bendbot
523 posts

bendbot
@bendbotbtc
Lost all my Bitcoin on Spanish Galleon San Jose. tpm2_getrandom --hex 32 #trustmebro 😉







Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

@nvk apparently, that still is the psychotic marketing they are using.


アメリカのアニキ達、 自分はJDFで5年勤務して、今は日本のエアソフターなんだ。 日本では本物が持てないからBBガンで我慢するしかないから。 だから俺に本場のアニキ達の自慢の銃を見せて欲しい。 .50calを撃ちたいとも言ったが 俺が好きなのは45の1911とSAAなんだ。


The Cubs broadcast showed fans working remotely from Wrigley Field during the team's day game 💻















