Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Prompting and Using Cloud AI for Reverse Engineering (https://forum.exetools.com/showthread.php?t=21735)

th3tuga 09-10-2026 21:29

Quote:

Originally Posted by deepzero (Post 136117)
Somehow it really doesnt feel good to depend my reverse engineering results on leaked/stolen webaccounts or relying on tricking AI censorship. Neither are reliable and can disappear overnight.

I was inspired by @Shub-Nigurrath tut last year on hunting for publicly exposed Ollama LLM instances:
Quote:

https://forum.exetools.com/showpost.php?p=133352&postcount=17
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc).

I want to emphasize that we never hack any military servers or websites. We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee. These accounts are accessed through their own proxy servers, so we have no direct interaction with the military or any government agency.
All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours. As long as we avoid supplying any personally identifying information to the models, our identities remain protected.
As @Shub-Nigurrath noted in the post last year about hunting for unsecured Ollama servers, this practice is no more illegal than using cracked software.


Quote:

Originally Posted by deepzero (Post 136117)
S
I think we should focus on a) less-restricted chinese models, preferable opensource ones b) smaller local models or c) running opensource models on rented GPUs online.
e.g. Exodia is running 2x DGX Spark (~12k usd): https://x.com/mrexodia/status/2090806161813405917

I like this approach. You can see me repeatedly ask @Shub-Nigurrath last week how we can hook up the mcp to local LLM like the Qwen models.

chants 09-10-2026 23:13

Quote:

Originally Posted by th3tuga
From that point onward, my efforts shifted to locating the Claude and OpenAI accounts that IT‑security staff share(from companies they are employed like KrebsOnSecurity etc)... We simply use the frontier‑AI accounts that the military and other government agencies provide, which lower‑level personnel hand out for a modest fee... accessed through their own proxy servers...
Look at how fast those goalposts are moving! :eek:
First it was "totally legit leaked US Military accounts on Telegram." Now that they got called out on how impossible it is to scan the US Military network with Shodan, the story completely flips. Now it's "Oh, we aren't hacking them, lower-level personnel are just renting out their access codes for a modest fee through a proxy server!"
This is hilarious. Let's break down the new set of lies they are cooking up to keep the scam alive:
1. The "Corrupt Low-Level Personnel" Lie
Do you honestly believe that an analyst at a top federal agency or a tier-1 cybersecurity firm like KrebsOnSecurity is risking a felony conviction, losing their security clearance, and getting blacklisted from the entire tech industry just to make a "modest fee" splitting an OpenAI API key on Telegram?
Furthermore, high-level corporate and government API access doesn't just work with a simple username and password you can pass to a buddy. It is locked behind strict enterprise Single Sign-On (SSO), hardware security keys (YubiKeys), and strict device posture checks. A "low-level" employee couldn't easily pipe this out to a random internet proxy even if they wanted to.
2. The Reverse-Proxy Smoke Screen
"All requests to the AI providers appear to come from the reverse‑proxy IP addresses, not ours... our identities remain protected."
This is standard scam-operator jargon meant to sound deeply technical to newbies. If you route your traffic through a proxy server provided by the seller, you are the one being spied on. The person running that reverse proxy can see every single line of code you paste into that model, your reverse-engineering targets, and your own actual IP address if the proxy isn't configured right. You aren't "protected"—you are handing your data directly to a sketchy middleman.
3. The Classic "Bait and Switch" Technique
Notice how th3tuga tries to gain unearned credibility by name-dropping respected community figures (like mrexodia) and talking about local open-source setups like Qwen and MCP (Model Context Protocol).
  • They start with actual, legitimate tech topics (running open-source models on rented GPUs, local LLMs).
  • Then they smoothly pivot back to justifying their sketchy, paid "leaked frontier accounts" service.
This is a classic social engineering trick: wrap a blatant lie inside 80% genuine tech talk so that beginners can't tell where the facts end and the scam begins.
The Bottom Line:
They are trying desperately to sanitize their scam because their original "US Military hack" story fell apart under scrutiny. It's the same old tune: they want you to trust a "proxy" controlled by god-knows-who, to use "leaked" enterprise access that will likely get banned in 48 hours anyway.
If you want to use LLMs for reverse engineering reliably, stick to what deepzero ironically suggested at the bottom: run capable open-source models (like Qwen or Llama 3) locally or on a clean, legitimate cloud GPU instance (like Vast.ai or RunPod). Don't pay middlemen for "magical military proxies."

dyers eve 09-11-2026 03:06

Quote:

Originally Posted by squareD (Post 136119)
It's intangible what's going on here...
I just was asking for some tips for jailbreak, being here since 20 years and didn't wanted to offer secrets from any crack here
Buy for some nonsens, never ever...

Like @th3tuga said, I was also inspired by @Shub-Nigurrath tut last year on hunting for publicly exposed Ollama LLM instances:
Quote:

https://forum.exetools.com/showpost.php?p=133352&postcount=17
It is indeed a remarkable post from him!

Just to be clear, I’m not affiliated with any sellers and I’m not trying to sell anything. Someone asked how to get access to Enterprise accounts, and I answered. That’s all.
If genuine members here have questions, feel free to ask! I’m happy to help or put together some tutorials.
However, I will not engage with trolls or bad-faith posts. :)

chants 09-11-2026 08:33

So it is too late to deny this. He has been identified as a threat to US national security and ntelligence. He was reported by multiple parties to the FBI and will be investigated and prosecuted to the fullest extent of the law. The agent responding on the FBI tip line confirmed that dyers_eve, th3tuga and Ibrahim Mihai are all controlled by the former banned alias TechLord. It turns out he is a known crook but mostly doing social engineering nonsense and trolling and harsssment on online forums. Where he peddled his scams. And we have debunked and thoroughly dismantled all the techniques and tactics. But given his most recent claims of attacking the US military, hss given opportunity to get a search warrant. It is unclear if they will grab Erich Gropper from his home in a midnight raid or hunt him down in broad daylight at the Hadarom Comtainer Terminal before his extradition on espionage charges. But good riddance. Good to see a rat in a cage.

Shub-Nigurrath 09-11-2026 17:26

Guys, stop mentioning me as "proof of truth". I will report you, users, to the admin if my name is mentioned again not for technical reasons

th3tuga 09-11-2026 19:45

Quote:

Originally Posted by Shub-Nigurrath (Post 136135)
Guys, stop mentioning me as "proof of truth". I will report you, users, to the admin if my name is mentioned again not for technical reasons

Well, you did make that post last year on hunting for publicly exposed Ollama LLM instances. What is the problem in mentioning that? I didn't meant it in any bad way!
Are you regretting making that post last year or anything?:confused:

th3tuga 09-12-2026 02:30

Quote:

Originally Posted by chants (Post 136127)
So it is too late to deny this. He has been identified as a threat to US national security and ntelligence. He was reported by multiple parties to the FBI and will be investigated and prosecuted to the fullest extent of the law. The agent responding on the FBI tip line confirmed that dyers_eve, th3tuga and Ibrahim Mihai are all controlled by the former banned alias TechLord. It turns out he is a known crook but mostly doing social engineering nonsense and trolling and harsssment on online forums. Where he peddled his scams. And we have debunked and thoroughly dismantled all the techniques and tactics. But given his most recent claims of attacking the US military, hss given opportunity to get a search warrant. It is unclear if they will grab Erich Gropper from his home in a midnight raid or hunt him down in broad daylight at the Hadarom Comtainer Terminal before his extradition on espionage charges. But good riddance. Good to see a rat in a cage.

Why do you insist on doing this all over again? After 10 years? When your original enemy is already dead 3 years ago?!
I am old enough to remember all that.
But if you insist, and if you want to do names, why not start with your own???

Check out the real youtube videos of chants alias Gregory Morse alias Abdul Muid here:

Playlist of all his videos
https://www.youtube.com/@JihadiAbdulMuid/videos

The more interesting ones:

USA Persecution, Crimes and Abuse against Gregory (Abdul Muid) Morse Chapter 1
https://www.youtube.com/watch?v=TyirrDER5L0

USA Persecution, Crimes and Abuse against Gregory (Abdul Muid) Morse Chapter 2:
https://www.youtube.com/watch?v=UpK9ezmASgQ

USA Persecution, Crimes and Abuse against Gregory (Abdul Muid) Morse Chapter 3
https://www.youtube.com/watch?v=HFk_ouetxVI


These are from the pre-AI era. 10-15 year old original videos of chants.


All times are GMT +8. The time now is 05:30.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX