Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 09-10-2026, 21:29
th3tuga th3tuga is offline
Friend
 
Join Date: Oct 2023
Posts: 56
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 23 Times in 14 Posts
th3tuga Reputation: 0
Quote:
Originally Posted by deepzero View Post
Somehow it really doesnt feel good to depend my reverse engineering results on leaked/stolen webaccounts or relying on tricking AI censorship. Neither are reliable and can disappear overnight.
I was inspired by @Shub-Nigurrath tut last year on hunting for publicly exposed Ollama LLM instances:
Quote:
https://forum.exetools.com/showpost.php?p=133352&postcount=17
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc).

I want to emphasize that we never hack any military servers or websites. We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee. These accounts are accessed through their own proxy servers, so we have no direct interaction with the military or any government agency.
All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours. As long as we avoid supplying any personally identifying information to the models, our identities remain protected.
As @Shub-Nigurrath noted in the post last year about hunting for unsecured Ollama servers, this practice is no more illegal than using cracked software.


Quote:
Originally Posted by deepzero View Post
S
I think we should focus on a) less-restricted chinese models, preferable opensource ones b) smaller local models or c) running opensource models on rented GPUs online.
e.g. Exodia is running 2x DGX Spark (~12k usd): https://x.com/mrexodia/status/2090806161813405917
I like this approach. You can see me repeatedly ask @Shub-Nigurrath last week how we can hook up the mcp to local LLM like the Qwen models.
Reply With Quote
  #17  
Old 09-10-2026, 23:13
chants's Avatar
chants chants is offline
VIP
 
Join Date: Jul 2016
Posts: 884
Rept. Given: 48
Rept. Rcvd 53 Times in 32 Posts
Thanks Given: 766
Thanks Rcvd at 1,182 Times in 550 Posts
chants Reputation: 53
Thumbs down

Quote:
Originally Posted by th3tuga
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc)... We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee... accessed through their own proxy servers...
Look at how fast those goalposts are moving!
First it was "totally legit leaked US Military accounts on Telegram." Now that they got called out on how impossible it is to scan the US Military network with Shodan, the story completely flips. Now it's "Oh, we aren't hacking them, lower-level personnel are just renting out their access codes for a modest fee through a proxy server!"
This is hilarious. Let's break down the new set of lies they are cooking up to keep the scam alive:
1. The "Corrupt Low-Level Personnel" Lie
Do you honestly believe that an analyst at a top federal agency or a tier-1 cybersecurity firm like KrebsOnSecurity is risking a felony conviction, losing their security clearance, and getting blacklisted from the entire tech industry just to make a "modest fee" splitting an OpenAI API key on Telegram?
Furthermore, high-level corporate and government API access doesn't just work with a simple username and password you can pass to a buddy. It is locked behind strict enterprise Single Sign-On (SSO), hardware security keys (YubiKeys), and strict device posture checks. A "low-level" employee couldn't easily pipe this out to a random internet proxy even if they wanted to.
2. The Reverse-Proxy Smoke Screen
"All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours... our identities remain protected."
This is standard scam-operator jargon meant to sound deeply technical to newbies. If you route your traffic through a proxy server provided by the seller, you are the one being spied on. The person running that reverse proxy can see every single line of code you paste into that model, your reverse-engineering targets, and your own actual IP address if the proxy isn't configured right. You aren't "protected"—you are handing your data directly to a sketchy middleman.
3. The Classic "Bait and Switch" Technique
Notice how th3tuga tries to gain unearned credibility by name-dropping respected community figures (like mrexodia) and talking about local open-source setups like Qwen and MCP (Model Context Protocol).
  • They start with actual, legitimate tech topics (running open-source models on rented GPUs, local LLMs).
  • Then they smoothly pivot back to justifying their sketchy, paid "leaked frontier accounts" service.
This is a classic social engineering trick: wrap a blatant lie inside 80% genuine tech talk so that beginners can't tell where the facts end and the scam begins.
The Bottom Line:
They are trying desperately to sanitize their scam because their original "US Military hack" story fell apart under scrutiny. It's the same old tune: they want you to trust a "proxy" controlled by god-knows-who, to use "leaked" enterprise access that will likely get banned in 48 hours anyway.
If you want to use LLMs for reverse engineering reliably, stick to what deepzero ironically suggested at the bottom: run capable open-source models (like Qwen or Llama 3) locally or on a clean, legitimate cloud GPU instance (like Vast.ai or RunPod). Don't pay middlemen for "magical military proxies."
__________________

Last edited by chants; 09-10-2026 at 23:18.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 02:11.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )