I Spent 30 Years Building Trust. Now I Hunt the People Who Fake It.
A file called image.jpg.php isn't an image. And I used to be the guy who made things look like something they weren't.

Part 9 of an ongoing series about my journey. Start with Part 1 here.
image.jpg.php
That's it. That's the whole trick. Two extensions stacked on top of each other, and if you're not looking closely, your eye stops at .jpg and moves on. It's a web shell wearing a costume. Somewhere in an /uploads/ folder, or buried in /tmp/, or sitting quietly in /var/www/html/ like it belongs there, a file is pretending to be a picture so a server will let it through the door.
I spent this week learning to catch that. SQL injection hiding behind a sqlmap user-agent string that gives away the whole game if you know where to look. Cross-site scripting, injecting code into a page so it runs in someone else's browser, using someone else's trust in that page against them. And web shells — the double extension, the weird request methods, the file that shouldn't exist sitting exactly where an attacker would want it to.
Here's the thing nobody tells you when they say "career change." Some skills don't transfer. And some skills were never really about the industry you learned them in. They were about something underneath it, and the industry was just where you happened to practice.
I know how to spot something dressed up as something else. I've known that for thirty years. I just used to be on the other side of it.
Let me be honest about what a Creative Director's job actually is, without the LinkedIn gloss.
You make things look like something they're not, on purpose, for money. A product launch looks like a movement. A discount looks like an event. A brand looks like a friend. None of that is lying, exactly — it's closer to costume design. You dress the truth up so it lands. And the best people in advertising are the best precisely because they understand, at a bone-deep level, what makes something look convincing versus what makes something be convincing. The difference between a headline that reads true and one that reads like copy.
You learn to smell fake from the inside, because you build fake for a living. You learn every seam, every place someone might peek behind the curtain, because it's your job to make sure they don't.
A web shell disguised as an image file is the same move. Someone built something to look convincing to a system that isn't paying close attention. .jpg.php — trust the first extension, ignore the second, let it through. It's a pitch. A bad one, technically, but a pitch: here's a thing, believe what it appears to be, don't check the fine print.
This week, for the first time, I was the one checking the fine print. And it felt like coming home to a room I didn't know I'd already furnished.
The tell, in both worlds, is always in the details nobody bothers to check.
In advertising: does the testimonial sound like an actual human said it, or does it sound like eleven people in a conference room negotiated a sentence? Does the "limited time offer" have an actual limit, or is it permanently ending soon? You get a nose for the places where the construction shows.
In web security this week: does the request pattern match what a real user would do, or is something hitting the server with GET, POST, DELETE, PUT, OPTIONS, and HEAD in a sequence no browser would generate on its own? Is that upload genuinely an image, or is it an image-shaped Trojan horse sitting in a directory that has no business executing code? Does that query in the log go on for four hundred characters, half of it Base64, because nobody writes a real search that long?
Same instinct. Same muscle. Look at the thing that's presenting itself as normal, and ask what it would look like if it weren't.
I've read a lot of SPARC FLOW this month, and there's a line of thinking running through his stuff that I keep bumping into: the attacker isn't smarter than you, necessarily. The attacker is just patient about the details everyone else assumes are fine. That's true of a phishing email. It's true of a web shell. It's also true of a mediocre ad campaign that nobody stress-tested — it works right up until someone actually reads the fine print.
I want to sit with the discomfort of this for a second, because it's real and I'd rather name it than dress it up.
For thirty years, I was good at the thing I'm now learning to hunt. I wasn't writing malware, obviously — nobody got hacked by my Christmas campaign. But the underlying skill, manufacturing something that presents better than it is, is not morally neutral. Advertising runs on it. I ran on it. I was good at it because I understood, intimately, how belief gets constructed and where people stop scrutinizing.
So there's a version of this story that's just redemption arc, and I don't fully trust that version because it's too clean. The more honest version is: I'm not a different person than the one who wrote those campaigns. I'm the same pattern-recognition, aimed somewhere else. The skill was never good or bad. It just needed a target worth aiming at.
This week gave me one. A file lying about its extension. A request lying about its intent. A shell hiding in a directory, patient, waiting for nobody to look closely enough.
I looked closely. That's the job now.
There's a version of me — 1987, a Commodore 64, a bedroom in Germany — who would've loved this. Not the advertising years. This part. Finding the thing that's pretending, and pulling the thread until the pretending falls apart.
Turns out the C64 kid and the guy who wrote thirty years of ad copy were building the same skill from two different directions. One learned to construct convincing fictions. The other is learning to dismantle them.
I contain both now. Some days that feels like a contradiction. Most days it just feels like the job.
image.jpg.php isn't a picture. I know that now, professionally, in a way I only used to know instinctively. That's the comeback, in one file name.






