Your firewall sees Spotify traffic.
It may not see a command channel.
Came across SpotifyC2, a Windows security research PoC that uses:
- Spotify playlist titles to deliver commands
- A local client to execute them
- Telegram to return the output
No traditional C2 server.
No obviously malicious infrastructure.
Just trusted cloud services being used in ways defenders may not expect.
A useful reminder: allowlisting a domain does not mean the activity behind it is safe.
Interesting research for anyone working in threat detection, EDR, network security, or cloud abuse detection.
Tool: https://t.co/cknPN7q7BY
🔥 Ok, levantamos una herramienta simple pero potente, permite consultar si un RUT determinado aparece en la filtración de casi 250.000 credenciales de #ClaveUnica expuestas en Telegram (#Rutify).
🔹 https://t.co/l4ipVS6R7Z
📢 Si puedes, COMPARTE, quizás alguien cercano lo necesite y aún no lo sepa.
Hi, it's tuts-for-nerds giveaway ??? (lost track of giveaways)
Our friends at @MalDevAcademy hooked us up with x3 lifetime access plans and x3 database access plans
Thank you, mr.d0x and friends for hooking us up and supporting our giveaways.
If you'd like to learn about malware development, leave a comment below
- Winners will be selected randomly in the next 24 hours.
- We will DM winners.
- If you do not confirm your win in 24 hours a new winner will be selected
- If your DMs are closed, you automatically forfeit your prize
Have a nice day
Sql injection is not necessary inject at payload,
You can inject in path
Path: /en/gallery/1
POC: en/gallery/1'XOR(if(now()=sysdate(),sleep(3),0))OR'
#bugbountytips#bugbounty
Big thanks guy's for help
If the second parameter is vulnerable and you want to test it, copy request from burp than put it in sqlmap
command: sqlmap -r request.txt --dbs --random-agent --time-sec=12 --level=1 --risk=1
don't forget to put * at parameter value
#bugbountytips
@PublimetroChile La loca más agresiva del reality, pasándose rollos desde el día 1 , no reconoce errores tóxica a cagar la inconsecuencia siendo persona
EDRSandblast-GodFault: a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Notify Routine callbacks, Object Callbacks and ETW TI provider) and LSASS protections https://t.co/aKaAzjzNAi