Bit_Jon_Trade
4.7K posts









Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

🚨 CYBER THREAT INTELLIGENCE ALERT: ALLEGED CRITICAL COMPROMISE – CENTRAL BANK OF BRAZIL (BCB) An offer has been detected for the sale of alleged administrative access (unverified) to the portal sta.bcb.gov.br—a critical hub for the Financial System Network (RSFN) and the PIX payment ecosystem in 🇧🇷 Brazil. 👤 Threat Actor: pstipwner 📍 Target: Central Bank of Brazil (BCB) / PSTI (Information Technology Service Provider) 🔑 Incident Type: Network access sale / Alleged administrative credential breach. 📉 Verification Status: PENDING. No definitive technical samples (PoCs) have been published, although the actor claims to have established persistence and alleges prior sales of certificates. Monitor: analyzer.vecert.io #Cybersecurity #PIX #CentralBank #Brazil #ThreatIntelligence #PSTI #CyberAttack #VECERT #DarkWeb #InfoSec #UnverifiedAllegation

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.


Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.



Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.





Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.




Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.


The bitcoin faucet is back. 04.06.26 btc.day

Ok so.. they left their CDN exposed. If you ping the domain, you get this ip: 151.101.129.49 It turns out this is a fastly.com IP . I had never heard of fastly but it looked to be something similar to vercel, so I figured maybe they had custom deployment links like vercel does. Tried a few different combos and BINGO: btc.day.global.prod.fastly.net This took me to this: d325bmwzjz2yc7.cloudfront.net That’s their CDN bucket on AWS. They currently have it setup so that any invalid endpoints redirect back to index.html I went on a hunch and figured that they’d probably already have their production app stored somewhere in the CDN ready for deployment I used SECLISTs (github.com/danielmiessler… )and ffuf to try out over 20k different combinations on this URL. After some sleuthing, BINGO!! I found these two files: > live.html > .DS_STORE The important one here that immediately caught my eye was “live.html”. That sounded like a prod deployment. And sure enough, it was! This is what the btc.day site will look like on the day the faucet goes live: d325bmwzjz2yc7.cloudfront.net/live.html d325bmwzjz2yc7.cloudfront.net/bitkey.html It turns out the entire faucet will be revealed to just be a promotion scheme to get you to buy a bitkey and use cash app. There is no faucet - at least in the sense most were expecting.

In 2010, this website would give away 5 #Bitcoin per visitor for free. 5 #BTC is worth $334,000 today. Jack Dorsey's Block is now launching a faucet in two days to give out free bitcoin 👀














