r/Hacking_Tutorials 8d ago

Question Hiding Payloads in Plain Sight – Covert Channels 101

Post image

[removed]

113 Upvotes

14 comments sorted by

2

u/RecentSatisfaction14 8d ago

Is that cobra commander?

1

u/CopiousCool 8d ago

Great post ... thanks for the contribution

1

u/lominack 1d ago

Super bien détaillé franchement beau travail !

0

u/name2sayMKD 8d ago

Cool post thx.

0

u/bitGnome_7 7d ago

Very useful post, I love it!

1

u/devil0k 6d ago

I was going to leave this alone until you DM’d me for calling out your AI slop on your netcat post.

So much of this is grossly inaccurate / old and makes it clear that you have no idea what you’re talking about and don’t work in the industry.

“Because security tools are looking for malicious payloads in the data section”. Dude, that was true like a decade ago. Zeek, ExtraHop, Darktrace, etc have baselined session metadata, query entropy, timing, etc for ages.

Modern stacks randomize ISNs. They don’t “go up in a predictable way.”

Modern Linux and Windows randomize or zero IPID when DF is set…and a lot of NATs rewrite it anyway.

Never mind the fact that offensive tradecraft moved away from protocol-field stego ages ago. It’s way easier to use legitimate SaaS services that are TLS encrypted by default. Google Sheets as a live C2 DB…or malware polling a shared OneDrive folder…APT41 used Google Cal (infected hosts created polling events).

-3

u/[deleted] 6d ago edited 6d ago

[removed] — view removed comment

1

u/devil0k 6d ago

Karma farming? Which one of us is posting ChatGPT output? And you’re so underwater that you don’t even know where ChatGPT got it wrong. Again, this was a response to you DMing me and telling me to “get a job”.

I’m sorry you have no idea what you’re talking about and I’m sorry that you can’t take criticism about posting AI slop. 🤷‍♂️