[Journey] Let's exploit a site for $10m! AI for the win!

Status
Not open for further replies.
Its either sports betting or crypto gambling related, yes or no?
 
It would be more useful to create a real case study about it when it's patched. ''How I earned $10M (or whatever amount you earn after all) exploiting a website''

This journey seems a bla bla bla generator, the real questions can't be answered, people will just keep trying to guess what is it, OP will keep saying ''for privacy reasons, bla bla bla'' and nobody will learn anything from it, just vague updates.

Whatever, good luck exploiting it, someone tag me here when it's finally patched and the important questions are finally answered
 
It would be more useful to create a real case study about it when it's patched. ''How I earned $10M (or whatever amount you earn after all) exploiting a website''

This journey seems a bla bla bla generator, the real questions can't be answered, people will just keep trying to guess what is it, OP will keep saying ''for privacy reasons, bla bla bla'' and nobody will learn anything from it, just vague updates.

Whatever, good luck exploiting it, someone tag me here when it's finally patched and the important questions are finally answered
I absolutely will do that. Will ping you once that's done, though, that might be weeks or months away (or heck it could be tomorrow for all i know)
10M ???
It's an imaginary number :eek:
a more realistic number could be something like $10k in the lowest end and about $2m if I can go all the way as I imagine
but it really depends how long I can execute and if I can actually negotiate a bug bounty "consulting fee"
 
extortion scam emails? ransomware? talking about bypassing spam filters..must be sending emails?
 
extortion scam emails? ransomware? talking about bypassing spam filters..must be sending emails?
yes, emails are part of it, but they are not part of the exploit system
 
I really don't understand what's going on! Care to explain in a practice way so that we can understand?
 
I really don't understand what's going on! Care to explain in a practice way so that we can understand?
In very short, I'm exploiting a site's vulnerability for profit.
I can't go in deep detail of what I'm doing as the exploit is still going and I don't want unnecessary competition.

Though, once it gets patched I can disclose a lot of info.

--------


UPDATE

Profits are under $5k. I won't go on exact amounts for OSINT and OPSEC reasons, but I can give a ballpark of the profit so far.

AI has been quite helpful in developing code and the speed is insane. Everything AI has helped with I would have done it but I would have taken a lot longer to develop.

For now, everything is going great and smooth. Making money daily. Sometimes it's unreal how you can literally make money from simple dev mistakes.

Also, as it's a "smaller" company, they don't have red/blue teams testing their systems but they do have the budget to do so, but I guess they are too lazy or too cheap to even test their systems.


How can I scale?

Well, usually when you find a vulnerability in a site, you can bet your ass there are more out there waiting to be discovered. So the plan is to keep testing everything to try and find a new exploit and drain it all dry.

I have to think what the devs were thinking to overlook such a vulnerability and test other systems that might have similar structures to see if the devs also overlooked vulnerabilities there.


Key things to consider:

- Stay under the radar
- Keep greed in check

Greed can make or break something and can close doors sooner than they should

So, in short, what I keep working on:

- Testing more systems to try and find vulnerabilities
- Keep making $$$ and stay under the radar
- Keep greed on check and stay UNDER THE RADAR


keep making money, guys
 
Checked with AI, here is what I found does anything match?

Exploit TypeDescriptionExample
Referral abuseCreate multiple fake accounts to claim signup bonusesUber, PayPal
Airdrop farmingFarm token airdrops by simulating real activityCrypto platforms
Price arbitrage botsBuy low/sell high automatically between exchangesStock/crypto trading
Ad click fraudFake traffic or clicks for ad revenueAdSense, affiliate platforms
Loyalty abuseGame point systems by automating interactionsAirline miles, cashback
API rate bypassCircumvent limits to extract more data/valueFree-tier APIs
 
Checked with AI, here is what I found does anything match?

Exploit TypeDescriptionExample
Referral abuseCreate multiple fake accounts to claim signup bonusesUber, PayPal
Airdrop farmingFarm token airdrops by simulating real activityCrypto platforms
Price arbitrage botsBuy low/sell high automatically between exchangesStock/crypto trading
Ad click fraudFake traffic or clicks for ad revenueAdSense, affiliate platforms
Loyalty abuseGame point systems by automating interactionsAirline miles, cashback
API rate bypassCircumvent limits to extract more data/valueFree-tier APIs
Those are nice tactics, but what I'm doing is a more of a "use their systems against them" kind of approach

Basically, they left the window open where I can manipulate their systems to my advantage
 
This is utter nonsense and you've wasted 2 minutes of my life. You've provided NOTHING.
Once it's patched I will reveal how it works and how I made profit. Until then, I have to be vague
 
Congrats on making 5k so far :) Is it illegal what you're doing like cc fraud etc? or just blackhat like breaking tos etc
 
Congrats on making 5k so far :) Is it illegal what you're doing like cc fraud etc? or just blackhat like breaking tos etc
technically speaking, it's not fraud and not breaking tos as there is no clause where you are forbidden to make profit from exploits found ;)
 
@DarkerAds I want you to know that I don't like this thread or the posts you're making. Constantly making references to not "technically" being against any TOS and alluding to things that you can't discuss here on BHW is bringing up so many red flags that I could make a nice parade out of them.

That's on top of the fact that your journey is an incredible amount of vague information that appears to amount to nothing. You've presented absolutely no evidence of anything whatsoever, which leads me to conclude, at this stage, that this is thinly-veiled engagement bait. This thread is being monitored - closely.
 
Constantly making references to not "technically" being against any TOS
I mean if the site attacked doesn't state in it's TOS that you can't make profit from a vulnerability, then you are NOT breaking it's TOS.
alluding to things that you can't discuss here on BHW
Yeah, I even asked mod BTB as to what I can and cannot share
thinly-veiled engagement bait
far from that. Once the vulnerability gets patched, I will share a lot more details and strategies - all which shouldn't break BHW TOS
This thread is being monitored - closely.
Thank you
 
@DarkerAds I want you to know that I don't like this thread or the posts you're making. Constantly making references to not "technically" being against any TOS and alluding to things that you can't discuss here on BHW is bringing up so many red flags that I could make a nice parade out of them.

That's on top of the fact that your journey is an incredible amount of vague information that appears to amount to nothing. You've presented absolutely no evidence of anything whatsoever, which leads me to conclude, at this stage, that this is thinly-veiled engagement bait. This thread is being monitored - closely.
Don't hurt him king. The forum needs a hacker.
 
I mean if the site attacked doesn't state in it's TOS that you can't make profit from a vulnerability, then you are NOT breaking it's TOS.

Yeah, I even asked mod BTB as to what I can and cannot share

far from that. Once the vulnerability gets patched, I will share a lot more details and strategies - all which shouldn't break BHW TOS

Thank you
well, if you are saying you'll share more details once it's patched, then as other members have already asked - could you share a previously patched exploit? we'll have some info on the nature of this journey and the "exploits".
 
Status
Not open for further replies.
Back
Top