nop

53 posts

nop

nop

@84464dao

过春风十里,眼中仍为你🎵🎶

Katılım Eylül 2017
313 Takip Edilen8 Takipçiler
nop retweetledi
tetsuo
tetsuo@tetsuoai·
11 hours of reverse engineering, exploit dev, rop chains, custom shellcode, code caves. In 11 minutes.
English
34
86
1K
50.9K
nop
nop@84464dao·
@0xazanul Wwow, congrat bro
English
1
0
0
180
Azanul
Azanul@0xazanul·
the fuzzing continues. recently received a $500 reward for a report that came out of techniques i've been learning and documenting along the way. still experimenting. still learning. #fuzzing #bugbounty #TogetherWeHitHarder
Azanul tweet media
English
11
5
137
6.2K
Medusa
Medusa@medusa_0xf·
Just got rewarded with $3500 on @Hacker0x01 🐍✨
Medusa tweet mediaMedusa tweet mediaMedusa tweet media
English
21
10
486
10.7K
nop
nop@84464dao·
@dp7954 Congrat man
English
1
0
0
62
Dp
Dp@dp7954·
At least, I got feedback...
Dp tweet media
English
13
0
59
5.4K
Essential
Essential@only01Essential·
$3,000 bounty for another chain-halt bug. If exploited, any normal user could have completely halted the chain. Recovery would have required a patch and coordinated network upgrade.
Essential tweet mediaEssential tweet media
English
51
7
362
27.4K
nop
nop@84464dao·
@Kle0z congrat bro
English
0
0
1
83
Kle0z
Kle0z@Kle0z·
This was a 10k USD simple but critical time-based sqli bug i found a while ago, with the help of bbradar.io notifications. > New target went live -> Instant Discord notification > Basic recon > Ghauri against api endpoints > Full db dump Sometimes its as simple as being first.
Kle0z@Kle0z

Finally confirmed!

English
3
18
213
13.2K
Cantina 🪐
Cantina 🪐@cantinasecurity·
$500,000 to @rileyholterhus through Cantina Bounties. 🪐 The researchers who consistently find the bugs that matter don't chase volume. They follow programs where scope is tight, triage is fast, and rewards match actual impact. Well done, Riley!
Cantina 🪐 tweet media
English
34
29
349
46.5K
Habib0x
Habib0x@habib0x0·
Hacking #Agents at Cantina Made my first $1000 bounty today
Habib0x tweet media
English
5
3
144
5.4K
Whitehat Bandit
Whitehat Bandit@banditx0x·
Trying my AI vulnerability researcher 🤖 in the wild. 0 LOC read by a human.
Whitehat Bandit tweet media
English
8
1
172
11.4K
nop
nop@84464dao·
@akokoi1 thank for the feedback. Damn it, if that’s true…
English
0
0
0
1.2K
WY
WY@akokoi1·
浪费了$20帮你们测试了2个席位的ChatGPT team。 结论:不要开!被反撸了,单个账号Codex额度不到Plus会员的四分之一,基本不可用。
WY tweet media
中文
85
11
252
77.5K
nop retweetledi
Shadan
Shadan@skshadan_·
I just gave Claude Code a rooted Android phone… It autonomously reverse-engineered Subway Surfers, hooked the coin logic, bypassed the anti-cheat, and gave itself UNLIMITED coins in ONE session.
English
126
378
5.7K
511.9K
nop retweetledi
Md Ismail Šojal 🕷️
Md Ismail Šojal 🕷️@0x0SojalSec·
Claude Code with agent, autonomously hacked Subway Surfers, and printed millions of coins. A rooted Android phone... and it turned Subway Surfers into a money printer. From 4 coins to 2,000,000+ coins in two runs. autonomous loop, analyzed, and pwned a Unity game in one session, intercepts traffic, bypasses SSL pinning, and even reverse-engineers offline games. The full Setup: Rooted emulator via rootAVD + Magisk + AlwaysTrustUserCerts. Toolchain: UI Automator, mitmproxy traffic capture, Frida bypass scripts, APK static analysis. The agent loops by itself: - Dump screen & UI elements - Tap/swipe via ADB - Analyze traffic or binary - Decide next move without a human. It played the game, reverse-engineered the Unity IL2CPP binary, hooked Frida on SafeInt anti-cheat, and silently multiplied currency. Subway Surfers (com.kiloo.subwaysurf) Almost zero network traffic to agent pivots. Detects Unity IL2CPP parses global-metadata.dat Finds WalletModel, RunSessionData, AddCoins, and SetCurrencySilently. Then hooks with Frida and multiplies rewards ×100+. Result: 4 coins to over 2 million. SafeInt anti-cheat? Bypassed Stealth mode This is the future of mobile pentesting? credit via: @skshadan_ - workers.io/blog/autonomou…
English
11
66
359
33K