Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 538

Help with guidance to hack a scam website?

by Gramby - 29 December, 2023 - 01:33 PM
This post is by a banned member (Gramby) - Unhide
Gramby  
Registered
5
Posts
1
Threads
#1
(This post was last modified: 29 December, 2023 - 10:14 PM by Gramby. Edited 1 time in total.)
Hello,
I have a friend who for some reason believed in the scammers of https://comma-entertainmentpro.com/ . They lock in the persons so they will put in more money with the hope to get back his own money and a "commission" they were quiet helpful when I looked at their communication.

I know he will not be able to get back the money but I would like to do something anyway.

so far I have written a python script that register new users and registered a couple of thousands of users. They had to close the registration for a while but are we back again. I have started using different APIs that I identified to continue send POST commands. next I will start using GET to send multiple request.

The python script starts multiple process with multiple threads.

Now I would like to know if you have other ideas for measures I can take?
This post is by a banned member (Wo0dy36) - Unhide
Wo0dy36  
Infinity
30
Posts
14
Threads
#2
if the page has a search box or some fields to type in you can see if they are sanitized or if it allows you to execute payloads, that way you can find a space where you can enter.
This post is by a banned member (Gramby) - Unhide
Gramby  
Registered
5
Posts
1
Threads
#3
(29 December, 2023 - 06:36 PM)Wo0dy36 Wrote: Show More
if the page has a search box or some fields to type in you can see if they are sanitized or if it allows you to execute payloads, that way you can find a space where you can enter.

Unfotunatly there are none. At the moment I have used the inspection mode on the browser and Wireshark. But inspection mode was enough. I have mapped the available API for the website and am trying to use that.
But the only API that I found able to affect the database or backend is the register API.
This post is by a banned member (GetHub) - Unhide
GetHub  
Registered
97
Posts
37
Threads
1 Year of service
#4
goodluck reported their website at the host
Like my posts for sharing more

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)