Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

> Lazada Discussion V23 | #ScamMYUniverse #LazadaOR, lalalaxx.com | pricecampers.com

views
     
Enigmatic
post Nov 11 2017, 01:49 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
I was actually working on something so you guys will need to "work" a bit to get the vouchers, making it harder to spam use/disable. tongue.gif With this I could publicly share the vouchers, but no one at one time could have access to all of them.

user posted image


Code is a bit dirty but some things are intentional to make things less efficient. Unfortunately they disabled all the codes so things are for moot.

This post has been edited by Enigmatic: Nov 11 2017, 01:52 PM
Enigmatic
post Nov 11 2017, 02:27 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(adam_lss @ Nov 11 2017, 02:11 PM)
It's times like this I wished my earlier suggestion of having a FB closed group would be best, else LZD people come in n counter all the vouchers 😭😭😭
*
I have thought of this as well, but I am not very fond of it for the below reasons:

1. The vouchers are public property - And should be shared to the public as much as possible. These vouchers should give everyone a good time.
2. Having a closed group does not stop sybil attacks, someone could still spam use the vouchers, or someone from Lazada could be among the many as well.



Hence I was cooking up that piece of code in the screenshot - All vouchers will be public, everyone can try to get a voucher, it helps with distribution, and it is unlikely that one is lucky enough to get a large number of vouchers off that list.

In fact I wasn't too happy I had to post in hnngh because junior members would have no access to them, but I needed an interim workaround.
Enigmatic
post Nov 11 2017, 02:45 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(theozis @ Nov 11 2017, 02:30 PM)
女性?
俺は彼が男性と思う
*
あたしの性別は................................................. ひみつ.
Enigmatic
post Nov 11 2017, 03:06 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(afizudin @ Nov 11 2017, 03:05 PM)
managed to create makeid and get the link src of SHA3, but still got syntax error.. sigh...
is the hashed array of the img show all the code sifu?
*
No point - Vouchers are all disabled.

This post has been edited by Enigmatic: Nov 11 2017, 03:06 PM
Enigmatic
post Nov 11 2017, 03:15 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(afizudin @ Nov 11 2017, 03:08 PM)
just for educational purpose  biggrin.gif
*
The logic is this:

I have a list of vouchers which I will hash using SHA3 using another piece of code I have.
Hashed results will be displayed as plaintext, and stored as an array of hash strings.

There will be a random function generating a group of 6 alphanumeric characters, appended to either 29OR11 or 15OR11, then hashed with SHA3 and searched for in the array. If it exists within the array, you've gotten yourself a voucher. If not, the tool will continue looping and trying.


====


From users' perspective, they just need to copy paste the provided code lines into a text file, rename it to HTML, and press a button to start attempting (or I could provide the html page as well for the less technically inclined). When a voucher is found it'd prompt an alert.



But oh well.....

This post has been edited by Enigmatic: Nov 11 2017, 03:21 PM
Enigmatic
post Nov 11 2017, 03:27 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(naturalfool @ Nov 11 2017, 03:21 PM)
Ok I am paying attention here...for future reference.

Start copying from which portion? <script>?

Paste in text file...notepad can? After that save as .html

Press what button  confused.gif
*
The screenshot is not the full thing. What I was originally intending to provide is a text file which you just need to rename to .html, open in your browser, and do a single click to run.

But moot point to discuss this now. Next time maybe.
Enigmatic
post Nov 11 2017, 04:32 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(otakotak @ Nov 11 2017, 03:46 PM)
imo this will not slow anyone down, hashing and finding matching hash is not that difficult.

i would suggest to keep existing approach but post scrambled voucher in image/screenshot form instead of plaintext.
manual typing the voucher should be good enough to slow down everyone  brows.gif
*
Feel free to drop me a PM if you'd like to chat further on this topic since it is going off-topic. There are things which can be done for this.

Ultimately the goal is to make it hard to have access to all vouchers at a single time, without making it too difficult for people who genuinely wants to use them, while retaining the vouchers in public domain. Solving hashes in bulk is more expensive compared to just wanting to solve enough to get one or two vouchers.



Enigmatic
post Nov 11 2017, 07:32 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(rhytion @ Nov 11 2017, 07:13 PM)
Enigmatic 29% revalidated, please release more here, waiting for your SHA3 method. brows.gif
*
Was on the road. Give me 15 minutes. There's only less than 5 hours today so I don't really want to make it too hard for people to get their codes.
Enigmatic
post Nov 11 2017, 07:48 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(rhytion @ Nov 11 2017, 07:43 PM)
15% cannot use anymore
*
Adui.
Enigmatic
post Nov 11 2017, 07:56 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
Doing final tests. 5 mins. Not doing anything fancy.

For those who are really that unfortunate to not hit anything with the script - I'll still be posting a few codes here and there throughout the night.
Enigmatic
post Nov 11 2017, 08:00 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
Just rename the text file to .html, and click the only button there. Page will look like it hanged but it is looping.
File uploaded in plain text for people can see it is not anything malicious. Just simple js.

As I said, I am not using anything fancy (no nonce) so I hope you guys will be able to find some 29s. There are a ton of 15s in there too but I don't think they work.

Will post some 29s later as well for those less fortunate.


OH LOL I UPLOADED THE WRONG FILE.

This post has been edited by Enigmatic: Nov 11 2017, 08:08 PM
Enigmatic
post Nov 11 2017, 08:07 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
Those who gotten codes and used them - Please post here so people can cross check if the codes they've gotten are redeemed.


The person who approached Lazada is the real MVP.
Enigmatic
post Nov 11 2017, 08:09 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
Now that was embarrassing. sweat.gif
Enigmatic
post Nov 11 2017, 08:36 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
*coughs*

Well, that was. Hmm.

Attached is the correct one.
There are 60 29s in this. Tons more 15s but those are just smokescreen. Rename to .html. Click the only button. Might look like your tab is hanging but it is normal.

Let it run until an alert pops up with a code.

All the best.


Attached File(s)
Attached File  thisissoembarassing.txt ( 31.29k ) Number of downloads: 2070
Enigmatic
post Nov 11 2017, 08:38 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
Will still post up a few more vouchers tonight for the less fortunate, closer to 11PM. Hnngh will get some earlier.


Just give that script a try and see how well it works.
Enigmatic
post Nov 11 2017, 08:39 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(kuroro6262 @ Nov 11 2017, 08:38 PM)
thanks master, but dont know how to set...very tq
*
Right click download, rename .txt to .html. Double click the file, click the only button. Do something else/wait.
Enigmatic
post Nov 11 2017, 08:46 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(adam_lss @ Nov 11 2017, 08:42 PM)
Blank page with start working, that's it...
*
Don't mind the front end please... At least I didn't embed a nyancat video.


I'll leave the rest to you guys - Should be straightforward to run. Haven't eaten yet.

This post has been edited by Enigmatic: Nov 11 2017, 08:46 PM
Enigmatic
post Nov 11 2017, 08:53 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
QUOTE(Jigoku @ Nov 11 2017, 08:51 PM)
Looks like my browser failing me.

I got the "start working" button after clicking it.

wait a while page become blank but nothing still waiting...
*
Mine is as blank as yours. It's normal.
Enigmatic
post Nov 11 2017, 08:55 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
After you guys used the codes please inform others - Don't let people have false hope.


I'm still waiting for a 29. Pfft.
Enigmatic
post Nov 11 2017, 09:06 PM

Tralala?
*******
Senior Member
3,291 posts

Joined: Jan 2005
From: Nowhere Everywhere
user posted image


I've written this script and this is what I get. doh.gif Tsk.


Btw guys - 15* vouchers are all disabled. Only 29* works.

This post has been edited by Enigmatic: Nov 11 2017, 09:06 PM

3 Pages < 1 2 3 >
Bump Topic Topic ClosedOptions New Topic
 

Change to:
| Lo-Fi Version
0.1350sec    0.29    7 queries    GZIP Disabled
Time is now: 15th December 2025 - 05:10 PM