HomeSecurityHidden backdoor in the EXIF ​​data of the Joomla CMS logo

Hidden backdoor in the EXIF ​​data of the Joomla CMS logo

Security researchers at Sucuri, a company specializing in providing security solutions to website owners, have discovered a clever trick used by hackers, who managed to hide a backdoor in one of the most innocent places, the Joomla CMS logo.

Hidden backdoor in the EXIF ​​data of the Joomla CMS logo

The researchers found the backdoor on a previously infected website, which they had just analyzed at the time.

The backdoor was base64 encoded and added to the copyright field of the Joomla CMS JPEG logo, within the EXIF ​​metadata of its header.

This image is normally displayed via the application.php file, in which the hackers modified the line of code from where the logo was loaded, adding a function that ensured the EXIF ​​data was read and executed by the CMS.

While this ensured that the backdoor would be executed on the infected websites, it was also the sign that betrayed the hackers.

Unlike other cases where code was hidden within images, in this particular case, the attackers managed to embed their backdoor code into the JPEG file without corrupting the final image.

Hidden backdoor in the EXIF ​​data of the Joomla CMS logo

 

This is not the first time security researchers have found malicious code hidden in images.

In computer science theory, the technique of hiding data inside an image is called steganography and has been used many times in the past. Specifically, there have been a number of cases in the past, including the information thief, Stegoloader, which hides in PNG files and the Vawtrack banking Trojan which hides in file icons.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS