Say something wrong shape on target.com

nexn48

Newbie
Joined
Aug 17, 2023
Messages
11
Reaction score
1
How to bypass him? It's a pain in the ass for a while. Thanks
 
I can't say that I fully understand you. Are you asking about an issue you're experiencing here with some kind of captcha on target.com, could you elaborate a little more?
 
Does a topic being two weeks old require us not to reply? Asking because I'm new.

This is called necro-bumping in the online world. Which basically means reviving an old/dead/dormant topic.

While 2 weeks isn't a long enough time, some people will innocuously search the forums and bump 6 month, 1 year or even 14 year old threads.

If a thread is unanswered, and you have something valuable to add to it - then by all means go ahead. (Provided it is within reasonable time).
 
This is called necro-bumping in the online world. Which basically means reviving an old/dead/dormant topic.

While 2 weeks isn't a long enough time, some people will innocuously search the forums and bump 6 month, 1 year or even 14 year old threads.

If a thread is unanswered, and you have something valuable to add to it - then by all means go ahead. (Provided it is within reasonable time).
It will be nice if you followed your own advice and not just post on topics you have zero clue about while parroting the previous post to inflate your post count.

I'm not even sure where you saw Geetest Captcha on Target because I've never seen it before and I've been working on target for a long time, not sure if you asked ChatGPT for that answer.

What the OP is referring to is the anti-bot called Shape Security which is found on many sites, but he is talking specifically about the login end point for target.

https://www.target.com/login?client_id=ecom-web-1.0.0&ui_namespace=ui-default&back_button_action=browser&keep_me_signed_in=true&kmsi_default=false&actions=create_session_create_account
On the login, two Shape Security's links are loaded:

This is the kernel: https://assets.targetimg1.com/ssx/ssx.mod.js?seed=AAD-YreLAQAAIc7ptBxPX402FNeWqGAh4e16ZuE4lza7t3bDMYhmqplX_1mQ&X-GyJwza5Z--z=q

And this is the launcher file the contains the transactionToken, custom base64 alphabet and the encryption keys used to encrypt their payloads.

So when you make a login request to: https://gsp.target.com/gsp/authentications/v1/credential_validations?client_id=ecom-web-1.0.0

You will see 5 headers

X-Gyjwza5z-A, X-Gyjwza5z-B, X-Gyjwza5z-C, X-Gyjwza5z-D, X-Gyjwza5z-F, X-Gyjwza5z-Z but the header ending with -A is the one that has the payload.

You basically have to reverse their script in order to get the signals they use on the -A header and then do that for every seed.

I'm also super irritated at the OP, because is clear the OP has no freaking idea of what botting he is doing when he is asking for help on how to do his basic job. If you are going to be botting sites like ticketmaster, target, walmart and you have no idea how to bypass antibots and asking dumb ass questions with broken English to a forum full of JR Executive VIP's that just go around posting useless posts on topics they have zero freaking clue about, then I'm sorry you already failed at the botting game.

If the OP actually had the skills he was advertising I could easily see him getting 5-10k at minimum per month, but he is far from being competent at his job. Anyone able to bypass Shape Security or even basic TicketMaster's Nudata, Incapsula and Perimeter X will be worth a lot.
 
It will be nice if you followed your own advice and not just post on topics you have zero clue about while parroting the previous post to inflate your post count.

I'm not even sure where you saw Geetest Captcha on Target because I've never seen it before and I've been working on target for a long time, not sure if you asked ChatGPT for that answer.

What the OP is referring to is the anti-bot called Shape Security which is found on many sites, but he is talking specifically about the login end point for target.

https://www.target.com/login?client...t=false&actions=create_session_create_account
On the login, two Shape Security's links are loaded:

This is the kernel: https://assets.targetimg1.com/ssx/s...h4e16ZuE4lza7t3bDMYhmqplX_1mQ&X-GyJwza5Z--z=q

And this is the launcher file the contains the transactionToken, custom base64 alphabet and the encryption keys used to encrypt their payloads.

So when you make a login request to: https://gsp.target.com/gsp/authentications/v1/credential_validations?client_id=ecom-web-1.0.0

You will see 5 headers

X-Gyjwza5z-A, X-Gyjwza5z-B, X-Gyjwza5z-C, X-Gyjwza5z-D, X-Gyjwza5z-F, X-Gyjwza5z-Z but the header ending with -A is the one that has the payload.

You basically have to reverse their script in order to get the signals they use on the -A header and then do that for every seed.

I'm also super irritated at the OP, because is clear the OP has no freaking idea of what botting he is doing when he is asking for help on how to do his basic job. If you are going to be botting sites like ticketmaster, target, walmart and you have no idea how to bypass antibots and asking dumb ass questions with broken English to a forum full of JR Executive VIP's that just go around posting useless posts on topics they have zero freaking clue about, then I'm sorry you already failed at the botting game.

If the OP actually had the skills he was advertising I could easily see him getting 5-10k at minimum per month, but he is far from being competent at his job. Anyone able to bypass Shape Security or even basic TicketMaster's Nudata, Incapsula and Perimeter X will be worth a lot.

Noice!

Did that make you feel good? You showed me!

I got confused for a minute - and thought it's Geetest and not F5. I apologise profusely to you for this lapse.

Hope you feel better man.
 
Noice!

Did that make you feel good? You showed me!

I got confused for a minute - and thought it's Geetest and not F5. I apologise profusely to you for this lapse.

Hope you feel better man.
Yes, please stick to the blogging/SEO section next time. I understand you have to meet your quota

I'm just giving you the same energy you give to other members : https://www.blackhatworld.com/seo/prediction-about-saas-and-ai.1544206/post-16984281

You talk big about telling other users on contributing to the forum, but I don't see how your post was more than an obvious attempt to meet your daily BHW posting quota.
 
I can't say that I fully understand you. Are you asking about an issue you're experiencing here with some kind of captcha on target.com, could you elaborate a little more?
Yes it is an issue. When i try to login multiple times I got message
It will be nice if you followed your own advice and not just post on topics you have zero clue about while parroting the previous post to inflate your post count.

I'm not even sure where you saw Geetest Captcha on Target because I've never seen it before and I've been working on target for a long time, not sure if you asked ChatGPT for that answer.

What the OP is referring to is the anti-bot called Shape Security which is found on many sites, but he is talking specifically about the login end point for target.

https://www.target.com/login?client_id=ecom-web-1.0.0&ui_namespace=ui-default&back_button_action=browser&keep_me_signed_in=true&kmsi_default=false&actions=create_session_create_account
On the login, two Shape Security's links are loaded:

This is the kernel: https://assets.targetimg1.com/ssx/ssx.mod.js?seed=AAD-YreLAQAAIc7ptBxPX402FNeWqGAh4e16ZuE4lza7t3bDMYhmqplX_1mQ&X-GyJwza5Z--z=q

And this is the launcher file the contains the transactionToken, custom base64 alphabet and the encryption keys used to encrypt their payloads.

So when you make a login request to: https://gsp.target.com/gsp/authentications/v1/credential_validations?client_id=ecom-web-1.0.0

You will see 5 headers

X-Gyjwza5z-A, X-Gyjwza5z-B, X-Gyjwza5z-C, X-Gyjwza5z-D, X-Gyjwza5z-F, X-Gyjwza5z-Z but the header ending with -A is the one that has the payload.

You basically have to reverse their script in order to get the signals they use on the -A header and then do that for every seed.

I'm also super irritated at the OP, because is clear the OP has no freaking idea of what botting he is doing when he is asking for help on how to do his basic job. If you are going to be botting sites like ticketmaster, target, walmart and you have no idea how to bypass antibots and asking dumb ass questions with broken English to a forum full of JR Executive VIP's that just go around posting useless posts on topics they have zero freaking clue about, then I'm sorry you already failed at the botting game.

If the OP actually had the skills he was advertising I could easily see him getting 5-10k at minimum per month, but he is far from being competent at his job. Anyone able to bypass Shape Security or even basic TicketMaster's Nudata, Incapsula and Perimeter X will be worth a lot.

It will be nice if you followed your own advice and not just post on topics you have zero clue about while parroting the previous post to inflate your post count.

I'm not even sure where you saw Geetest Captcha on Target because I've never seen it before and I've been working on target for a long time, not sure if you asked ChatGPT for that answer.

What the OP is referring to is the anti-bot called Shape Security which is found on many sites, but he is talking specifically about the login end point for target.

https://www.target.com/login?client_id=ecom-web-1.0.0&ui_namespace=ui-default&back_button_action=browser&keep_me_signed_in=true&kmsi_default=false&actions=create_session_create_account
On the login, two Shape Security's links are loaded:

This is the kernel: https://assets.targetimg1.com/ssx/ssx.mod.js?seed=AAD-YreLAQAAIc7ptBxPX402FNeWqGAh4e16ZuE4lza7t3bDMYhmqplX_1mQ&X-GyJwza5Z--z=q

And this is the launcher file the contains the transactionToken, custom base64 alphabet and the encryption keys used to encrypt their payloads.

So when you make a login request to: https://gsp.target.com/gsp/authentications/v1/credential_validations?client_id=ecom-web-1.0.0

You will see 5 headers

X-Gyjwza5z-A, X-Gyjwza5z-B, X-Gyjwza5z-C, X-Gyjwza5z-D, X-Gyjwza5z-F, X-Gyjwza5z-Z but the header ending with -A is the one that has the payload.

You basically have to reverse their script in order to get the signals they use on the -A header and then do that for every seed.

I'm also super irritated at the OP, because is clear the OP has no freaking idea of what botting he is doing when he is asking for help on how to do his basic job. If you are going to be botting sites like ticketmaster, target, walmart and you have no idea how to bypass antibots and asking dumb ass questions with broken English to a forum full of JR Executive VIP's that just go around posting useless posts on topics they have zero freaking clue about, then I'm sorry you already failed at the botting game.

If the OP actually had the skills he was advertising I could easily see him getting 5-10k at minimum per month, but he is far from being competent at his job. Anyone able to bypass Shape Security or even basic TicketMaster's Nudata, Incapsula and Perimeter X will be worth a lot.
@dasnorth telegram
 
Back
Top