SMJS

736 posts

SMJS banner
SMJS

SMJS

@SMJSGaming

23 | I modify games in my free time. Discord: @smjs

Katılım Şubat 2019
42 Takip Edilen586 Takipçiler
Sabitlenmiş Tweet
SMJS
SMJS@SMJSGaming·
GDIntercept is out for most platforms including: - Android (32/64 bit) - Windows - Macbook (M1 chipset)
SMJS tweet media
English
3
8
315
47.9K
SMJS
SMJS@SMJSGaming·
@ZURC_99 I mean you're surprised? This would be far from the first time encryption methods had a universal key. By now I've just come to expect this from tools which aren't public source.
English
1
0
1
25
Cruz
Cruz@ZURC_99·
@SMJSGaming Speaking of Windows did you hear about the possible back door that they found for BitLocker lol
English
1
0
0
33
SMJS
SMJS@SMJSGaming·
Gotta love it when you spent 5 days debugging just to find out that your hook was partially inlined on Windows making it pretty much useless (images shown is the uses of the method on Windows VS Android)
SMJS tweet mediaSMJS tweet media
English
1
0
4
121
SMJS
SMJS@SMJSGaming·
@bakathesussy Besides the subdomains which are already there what for?
English
0
0
0
507
:3
:3@bakathesussy·
@SMJSGaming make a robtopx email or subdomains please 🙏🙏
English
1
0
1
1.2K
SMJS
SMJS@SMJSGaming·
#GeometryDash So currently I have all the Android app IDs robtop uses for his GD variants connected to my Discord account (I own the domain)
SMJS tweet media
English
8
8
463
22.2K
SMJS
SMJS@SMJSGaming·
@1aubreygraham1 Likely just following the trend back then of everything having an X in the name
English
0
0
13
1.6K
xenon
xenon@1aubreygraham1·
@SMJSGaming why does he even have the X in the package name
English
1
0
6
2.5K
SMJS
SMJS@SMJSGaming·
@ddeaen Nah they redirect to Geode
English
1
0
55
3K
deaen
deaen@ddeaen·
@SMJSGaming redirect it to very scary jumpscare malware scam
English
1
0
6
3.2K
SMJS
SMJS@SMJSGaming·
Just realized it's geometryjumplite rather than geometrydashlite so fixing that small error right now
English
0
0
57
3.5K
Finelb
Finelb@finobedoticu·
@SMJSGaming @brint is he really relying on Cloudflare to prevent sql injection?
English
1
0
0
87
SMJS
SMJS@SMJSGaming·
#GeometryDash So considering RobTop never did the due diligence he should have as a European company to report what was leaked. I may as well just reveal one thing I kept secret for quite a while to not immediately soil his reputation. In the DB leak were unencrypted passwords.
English
39
108
1.2K
76.6K
SMJS
SMJS@SMJSGaming·
If you think about it. Some of the most critical logins on the web (sftp & ssh which are the protocols to remotely communicate with a server) don't support 2 factor authentication. Kind of a scary thought).
English
3
0
10
606
SMJS
SMJS@SMJSGaming·
@33YYYYYYY @chrissvector @RobTopGames 1) 2 way obfuscation is useless 2) Nah, most apps use a one time access token which can be revoked at any time when it's compromised. Besides no party involved should have any reason to leave a password 2 way encrypted/encoded since you should test against the hash.
English
0
0
1
41
❄️ __felix__
❄️ __felix__@33YYYYYYY·
@chrissvector @SMJSGaming @RobTopGames dude, 1) the password in the save file is somewhat obfuscated and 2) you're SUPPOSED to store passwords locally (such as in cookies). ALL apps with authenication store it locally unencrypted (or decryptable by one with access to your computer which is essentially that)
English
1
0
1
100
SMJS
SMJS@SMJSGaming·
@ArcadiacManiac @ClingingBogGMD @tricipital14 Anyone confirmed compromised through this person's messages was already informed. But unless RobTop goes through the SQL logs (which sadly he isn't doing) I have no way to confirm the scale of the exploit abuse.
English
0
0
0
186
SMJS
SMJS@SMJSGaming·
@ArcadiacManiac @ClingingBogGMD @tricipital14 Due to sensitivity on this topic I'm not providing anything identifiable but please refer to my reply on the top comment in this thread to explain how non temp this really is.
English
1
0
0
149
Arcadiac
Arcadiac@ArcadiacManiac·
@SMJSGaming @ClingingBogGMD @tricipital14 “This same person also got into a bunch of accounts at the time” could you list examples because if so then yea maybe there’s some legitimacy to those login details. But I highly doubt a table named “temp” would contain actual user data
English
1
0
3
147
SMJS
SMJS@SMJSGaming·
@ArcadiacManiac @ClingingBogGMD @tricipital14 This same person also got into a bunch of accounts at the time, so there's a high likelihood that they used this same table or used a login bypass trick you can execute when you have read access to the DB.
English
1
0
0
173
SMJS
SMJS@SMJSGaming·
@ArcadiacManiac @ClingingBogGMD @tricipital14 Currently the person from who we found evidence of knowing about this exploit before pen testers got to it has been inactive. I've always said that it's currently unknown to what extend the breach was abused. Just that the possibility of this data was leaked.
English
1
0
0
345
SMJS
SMJS@SMJSGaming·
@tricipital14 Basically rob seems to have made this table to find common passwords bots check for so that he can blacklist these. However, he just straight up captures raw login inputs from anyone to achieve this. This table has also existed for years.
English
0
0
6
983
tri
tri@tricipital14·
@SMJSGaming So the table you had access to was called "tempLoginTest" ? Can you give a little more info because a leak of a table with both "Temporary" and "Test" in the title implies that the data inside is worthless or not worth causing a panic over
English
6
0
15
3K
SMJS
SMJS@SMJSGaming·
@greyogd He did in the sense that he immediately patched it once it was reported. But when I told him that others had also found it and that he legally has to disclose that publicly he completely ignored it.
English
0
0
16
854
Greyo
Greyo@greyogd·
@SMJSGaming how tf he didn't even care about that
English
1
0
0
851
SMJS
SMJS@SMJSGaming·
@Ripnium It has been running for years and actively inserting data so I wouldn't call it temporary at all
English
1
2
13
3.1K
SMJS
SMJS@SMJSGaming·
@greyogd It was from February but I kept silent about plain text passwords to give RobTop the chance to disclose it properly. Because he didn't I decided to just put that out there.
English
1
0
14
2.7K
Greyo
Greyo@greyogd·
@SMJSGaming Is this new leak from today or something older
English
1
0
0
3.1K
SMJS
SMJS@SMJSGaming·
I reported the fact that RobTop hasn't disclosed anything to IMY (The Swedish privacy protection authory).
English
1
3
79
5.7K
SMJS
SMJS@SMJSGaming·
When I briefly had access to the DB I managed to find one table filled with raw logins called tempLoginTest which had the following columns: - accountID - date - password - username These were raw login inputs which were likely captured and immediately put into the DB on login.
English
1
6
250
12.6K
SMJS
SMJS@SMJSGaming·
@arnthorrr that was just bruteforce
English
0
0
2
206
gg
gg@arnthorrr·
@SMJSGaming is this how teamtuff hacked accounts or was that just bruteforce
English
3
0
3
442