@winhelpwin Dots "." are treated as a sorta invisible character to the Gmail parsing system, so warriorsFan[at]gmail[dot]com with 1 or more "."s anywhere in the "warriorsFan" portion will be ignored and still forwarded to the original email
New Robinhood phishing chain that's kinda beautiful:
1. Attacker creates an RH account using the Gmail dot trick of your email (same inbox, different address)
2. Sets device name to HTML
3. RH's "unrecognized activity" email renders the device name unsanitized (html injection)
The result is a real email from [email protected], DKIM pass, SPF pass, DMARC pass, with a phishing CTA
Just because it's real, doesn't mean it's safe... $HOOD
@bmgentile Yes, HTML injection via the device name. Basically XSS with no scripting, just HTML.
I did check, the URL is a phishing URL, albeit I refrained from linking it.
Excited to share we’ve raised $2.75M for @CubbyLaw from @LudlowVentures, @SamHinkie, and @PSUMVC.
We’re building the first AI teaching assistant for law students, powered by our own legal intelligence model trained on thousands of professors’ syllabi, past exams, outlines, and grading rubrics.
Cubby started as a horizontal AI research tool, but when law students began adopting it fast, we went all in.
Law school prep is broken:
• Curve-based grading
• 100+ hrs building outlines
• Legacy tools students still pay thousands for
Cubby brings it all into one connected workspace: case briefs, outlines, and practice exams, calibrated to how your professor teaches and tests.
Law school is our first step toward a new era in legal tech.
@B_nnett@AppStore A few apps I have just make this a secret. The main app is free and has limited demo/free functionality. You then go to settings, press and hold an unrelated icon or piece of text, and then the license box pops up.
Throwback to when I found a bypass to Adidas splash.
It worked because Adidas development team still returned developer cookies on a GET to the staging splash page, even with invalid auth. I'd GET staging, take the hmac, transfer to the live domain, and bypass splash.
@B_nnett Yeezy Mafia, Sole Slayer, AIOBot, OG YZYlab, Heatedsneaks refresh bypass, Wrath Adidas (Wrath logo is Adidas upside down), and way, way, way more. Been in the botting game since 16' and sneakers since 15', and I have seen a lot in that time. Way too much to list.
@3liet I think that this is the problem. The Ivy League and similar have a leg up mentally. You're not even given a shot with interviews otherwise. The people I know who DID find a way to get an interview had amazing results. It's that first leg that's the hardest.
The undervaluing of sneaker devs in the corporate world is mind boggling to me.
Recruiters literally have a cheat code to the brightest minds yet they don’t use it.