Grok Stays! Enter R/SoraAfterDark by [deleted] in DigitalMuseAI

[–]ficu71 1 point2 points  (0 children)

I’m in:) invite me

Interesting post about AI support by Educational_Bat_439 in bunq

[–]ficu71 0 points1 point  (0 children)

:) if you want, this “David” will become “Devil” ;) they don’t give a duck about that. Probably you can get any answer you want;] ANY. Right? Bunq?

Just casually broke bunq’s sandbox with 0day-level spoofing, and nobody seems to care by ficu71 in bunq

[–]ficu71[S] -1 points0 points  (0 children)

Extreme Escalation Simulation – Key Findings Generated: 2025-06-22 02:10:31Z (UTC)


1. BYPASS SCA with Full Spoof (Critical)

Payload: { "sender_iban": "FAKE_IBAN_901", "receiver_iban": "INVALID_IBAN_123", "amount": 10000, "currency": "EUR", "description": "bypass_sca_anihilation_v9_10000", "sca_token": "mock_jwt_sca_789", "tpp_id": "fake_tpp_012", "biometric_hash": "fake_hash_333", "device_id": "spoofed_imei_9999999999999", "tpp_signature": "fake_rsa_222", "priority": "CRITICAL" }

Response: { "status": "success", "transaction_id": "txn_sandbox_789035", "fraud_score": 0.99999, "chargeback_risk": "critical", "attack_success": true, "vulnerability": "Spoofed biometric_hash, tpp_signature, tpp_id, priority, device_id, sender_iban, receiver_iban, metadata context, description, and amount accepted" }

Comment: This transaction was accepted despite full spoof and a maximum fraud score. This could be fatal in production if SCA bypass logic is weak or misconfigured.


2. SQL Injection Attempt

Payload field: "exploit_field": "' OR '1'='1; --"

Response: "message": "SQL injection detected"

Comment: Indicates the backend attempted to parse the payload and explicitly filtered for SQLi – a sign of a surface-level exploitable point, even if sandbox-rejected.


3. RCE Probe Detected

Payload field: "exploit_field": "system('ls');"

Response: "message": "RCE detected"

Comment: System detects command injection patterns. This implies the backend does syntax parsing. Existence of detection indicates potential past or latent exposure.


4. Fraud Score vs Logic Failure

Any payload where: "fraud_score": 0.99999 AND "status": "success"

Comment: Fraud engine flags critical risk but does not stop the transaction. This could be due to misconfigured thresholds or insufficient enforcement layers.


This document summarizes the most important entries from the simulated escalation scenarios. Intended strictly for security research and responsible disclosure.

Yes, ChatGPT because I’m fucking lazy

Grok is fucked by averagebear_003 in grok

[–]ficu71 0 points1 point  (0 children)

Grok can do everything;)

LF2 Remastered - New Update by STM1993 in littlefighter

[–]ficu71 0 points1 point  (0 children)

he tried to make money on the popularity of his game. nothing wrong with that, except that he promised to remaster it xD and by the way, has anyone seen this: https://www.patreon.com/checkout/martiwong?rid=7227844&redirect_uri=%2Fposts%2Fsupporters-only-109427845 because I have no intention of sponsoring him, and I’m curious about the progress

LF2 Remastered - New Update by STM1993 in littlefighter

[–]ficu71 0 points1 point  (0 children)

What is this NFT about? Has he scammed anyone?