User Controls
Thanked Posts by Sophie
-
2021-12-28 at 4:50 PM UTC in Wariat’s PI
-
2021-12-28 at 4:43 PM UTC in Is your city overrun with pandemic shantytowns?Nah we shoot the homeless and destitute.
-
2021-12-28 at 9:29 AM UTC in Will Pedo Wariat ever get his ass licked?
-
2021-12-27 at 3:10 PM UTC in What if you made first contact with aleansHonestly i'd probably just assume i'd be losing my mind.
-
2021-12-27 at 3:17 PM UTC in Best way to kill 100 people along with SWIMself
Originally posted by Meikai ANFO is the obvious choice, as borne out by Timothy McVeigh. But you could obviously, probably, improve on that. ANFO is stable so loading up a truck with a shit ton of that remains a tried and tried option, but you can definitely just substitute all that ANFO with peroxides if you're very very careful. Probably.
Kek, don't bump into anything with fucking van full off TATP. -
2021-12-22 at 5:49 AM UTC in It's Winter Solstice.Yule tidings, it is Winter Solstice niggas.
Favor of Frija and Mimir -Lord of Lore and The Mysteries- upon you. May they grant you the wisdom and insight of the Allfather.
Ef ek skal til orrostu leiða langvini, und randir ek gel En þeir með ríki fara. Heilir hildar til. Heilir hildi frá. Koma þeir heilir hvaðan. -
2021-12-20 at 3:02 PM UTC in Grabbing Crypto Addresses with regex. And more.Preamble
I'd like to use this thread as a bit of a resources to post regex that may be useful in filtering and identifying crypto addresses and other strings with regards to financial information.
regex
py_dict= {'legacy_btc': '^[13][a-km-zA-HJ-NP-Z1-9]{25,34}$',
'segwit_btc': '^(bc1|[13])[a-zA-HJ-NP-Z0-9]{25,39}$',
'xmr': '4[0-9AB][123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{93}',
'eth': '^0x[a-fA-F0-9]{40}$',
'lite': '^[LM3][a-km-zA-HJ-NP-Z1-9]{26,33}$',
'dash': '^X[1-9A-HJ-NP-Za-km-z]{33}$',
'ripple': '^r[0-9a-zA-Z]{24,34}$',
'doge': '^D{1}[5-9A-HJ-NP-U]{1}[1-9A-HJ-NP-Za-km-z]{32}$'}
This is a Python dictionary object that has regex for the crypto coins you can see defined. Dictionaries like this are handy for a number of reasons not least of all since it allows you to easily read/write JSON files. Therefore when it comes to any program that needs the ability to recognize certain strings as valid crypto addresses you can easily write a config file in JSON format to specify the types of coins you're after.
You could also have a dictionary like this in your malware, say a keylogger, so it can automatically recognize/grab/copy/replace any strings like this by comparing the keystrokes to your regexes. If you're gonna make a python keylogger though i do suggest you sue the Ctypes lib, and create a proper keymap, like you would in a C or C++ based malware instead of relying on PyHook and such to hook the keyboard. On that note handling registry operations in Python with Ctypes is definitely the way to go as well.
Below is a small sample of regex, that should work with C++.
regex bitpat{ "^(bc1|[13])[a-zA-HJ-NP-Z0-9]{25,39}$" };
regex litpat{ "^[LM3][a-km-zA-HJ-NP-Z1-9]{26,33}$" };
regex monpat{ "^4([0-9]|[A-B])(.){93}" };
regex ethpat{ "^0x[a-fA-F0-9]{40}$" };
I had a bunch more regexes for CC info, important strings to do with banking such as IBAN and SEPA, but i got those on a box, that is currently offline and in need of some repairs i can't be assed to get the HDD and look for the specific files in question.
This is just a small sample size, please feel free to add some more.
Moar
Related to this, if you'e in the business of hijacking API keys for payment processors the following might be for you. not exactly regex but ways to verify the API tokens/secrets you may come across.
API verify and info
Paypal
Paypal client id and secret key
curl -v https://api.sandbox.paypal.com/v1/oauth2/token \
-H "Accept: application/json" \
-H "Accept-Language: en_US" \
-u "client_id:secret" \
-d "grant_type=client_credentials"
The access token can be further used to extract data from the PayPal API. More info
This can be verified using:
curl -v -X GET "https://api.sandbox.paypal.com/v1/identity/oauth2/userinfo?schema=paypalv1.1" -H "Content-Type: application/json" -H "Authorization: Bearer [ACCESS_TOKEN]"
Stripe
Stripe Live Token
curl https://api.stripe.com/v1/charges -u token_here:
Keep the colon at the end of the token to prevent cURL from requesting a password.
The token is always in the following format: `sk_live_24charshere`, where the `24charshere` part contains 24 characters from `a-z A-Z 0-9`. There is also a test key, which starts with `sk_test`, but this key is worthless since it is only used for testing purposes and most likely doesn't contain any sensitive information. The live key, on the other hand, can be used to extract/retrieve a lot of info — ranging from charges to the complete product list.
Keep in mind that you will never be able to get the full credit card information since Stripe only gives you the last 4 digits.
More info/complete documentation https://stripe.com/docs/api/authentication.
Razorpay
Razorpay API key and Secret key
This can be verified using:
curl -u <YOUR_KEY_ID>:<YOUR_KEY_SECRET> \
https://api.razorpay.com/v1/payments
Anyway figured i'd post it here to get a good list going and provide those that are/were unaware, with this information for your enjoyment. Got anything interesting to add? Please feel free to do so. -
2021-12-20 at 6:27 AM UTC in Sudo is full of gloom & doom...
Originally posted by Sudo I went to a psychologist the other day for the first time so was going over a timeline of my life and when I mentioned opiate addiction she interrupted me to tell me about thr time she broke her wrist skiing then got injected with fentanyl and loved it. Then she told me the same story again later in the session.
I think she was trying to see if I would offer to get her fentanyl
Psychology departments get filled with neuro-deficients. I went to a psychologist once, she was this brunette straight outta college. She was hot so i couldn't help myself and charmed her. She wanted the D. this is going to sound silly but after i charmed her i was kind of disappointed. I thought you're supposed to help me bitch, if you can't see through the smoke and mirrors, you ain't gonna manage that. i realize that's a very borderline line of thinking but that's why i was there in the first place. -
2021-12-19 at 4:49 PM UTC in So let me get this straightMy unhealthy groping mechanism consists of dislocating my shoulder so i can squeeze the ass on the subway from unexpected angles. They never realize it's me.
-
2021-12-19 at 5:11 PM UTC in I made a throwaway account to shitpost but there isn't even anything good to shitpost to"You'll cry forever" Lol.
That's a way too cutesy thing to say for you don't do it. -
2021-12-11 at 3:45 PM UTC in wariat containment thread
Originally posted by aldra probably sploo
While i'm taking a stroll down memory lane, remember when Sploo got the hammer for a month or two and Gun lover made the post like; i banned Sploo. He literally got more than 50 thanks. It was pretty impressive how Sploo was able to alienate so many people in such a short time. -
2021-12-11 at 5:57 PM UTC in Glory to the king of Kings.
-
2021-12-11 at 12:43 AM UTC in Ghislaine maxwell trial odd af
Originally posted by Quick Mix Ready over and over and over again
but people like us never get a break if we fucked up. not even half the level of evil that these people have done.
anyone not rich, powerful, famous etc unless they lashed out at others and are new money. then and only then to they get treated like the rest.
Jeffy Epstein was arrested around 2000 for trying to have underage girls come to him for sex and he was allowed to pay for his own jail cell which was the size of a one-bedroom apartment and able to come and go outside in the yard.
there is no doubt in my mind that the stories of Bill Clinton as Gov of Arkansas and the Mena connections is fabricated. non at all. him and his wife are sick sick people with a power trip.
Hilary punched a Secret Service agent. or threw something at him. Why wasn't she charged? thats fucking insane.
FBI give little fucks "And you can't just call us whenever you feel like it" but Jennifer Lawrense and her stolen phone has dozens of these agents coming to her rescue.
Obama, Clinton, Cuomo and the Weather Ground Organization
James Comey and Jeff Hunter. Same time, Same Company. Full Transparency clause. 2013. Ray Daleo. now his daughter is on this case?
it's laughably obvious.
the hand picks have full control
The FBI is a domestic intelligence agency, they are not a law enforcement agency. Maybe not de jure but de facto. And they have been for a long time. Of course they would be very interested in J-Law's phone, contacts, compromat, dirt, you know, the works.
This is also why the FBI will never ever ever willingly give up all the evidence they collected from MUH NAME A JEFF's Island/Home/Office/whatever. It gives them leverage over too many important pieces on the board for them to do that. In fact it's so fucking bad, that they are fully aware and cognizant that no one believes JEFF offed himself and that everyone knows Maxwell's trial is a show trial. They would rather have the justice system which they are supposed to serve take a huge credibility hit than give up that leverage.
At least the mask is off, but good God, imagine what you could do with this power. They guard it jealously against all moral fiber, against all 'common sense' against all the negative PR, against everything.
This is why this whole situation is so rife with fuckery. -
2018-04-28 at 11:47 PM UTC in SpectraL has died.
-
2021-11-26 at 9:51 PM UTC in I told you multiple times. And I was RIGHTI didn't know 'msn.com' still existed.
-
2021-09-29 at 4:09 PM UTC in Amputation: dominate arm above elbow
Originally posted by hydromorphone Despite you being the last one here I’d likely ever meet irl I KNOW you’d most certainly be the best and funnest with you and your gf if I ever did meet you both irl fuck what anyone else says you’re like one of the best people here
Thank you. I think understanding is an important component of empathy, no matter who anyone is or 'what' anyone is. That said.
Don't praise me too much though it'll go straight to my head. -
2021-11-29 at 3:47 AM UTC in What do you do with your Anger?I am very far from normal, needless to say i don't deal with anger very well.
-
2021-11-29 at 5:17 AM UTC in We need to have a talk about apples new invasion of privacy
Originally posted by Quick Mix Ready think about the NSA guys or private groups hired to watch people of suspicion in their own homes, with occasionally the wife or even child walking in the house naked to the shower or from. then taking a photo with his or her own personal phone cam to share later. I know this has happened. and no doubt more than once.
Hiring a single 'operative' is gonna cost you an arm and a leg, hiring a group of them is unaffordable for most people. And the NSA might have everyone's data sitting in their servers, but it's not actively being used to compromise everyone's privacy all at once. It's way too much data for that. Even for the NSA. So Joe the bricklayer from Smalltown USA is going to be fine. And you will be too right up until the moment you cause a shitstorm of a magnitude to cross the threshold into 'worth the time and resources to investigate further' territory.
Like aldra said, it sets a bad precedent if all of a sudden any enterprise with the capabilities to do so can just decide you don't have privacy anymore. And the best part is they won't even have to have expensive surveillance programs, because you'll buy their fucking trinkets from them. You'll be funding your own ass raping. -
2021-11-29 at 4:37 AM UTC in We need to have a talk about apples new invasion of privacyWell it was always kind of silly to keep your CP on your phone now wasn't it?
-
2021-11-26 at 10:09 PM UTC in Lala is teaching me how to drive