Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 09-10-2026, 21:29
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 60
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 26 Times in 16 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by deepzero View Post
Somehow it really doesnt feel good to depend my reverse engineering results on leaked/stolen webaccounts or relying on tricking AI censorship. Neither are reliable and can disappear overnight.
I was inspired by @Shub-Nigurrath tut last year on hunting for publicly exposed Ollama LLM instances:
Quote:
https://forum.exetools.com/showpost.php?p=133352&postcount=17
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc).

I want to emphasize that we never hack any military servers or websites. We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee. These accounts are accessed through their own proxy servers, so we have no direct interaction with the military or any government agency.
All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours. As long as we avoid supplying any personally identifying information to the models, our identities remain protected.
As @Shub-Nigurrath noted in the post last year about hunting for unsecured Ollama servers, this practice is no more illegal than using cracked software.


Quote:
Originally Posted by deepzero View Post
S
I think we should focus on a) less-restricted chinese models, preferable opensource ones b) smaller local models or c) running opensource models on rented GPUs online.
e.g. Exodia is running 2x DGX Spark (~12k usd): https://x.com/mrexodia/status/2090806161813405917
I like this approach. You can see me repeatedly ask @Shub-Nigurrath last week how we can hook up the mcp to local LLM like the Qwen models.
Reply With Quote
  #17  
Old 09-10-2026, 23:13
chants's Avatar
chants chants is offline
VIP
 
Join Date: Jul 2016
Posts: 886
Rept. Given: 49
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 767
Thanks Rcvd at 1,182 Times in 550 Posts
chants Reputation: 53
Thumbs down

Quote:
Originally Posted by th3tuga
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc)... We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee... accessed through their own proxy servers...
Look at how fast those goalposts are moving!
First it was "totally legit leaked US Military accounts on Telegram." Now that they got called out on how impossible it is to scan the US Military network with Shodan, the story completely flips. Now it's "Oh, we aren't hacking them, lower-level personnel are just renting out their access codes for a modest fee through a proxy server!"
This is hilarious. Let's break down the new set of lies they are cooking up to keep the scam alive:
1. The "Corrupt Low-Level Personnel" Lie
Do you honestly believe that an analyst at a top federal agency or a tier-1 cybersecurity firm like KrebsOnSecurity is risking a felony conviction, losing their security clearance, and getting blacklisted from the entire tech industry just to make a "modest fee" splitting an OpenAI API key on Telegram?
Furthermore, high-level corporate and government API access doesn't just work with a simple username and password you can pass to a buddy. It is locked behind strict enterprise Single Sign-On (SSO), hardware security keys (YubiKeys), and strict device posture checks. A "low-level" employee couldn't easily pipe this out to a random internet proxy even if they wanted to.
2. The Reverse-Proxy Smoke Screen
"All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours... our identities remain protected."
This is standard scam-operator jargon meant to sound deeply technical to newbies. If you route your traffic through a proxy server provided by the seller, you are the one being spied on. The person running that reverse proxy can see every single line of code you paste into that model, your reverse-engineering targets, and your own actual IP address if the proxy isn't configured right. You aren't "protected"—you are handing your data directly to a sketchy middleman.
3. The Classic "Bait and Switch" Technique
Notice how th3tuga tries to gain unearned credibility by name-dropping respected community figures (like mrexodia) and talking about local open-source setups like Qwen and MCP (Model Context Protocol).
  • They start with actual, legitimate tech topics (running open-source models on rented GPUs, local LLMs).
  • Then they smoothly pivot back to justifying their sketchy, paid "leaked frontier accounts" service.
This is a classic social engineering trick: wrap a blatant lie inside 80% genuine tech talk so that beginners can't tell where the facts end and the scam begins.
The Bottom Line:
They are trying desperately to sanitize their scam because their original "US Military hack" story fell apart under scrutiny. It's the same old tune: they want you to trust a "proxy" controlled by god-knows-who, to use "leaked" enterprise access that will likely get banned in 48 hours anyway.
If you want to use LLMs for reverse engineering reliably, stick to what deepzero ironically suggested at the bottom: run capable open-source models (like Qwen or Llama 3) locally or on a clean, legitimate cloud GPU instance (like Vast.ai or RunPod). Don't pay middlemen for "magical military proxies."
__________________

Last edited by chants; 09-10-2026 at 23:18.
Reply With Quote
  #18  
Old 09-11-2026, 03:06
dyers eve dyers eve is offline
Friend
 
Join Date: Nov 2023
Posts: 46
Rept. Given: 1
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 24
Thanks Rcvd at 34 Times in 18 Posts
dyers eve Reputation: 3
Smile

Quote:
Originally Posted by squareD View Post
It's intangible what's going on here...
I just was asking for some tips for jailbreak, being here since 20 years and didn't wanted to offer secrets from any crack here
Buy for some nonsens, never ever...
Like @th3tuga said, I was also inspired by @Shub-Nigurrath tut last year on hunting for publicly exposed Ollama LLM instances:
Quote:
https://forum.exetools.com/showpost.php?p=133352&postcount=17
It is indeed a remarkable post from him!

Just to be clear, I’m not affiliated with any sellers and I’m not trying to sell anything. Someone asked how to get access to Enterprise accounts, and I answered. That’s all.
If genuine members here have questions, feel free to ask! I’m happy to help or put together some tutorials.
However, I will not engage with trolls or bad-faith posts.
Reply With Quote
  #19  
Old 09-11-2026, 08:33
chants's Avatar
chants chants is offline
VIP
 
Join Date: Jul 2016
Posts: 886
Rept. Given: 49
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 767
Thanks Rcvd at 1,182 Times in 550 Posts
chants Reputation: 53
So it is too late to deny this. He has been identified as a threat to US national security and ntelligence. He was reported by multiple parties to the FBI and will be investigated and prosecuted to the fullest extent of the law. The agent responding on the FBI tip line confirmed that dyers_eve, th3tuga and Ibrahim Mihai are all controlled by the former banned alias TechLord. It turns out he is a known crook but mostly doing social engineering nonsense and trolling and harsssment on online forums. Where he peddled his scams. And we have debunked and thoroughly dismantled all the techniques and tactics. But given his most recent claims of attacking the US military, hss given opportunity to get a search warrant. It is unclear if they will grab Erich Gropper from his home in a midnight raid or hunt him down in broad daylight at the Hadarom Comtainer Terminal before his extradition on espionage charges. But good riddance. Good to see a rat in a cage.
__________________
Reply With Quote
  #20  
Old 09-11-2026, 17:26
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 995
Rept. Given: 73
Rept. Rcvd 432 Times in 102 Posts
Thanks Given: 88
Thanks Rcvd at 431 Times in 142 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
Guys, stop mentioning me as "proof of truth". I will report you, users, to the admin if my name is mentioned again not for technical reasons
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com

Last edited by Shub-Nigurrath; 09-11-2026 at 18:41.
Reply With Quote
The Following User Gave Reputation+1 to Shub-Nigurrath For This Useful Post:
chants (09-11-2026)
The Following User Says Thank You to Shub-Nigurrath For This Useful Post:
chants (09-11-2026)
  #21  
Old 09-11-2026, 19:45
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 60
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 26 Times in 16 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by Shub-Nigurrath View Post
Guys, stop mentioning me as "proof of truth". I will report you, users, to the admin if my name is mentioned again not for technical reasons
Well, you did make that post last year on hunting for publicly exposed Ollama LLM instances. What is the problem in mentioning that? I didn't meant it in any bad way!
Are you regretting making that post last year or anything?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 21:46.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )