I got asked some questions I want to answer :
Is it suitable for people that don't know shit about auditing ?
Yes and no , you can still find vulns chains that are pretty hard for the automated system to exploit , so that would require manual work or manual directive for the AI
Is it future proof ?
Yes , as the AI gets better the system is alredy studied to work with better and better systems
How much will it cost ?
Around 25.000 - 30.000$/week
I have to stick to your AI server or I can use my own apis ?
The system is well suitable for basically any AI, im currently using my own RAG + openrouter , both work smooth, if you are intrested and have a local RAG I can build a custom configuration
Is it really dumping itself ?
As the AI finds singals for idor , example /api/getinfo , payload USERID = 1 , if it can correctly confirm that with any userid it can actually get other user data , it will dynamically make a full extraction
Hope this answered everyone questions ! I know the price is high, but no public tools like this exist on the market, it took me 2 months +
Is it suitable for people that don't know shit about auditing ?
Yes and no , you can still find vulns chains that are pretty hard for the automated system to exploit , so that would require manual work or manual directive for the AI
Is it future proof ?
Yes , as the AI gets better the system is alredy studied to work with better and better systems
How much will it cost ?
Around 25.000 - 30.000$/week
I have to stick to your AI server or I can use my own apis ?
The system is well suitable for basically any AI, im currently using my own RAG + openrouter , both work smooth, if you are intrested and have a local RAG I can build a custom configuration
Is it really dumping itself ?
As the AI finds singals for idor , example /api/getinfo , payload USERID = 1 , if it can correctly confirm that with any userid it can actually get other user data , it will dynamically make a full extraction
Hope this answered everyone questions ! I know the price is high, but no public tools like this exist on the market, it took me 2 months +
CoinRoyale's "provably fair" has a hole π°
The verifier checks sha256(server_data|server_seed) === digest and that the roll is consistent β but it never proves the digest existed before your bet. No signed timestamp, no pre-bet anchor.
How a dishonest house cheats: it receives your bet (say hi), then generates random server_data values until it finds one whose roll makes you lose (~2 tries, since 60% of candidates already lose). Reveals that one β your verification still passes, because digest + roll are perfectly coherent.
The "32-bit seed" thing is a red herring (parseInt(sha256(...).slice(-8),16)). It's just code smell, not the vector β grinding works the same with a full 256-bit seed.
You can't predict as a player: server_data is hidden pre-roll, fresh & independent each round, no chain. Confirmed on
a real live round (roll 976155 reproduced β)
Only way to catch them: statistics β 1000+ rolls at fixed target + chi-square. A grinding house shows win-rate systematically below the expected 40%. Single roll: invisible.
Missing the real fix: a proof the digest premp / hash chain / player commit before seeing digest). Without it, "provably fair" = "trust us, bro."
The verifier checks sha256(server_data|server_seed) === digest and that the roll is consistent β but it never proves the digest existed before your bet. No signed timestamp, no pre-bet anchor.
How a dishonest house cheats: it receives your bet (say hi), then generates random server_data values until it finds one whose roll makes you lose (~2 tries, since 60% of candidates already lose). Reveals that one β your verification still passes, because digest + roll are perfectly coherent.
The "32-bit seed" thing is a red herring (parseInt(sha256(...).slice(-8),16)). It's just code smell, not the vector β grinding works the same with a full 256-bit seed.
You can't predict as a player: server_data is hidden pre-roll, fresh & independent each round, no chain. Confirmed on
a real live round (roll 976155 reproduced β)
Only way to catch them: statistics β 1000+ rolls at fixed target + chi-square. A grinding house shows win-rate systematically below the expected 40%. Single roll: invisible.
Missing the real fix: a proof the digest premp / hash chain / player commit before seeing digest). Without it, "provably fair" = "trust us, bro."
Selling pack opening site exploit
50$ -> unlimited balance
deposits are in crypto , withdrawals with US bank account
Payment processor for withdrawals : coinflow.cash
Have only been exploited on a test account , will not be resold/used after sale
Around 1100 online players in the moment im sending this message
@half for offers
50$ -> unlimited balance
deposits are in crypto , withdrawals with US bank account
Payment processor for withdrawals : coinflow.cash
Have only been exploited on a test account , will not be resold/used after sale
Around 1100 online players in the moment im sending this message
@half for offers
1.96K
@half lounge
Selling pack opening site exploit 50$ -> unlimited balance deposits are in crypto , withdrawals with US bank account Payment processor for withdrawals : coinflow.cash Have only been exploited on a test account , will not be resold/used after sale Aroundβ¦
dont offer less than 10k please β‘οΈ
Please open Telegram to view this post
VIEW IN TELEGRAM
Another exploit for sale
Crypto Exchange ( 35k users on telegram group )
The exchange gives you daily rewards based on vip level ( higher the vip level = higher payout )
My exploits gives you duplicate prizes ( up to 10x per account , per day )
Im not looking to work on % , the exploit has only been tested on my test account + tested a 10$ withdraw ( successful )
Only decent offers , no brokies please
@half
Crypto Exchange ( 35k users on telegram group )
The exchange gives you daily rewards based on vip level ( higher the vip level = higher payout )
My exploits gives you duplicate prizes ( up to 10x per account , per day )
Im not looking to work on % , the exploit has only been tested on my test account + tested a 10$ withdraw ( successful )
Only decent offers , no brokies please
@half
as always all the transactions go via MM , not looking to go first or to make you go first, you pay, verify the exploit, works , money release
@half lounge
Selling pack opening site exploit 50$ -> unlimited balance deposits are in crypto , withdrawals with US bank account Payment processor for withdrawals : coinflow.cash Have only been exploited on a test account , will not be resold/used after sale Aroundβ¦
exploit still active, admins are pretty dumb
Selling chinese wechat app access
Its a clone of tiktok shop but on wechat
Redis access exposing (around 5000 sellers), contains active sessions :
nick_name
phone
address
avatar_url
shop_examine
shop_examine_info
shop_list
shop_user
- WeChat App Secret
- RabbitMQ access
- Aliyun OSS access
- JWT secret able to impersonificate every user
@half for offers
Its a clone of tiktok shop but on wechat
Redis access exposing (around 5000 sellers), contains active sessions :
nick_name
phone
address
avatar_url
shop_examine
shop_examine_info
shop_list
shop_user
- WeChat App Secret
- RabbitMQ access
- Aliyun OSS access
- JWT secret able to impersonificate every user
@half for offers
@half lounge
Selling pack opening site exploit 50$ -> unlimited balance deposits are in crypto , withdrawals with US bank account Payment processor for withdrawals : coinflow.cash Have only been exploited on a test account , will not be resold/used after sale Aroundβ¦
Selling another similar exploit, this time site has venmo instant WD , pm for offers ONLY DEALS W MM @half
id fecha_crea fecha_mod us_crea us_mod borrado username clave depende_de razon nombre direccion cp localidad provincia cif_nif telefono web nombre_contacto apellidos_contacto estado_civil_contacto fecha_nacimiento_contacto cif_nif_contacto direccion_contacto cp_contacto provincia_contacto telefono_contacto alineacion amortiguadores autodiagnosis autogas_glp baterias carroceria chapa_pintura climatizacion direccion_actividad correas electricidad electronica equilibrado escape_emisiones filtros frenos_abs iluminacion revision_oficial inyeccion_gasolina inyeccion_diesel lubricantes mecanica_rapida motor neumaticos pre_itv suspension otros superficie_total zona_taller resto empleados fachada puertas_medidas fax email tipo_contacto grupo comentarios email_contacto microsite aprobado mostrar horario_manyana_semana horario_tarde_semana horario_tarde_sabado horario_manyana_sabado coordenadas_google codigo_care codigo_asociado centro_regulador anyo_apertura imagen fecha_care imagen_interior id_licencia citas_concurrentes id_stall permalink ultimo_acceso elpuntazo
If anyone intrested ENVFUCKER has been updated π₯
All-in-one tool for scanning public hosts for .env files, config leaks, credential dumps, API keys, and more. Includes CVE engine, product fingerprinting, WAF detection + automatic bypass, Shodan integration, and a full web dashboard.
π Scan Engine
- 1500+ probe paths (.env, .git, AWS, GCP, Azure, Spring Actuator, WordPress, Laravel, Docker, K8s, Terraform, etc.)
- Contextual path generation β when /.env is found, it probes /.env.production, /www/.env, /.env.bak, etc.
- QueryProbes β debug mode detection via query strings
- Heuristic Anomaly Detection β stack traces, credential dumps, JSON leaks, debug headers
- Compressed backup extraction β auto-decompresses .zip, .tar.gz, .gz, .bz2 and scans contents
- Directory listing follower β follows Index of / pages to find hidden files
π‘ WAF Intelligence
- Detection of 25+ WAF vendors (Cloudflare, AWS WAF, Akamai, Imperva, F5, Palo Alto, Fortinet, Azure WAF, GCP Cloud Armor, Zscaler, etc.)
- 100+ bypass techniques
- Automatic block page detection
π CVE Engine
- 90+ product fingerprints with mapped CVEs
- Version-aware assessment (semver) for 30+ products
- 150+ CVEs covered (Confluence, Jenkins, GitLab, Tomcat, Exchange, Veeam, ScreenConnect, Ivanti, Fortinet, VMware, Flowise, Langflow, LiteLLM, and more)
- CISA KEV catalog integration
π Shodan Integration
- 600+ curated search presets (AI/LLM, Spring Boot, cloud, databases, CVE-specific, secret patterns, port scans)
- Budget allocator for credit management
- InternetDB lookup
π Web Dashboard
- Overview β live scan progress, throughput chart (REQ/s + HIT/s), distribution donut, top signals, WAF panel
- Results β sortable findings with detail page per hit
- Keys β credential browser with masking, live verification (AWS, OpenAI, Stripe, GitHub, etc.)
- SMTP β integrated mail sender: test SMTP credentials, multi-recipient campaigns
- DB Browser β explore discovered databases (PostgreSQL, MySQL, MongoDB, Redis, MSSQL) with live query editor
- Cloud Browser β S3 bucket explorer (list, get, download), AWS EC2/RDS inventory
- Shopify Browser β explore Shopify stores with discovered tokens
- Mail Campaign β bulk sending with credential rotation, skip-on-fatal
- WAF Panel β live WAF detection + bypass results
- Credential Manager β manage discovered credentials (hide/show/verify)
- Config β scan settings, OSINT API keys, Purge all findings
- Dumps β bulk export (JSONL, CSV, TXT, ZIP)
β‘οΈ Verify Engine
- Live verification of 100+ providers (AWS, OpenAI, Anthropic, Stripe, GitHub, GitLab, Twilio, SendGrid, Discord, Telegram, Shopify, Datadog, Cloudflare, GCP, Azure, and more)
- Rate limiting, concurrency cap, retry logic, revoked blocklist
π§ Scan Modes
- Auto-mode with discovery ([crt.sh](http://crt.sh/), HackerTarget, Shodan, URLScan, OTX, SecurityTrails, DNS brute-force)
- Crawler-mode (follows links from root page)
- Skip megacorps / cloud provider filters
@envfucker π
All-in-one tool for scanning public hosts for .env files, config leaks, credential dumps, API keys, and more. Includes CVE engine, product fingerprinting, WAF detection + automatic bypass, Shodan integration, and a full web dashboard.
π Scan Engine
- 1500+ probe paths (.env, .git, AWS, GCP, Azure, Spring Actuator, WordPress, Laravel, Docker, K8s, Terraform, etc.)
- Contextual path generation β when /.env is found, it probes /.env.production, /www/.env, /.env.bak, etc.
- QueryProbes β debug mode detection via query strings
- Heuristic Anomaly Detection β stack traces, credential dumps, JSON leaks, debug headers
- Compressed backup extraction β auto-decompresses .zip, .tar.gz, .gz, .bz2 and scans contents
- Directory listing follower β follows Index of / pages to find hidden files
π‘ WAF Intelligence
- Detection of 25+ WAF vendors (Cloudflare, AWS WAF, Akamai, Imperva, F5, Palo Alto, Fortinet, Azure WAF, GCP Cloud Armor, Zscaler, etc.)
- 100+ bypass techniques
- Automatic block page detection
π CVE Engine
- 90+ product fingerprints with mapped CVEs
- Version-aware assessment (semver) for 30+ products
- 150+ CVEs covered (Confluence, Jenkins, GitLab, Tomcat, Exchange, Veeam, ScreenConnect, Ivanti, Fortinet, VMware, Flowise, Langflow, LiteLLM, and more)
- CISA KEV catalog integration
π Shodan Integration
- 600+ curated search presets (AI/LLM, Spring Boot, cloud, databases, CVE-specific, secret patterns, port scans)
- Budget allocator for credit management
- InternetDB lookup
π Web Dashboard
- Overview β live scan progress, throughput chart (REQ/s + HIT/s), distribution donut, top signals, WAF panel
- Results β sortable findings with detail page per hit
- Keys β credential browser with masking, live verification (AWS, OpenAI, Stripe, GitHub, etc.)
- SMTP β integrated mail sender: test SMTP credentials, multi-recipient campaigns
- DB Browser β explore discovered databases (PostgreSQL, MySQL, MongoDB, Redis, MSSQL) with live query editor
- Cloud Browser β S3 bucket explorer (list, get, download), AWS EC2/RDS inventory
- Shopify Browser β explore Shopify stores with discovered tokens
- Mail Campaign β bulk sending with credential rotation, skip-on-fatal
- WAF Panel β live WAF detection + bypass results
- Credential Manager β manage discovered credentials (hide/show/verify)
- Config β scan settings, OSINT API keys, Purge all findings
- Dumps β bulk export (JSONL, CSV, TXT, ZIP)
β‘οΈ Verify Engine
- Live verification of 100+ providers (AWS, OpenAI, Anthropic, Stripe, GitHub, GitLab, Twilio, SendGrid, Discord, Telegram, Shopify, Datadog, Cloudflare, GCP, Azure, and more)
- Rate limiting, concurrency cap, retry logic, revoked blocklist
π§ Scan Modes
- Auto-mode with discovery ([crt.sh](http://crt.sh/), HackerTarget, Shodan, URLScan, OTX, SecurityTrails, DNS brute-force)
- Crawler-mode (follows links from root page)
- Skip megacorps / cloud provider filters
@envfucker π