[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFSvEpSF1WCY8aw21CIIPbC0XffIJ65IJkZKQHm4n8Ds":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},290,"What is the role of the IDAT data chunk in PNG LSB steganography, and how is it compressed?","The IDAT data chunk stores the actual pixel data of the PNG image. It uses a compression algorithm based on LZ77 (deflate), and the compressed data can be decompressed using zlib. In LSB steganography, the payload is hidden by altering the least significant bits of the decompressed pixel data before re-compressing it into the IDAT chunk. Tools like [cloacked-pixel](https:\u002F\u002Fgithub.com\u002Fcyberinc\u002Fcloacked-pixel) replace all other chunks with only the essential IDAT chunk.","\u003Cp>The IDAT data chunk stores the actual pixel data of the PNG image. It uses a compression algorithm based on LZ77 (deflate), and the compressed data can be decompressed using zlib. In LSB steganography, the payload is hidden by altering the least significant bits of the decompressed pixel data before re-compressing it into the IDAT chunk. Tools like [cloacked-pixel](https:\u002F\u002Fgithub.com\u002Fcyberinc\u002Fcloacked-pixel) replace all other chunks with only the essential IDAT chunk.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsteganography-techniques-lsb-steganography-in-png-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-role-of-the-idat-data-chunk-in-png-lsb-steganography-and-how-is-it-c-1777484476066","IDAT, LZ77, zlib compression, PNG file format, steganography",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},75,"Steganography Techniques - LSB Steganography in PNG Files","steganography-techniques-lsb-steganography-in-png-files","Learn LSB steganography techniques to hide payloads in PNG files using IDAT chunks. Includes Python implementation and analysis tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>The previous article analyzed the PNG file format and introduced how to insert payloads into PNG files in the auxiliary data chunk tEXt format without affecting normal browsing. This time, we will introduce a technique for hiding payloads under the image data chunk IDAT—LSB steganography\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018791268_0_4621063e19.jpeg\">\u003C\u002Fp>\u003Cp>Image sourced from http:\u002F\u002Fdatagenetics.com\u002Fblog\u002Fmarch12012\u002Findex.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>IDAT Data Chunk\u003C\u002Fh3>\u003Cul>\u003Cli>Stores image pixel data\u003C\u002Fli>\u003Cli>Can contain multiple consecutive image data chunks in the data stream\u003C\u002Fli>\u003Cli>Compressed using a derivative algorithm of LZ77\u003C\u002Fli>\u003Cli>Can be decompressed with zlib\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Python implementation code for zlib decompression:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#! \u002Fusr\u002Fbin\u002Fenv python\u003Cbr>import zlib\u003Cbr>import binascii\u003Cbr>IDAT = \"789C5D91011280400802BF04FFFF5C75294B5537738A21A27D1E49CFD17DB3937A92E7E603880A6D485100901FB0410153350DE83112EA2D51C54CE2E585B15A2FC78E8872F51C6FC1881882F93D372DEF78E665B0C36C529622A0A45588138833A170A2071DDCD18219DB8C0D465D8B6989719645ED9C11C36AE3ABDAEFCFC0ACF023E77C17C7897667\".decode('hex')\u003Cbr>result = binascii.hexlify(zlib.decompress(IDAT))\u003Cbr>print result\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cited from http:\u002F\u002Fdrops.wooyun.org\u002Ftips\u002F4862\u003C\u002Fp>\u003Ch3>LSB Steganography\u003C\u002Fh3>\u003Cul>\u003Cli>LSB stands for least significant bit\u003C\u002Fli>\u003Cli>In PNG files, image pixels are typically composed of three primary colors: red, green, and blue (RGB). Each color occupies 8 bits, with a value range from 0x00 to 0xFF, meaning there are 256 possible values per color. This results in a total of 256^3 colors, which is 16,777,216 colors.\u003C\u002Fli>\u003Cli>The human eye can distinguish approximately 10 million different colors.\u003C\u002Fli>\u003Cli>This means the human eye cannot distinguish the remaining approximately 6,777,216 colors.\u003C\u002Fli>\u003Cli>LSB steganography involves modifying the least significant bit (LSB) of the RGB color components, and the human eye does not notice the change before and after.\u003C\u002Fli>\u003Cli>Each pixel can carry 3 bits of information.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Python Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Notable projects on GitHub for learning about LSB steganography:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRobinDavid\u002FLSB-Steganography\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberinc\u002Fcloacked-pixel\u003C\u002Fp>\u003Cp>Testing cloacked-pixel below\u003C\u002Fp>\u003Cp>Test image:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018802152_1_47836c804e.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Source file download URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.easyicon.net\u002Flanguage.en\u002F1119182-Enderman_Png_icon.html\u003C\u002Fp>\u003Ch3>1. Encryption\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py hide big.png 1.txt 123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>hide: indicates encryption mode\u003C\u002Fp>\u003Cp>big.png: PNG image to be encrypted\u003C\u002Fp>\u003Cp>1.txt: stores the payload\u003C\u002Fp>\u003Cp>123456: encryption password\u003C\u002Fp>\u003Cp>After running, generate the image big.png-stego.png\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018808891_2_cc3a1be74d.png\">\u003C\u002Fp>\u003Cp>Analyze the format of the encrypted image big.png-stego.png using the check.cpp introduced in the previous article\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Comparison before and after encryption as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815442_3_67620c6d6f.png\">\u003C\u002Fp>\u003Cp>cloacked-pixel deletes other data chunks during encryption, retaining only the key IDAT data chunks\u003C\u002Fp>\u003Cp>Using HexEditorNeo to view the encrypted image also confirms our judgment, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018824544_4_e5d0bb9ef4.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, analysis can also be performed by reading the source code\u003C\u002Fp>\u003Ch3>2. Decryption\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py extract big.png-stego.png 3.txt 123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>extract: indicates decryption mode\u003C\u002Fp>\u003Cp>big.png-stego.png: PNG image to be decrypted\u003C\u002Fp>\u003Cp>3.txt: stores the exported payload\u003C\u002Fp>\u003Cp>123456: decryption password\u003C\u002Fp>\u003Cp>As shown, successfully decrypted to obtain payload\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018829533_5_b23e2680ac.png\">\u003C\u002Fp>\u003Ch3>3. Analysis\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py analyse big.png-stego.png\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>analyse: indicates analysis mode\u003C\u002Fp>\u003Cp>big.png-stego.png: PNG image to be analyzed\u003C\u002Fp>\u003Cp>After running, the image will be analyzed, divided into blocks, and the least significant bits of each block will be marked\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018832750_6_92259876cf.png\">\u003C\u002Fp>\u003Cp>This is a comparative analysis diagram before and after encryption\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018836161_7_eb6ceb1e70.jpeg\">\u003C\u002Fp>\u003Cp>The difference in the images is almost indistinguishable to the naked eye, because the shorter the payload, the smaller the difference in the analysis diagram. Here we can use software to assist in the analysis\u003C\u002Fp>\u003Cp>\u003Cstrong>Tool name:\u003C\u002Fstrong>Stegsolve\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.caesum.com\u002Fhandbook\u002FStegsolve.jar\u003C\u002Fp>\u003Cp>\u003Cstrong>Environment setup:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Install JDK and configure the Java environment\u003C\u002Fp>\u003Cp>Open a.png with Stegsolve, select Analyse-Image Combiner, and choose b.png\u003C\u002Fp>\u003Cp>Perform XOR comparison, as shown in the figure, subtle differences are detected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018837253_8_82c38ce5b7.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 C++ Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Grant Curell shared a method implemented through C++, which is worth learning, so here we introduce and test it.\u003C\u002Fp>\u003Cp>\u003Cstrong>Article address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F581298\u002FPNG-Image-Steganography-with-libpng\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant Curell\u003C\u002Fp>\u003Cp>\u003Cstrong>Code download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.codeproject.com\u002FKB\u002Fsecurity\u002F581298\u002FPNG_stego.zip\u003C\u002Fp>\u003Cp>\u003Cstrong>Test environment:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 X64\u003C\u002Fp>\u003Cp>vs2012\u003C\u002Fp>\u003Ch3>1. Direct compilation will report an error\u003C\u002Fh3>\u003Cp>The zlib project can be compiled successfully directly\u003C\u002Fp>\u003Cp>Compiling the libpng project, the error is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fatal error C1083: Cannot open include file: 'zlib.h': No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add include directory to the project\u003C\u002Fp>\u003Cp>Right-click - Property - VC++ Directories\u003C\u002Fp>\u003Cp>Select Include Directories\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018838199_9_4b0eed0f8c.png\">\u003C\u002Fp>\u003Cp>Add zlib-1.2.3, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\..\\..\\zlib-1.2.3;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018839474_10_a8860402ee.jpeg\">\u003C\u002Fp>\u003Cp>Compile again, error reported as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fatal error LNK1181: cannot open input file 'zlib.lib'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add lib directory to the project\u003C\u002Fp>\u003Cp>Select Library Directories\u003C\u002Fp>\u003Cp>Add zlib.lib, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\..\\..\\LIB Debug;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, compilation succeeded\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018840585_11_3d5c17235d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Tips:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In Include Directories and Library Directories, absolute paths can also be directly specified (e.g., C:\\test\\cloacked-pixel-master\\PNG_stego\\zlib-1.2.3). This example uses ..\\ to represent relative paths\u003C\u002Fp>\u003Cp>When compiling the project PNG_encode_decode, the same compilation error occurs\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add zlib-1.2.3 and libpng-1.2.37-src under Include Directories, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\u002Fzlib-1.2.3;..\u002Flibpng-1.2.37-src;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add libpng.lib under Library Directories, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\LIB Debug;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, final compilation succeeded\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018841544_12_0ae75759f5.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Three project components have sequential dependencies, so the compilation order is zlib-libpng-PNG_encode_decode\u003C\u002Fp>\u003Ch3>2. Encryption Testing\u003C\u002Fh3>\u003Cp>File to be encrypted: big.png\u003C\u002Fp>\u003Cp>Payload file: 1.txt\u003C\u002Fp>\u003Cp>Output encrypted file: bigen.png\u003C\u002Fp>\u003Cp>Modify main.cpp in project PNG_encode_decode as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"PNG_file.h\"\u003Cbr>void main() {\u003Cbr>\u003Cbr>\tPNG_file link = PNG_file(\"big.png\");\u003Cbr>\tlink.encode(\"1.txt\");\u003Cbr>\tlink.outputPNG(\"bigen.png\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, bigen.png is generated as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018843266_13_24e9aeeea7.png\">\u003C\u002Fp>\u003Cp>Comparing files before and after encryption shows size differences as illustrated\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018844406_14_37bb02b6b1.jpeg\">\u003C\u002Fp>\u003Cp>In principle, LSB steganography does not change file size; investigate the cause\u003C\u002Fp>\u003Cp>Using check.cpp to parse the data chunk directory, several additional tTXt segments were found after encryption\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018845454_15_730c74dded.jpeg\">\u003C\u002Fp>\u003Cp>Using HexEditorNeo to view the details of the encrypted image, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018846523_16_a7a31948c3.jpeg\">\u003C\u002Fp>\u003Cp>The encrypted image contains some information from the original image, resulting in different image sizes\u003C\u002Fp>\u003Ch3>3. Remove redundant information\u003C\u002Fh3>\u003Cp>\u003Cstrong>Method a:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use HexEditorNeo to directly delete redundant information\u003C\u002Fp>\u003Cp>\u003Cstrong>Method b:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use compress.cpp\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Generate encrypted image bigensimple.png with redundant tTXt chunks removed, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018847242_17_50053f896f.png\">\u003C\u002Fp>\u003Cp>bigensimple.png has the same size as the original image, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018847822_18_f1a3b9ffdc.jpeg\">\u003C\u002Fp>\u003Ch3>4. Decryption Test\u003C\u002Fh3>\u003Cp>Modify main.cpp in project PNG_encode_decode as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"PNG_file.h\"\u003Cbr>void main() {\u003Cbr>\u003Cbr>\tPNG_file link = PNG_file(\"bigensimple.png\");\u003Cbr>\tlink.decode(\"2.txt\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After running, 2.txt is generated, obtaining the stored encrypted payload\u003C\u002Fp>\u003Ch3>(5) Analysis\u003C\u002Fh3>\u003Cp>For LSB steganography, Stegsolve can be used for auxiliary analysis\u003C\u002Fp>\u003Cp>After opening the encrypted image, select Analyse-DataExtract\u003C\u002Fp>\u003Cp>Select the 0th bit of Reg, Green, and Blue in Bit Planes\u003C\u002Fp>\u003Cp>Select LSB First in Bit Order\u003C\u002Fp>\u003Cp>Select RGB in Bit Plane Order\u003C\u002Fp>\u003Cp>The encrypted form of the payload can be seen, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018848148_19_a9d21dd9e1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, the encrypted data of the image can be found by reading the program source code. This example only provides some reference ideas for image analysis.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to implement LSB steganography for PNG files using Python and C++ respectively. By following the analysis ideas in the article, common LSB steganography data can also be extracted and analyzed.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The modified PNG_stego project has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>More learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffgrimme\u002FMatroschka\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwaronpants.net\u002Farticle\u002Fpng-steganography\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwaronpants.net\u002Fpngsteg\u002Ftrunk\u002Fsteg.c\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww1.chapman.edu\u002F~nabav100\u002FImgStegano\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.libpng.org\u002Fpub\u002Fpng\u002Flibpng-1.2.5-manual.html#section-3.1\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.w3.org\u002FTR\u002FPNG\u002F\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>The previous article analyzed the PNG file format and introduced how to insert payloads into PNG files in the auxiliary data chunk tEXt format without affecting normal browsing. This time, we will introduce a technique for hiding payloads under the image data chunk IDAT—LSB steganography\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018791268_0_4621063e19-1.jpeg\">\u003C\u002Fp>\u003Cp>Image sourced from http:\u002F\u002Fdatagenetics.com\u002Fblog\u002Fmarch12012\u002Findex.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>IDAT Data Chunk\u003C\u002Fh3>\u003Cul>\u003Cli>Stores image pixel data\u003C\u002Fli>\u003Cli>Can contain multiple consecutive image data chunks in the data stream\u003C\u002Fli>\u003Cli>Compressed using a derivative algorithm of LZ77\u003C\u002Fli>\u003Cli>Can be decompressed with zlib\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Python implementation code for zlib decompression:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#! \u002Fusr\u002Fbin\u002Fenv python\u003Cbr>import zlib\u003Cbr>import binascii\u003Cbr>IDAT = \"789C5D91011280400802BF04FFFF5C75294B5537738A21A27D1E49CFD17DB3937A92E7E603880A6D485100901FB0410153350DE83112EA2D51C54CE2E585B15A2FC78E8872F51C6FC1881882F93D372DEF78E665B0C36C529622A0A45588138833A170A2071DDCD18219DB8C0D465D8B6989719645ED9C11C36AE3ABDAEFCFC0ACF023E77C17C7897667\".decode('hex')\u003Cbr>result = binascii.hexlify(zlib.decompress(IDAT))\u003Cbr>print result\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cited from http:\u002F\u002Fdrops.wooyun.org\u002Ftips\u002F4862\u003C\u002Fp>\u003Ch3>LSB Steganography\u003C\u002Fh3>\u003Cul>\u003Cli>LSB stands for least significant bit\u003C\u002Fli>\u003Cli>In PNG files, image pixels are typically composed of three primary colors: red, green, and blue (RGB). Each color occupies 8 bits, with a value range from 0x00 to 0xFF, meaning there are 256 possible values per color. This results in a total of 256^3 colors, which is 16,777,216 colors.\u003C\u002Fli>\u003Cli>The human eye can distinguish approximately 10 million different colors.\u003C\u002Fli>\u003Cli>This means the human eye cannot distinguish the remaining approximately 6,777,216 colors.\u003C\u002Fli>\u003Cli>LSB steganography involves modifying the least significant bit (LSB) of the RGB color components, and the human eye does not notice the change before and after.\u003C\u002Fli>\u003Cli>Each pixel can carry 3 bits of information.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Python Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Notable projects on GitHub for learning about LSB steganography:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRobinDavid\u002FLSB-Steganography\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberinc\u002Fcloacked-pixel\u003C\u002Fp>\u003Cp>Testing cloacked-pixel below\u003C\u002Fp>\u003Cp>Test image:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018802152_1_47836c804e-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Source file download URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.easyicon.net\u002Flanguage.en\u002F1119182-Enderman_Png_icon.html\u003C\u002Fp>\u003Ch3>1. Encryption\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py hide big.png 1.txt 123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>hide: indicates encryption mode\u003C\u002Fp>\u003Cp>big.png: PNG image to be encrypted\u003C\u002Fp>\u003Cp>1.txt: stores the payload\u003C\u002Fp>\u003Cp>123456: encryption password\u003C\u002Fp>\u003Cp>After running, generate the image big.png-stego.png\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018808891_2_cc3a1be74d-1.png\">\u003C\u002Fp>\u003Cp>Analyze the format of the encrypted image big.png-stego.png using the check.cpp introduced in the previous article\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Comparison before and after encryption as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815442_3_67620c6d6f-1.png\">\u003C\u002Fp>\u003Cp>cloacked-pixel deletes other data chunks during encryption, retaining only the key IDAT data chunks\u003C\u002Fp>\u003Cp>Using HexEditorNeo to view the encrypted image also confirms our judgment, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018824544_4_e5d0bb9ef4-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, analysis can also be performed by reading the source code\u003C\u002Fp>\u003Ch3>2. Decryption\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py extract big.png-stego.png 3.txt 123456\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>extract: indicates decryption mode\u003C\u002Fp>\u003Cp>big.png-stego.png: PNG image to be decrypted\u003C\u002Fp>\u003Cp>3.txt: stores the exported payload\u003C\u002Fp>\u003Cp>123456: decryption password\u003C\u002Fp>\u003Cp>As shown, successfully decrypted to obtain payload\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018829533_5_b23e2680ac-1.png\">\u003C\u002Fp>\u003Ch3>3. Analysis\u003C\u002Fh3>\u003Cp>Run:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python lsb.py analyse big.png-stego.png\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>analyse: indicates analysis mode\u003C\u002Fp>\u003Cp>big.png-stego.png: PNG image to be analyzed\u003C\u002Fp>\u003Cp>After running, the image will be analyzed, divided into blocks, and the least significant bits of each block will be marked\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018832750_6_92259876cf-1.png\">\u003C\u002Fp>\u003Cp>This is a comparative analysis diagram before and after encryption\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018836161_7_eb6ceb1e70-1.jpeg\">\u003C\u002Fp>\u003Cp>The difference in the images is almost indistinguishable to the naked eye, because the shorter the payload, the smaller the difference in the analysis diagram. Here we can use software to assist in the analysis\u003C\u002Fp>\u003Cp>\u003Cstrong>Tool name:\u003C\u002Fstrong>Stegsolve\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.caesum.com\u002Fhandbook\u002FStegsolve.jar\u003C\u002Fp>\u003Cp>\u003Cstrong>Environment setup:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Install JDK and configure the Java environment\u003C\u002Fp>\u003Cp>Open a.png with Stegsolve, select Analyse-Image Combiner, and choose b.png\u003C\u002Fp>\u003Cp>Perform XOR comparison, as shown in the figure, subtle differences are detected\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018837253_8_82c38ce5b7-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 C++ Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Grant Curell shared a method implemented through C++, which is worth learning, so here we introduce and test it.\u003C\u002Fp>\u003Cp>\u003Cstrong>Article address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F581298\u002FPNG-Image-Steganography-with-libpng\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant Curell\u003C\u002Fp>\u003Cp>\u003Cstrong>Code download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.codeproject.com\u002FKB\u002Fsecurity\u002F581298\u002FPNG_stego.zip\u003C\u002Fp>\u003Cp>\u003Cstrong>Test environment:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 X64\u003C\u002Fp>\u003Cp>vs2012\u003C\u002Fp>\u003Ch3>1. Direct compilation will report an error\u003C\u002Fh3>\u003Cp>The zlib project can be compiled successfully directly\u003C\u002Fp>\u003Cp>Compiling the libpng project, the error is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fatal error C1083: Cannot open include file: 'zlib.h': No such file or directory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add include directory to the project\u003C\u002Fp>\u003Cp>Right-click - Property - VC++ Directories\u003C\u002Fp>\u003Cp>Select Include Directories\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018838199_9_4b0eed0f8c-1.png\">\u003C\u002Fp>\u003Cp>Add zlib-1.2.3, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\..\\..\\zlib-1.2.3;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018839474_10_a8860402ee-1.jpeg\">\u003C\u002Fp>\u003Cp>Compile again, error reported as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fatal error LNK1181: cannot open input file 'zlib.lib'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add lib directory to the project\u003C\u002Fp>\u003Cp>Select Library Directories\u003C\u002Fp>\u003Cp>Add zlib.lib, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\..\\..\\LIB Debug;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, compilation succeeded\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018840585_11_3d5c17235d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Tips:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In Include Directories and Library Directories, absolute paths can also be directly specified (e.g., C:\\test\\cloacked-pixel-master\\PNG_stego\\zlib-1.2.3). This example uses ..\\ to represent relative paths\u003C\u002Fp>\u003Cp>When compiling the project PNG_encode_decode, the same compilation error occurs\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add zlib-1.2.3 and libpng-1.2.37-src under Include Directories, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\u002Fzlib-1.2.3;..\u002Flibpng-1.2.37-src;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add libpng.lib under Library Directories, input:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>..\\LIB Debug;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, final compilation succeeded\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018841544_12_0ae75759f5-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Three project components have sequential dependencies, so the compilation order is zlib-libpng-PNG_encode_decode\u003C\u002Fp>\u003Ch3>2. Encryption Testing\u003C\u002Fh3>\u003Cp>File to be encrypted: big.png\u003C\u002Fp>\u003Cp>Payload file: 1.txt\u003C\u002Fp>\u003Cp>Output encrypted file: bigen.png\u003C\u002Fp>\u003Cp>Modify main.cpp in project PNG_encode_decode as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"PNG_file.h\"\u003Cbr>void main() {\u003Cbr>\u003Cbr>\tPNG_file link = PNG_file(\"big.png\");\u003Cbr>\tlink.encode(\"1.txt\");\u003Cbr>\tlink.outputPNG(\"bigen.png\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, bigen.png is generated as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018843266_13_24e9aeeea7-1.png\">\u003C\u002Fp>\u003Cp>Comparing files before and after encryption shows size differences as illustrated\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018844406_14_37bb02b6b1-1.jpeg\">\u003C\u002Fp>\u003Cp>In principle, LSB steganography does not change file size; investigate the cause\u003C\u002Fp>\u003Cp>Using check.cpp to parse the data chunk directory, several additional tTXt segments were found after encryption\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018845454_15_730c74dded-1.jpeg\">\u003C\u002Fp>\u003Cp>Using HexEditorNeo to view the details of the encrypted image, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018846523_16_a7a31948c3-1.jpeg\">\u003C\u002Fp>\u003Cp>The encrypted image contains some information from the original image, resulting in different image sizes\u003C\u002Fp>\u003Ch3>3. Remove redundant information\u003C\u002Fh3>\u003Cp>\u003Cstrong>Method a:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use HexEditorNeo to directly delete redundant information\u003C\u002Fp>\u003Cp>\u003Cstrong>Method b:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use compress.cpp\u003C\u002Fp>\u003Cp>\u003Cstrong>Download link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Generate encrypted image bigensimple.png with redundant tTXt chunks removed, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018847242_17_50053f896f-1.png\">\u003C\u002Fp>\u003Cp>bigensimple.png has the same size as the original image, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018847822_18_f1a3b9ffdc-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Decryption Test\u003C\u002Fh3>\u003Cp>Modify main.cpp in project PNG_encode_decode as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"PNG_file.h\"\u003Cbr>void main() {\u003Cbr>\u003Cbr>\tPNG_file link = PNG_file(\"bigensimple.png\");\u003Cbr>\tlink.decode(\"2.txt\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After running, 2.txt is generated, obtaining the stored encrypted payload\u003C\u002Fp>\u003Ch3>(5) Analysis\u003C\u002Fh3>\u003Cp>For LSB steganography, Stegsolve can be used for auxiliary analysis\u003C\u002Fp>\u003Cp>After opening the encrypted image, select Analyse-DataExtract\u003C\u002Fp>\u003Cp>Select the 0th bit of Reg, Green, and Blue in Bit Planes\u003C\u002Fp>\u003Cp>Select LSB First in Bit Order\u003C\u002Fp>\u003Cp>Select RGB in Bit Plane Order\u003C\u002Fp>\u003Cp>The encrypted form of the payload can be seen, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018848148_19_a9d21dd9e1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, the encrypted data of the image can be found by reading the program source code. This example only provides some reference ideas for image analysis.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to implement LSB steganography for PNG files using Python and C++ respectively. By following the analysis ideas in the article, common LSB steganography data can also be extracted and analyzed.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The modified PNG_stego project has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>More learning materials:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffgrimme\u002FMatroschka\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwaronpants.net\u002Farticle\u002Fpng-steganography\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwaronpants.net\u002Fpngsteg\u002Ftrunk\u002Fsteg.c\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww1.chapman.edu\u002F~nabav100\u002FImgStegano\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.libpng.org\u002Fpub\u002Fpng\u002Flibpng-1.2.5-manual.html#section-3.1\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.w3.org\u002FTR\u002FPNG\u002F\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1403,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"LSB Steganography in PNG Files: Hide Data in Images","LSB steganography, PNG steganography, data hiding, image encryption, IDAT chunk, cloacked-pixel, Stegsolve",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],293,292,291,289,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.330Z","2026-07-23T16:01:20.544Z","draft","2026-07-23T16:05:06.957Z"]