Abdel

1.8K posts

Abdel banner
Abdel

Abdel

@rockkdev

cto @cubbylaw, prev. edge security @vercel

Los Angeles Joined Temmuz 2015
266 Following1.4K Followers
Abdel
Abdel@rockkdev·
@winhelpwin Dots "." are treated as a sorta invisible character to the Gmail parsing system, so warriorsFan[at]gmail[dot]com with 1 or more "."s anywhere in the "warriorsFan" portion will be ignored and still forwarded to the original email
English
3
1
97
62.2K
winhelpwin
winhelpwin@winhelpwin·
@rockkdev Sorry if this is a dumb question but can you elaborate what (1) means? If my email is warriorsFan[at]gmail[dot]com what would the “Gmail dot trick…” be?
English
12
0
19
70.9K
Abdel
Abdel@rockkdev·
New Robinhood phishing chain that's kinda beautiful: 1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address) 2. Sets device name to HTML 3. RH's "unrecognized activity" email renders the device name unsanitized (html injection) The result is a real email from noreply@robinhood.com, DKIM pass, SPF pass, DMARC pass, with a phishing CTA Just because it's real, doesn't mean it's safe... $HOOD
Abdel tweet mediaAbdel tweet mediaAbdel tweet media
English
178
366
3.8K
2.9M
David Gobaud
David Gobaud@davidgobaud·
@rockkdev Steps probably wrong. No need to make account. They hacked @RobinhoodApp SendGrid @twilio or somehow got a Robinhood domain confirmed @vladtenev
David Gobaud@davidgobaud

Robinhood's email service SendGrid (not on 𝕏 🤦‍♂️) @twilio is hacked or somehow verified a robinhood\.com domain sending out phishing emails @RobinhoodApp @AskRobinhood Received: from http://o2\.email.robinhood.com (http://o2\.email.robinhood.com. [50.31.40.73])

English
3
7
97
97.7K
Abdel
Abdel@rockkdev·
@linguinelabs Yeah; this is one of those things that seems obvious in retrospect, but honestly really easy to miss as an engineer
English
1
1
182
36.8K
Kevin
Kevin@linguinelabs·
@rockkdev So this would be fixed with proper sanitization right
English
2
0
123
40.8K
Abdel
Abdel@rockkdev·
@bmgentile Yes, HTML injection via the device name. Basically XSS with no scripting, just HTML. I did check, the URL is a phishing URL, albeit I refrained from linking it.
English
3
3
202
66K
brady 🌴
brady 🌴@bmgentile·
@rockkdev hold on, but when you click the CTA link from the legitimate Robinhood email (which you received for their Gmail account that routes to you)… how can there be an outcome which results in your creds being compromised? Are they somehow injecting a URL into the email’s CTA..?
English
6
0
72
80.3K
Abdel retweeted
Truman Sacks
Truman Sacks@trumansacks1·
Day 1! Come say hi if you are in NYC this week! 🏇
Truman Sacks tweet mediaTruman Sacks tweet media
Truman Sacks@trumansacks1

Excited to share we’ve raised $2.75M for @CubbyLaw from @LudlowVentures, @SamHinkie, and @PSUMVC. We’re building the first AI teaching assistant for law students, powered by our own legal intelligence model trained on thousands of professors’ syllabi, past exams, outlines, and grading rubrics. Cubby started as a horizontal AI research tool, but when law students began adopting it fast, we went all in. Law school prep is broken: • Curve-based grading • 100+ hrs building outlines • Legacy tools students still pay thousands for Cubby brings it all into one connected workspace: case briefs, outlines, and practice exams, calibrated to how your professor teaches and tests. Law school is our first step toward a new era in legal tech.

English
5
1
87
17.4K
Abdel
Abdel@rockkdev·
Excited to be apart of this 🏇
Truman Sacks@trumansacks1

Excited to share we’ve raised $2.75M for @CubbyLaw from @LudlowVentures, @SamHinkie, and @PSUMVC. We’re building the first AI teaching assistant for law students, powered by our own legal intelligence model trained on thousands of professors’ syllabi, past exams, outlines, and grading rubrics. Cubby started as a horizontal AI research tool, but when law students began adopting it fast, we went all in. Law school prep is broken: • Curve-based grading • 100+ hrs building outlines • Legacy tools students still pay thousands for Cubby brings it all into one connected workspace: case briefs, outlines, and practice exams, calibrated to how your professor teaches and tests. Law school is our first step toward a new era in legal tech.

English
2
0
3
760
Abdel
Abdel@rockkdev·
@stockxsucks you're just hanging around the wrong areas 💯
English
1
0
1
140
Abdel
Abdel@rockkdev·
@pookybypass 👀 their cold pressed juices and protein smoothies are actually pretty good
English
0
0
1
148
Abdel
Abdel@rockkdev·
LA is under appreciated
Abdel tweet mediaAbdel tweet mediaAbdel tweet mediaAbdel tweet media
English
1
0
5
2.9K
Abdel
Abdel@rockkdev·
@cultured Built a Minecraft server
English
0
0
6
216
Steven Schwartz 🦅
Steven Schwartz 🦅@cultured·
If you were a kid that: 1/ Jailbroke your phone 2/ Resold sneakers 3/ Dropshipped 4/ Played crypto dice 5/ Sent your iOS UDID to someone 6/ Made a big commerce store 7/ Used Limewire Like this tweet What am I missing?
English
39
3
630
33.7K
Abdel
Abdel@rockkdev·
@B_nnett @AppStore A few apps I have just make this a secret. The main app is free and has limited demo/free functionality. You then go to settings, press and hold an unrelated icon or piece of text, and then the license box pops up.
English
0
0
0
284
Bennett
Bennett@b_nnett·
how do i get around this on @AppStore review? building a companion app, and they've rejected it due to having license key sign-in?
Bennett tweet media
English
7
0
1
2.1K
Abdel
Abdel@rockkdev·
@aycdjake Some drop shipping stores probably do more revenue 😭
English
0
0
1
132
aycdjake
aycdjake@aycdjake·
Can yall be done with the Hellstar meat riding already 🤣 They think they are 2019 Supreme 😭
aycdjake tweet media
English
26
5
141
47.4K
Abdel
Abdel@rockkdev·
I have so many things I want to create that I end up getting put in a mental gridlock where I don’t create anything.
English
0
0
11
1.6K
Abdel
Abdel@rockkdev·
@umasiii Childhood dream from 2015 secured
Abdel tweet media
English
0
0
0
200
Abdel
Abdel@rockkdev·
Throwback to when I found a bypass to Adidas splash. It worked because Adidas development team still returned developer cookies on a GET to the staging splash page, even with invalid auth. I'd GET staging, take the hmac, transfer to the live domain, and bypass splash.
Abdel tweet media
English
8
1
119
28.9K
Abdel
Abdel@rockkdev·
@B_nnett Yeezy Mafia, Sole Slayer, AIOBot, OG YZYlab, Heatedsneaks refresh bypass, Wrath Adidas (Wrath logo is Adidas upside down), and way, way, way more. Been in the botting game since 16' and sneakers since 15', and I have seen a lot in that time. Way too much to list.
English
0
0
5
500
Bennett
Bennett@b_nnett·
before i start researching am i missing any key era's
Bennett tweet media
English
34
1
193
36.8K
Abdel
Abdel@rockkdev·
@stockxsniper The fact this isn’t even a meme 😭
English
0
0
9
2.8K
nik
nik@stockxsniper·
i once asked Adam 22 to take a picture of me thinking he was just a random dude, instead he took a video of me roasting me on his story
English
10
1
161
39.2K
Abdel
Abdel@rockkdev·
@3liet I think that this is the problem. The Ivy League and similar have a leg up mentally. You're not even given a shot with interviews otherwise. The people I know who DID find a way to get an interview had amazing results. It's that first leg that's the hardest.
English
0
0
3
1.6K
Eliot
Eliot@3liet·
@rockkdev Have to sell yourself well and have a college education tbh. You can compete with Ivy League kids with sneakers on your resume, just have to have all the other boxes checked off as well.
English
1
0
7
2K
Abdel
Abdel@rockkdev·
The undervaluing of sneaker devs in the corporate world is mind boggling to me. Recruiters literally have a cheat code to the brightest minds yet they don’t use it.
English
16
1
82
52.7K