Just Saying Exploit

Elliot305

BANNED
Joined
Jul 21, 2010
Messages
641
Reaction score
1,889
This video is just to demonstrate that there are always ways around things. (p.s., I haven't done this one for a couple years so who knows how well it works still. It's kind of a last option resort when it came to my sending...but it worked and made me some extra $ doing it.) Doing the straight test send email exploit worked so much better.

 
Last edited by a moderator:

DatMoney

Regular Member
Joined
Jul 20, 2014
Messages
238
Reaction score
106
Just downloaded the video. Will watch later. I am sure it will be kickass just like all of your threads.
 

Elliot305

BANNED
Joined
Jul 21, 2010
Messages
641
Reaction score
1,889
Yeah the second vid is just more of a demonstration of how to get around certain things. The first vid is where it's at. Straight sending is the way to go, followed by abusing the test send email function.
 

mechaman88

Newbie
Joined
Aug 4, 2014
Messages
42
Reaction score
7
I am about to go full on test email method. I saw your follow up video, very clever work around ;)

do you have suggestions on what converts the best?
 

Elliot305

BANNED
Joined
Jul 21, 2010
Messages
641
Reaction score
1,889
Forgot to mention. For anybody emailing from a self-serve platform and taking advantage of them...always try and use your own links...never use theirs. Reason being if they disable you after you've sent out a mill lets say, all the links in your emails are bad as they are hosted on the companies server...the emails are useless. With some companies you have no choice but most allow you to use your own. I learned the hard way with this.

Also, I wouldn't suggest you use Godaddy to host your domain on. They disabled my accounts pretty quick when spam complaints came in. Another point, if you do start sending BIG, keep changing your domain every 100k emails or so. After enough spam complaints it gets listed on spamhaus or other spam type websites. I don't know how this is done, but at one point my domains were being redirected to a spamhaus type page saying it was malicious, etc... The domain was still up, the links still worked, but they ended up on those type pages anyway.

Another tip, if you are having a hard time inboxing because of content, make the whole campaign a clickable image. You can also make the campaign as an attachment, which surprisingly worked very well. Check out this image and see how I shaped the message around being an attachment. When you attach it, you name it something that would grab their attention. For my campaign, I named them stuff like: AOL NOTICE (VIEW ATTACHMENT), IMPORTANT NOTICE REGARDING YOUR ACCOUNT, RE-YOUR ACCOUNT. Attachment campaigns are a good way to stay undetected from email filters. They can really only see your attachment name and the size of it this way...very easy to change around. The domain in an attachment type of campaign should always have both the singular and plural versions of it. After some research I learned about 20% of my traffic was coming from the mispelled version so I always bought both.

P.S. I wouldn't recommend using my attachment name examples with Gmail as they've been used heavily already.

View attachment 53584
 
Last edited:

JinxY

Regular Member
Joined
May 14, 2007
Messages
376
Reaction score
103
Thanks for your posts Elliot, very impressive. I want to ask you, are you using your real info for registering to the CPA accounts? How are you protecting yourself and still be able to cash out the money, as you are not only spamming but also impersonating big companies (google, apple, etc) which may result in lawsuits?

Also about the casino exploit, you're just using HMA, which may keep logs of your activity? And the bitcoins from the casinos, are you laundering them, as they are not really anonymous?
Thanks!
 

Elliot305

BANNED
Joined
Jul 21, 2010
Messages
641
Reaction score
1,889
Thanks for your posts Elliot, very impressive. I want to ask you, are you using your real info for registering to the CPA accounts? How are you protecting yourself and still be able to cash out the money, as you are not only spamming but also impersonating big companies (google, apple, etc) which may result in lawsuits?

Also about the casino exploit, you're just using HMA, which may keep logs of your activity? And the bitcoins from the casinos, are you laundering them, as they are not really anonymous?
Thanks!

For CPA companies, I did use real info. You need to be upfront with the network so they don't get blindsided later on. I was lucky enough to run with a couple networks (no longer with us) who were down with this. I suppose there was a possibility of the big companies wanting to sue me. The way I looked at it...take a number and get in line. Yes, I am using HMA. I don't see a bitcoin casino convincing the Feds to subpoena HMAs records in order to find me. Besides, HMA was registered with fake info. For each casino I find vulnerabilities on, I use a separate wallet address and no other transaction will be done within that address.
 

ahiddenman

Elite Member
Joined
Dec 11, 2010
Messages
2,740
Reaction score
2,156
Another quality post from you!

Keep it up man, wish BHW had a rep button still :p
 

JinxY

Regular Member
Joined
May 14, 2007
Messages
376
Reaction score
103
For CPA companies, I did use real info. You need to be upfront with the network so they don't get blindsided later on. I was lucky enough to run with a couple networks (no longer with us) who were down with this. I suppose there was a possibility of the big companies wanting to sue me. The way I looked at it...take a number and get in line. Yes, I am using HMA. I don't see a bitcoin casino convincing the Feds to subpoena HMAs records in order to find me. Besides, HMA was registered with fake info. For each casino I find vulnerabilities on, I use a separate wallet address and no other transaction will be done within that address.

Thank you for explaining.
 

ECoin

Newbie
Joined
May 29, 2014
Messages
2
Reaction score
1
How do you get Jr VIP ? I wanted to get donor status but I dont see anywhere for purchasing Jr. VIP.
 

badd

Regular Member
Joined
Jan 22, 2008
Messages
487
Reaction score
96
I like this Elliot, quite creative. Keep up the good work.

Forgot to mention. For anybody emailing from a self-serve platform and taking advantage of them...always try and use your own links...never use theirs. Reason being if they disable you after you've sent out a mill lets say, all the links in your emails are bad as they are hosted on the companies server...the emails are useless. With some companies you have no choice but most allow you to use your own. I learned the hard way with this.

Also, I wouldn't suggest you use Godaddy to host your domain on. They disabled my accounts pretty quick when spam complaints came in. Another point, if you do start sending BIG, keep changing your domain every 100k emails or so. After enough spam complaints it gets listed on spamhaus or other spam type websites. I don't know how this is done, but at one point my domains were being redirected to a spamhaus type page saying it was malicious, etc... The domain was still up, the links still worked, but they ended up on those type pages anyway.

Another tip, if you are having a hard time inboxing because of content, make the whole campaign a clickable image. You can also make the campaign as an attachment, which surprisingly worked very well. Check out this image and see how I shaped the message around being an attachment. When you attach it, you name it something that would grab their attention. For my campaign, I named them stuff like: AOL NOTICE (VIEW ATTACHMENT), IMPORTANT NOTICE REGARDING YOUR ACCOUNT, RE-YOUR ACCOUNT. Attachment campaigns are a good way to stay undetected from email filters. They can really only see your attachment name and the size of it this way...very easy to change around. The domain in an attachment type of campaign should always have both the singular and plural versions of it. After some research I learned about 20% of my traffic was coming from the mispelled version so I always bought both.

P.S. I wouldn't recommend using my attachment name examples with Gmail as they've been used heavily already.

View attachment 53584
 
Top