An Empirical Analysis of Parser Divergence and Structural Evasion in JPEG-Based Polyglot Files
DOI:
https://doi.org/10.69667/f69wpq57الكلمات المفتاحية:
Parser Divergence, Polyglot Files, JPEG Metadata Exploitation, File Upload Security, Structural Evasion, ExifTool, Malware Detection Evasionالملخص
Traditional file-security models rest on an assumption that a binary object has one identity, verified once at the boundary of a system. This paper examines a structural weakness that breaks that assumption: parser divergence, the phenomenon by which two independent interpreting engines apply contradictory rules to the same byte stream and arrive at two mutually exclusive, and equally valid, conclusions about what the file is. We show that this divergence can be deliberately engineered, rather than discovered by accident, to build a single binary object that satisfies the structural expectations of a standard image viewer while simultaneously carrying a fully executable command sequence. The mechanism exploited here is the error-tolerant design mandated by the JPEG specification itself (ITU-T T.81, 1992): decoding engines are required to skip unrecognized data blocks rather than reject the file outright, a rule intended to preserve compatibility with minor transmission corruption or vendor-specific metadata. A proof-of-concept file was constructed by embedding a Windows batch payload inside the comment segment (marker 0xFFFE) of a standards-compliant JPEG image using ExifTool [4], a Perl-based metadata utility. The resulting object renders as an ordinary photograph in every image viewer tested, yet executes the embedded command sequence when the same bytes are read by the Windows command interpreter.
التنزيلات
التنزيلات
منشور
إصدار
القسم
الرخصة
الحقوق الفكرية (c) 2026 مجلة القلم للعلوم

هذا العمل مرخص بموجب Creative Commons Attribution 4.0 International License.





