@offlinei
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
Probably the hackiest "bypasses" I've ever pulled off in botting:
The Shopify REST API was for a long time the best and fastest way to checkout on Shopify. High rate limits, no captchas, no checkpoint and easy to work with. This is what gave Cyber the edge at the very start in 2018 (Dashe days)
The Shopify team (with @jmwind at the helm) spent years plugging the holes to make sure it wasn't used during drops.
Around 2020, Shopify released Shopify Pay, which allowed you to expedite checkouts on all stores by linking your details to a phone number. Turned out the payment tokens generated through there allowed you to use the payments API as you could 2 years back.
We generated around 3k Shop Pay accounts with randomised details, load balanced them across Cyber tasks (as rate limits were per account) and dominated every single release (...until it got patched).
We called it Fast2.
3 years later I noticed that the payments API could still be used with Shopify mobile apps using Apple Pay. Turns out you could still send the users' tokenised credit card data in the request and that would take precedence - and as long as a valid signed Apple Pay token generated in the last 2 minutes was also in the request data, the payment request would go through and bypass captcha and checkpoint.
Generating those Apple Pay tokens was the challenge, and reversing iOS frameworks was not an option. So I repurposed an old iPhone with a custom sideloaded Apple Pay app that would submit the token to our servers when the flow completed. And by combining accessibility macros, developer sandbox mode to prevent using real credit cards, a voice activation trigger and a old pair of earphones taped onto the microphone - a makeshift Apple Pay token server was born and Fast2 (or was it Fast3?) was back.
@jmwind thank you for providing me with the longest, most multi faceted puzzle ever.
Honestly what a time. And it's crazy to me that reselling is still profitable to this day... Still remember the days when we were using open source PHP scripts to generate Adidas ATC links...
This scene has taught me more than any master degree or corporate job possibly could. We were building and iterating faster than the engineering teams of the brands we were botting and the companies responsible for their infrastructure - at a fraction of the team size.
Nothing will beat the rush of deploying a last minute update to thousands of users or being the only bot hitting a drop.
The sheer amount of ingenuity required from devs of this community to find ways to beat the competition and get the slightest edge was just crazy and led to some insane finds from bypasses to undocumented APIs to admin tokens... the list goes on.
And to see some great talent go on to build even greater things is just amazing. I'm not surprised in the slightest way.
Good work @jmwind 🤝
Lucas retweeted
CYBERSOLE GIVEAWAY!
10 lucky individuals will each receive a free sweatshirt, crewneck and a monthly key. To enter, simply;
- Follow @Cybersole
- Like this tweet
- Retweet
Winners will be announced on April 1st.
Good luck! 🌐
Our public REST API docs are now available at docs.cybersole.io/
Lucas retweeted
What better way to start the weekend off than with an opportunity to win a lifetime Cybersole license key?
Follow @Cybersole
Like and RT
Reply with #Cybersole5
3 winners will be announced on Monday.
Good luck! 🌐
Leave some for the rest of us😳
I’m going to finally take cyber 5.0 for a spin, review it, and give away every pair that I cop to Twitter friends.
Which upcoming drop is the most hyped? Who wants some free sneakers?! #shoelantrophy