp>\u003Ch3>Color Model\u003C\u002Fh3>\u003Cp>Uses the YCrCb color model, which is more suitable for image compression than RGB\u003C\u002Fp>\u003Cul>\u003Cli>Y represents luminance\u003C\u002Fli>\u003Cli>Cr represents the red component\u003C\u002Fli>\u003Cli>Cb represents the blue component\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The human eye is far more sensitive to changes in luminance Y than to changes in chrominance C. If each point stores an 8-bit luminance value Y, and every 2x2 points store one CrCb value, the perceived visual quality of the image will not change significantly, while saving half the space.\u003C\u002Fp>\u003Cp>The RGB model requires 4x3=12 bytes for 4 points\u003C\u002Fp>\u003Cp>The YCrCb model requires 4+2=6 bytes for 4 points\u003C\u002Fp>\u003Cp>\u003Cstrong>[R G B] -&gt; [Y Cb Cr] conversion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Y = 0.299\u003Cem>R + 0.587\u003C\u002Fem>G + 0.114*B\u003C\u002Fp>\u003Cp>Cb = -0.1687\u003Cem>R - 0.3313\u003C\u002Fem>G + 0.5*B + 128\u003C\u002Fp>\u003Cp>Cr = 0.5\u003Cem>R - 0.4187\u003C\u002Fem>G - 0.0813*B + 128\u003C\u002Fp>\u003Cp>\u003Cstrong>[Y,Cb,Cr] -&gt; [R,G,B] conversion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>R = Y                    + 1.402  *(Cr-128)\u003C\u002Fp>\u003Cp>G = Y - 0.34414\u003Cem>(Cb-128) - 0.71414\u003C\u002Fem>(Cr-128)\u003C\u002Fp>\u003Cp>B = Y + 1.772  *(Cb-128)\u003C\u002Fp>\u003Ch3>File format\u003C\u002Fh3>\u003Cp>JPEG files can generally be divided into two parts: markers and compressed data\u003C\u002Fp>\u003Cp>\u003Cstrong>Markers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Consist of two bytes, the first byte is a fixed value 0xFF, and the second byte has different values depending on the meaning\u003C\u002Fp>\u003Cp>Any number of meaningless 0xFF fillers can be added before each marker, multiple consecutive 0xFF bytes can be interpreted as one 0xFF, indicating the start of a marker\u003C\u002Fp>\u003Cp>Common markers:\u003C\u002Fp>\u003Cul>\u003Cli>SOI  0xD8  Start of Image\u003C\u002Fli>\u003Cli>APP0 0xE0  Application Reserved Marker 0\u003C\u002Fli>\u003Cli>APPn 0xE1 - 0xEF  Application Reserved Marker n (n=1～15)\u003C\u002Fli>\u003Cli>DQT 0xDB Quantization Table (Define Quantization Table)\u003C\u002Fli>\u003Cli>SOF0 0xC0 Start of Frame (Start Of Frame)\u003C\u002Fli>\u003Cli>DHT 0xC4 Huffman Table (Define Huffman Table)\u003C\u002Fli>\u003Cli>DRI 0xDD Restart Interval (Define Restart Interval)\u003C\u002Fli>\u003Cli>SOS 0xDA Start of Scan (Start Of Scan)\u003C\u002Fli>\u003Cli>EOI 0xD9 End of Image\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Compressed Data:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The first two bytes store the length of the entire segment, including these two bytes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This length representation method follows high-order first, low-order last, which differs from the length representation method in PNG files\u003C\u002Fp>\u003Cp>For example, if the length is 0x12AB, the storage order is 0x12, 0xAB\u003C\u002Fp>\u003Ch3>Exif Information\u003C\u002Fh3>\u003Cp>Exif files are a type of JPEG file that comply with the JPEG standard, but include shooting information and thumbnail images in the file header information\u003C\u002Fp>\u003Cp>JPEG files taken with a camera will have this information\u003C\u002Fp>\u003Cp>Stored in the APP1 (0xFFE1) data area\u003C\u002Fp>\u003Cp>The next two bytes store the size of the APP1 data area (i.e., the Exif data area).\u003C\u002Fp>\u003Cp>Followed by the Exif Header, a fixed structure: 0x457869660000.\u003C\u002Fp>\u003Cp>Then comes the Exif data.\u003C\u002Fp>\u003Cp>Tool for viewing Exif information: exiftool.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Falchemy-fr\u002Fexiftool\u003C\u002Fp>\u003Cp>Tool for editing Exif information: MagicEXIF.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.magicexif.com\u002F\u003C\u002Fp>\u003Cp>The addition operation is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015145413_0_c46812dec9.png\">\u003C\u002Fp>\u003Ch2>0x02 Common Steganography Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>DCT encryption\u003C\u002Fli>\u003Cli>LSB encryption\u003C\u002Fli>\u003Cli>DCT LSB\u003C\u002Fli>\u003Cli>Average DCT\u003C\u002Fli>\u003Cli>High Capacity DCT\u003C\u002Fli>\u003Cli>High Capacity DCT - Algorithm\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The above steganography methods are referenced from:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fdocs\u002Fasia-14\u002Fmaterials\u002FOrtiz\u002FAsia-14-Ortiz-Advanced-JPEG-Steganography-And-Detection.pdf\u003C\u002Fp>\u003Cp>There are already many open-source tools capable of implementing the above advanced steganography methods\u003C\u002Fp>\u003Cp>\u003Cstrong>Common steganography tools:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>JSteg\u003C\u002Fli>\u003Cli>JPHide\u003C\u002Fli>\u003Cli>OutGuess\u003C\u002Fli>\u003Cli>Invisible Secrets\u003C\u002Fli>\u003Cli>F5\u003C\u002Fli>\u003Cli>appendX\u003C\u002Fli>\u003Cli>Camouflage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Of course, corresponding steganalysis tools have also existed for a long time\u003C\u002Fp>\u003Cp>For example: Stegdetect\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fabeluck\u002Fstegdetect\u003C\u002Fp>\u003Ch2>0x03 Hiding Payload Using JPEG File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Next, we introduce some hiding ideas generated after studying file formats:\u003C\u002Fp>\u003Ch3>1. Directly append data at the end\u003C\u002Fh3>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015147957_1_ccf2e33e26.jpeg\">\u003C\u002Fp>\u003Cp>As shown, it does not affect normal image viewing\u003C\u002Fp>\u003Ch3>2. Insert custom COM comment\u003C\u002Fh3>\u003Cp>COM comment is 0xff and 0xfe\u003C\u002Fp>\u003Cp>Insert data 0x11111111\u003C\u002Fp>\u003Cp>Length is 0x04\u003C\u002Fp>\u003Cp>Total length is 0x06\u003C\u002Fp>\u003Cp>The complete hexadecimal format is 0xffff000611111111\u003C\u002Fp>\u003Cp>Insert position is before DHT, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015149259_2_a1663a0c66.jpeg\">\u003C\u002Fp>\u003Cp>After insertion, as shown in the figure, it does not affect normal image viewing\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015150244_3_32ca08bfdb.jpeg\">\u003C\u002Fp>\u003Cp>Change ff to fe, as shown in the figure, also does not affect normal image viewing\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015151192_4_ead380a220.jpeg\">\u003C\u002Fp>\u003Ch3>3. Insert ignorable marker codes\u003C\u002Fh3>\u003Cp>Same principle as above, replace marker codes with special values that can be ignored\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>00\u003C\u002Fli>\u003Cli>01 *TEM\u003C\u002Fli>\u003Cli>d0 *RST0\u003C\u002Fli>\u003Cli>dc DNL\u003C\u002Fli>\u003Cli>ef APP15\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Testing shows that the above identification codes do not affect normal image viewing\u003C\u002Fp>\u003Ch3>4. Modify DQT\u003C\u002Fh3>\u003Cp>DQT: Define Quantization Table\u003C\u002Fp>\u003Cp>Identification code is 0xdb\u003C\u002Fp>\u003Cp>The next two bytes indicate length\u003C\u002Fp>\u003Cp>The next byte indicates QT configuration information\u003C\u002Fp>\u003Cp>First 4 bits are QT number\u003C\u002Fp>\u003Cp>Last 4 bits are QT precision, 0=8bit, otherwise 16bit\u003C\u002Fp>\u003Cp>Finally, QT information with length being an integer multiple of 64\u003C\u002Fp>\u003Cp>View DQT information of the test image, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015152192_5_e6d0577e8c.jpeg\">\u003C\u002Fp>\u003Cp>Length is 0x43, decimal 67\u003C\u002Fp>\u003Cp>00 indicates QT number 0, precision 8bit\u003C\u002Fp>\u003Cp>Next 64 bytes are QT information bytes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The DQT format here is referenced from http:\u002F\u002Fwww.opennet.ru\u002Fdocs\u002Fformats\u002Fjpeg.txt\u003C\u002Fp>\u003Cp>Try replacing these 64 bytes, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015153167_6_21c9043d89.jpeg\">\u003C\u002Fp>\u003Cp>Comparison before and after as shown in the figure reveals changes in the image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015154125_7_008e21e884.jpeg\">\u003C\u002Fp>\u003Cp>If only adjusting some bytes to payload, how much difference can it make? Compare as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015154741_8_7354eee1db.jpeg\">\u003C\u002Fp>\u003Cp>By analogy, there are many positions available for modification\u003C\u002Fp>\u003Ch2>0x04 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the above hiding methods, traces can be discovered using JPEG image format analysis tools\u003C\u002Fp>\u003Cp>For example, JPEGsnoop\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.impulseadventure.com\u002Fphoto\u002Fjpeg-snoop.html\u003C\u002Fp>\u003Cp>Supports format analysis for the following files:\u003C\u002Fp>\u003Cul>\u003Cli>.JPG - JPEG Still Photo\u003C\u002Fli>\u003Cli>.THM - Thumbnail for RAW Photo \u002F Movie Files\u003C\u002Fli>\u003Cli>.AVI* - AVI Movies\u003C\u002Fli>\u003Cli>.DNG - Digital Negative RAW Photo\u003C\u002Fli>\u003Cli>.PSD - Adobe Photoshop files\u003C\u002Fli>\u003Cli>.CRW, .CR2, .NEF, .ORF, .PEF - RAW Photo\u003C\u002Fli>\u003Cli>.MOV* - QuickTime Movies, QTVR (Virtual Reality \u002F 360 Panoramic)\u003C\u002Fli>\u003Cli>.PDF - Adobe PDF Documents\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As shown below, the COM comment added to the image was discovered\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015155480_9_de4502e7a0.jpeg\">\u003C\u002Fp>\u003Cp>As shown below, the added payload was identified by examining the DQT data, where 0x11 corresponds to decimal 17\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015156244_10_02573411d5.jpeg\">\u003C\u002Fp>\u003Cp>Similarly, JPEGsnoop can parse the EXIF information of JPEG images, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015157093_11_59f8cac532.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing purposes, the following values in the screenshot were manually added using MagicEXIF software:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>  EXIF Make\u002FModel:     OK   [test] [???]\u003Cbr>  EXIF Makernotes:     NONE\u003Cbr>  EXIF Software:       OK   [MagicEXIF Metadata Codec 1.02]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to PNG files, adding payloads to JPEG files is much simpler because JPEG files lack checksums for image data.\u003C\u002Fp>\u003Cp>The method of downloading JPEG images, parsing them, and executing payloads will not be discussed here.\u003C\u002Fp>\u003Cp>(Refer to https:\u002F\u002Fan-open-source-project\u002F%E9%9A%90%E5%86%99%E6%8A%80%E5%B7%A7-%E5%88%A9%E7%94%A8PNG%E6%96%87%E4%BB%B6%E6%A0%BC%E5%BC%8F%E9%9A%90%E8%97%8FPayload)\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the JPEG format, focusing on how to hide payloads using specific marker codes based on the JPEG file format. While this method does not affect normal image viewing, details can still be detected with format analysis software. There is much more to learn in the official documentation on the JPEG format; the deeper the understanding, the more techniques available for research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Continuing the study of image steganography techniques, this time focusing on learning and understanding the JPEG file format. Compared to PNG file formats, JPEG files are relatively simpler. The methods for extracting hidden payloads are largely similar, with the main difference lying in the file formats themselves, leading to variations in exploitable details.\u003C\u002Fp>\u003Ch3>Tools mentioned in this article:\u003C\u002Fh3>\u003Cul>\u003Cli>Hex Editor: Hex Editor\u003C\u002Fli>\u003Cli>Steganography Detection: Stegdetect\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fabeluck\u002Fstegdetect\u003C\u002Fp>\u003Cul>\u003Cli>Edit EXIF Information: MagicEXIF\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.magicexif.com\u002F\u003C\u002Fp>\u003Cul>\u003Cli>Analyze JPEG Image Format: JPEGsnoop\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.impulseadventure.com\u002Fphoto\u002Fjpeg-snoop.html\u003C\u002Fp>\u003Ch2>0x01 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>JPEG File\u003C\u002Fh3>\u003Cp>JPEG stands for Joint Photographic Experts Group\u003C\u002Fp>\u003Cp>Supports lossy compression\u003C\u002Fp>\u003Cp>Does not support transparency\u003C\u002Fp>\u003Cp>Does not support animation\u003C\u002Fp>\u003Cp>Non-vector\u003C\u002Fp>\u003Cp>\u003Cstrong>Difference between JPEG and JPG\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>JPEG can serve as both a file extension and represent the file format\u003C\u002Fp>\u003Cp>JPG is an abbreviation of JPEG, representing the file extension\u003C\u002Fp>\u003Cp>JPEG and JPG are essentially the same, and their formats are interchangeable\u003C\u002Fp>\u003Ch3>Color Model\u003C\u002Fh3>\u003Cp>Uses the YCrCb color model, which is more suitable for image compression than RGB\u003C\u002Fp>\u003Cul>\u003Cli>Y represents luminance\u003C\u002Fli>\u003Cli>Cr represents the red component\u003C\u002Fli>\u003Cli>Cb represents the blue component\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The human eye is far more sensitive to changes in luminance Y than to changes in chrominance C. If each point stores an 8-bit luminance value Y, and every 2x2 points store one CrCb value, the perceived visual quality of the image will not change significantly, while saving half the space.\u003C\u002Fp>\u003Cp>The RGB model requires 4x3=12 bytes for 4 points\u003C\u002Fp>\u003Cp>The YCrCb model requires 4+2=6 bytes for 4 points\u003C\u002Fp>\u003Cp>\u003Cstrong>[R G B] -&gt; [Y Cb Cr] conversion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Y = 0.299\u003Cem>R + 0.587\u003C\u002Fem>G + 0.114*B\u003C\u002Fp>\u003Cp>Cb = -0.1687\u003Cem>R - 0.3313\u003C\u002Fem>G + 0.5*B + 128\u003C\u002Fp>\u003Cp>Cr = 0.5\u003Cem>R - 0.4187\u003C\u002Fem>G - 0.0813*B + 128\u003C\u002Fp>\u003Cp>\u003Cstrong>[Y,Cb,Cr] -&gt; [R,G,B] conversion:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>R = Y                    + 1.402  *(Cr-128)\u003C\u002Fp>\u003Cp>G = Y - 0.34414\u003Cem>(Cb-128) - 0.71414\u003C\u002Fem>(Cr-128)\u003C\u002Fp>\u003Cp>B = Y + 1.772  *(Cb-128)\u003C\u002Fp>\u003Ch3>File format\u003C\u002Fh3>\u003Cp>JPEG files can generally be divided into two parts: markers and compressed data\u003C\u002Fp>\u003Cp>\u003Cstrong>Markers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Consist of two bytes, the first byte is a fixed value 0xFF, and the second byte has different values depending on the meaning\u003C\u002Fp>\u003Cp>Any number of meaningless 0xFF fillers can be added before each marker, multiple consecutive 0xFF bytes can be interpreted as one 0xFF, indicating the start of a marker\u003C\u002Fp>\u003Cp>Common markers:\u003C\u002Fp>\u003Cul>\u003Cli>SOI  0xD8  Start of Image\u003C\u002Fli>\u003Cli>APP0 0xE0  Application Reserved Marker 0\u003C\u002Fli>\u003Cli>APPn 0xE1 - 0xEF  Application Reserved Marker n (n=1～15)\u003C\u002Fli>\u003Cli>DQT 0xDB Quantization Table (Define Quantization Table)\u003C\u002Fli>\u003Cli>SOF0 0xC0 Start of Frame (Start Of Frame)\u003C\u002Fli>\u003Cli>DHT 0xC4 Huffman Table (Define Huffman Table)\u003C\u002Fli>\u003Cli>DRI 0xDD Restart Interval (Define Restart Interval)\u003C\u002Fli>\u003Cli>SOS 0xDA Start of Scan (Start Of Scan)\u003C\u002Fli>\u003Cli>EOI 0xD9 End of Image\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Compressed Data:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The first two bytes store the length of the entire segment, including these two bytes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This length representation method follows high-order first, low-order last, which differs from the length representation method in PNG files\u003C\u002Fp>\u003Cp>For example, if the length is 0x12AB, the storage order is 0x12, 0xAB\u003C\u002Fp>\u003Ch3>Exif Information\u003C\u002Fh3>\u003Cp>Exif files are a type of JPEG file that comply with the JPEG standard, but include shooting information and thumbnail images in the file header information\u003C\u002Fp>\u003Cp>JPEG files taken with a camera will have this information\u003C\u002Fp>\u003Cp>Stored in the APP1 (0xFFE1) data area\u003C\u002Fp>\u003Cp>The next two bytes store the size of the APP1 data area (i.e., the Exif data area).\u003C\u002Fp>\u003Cp>Followed by the Exif Header, a fixed structure: 0x457869660000.\u003C\u002Fp>\u003Cp>Then comes the Exif data.\u003C\u002Fp>\u003Cp>Tool for viewing Exif information: exiftool.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Falchemy-fr\u002Fexiftool\u003C\u002Fp>\u003Cp>Tool for editing Exif information: MagicEXIF.\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.magicexif.com\u002F\u003C\u002Fp>\u003Cp>The addition operation is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015145413_0_c46812dec9-1.png\">\u003C\u002Fp>\u003Ch2>0x02 Common Steganography Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>DCT encryption\u003C\u002Fli>\u003Cli>LSB encryption\u003C\u002Fli>\u003Cli>DCT LSB\u003C\u002Fli>\u003Cli>Average DCT\u003C\u002Fli>\u003Cli>High Capacity DCT\u003C\u002Fli>\u003Cli>High Capacity DCT - Algorithm\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The above steganography methods are referenced from:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fdocs\u002Fasia-14\u002Fmaterials\u002FOrtiz\u002FAsia-14-Ortiz-Advanced-JPEG-Steganography-And-Detection.pdf\u003C\u002Fp>\u003Cp>There are already many open-source tools capable of implementing the above advanced steganography methods\u003C\u002Fp>\u003Cp>\u003Cstrong>Common steganography tools:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>JSteg\u003C\u002Fli>\u003Cli>JPHide\u003C\u002Fli>\u003Cli>OutGuess\u003C\u002Fli>\u003Cli>Invisible Secrets\u003C\u002Fli>\u003Cli>F5\u003C\u002Fli>\u003Cli>appendX\u003C\u002Fli>\u003Cli>Camouflage\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Of course, corresponding steganalysis tools have also existed for a long time\u003C\u002Fp>\u003Cp>For example: Stegdetect\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fabeluck\u002Fstegdetect\u003C\u002Fp>\u003Ch2>0x03 Hiding Payload Using JPEG File Format\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Next, we introduce some hiding ideas generated after studying file formats:\u003C\u002Fp>\u003Ch3>1. Directly append data at the end\u003C\u002Fh3>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015147957_1_ccf2e33e26-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown, it does not affect normal image viewing\u003C\u002Fp>\u003Ch3>2. Insert custom COM comment\u003C\u002Fh3>\u003Cp>COM comment is 0xff and 0xfe\u003C\u002Fp>\u003Cp>Insert data 0x11111111\u003C\u002Fp>\u003Cp>Length is 0x04\u003C\u002Fp>\u003Cp>Total length is 0x06\u003C\u002Fp>\u003Cp>The complete hexadecimal format is 0xffff000611111111\u003C\u002Fp>\u003Cp>Insert position is before DHT, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015149259_2_a1663a0c66-1.jpeg\">\u003C\u002Fp>\u003Cp>After insertion, as shown in the figure, it does not affect normal image viewing\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015150244_3_32ca08bfdb-1.jpeg\">\u003C\u002Fp>\u003Cp>Change ff to fe, as shown in the figure, also does not affect normal image viewing\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015151192_4_ead380a220-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Insert ignorable marker codes\u003C\u002Fh3>\u003Cp>Same principle as above, replace marker codes with special values that can be ignored\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cul>\u003Cli>00\u003C\u002Fli>\u003Cli>01 *TEM\u003C\u002Fli>\u003Cli>d0 *RST0\u003C\u002Fli>\u003Cli>dc DNL\u003C\u002Fli>\u003Cli>ef APP15\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Testing shows that the above identification codes do not affect normal image viewing\u003C\u002Fp>\u003Ch3>4. Modify DQT\u003C\u002Fh3>\u003Cp>DQT: Define Quantization Table\u003C\u002Fp>\u003Cp>Identification code is 0xdb\u003C\u002Fp>\u003Cp>The next two bytes indicate length\u003C\u002Fp>\u003Cp>The next byte indicates QT configuration information\u003C\u002Fp>\u003Cp>First 4 bits are QT number\u003C\u002Fp>\u003Cp>Last 4 bits are QT precision, 0=8bit, otherwise 16bit\u003C\u002Fp>\u003Cp>Finally, QT information with length being an integer multiple of 64\u003C\u002Fp>\u003Cp>View DQT information of the test image, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015152192_5_e6d0577e8c-1.jpeg\">\u003C\u002Fp>\u003Cp>Length is 0x43, decimal 67\u003C\u002Fp>\u003Cp>00 indicates QT number 0, precision 8bit\u003C\u002Fp>\u003Cp>Next 64 bytes are QT information bytes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The DQT format here is referenced from http:\u002F\u002Fwww.opennet.ru\u002Fdocs\u002Fformats\u002Fjpeg.txt\u003C\u002Fp>\u003Cp>Try replacing these 64 bytes, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015153167_6_21c9043d89-1.jpeg\">\u003C\u002Fp>\u003Cp>Comparison before and after as shown in the figure reveals changes in the image\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015154125_7_008e21e884-1.jpeg\">\u003C\u002Fp>\u003Cp>If only adjusting some bytes to payload, how much difference can it make? Compare as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015154741_8_7354eee1db-1.jpeg\">\u003C\u002Fp>\u003Cp>By analogy, there are many positions available for modification\u003C\u002Fp>\u003Ch2>0x04 Detection and Identification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the above hiding methods, traces can be discovered using JPEG image format analysis tools\u003C\u002Fp>\u003Cp>For example, JPEGsnoop\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.impulseadventure.com\u002Fphoto\u002Fjpeg-snoop.html\u003C\u002Fp>\u003Cp>Supports format analysis for the following files:\u003C\u002Fp>\u003Cul>\u003Cli>.JPG - JPEG Still Photo\u003C\u002Fli>\u003Cli>.THM - Thumbnail for RAW Photo \u002F Movie Files\u003C\u002Fli>\u003Cli>.AVI* - AVI Movies\u003C\u002Fli>\u003Cli>.DNG - Digital Negative RAW Photo\u003C\u002Fli>\u003Cli>.PSD - Adobe Photoshop files\u003C\u002Fli>\u003Cli>.CRW, .CR2, .NEF, .ORF, .PEF - RAW Photo\u003C\u002Fli>\u003Cli>.MOV* - QuickTime Movies, QTVR (Virtual Reality \u002F 360 Panoramic)\u003C\u002Fli>\u003Cli>.PDF - Adobe PDF Documents\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As shown below, the COM comment added to the image was discovered\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015155480_9_de4502e7a0-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown below, the added payload was identified by examining the DQT data, where 0x11 corresponds to decimal 17\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015156244_10_02573411d5-1.jpeg\">\u003C\u002Fp>\u003Cp>Similarly, JPEGsnoop can parse the EXIF information of JPEG images, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015157093_11_59f8cac532-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing purposes, the following values in the screenshot were manually added using MagicEXIF software:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>  EXIF Make\u002FModel:     OK   [test] [???]\u003Cbr>  EXIF Makernotes:     NONE\u003Cbr>  EXIF Software:       OK   [MagicEXIF Metadata Codec 1.02]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to PNG files, adding payloads to JPEG files is much simpler because JPEG files lack checksums for image data.\u003C\u002Fp>\u003Cp>The method of downloading JPEG images, parsing them, and executing payloads will not be discussed here.\u003C\u002Fp>\u003Cp>(Refer to https:\u002F\u002Fan-open-source-project\u002F%E9%9A%90%E5%86%99%E6%8A%80%E5%B7%A7-%E5%88%A9%E7%94%A8PNG%E6%96%87%E4%BB%B6%E6%A0%BC%E5%BC%8F%E9%9A%90%E8%97%8FPayload)\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the JPEG format, focusing on how to hide payloads using specific marker codes based on the JPEG file format. While this method does not affect normal image viewing, details can still be detected with format analysis software. There is much more to learn in the official documentation on the JPEG format; the deeper the understanding, the more techniques available for research.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",375,"Onedaysec",6,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"JPEG Steganography Techniques: Hiding Payloads in Images","JPEG steganography, image steganography, DCT encryption, LSB encryption, Exif data, file format, payload hiding, stegdetect, JPEGsnoop",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],1036,1035,1034,1033,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.072Z","2026-07-23T16:02:27.096Z","draft","2026-07-23T16:16:15.884Z"]