[Journey] Let's exploit a site for $10m! AI for the win!

Status
Not open for further replies.

DarkerAds

BANNED
Joined
May 1, 2023
Messages
568
Reaction score
1,040
NOTE: In this thread I'm not going to openly discuss anything that is against BHW TOS nor talk about ways to "hack" a site or something that is illegal.
NOTE2: I tried searching for a bug bounty program of sorts, but there is none, so it's game on! :D

THOUGH, I will be discussing how to protect your site, discuss defense techniques and how I will proceed with this exploit.

For obvious reasons, I will be very vague in many aspects, to hide several aspects of my operation.




With that being said, hopefully you find lots of good educational content in this thread regarding DEFENSE and hope you learn to never let your guard down.


Anyway, in any case, as a little bit of history about me, I've been on this scene for many years and from time to time I've discovered exploits where I've made quite a bit of money. I won't tell exact amounts, but I can tell you that I'm quite knowledgeable when it comes to take max profit out of systems and staying under the radar.

When it comes to exploits, you can go two ways, the one huge hit, or you can go long term, staying under the radar to try and get the most out of it.

The way you choose between those options is to really analyze which option can give you the most profit.

Sometimes going big and taking one big hit is better than the longterm option, but if you can really stay under the radar and execute with perfection, then the long term option is the best one.


I'm not going to give details on what kind of exploit I found or how I execute as it's against BHW TOS, so unfortunately, I can't discuss any of that here.

As a programmer, I know how the systems work behind the scenes and how usually things should work.

It's fun when I think I found an exploit but it gets patched the moment where it could be profitable.

Also, in some exploits, automation is key, and sometimes just real human interaction is better. It depends on the task at hand


Nowadays, AI has been an incredible assistant on creating code that I've been using it for quite some time now. AI speeds up things.

Right now, for the exploit I'm working with, it can be automated and to do the automation I had to learn a lot, and with the help of AI, I learned what I needed to learn in record time.

Last time I needed to learn a new skill, it took me a few weeks, but now with AI, I learned it in a couple of days which is insane!



Anyway, the goal of this journey is to reach $10m in profit.

The way to go is to go long term and stay under the radar, as going with a big hit would yield a lot lower reward (maybe 3-4 figures LOL!), so going the long term way is the way to go.

The funny thing about this is that I believe that the management knows about this, but they don't think it's a serious risk. Fortunately, for me, I know how to execute, how things work and how to make it profitable.



Before automating, I had to truly go by hand and actually test the ins and outs of this to test the limits and see how much I can actually make.

Also, I had to take into account how profitable this is, as if you find an exploit where you can only make say $1-$5/ day, well, maybe it's only worth it you can do it for long term and 100% on autopilot

In any case, I found the limits of this and know to execute with perfection. Now, I have to keep working on my automation task to literally make money online hands-off



In short:

- Found an exploit
- Know how to make it profitable and worth it
- Working on automating it
- Stay under the radar
- Take max profit!


As of now, I found the exploit, found the limits, I know to execute at perfection and now I'm working on a way to automate it and get it up and running.

Key challenges:

- Staying under the radar. If you appear on the radar it's game over.
- Automate at perfection. Too many variables, but with enough workarounds and "hotfixes", I believe it can be done


AI is king when it comes to automation and working things out.

Profit as of now: Enough to know that this is profitable after automating at perfection. AI is an incredible help when it comes to this.

Stay tuned
 
Best of luck, But the things you are doing, you wont be able to share it properly. We would love to know the monetization part.
 
sounds interesting,

Is it an app or site?
site
Man, what are you talking about? Believe me, I'm dizzy. So much talk, but nothing. This must be art.
in very short, I'm exploiting a site and will take max profit ;)
Best of luck, But the things you are doing, you wont be able to share it properly. We would love to know the monetization part.
I won't be able to share a lot of things due to BHW TOS, but I will be discussing how to test systems and how to profit.

-------------

So far, the profits are in the range of around $500. Sure, not big, but remember that this is literally free money, and this number will skyrocket once I have the automation part done which should take a few days or a couple of weeks tops.

In the meantime, I found several defenses and I found ways to bypass them and on the way I literally, managed to find a way to almost TRIPLE the yield with the same tactics. I really can't wait to have the automation part done and really start making real dough. Until I have the automated part ready, I will keep doing this the old fasion way, by hand :D
 
$10 million, eh, from an exploit? This journey was started at the same time the boss of MS warned of AI Psychosis. lol
 
is it a gambling site or what? what KIND of site are you exploiting?
 
NOTE: In this thread I'm not going to openly discuss anything that is against BHW TOS nor talk about ways to "hack" a site or something that is illegal.
NOTE2: I tried searching for a bug bounty program of sorts, but there is none, so it's game on! :D

THOUGH, I will be discussing how to protect your site, discuss defense techniques and how I will proceed with this exploit.

For obvious reasons, I will be very vague in many aspects, to hide several aspects of my operation.




With that being said, hopefully you find lots of good educational content in this thread regarding DEFENSE and hope you learn to never let your guard down.


Anyway, in any case, as a little bit of history about me, I've been on this scene for many years and from time to time I've discovered exploits where I've made quite a bit of money. I won't tell exact amounts, but I can tell you that I'm quite knowledgeable when it comes to take max profit out of systems and staying under the radar.

When it comes to exploits, you can go two ways, the one huge hit, or you can go long term, staying under the radar to try and get the most out of it.

The way you choose between those options is to really analyze which option can give you the most profit.

Sometimes going big and taking one big hit is better than the longterm option, but if you can really stay under the radar and execute with perfection, then the long term option is the best one.


I'm not going to give details on what kind of exploit I found or how I execute as it's against BHW TOS, so unfortunately, I can't discuss any of that here.

As a programmer, I know how the systems work behind the scenes and how usually things should work.

It's fun when I think I found an exploit but it gets patched the moment where it could be profitable.

Also, in some exploits, automation is key, and sometimes just real human interaction is better. It depends on the task at hand


Nowadays, AI has been an incredible assistant on creating code that I've been using it for quite some time now. AI speeds up things.

Right now, for the exploit I'm working with, it can be automated and to do the automation I had to learn a lot, and with the help of AI, I learned what I needed to learn in record time.

Last time I needed to learn a new skill, it took me a few weeks, but now with AI, I learned it in a couple of days which is insane!



Anyway, the goal of this journey is to reach $10m in profit.

The way to go is to go long term and stay under the radar, as going with a big hit would yield a lot lower reward (maybe 3-4 figures LOL!), so going the long term way is the way to go.

The funny thing about this is that I believe that the management knows about this, but they don't think it's a serious risk. Fortunately, for me, I know how to execute, how things work and how to make it profitable.



Before automating, I had to truly go by hand and actually test the ins and outs of this to test the limits and see how much I can actually make.

Also, I had to take into account how profitable this is, as if you find an exploit where you can only make say $1-$5/ day, well, maybe it's only worth it you can do it for long term and 100% on autopilot

In any case, I found the limits of this and know to execute with perfection. Now, I have to keep working on my automation task to literally make money online hands-off



In short:

- Found an exploit
- Know how to make it profitable and worth it
- Working on automating it
- Stay under the radar
- Take max profit!


As of now, I found the exploit, found the limits, I know to execute at perfection and now I'm working on a way to automate it and get it up and running.

Key challenges:

- Staying under the radar. If you appear on the radar it's game over.
- Automate at perfection. Too many variables, but with enough workarounds and "hotfixes", I believe it can be done


AI is king when it comes to automation and working things out.

Profit as of now: Enough to know that this is profitable after automating at perfection. AI is an incredible help when it comes to this.

Stay tuned
@RML loves all about computer security!

Turn a exploit into 10 USD MILLION?

I'M IN! I'M FOLLOWING!

Some updates?

Keep us updated!

By the way, good journey and good luck.

Win!
 
How do you think $10m! is what you would get? Do you think they are going to offer you that amount for the bug or you steal that money from that site anyway? How does it work?
 
We would love to know the monetization part.
Extract max profit. That's the plan
is it a gambling site or what? what KIND of site are you exploiting?
I may disclose this once it gets patched/fixed and no longer works
@RML loves all about computer security!

Turn a exploit into 10 USD MILLION?

I'M IN! I'M FOLLOWING!

Some updates?

Keep us updated!

By the way, good journey and good luck.

Win!
It's like I'm taking the garbage of someone else and making profits hand over fist
How do you think $10m! is what you would get? Do you think they are going to offer you that amount for the bug or you steal that money from that site anyway? How does it work?
maybe $1m is a little bit too high, maybe a more realistic can be $300k-$2m or so at the highest end. But we will see
 
  • Like
Reactions: RML
Interesting read, didn't find much in OP. Is this in crypto like mev or something?
 
Interesting read, didn't find much in OP. Is this in crypto like mev or something?
Unfortunately, at this time I can't discuss the nature of the site until it gets patched.

---------


UPDATE

Yesterday was quite a productive day
I managed to create the first version (v1) of the automation code, and unfortunately, it can only do the first part of the exploit as the second part requires a lot more precision which is really hard to do, but I hope I can get it done in time.

So, for now, the code is running 100% on autopilot, making profit 24/7 and now the time has come where I have to be careful with my greed as if I come up too strong too fast, I could trigger all sorts of alarms, etc, so that's something I have to be careful with.

I have to stay under the radar

Also, now I have to focus on the v2 where the code executes the first part and second part at perfection. Part 1 is already done at perfection with all the caveats, tricks and ways to bypass them.

At this time, I think this code can generate around $100-$300 a day in it's current state but I have to be careful as to when I can scale, if at all as I don't want to trigger the management just yet.

Maybe, I can keep running this code until I have a sizable $$$ in the bag, and then I could approach management and try to negotiate a "bug bounty" reward and show them how this works and how to patch it.

But we will see
 
  • Like
Reactions: RML
UPDATE


First time I meet with the first line of defense! :D

It took a while to trigger it but I finally triggered a response.

Far from the end of the world and bypassing the line of defense was a piece of cake :D
 
It wasn't a line of defense, it was a simple spam filter :D
Easily bypassed
 
Being found by a spam filter doesn't mean they found the exploit. It just means that what I'm doing is triggering spam filters, so I have to be more stealth in my approach, which means it will take a little bit of tweaking to my set up, but in the end, it's all about running this as far as I can without being detected.
 
Status
Not open for further replies.
Back
Top