Taking over 60k spyware user accounts with SQL injection
Background#
Recently I was looking through a database of known stalkerware services and found one I wasn’t familiar with: Catwatchful. It seemed to be a full-featured Android spy app, to actually be its own service as opposed to a millionth FlexiSpy reseller, and to offer a 3-day free trial. Aside from a boilerplate disclaimer to only use it with consent, it also pretty brazenly advertised itself as stalkerware in the FAQ:
Q: Can I monitor a phone without them knowing?
A: Yes, you can monitor a ...
Read more at ericdaigle.ca