There is another, more fancy option: the shell code can be stored in JPEG metadata.
See the example below.
Download this picture and view it with a hex editor or any graphic viewer which is able to view the metadata.
Anything suspicious in EXIF? ;) This would work exactly the same way as example above...