[Journey] Let's exploit a site for $10m! AI for the win!

Status
Not open for further replies.
well, if you are saying you'll share more details once it's patched, then as other members have already asked - could you share a previously patched exploit? we'll have some info on the nature of this journey and the "exploits".
I will, but I will ask mods so I don't get banned here lol.

-----------


UPDATE

Unfortunately, it seems that the vulnerability was parcially patched. It seems to be working but the circumstances are unknown, which means that I will give it a rest for a couple of weeks or so and then come back.

I thought it would be up and running for weeks or months, but unfortunately, I think they have people looking out for things like this :D

So far, profit is under $5k. Sure, it's not a lot, but I have to remember that it was FREE money and it was done on autopilot mostly, so so far it's a good reward.

The only thing that I don't understand is that if they could fix this so quick, why did they let it go for so long?
It doesn't make sense, unless someone on the inside knew about it but just kept it to himself until I came and made a few bucks :D

Anyway, I will leave this for now and will come back in a few weeks or so to wait for the heat to dissipate and hopefully their defenses go back down again.

Overall, not a bad profit for a few days of automation :D
 
I will, but I will ask mods so I don't get banned here lol.

-----------


UPDATE

Unfortunately, it seems that the vulnerability was parcially patched. It seems to be working but the circumstances are unknown, which means that I will give it a rest for a couple of weeks or so and then come back.

I thought it would be up and running for weeks or months, but unfortunately, I think they have people looking out for things like this :D

So far, profit is under $5k. Sure, it's not a lot, but I have to remember that it was FREE money and it was done on autopilot mostly, so so far it's a good reward.

The only thing that I don't understand is that if they could fix this so quick, why did they let it go for so long?
It doesn't make sense, unless someone on the inside knew about it but just kept it to himself until I came and made a few bucks :D

Anyway, I will leave this for now and will come back in a few weeks or so to wait for the heat to dissipate and hopefully their defenses go back down again.

Overall, not a bad profit for a few days of automation :D
Are you sharing the real details now that’s been patched?
 
I will, but I will ask mods so I don't get banned here lol.

-----------


UPDATE

Unfortunately, it seems that the vulnerability was parcially patched. It seems to be working but the circumstances are unknown, which means that I will give it a rest for a couple of weeks or so and then come back.

I thought it would be up and running for weeks or months, but unfortunately, I think they have people looking out for things like this :D

So far, profit is under $5k. Sure, it's not a lot, but I have to remember that it was FREE money and it was done on autopilot mostly, so so far it's a good reward.

The only thing that I don't understand is that if they could fix this so quick, why did they let it go for so long?
It doesn't make sense, unless someone on the inside knew about it but just kept it to himself until I came and made a few bucks :D

Anyway, I will leave this for now and will come back in a few weeks or so to wait for the heat to dissipate and hopefully their defenses go back down again.

Overall, not a bad profit for a few days of automation :D
Thanks for sharing your journey.

In your opinion, what percentage of companies have security vulnerabilities on their websites? So if you tried to find it on 10 brands' websites, how many of them have open windows?
 
I will, but I will ask mods so I don't get banned here lol.

-----------


UPDATE

Unfortunately, it seems that the vulnerability was parcially patched. It seems to be working but the circumstances are unknown, which means that I will give it a rest for a couple of weeks or so and then come back.

I thought it would be up and running for weeks or months, but unfortunately, I think they have people looking out for things like this :D

So far, profit is under $5k. Sure, it's not a lot, but I have to remember that it was FREE money and it was done on autopilot mostly, so so far it's a good reward.

The only thing that I don't understand is that if they could fix this so quick, why did they let it go for so long?
It doesn't make sense, unless someone on the inside knew about it but just kept it to himself until I came and made a few bucks :D

Anyway, I will leave this for now and will come back in a few weeks or so to wait for the heat to dissipate and hopefully their defenses go back down again.

Overall, not a bad profit for a few days of automation :D
cool stuff, it was a short but very interesting journey. Are you sharing more details now that's been patched?
 
NOTE: In this thread I'm not going to openly discuss anything that is against BHW TOS nor talk about ways to "hack" a site or something that is illegal.
NOTE2: I tried searching for a bug bounty program of sorts, but there is none, so it's game on! :D

THOUGH, I will be discussing how to protect your site, discuss defense techniques and how I will proceed with this exploit.

For obvious reasons, I will be very vague in many aspects, to hide several aspects of my operation.




With that being said, hopefully you find lots of good educational content in this thread regarding DEFENSE and hope you learn to never let your guard down.


Anyway, in any case, as a little bit of history about me, I've been on this scene for many years and from time to time I've discovered exploits where I've made quite a bit of money. I won't tell exact amounts, but I can tell you that I'm quite knowledgeable when it comes to take max profit out of systems and staying under the radar.

When it comes to exploits, you can go two ways, the one huge hit, or you can go long term, staying under the radar to try and get the most out of it.

The way you choose between those options is to really analyze which option can give you the most profit.

Sometimes going big and taking one big hit is better than the longterm option, but if you can really stay under the radar and execute with perfection, then the long term option is the best one.


I'm not going to give details on what kind of exploit I found or how I execute as it's against BHW TOS, so unfortunately, I can't discuss any of that here.

As a programmer, I know how the systems work behind the scenes and how usually things should work.

It's fun when I think I found an exploit but it gets patched the moment where it could be profitable.

Also, in some exploits, automation is key, and sometimes just real human interaction is better. It depends on the task at hand


Nowadays, AI has been an incredible assistant on creating code that I've been using it for quite some time now. AI speeds up things.

Right now, for the exploit I'm working with, it can be automated and to do the automation I had to learn a lot, and with the help of AI, I learned what I needed to learn in record time.

Last time I needed to learn a new skill, it took me a few weeks, but now with AI, I learned it in a couple of days which is insane!



Anyway, the goal of this journey is to reach $10m in profit.

The way to go is to go long term and stay under the radar, as going with a big hit would yield a lot lower reward (maybe 3-4 figures LOL!), so going the long term way is the way to go.

The funny thing about this is that I believe that the management knows about this, but they don't think it's a serious risk. Fortunately, for me, I know how to execute, how things work and how to make it profitable.



Before automating, I had to truly go by hand and actually test the ins and outs of this to test the limits and see how much I can actually make.

Also, I had to take into account how profitable this is, as if you find an exploit where you can only make say $1-$5/ day, well, maybe it's only worth it you can do it for long term and 100% on autopilot

In any case, I found the limits of this and know to execute with perfection. Now, I have to keep working on my automation task to literally make money online hands-off



In short:

- Found an exploit
- Know how to make it profitable and worth it
- Working on automating it
- Stay under the radar
- Take max profit!


As of now, I found the exploit, found the limits, I know to execute at perfection and now I'm working on a way to automate it and get it up and running.

Key challenges:

- Staying under the radar. If you appear on the radar it's game over.
- Automate at perfection. Too many variables, but with enough workarounds and "hotfixes", I believe it can be done


AI is king when it comes to automation and working things out.

Profit as of now: Enough to know that this is profitable after automating at perfection. AI is an incredible help when it comes to this.

Stay tuned
wow a mysterious and interesting topic, wondering where you are because we might be from the same country because my country is full of people who exploit vulnerabilities and make money through those bugs. also I wonder if you have 1,2 other friends working with you or are you just working alone. because my previous experience is that exploiting this type of vulnerability will need people to work with, at least 2 people or more. before AI was launched and automation took over, where I was, they exploited day and night, like this person worked in the morning, the other person worked at night and shared the time and duration of the work.

also I advise you not to talk about that vulnerability in this forum because that vulnerability will definitely be patched in days or even hours, there are many valuable tips and information about black hat seo, promotion or spam after sharing in this group, it will be patched immediately. I say that so you understand :))
 
AI helping to cut weeks into days is insane, can’t wait to see the results.
 
Are you sharing the real details now that’s been patched?
I will do so if it still patched a few weeks down the road
Thanks for sharing your journey.

In your opinion, what percentage of companies have security vulnerabilities on their websites? So if you tried to find it on 10 brands' websites, how many of them have open windows?
i have seen exploits in big and small companies, so it really has no difference. Though, usually the smaller companies have bigger vulnerabilities but reward is smaller, while in bigger companies, the vulnerabilities are smaller but rewards are bigger
cool stuff, it was a short but very interesting journey. Are you sharing more details now that's been patched?
I will do so if in a few weeks the vulnerabilities are patched and none work anymore
wow a mysterious and interesting topic, wondering where you are because we might be from the same country because my country is full of people who exploit vulnerabilities and make money through those bugs. also I wonder if you have 1,2 other friends working with you or are you just working alone. because my previous experience is that exploiting this type of vulnerability will need people to work with, at least 2 people or more. before AI was launched and automation took over, where I was, they exploited day and night, like this person worked in the morning, the other person worked at night and shared the time and duration of the work.

also I advise you not to talk about that vulnerability in this forum because that vulnerability will definitely be patched in days or even hours, there are many valuable tips and information about black hat seo, promotion or spam after sharing in this group, it will be patched immediately. I say that so you understand :))
I'm dead sure there are red teams out there trying all kind of things
Usually the smaller fish get caught while the whales thrive making millions in the shadows ;)
AI helping to cut weeks into days is insane, can’t wait to see the results.
Yup, AI was an insane part in speeding this up. Without it, it would've taken me a few weeks dead serious
I need more information
about what?
 
UPDATE

Ok guys, so yesterday I found a way to bypass the "fix" they implemented for the vulnerability which means we are still running!

The profits of the past few hours is around $100-$200 mark, which is good as it's 100% on autopilot.

I'll run this up until the wheels fall of the car!

so far the total profit is under $5k, but it was 100% on autopilot, so it's not bad
 
@DarkerAds
Hey, this is not my business and all but.

TOS is something that company creates to defend their interests and etc. And basically its like a contract when u use certain service or product.

Now, for example if my website does not have TOS that does not mean that it can't be illegal if i do something that will damage their interest.

For example, if i cross certain security measures, and company does not have tos about forbidding people to access this sort of materials, that does not mean, that I am in a right and can do as I please. Because general laws apply and I might end up in jail for accessing and breaching security layers/resources and etc.

Even for example, if I find a bug in a system, and exploit it in a way, that damages company's interests, they can sue me, or even put file or two in police station if somewhere i crossed a line where it breaches civil matters. In both cases having or not having TOS does not matter that much to be honest. But of course if there are TOS thats another card against u, since it makes their possible claim even more valid.

Also, there is no such thing as technically not being a fraud, either it's a fraud or not. Again in case of fraud too, if people/company gets damaged by ur actions it can be fraud again even if their tos does not forbid certain activity. And it can be a other crime too, just depends.

There are also things, that can be in TOS by a company but if I breach them that it does not mean its illegal/crime. Civil matter? Maybe.

also testing system sounds errrm, not too good in this context, if i test BHW system without their permission, that yells trouble for me.

"site attacked" , does not sound good either.

Also, again dunno if you are doing something illegal or not.
 
@DarkerAds I want you to know that I don't like this thread or the posts you're making. Constantly making references to not "technically" being against any TOS and alluding to things that you can't discuss here on BHW is bringing up so many red flags that I could make a nice parade out of them.

That's on top of the fact that your journey is an incredible amount of vague information that appears to amount to nothing. You've presented absolutely no evidence of anything whatsoever, which leads me to conclude, at this stage, that this is thinly-veiled engagement bait. This thread is being monitored - closely.
He deceived everyone and, despite promising to do so, won't share his method. He first claimed the security vulnerability had been patched, but now he still claims the method works. Could he be marketing his method and selling via private message?
 
He deceived everyone and, despite promising to do so, won't share his method. He first claimed the security vulnerability had been patched, but now he still claims the method works. Could he be marketing his method and selling via private message?
We have received no reports of selling or marketing to date. But staff are continuing to monitor this thread,
 
@DarkerAds
Hey, this is not my business and all but.

TOS is something that company creates to defend their interests and etc. And basically its like a contract when u use certain service or product.

Now, for example if my website does not have TOS that does not mean that it can't be illegal if i do something that will damage their interest.

For example, if i cross certain security measures, and company does not have tos about forbidding people to access this sort of materials, that does not mean, that I am in a right and can do as I please. Because general laws apply and I might end up in jail for accessing and breaching security layers/resources and etc.

Even for example, if I find a bug in a system, and exploit it in a way, that damages company's interests, they can sue me, or even put file or two in police station if somewhere i crossed a line where it breaches civil matters. In both cases having or not having TOS does not matter that much to be honest. But of course if there are TOS thats another card against u, since it makes their possible claim even more valid.

Also, there is no such thing as technically not being a fraud, either it's a fraud or not. Again in case of fraud too, if people/company gets damaged by ur actions it can be fraud again even if their tos does not forbid certain activity. And it can be a other crime too, just depends.

There are also things, that can be in TOS by a company but if I breach them that it does not mean its illegal/crime. Civil matter? Maybe.

also testing system sounds errrm, not too good in this context, if i test BHW system without their permission, that yells trouble for me.

"site attacked" , does not sound good either.

Also, again dunno if you are doing something illegal or not.
I 100% understand that :)
He deceived everyone and, despite promising to do so, won't share his method. He first claimed the security vulnerability had been patched, but now he still claims the method works. Could he be marketing his method and selling via private message?
Bro, they had patched the vulnerability, then I said I would be coming back in a few weeks if I had found something (and I found something way earlier than a few weeks), then I started posting again.
We have received no reports of selling or marketing to date. But staff are continuing to monitor this thread,
Exactly. I'm not selling anything anywhere as there's nothing to sell. I'm just sharing my experience of eploiting a site for profit with the most discretion I can.
Ah yes, the classic: get rich with AI, but step 2 is always redacted. Can’t wait for your Netflix documentary: The Guy Who Almost Explained Stuff.
AI is just an accelerator, it helps coding a lot faster, but AI didn't discover this vulnerability, it has just helped with coding so I can automate the exploit
 
UPDATE


The exploit is going strong!

Should I consider negotiating a "bug bounty" with the company ? or should I just keep at it and try to get the most I can?

what do you say?
 
UPDATE


The exploit is going strong!

Should I consider negotiating a "bug bounty" with the company ? or should I just keep at it and try to get the most I can?

what do you say?
just go hard on scamming them
 
mind elaboratinga a bit more on it?
I don't mind at all.

Scamming is illegal and not allowed here.

Finding loophole that may break a site's ToS, and using that to generate revenue, as long as it is not an illegal act, is fine.
 
I'm starting to regret moaning about the new user AI spam threads/replies after reading this shite. Didn't know how good we had it.
 
Status
Not open for further replies.
Back
Top