vx-underground
TeaOnHer, the app meant to combat the infamous "TeaApp", is also a giant dumpster fire. It has been compromised. THE DEVELOPER MADE HIS PASSWORD TO THE ADMIN PANEL "Password1!". IT WAS STORED IN PLAIN TEXT ON THE LANDING PAGE. WHAT THE FUCK.
It's leaking nerds driver licenses too.
DAWG LOL STOP VIBE CODING
DAWG LOL STOP VIBE CODING
π€£85β€βπ₯7π€―4β€1π’1π1π―1
vx-underground
It's leaking nerds driver licenses too. DAWG LOL STOP VIBE CODING
WHAT IS BRO YAPPIN ABOUT?! NONE OF THIS IS TRUE
π€£81π12π’5β€2
vx-underground
WHAT IS BRO YAPPIN ABOUT?! NONE OF THIS IS TRUE
All information by Zach Whittacker. He reported on this last week but I somehow missed it
https://techcrunch.com/2025/08/06/a-rival-tea-app-for-men-is-leaking-its-users-personal-data-and-drivers-licenses/
https://techcrunch.com/2025/08/06/a-rival-tea-app-for-men-is-leaking-its-users-personal-data-and-drivers-licenses/
TechCrunch
TeaOnHer, a rival Tea app for men, is leaking users' personal data and driver's licenses | TechCrunch
The newly launched app, now trending on Apple's App Store, contains at least one major security flaw that exposes the private information of its users, including their uploaded selfies and government-issued IDs.
β€20π€©7π₯1π’1
I'll tell you one thing right now, Chat. If these video game companies require a drivers license to play a game, we got driver licenses FOR YEARS thanks to TeaApp and TeaOnHer.
It's free identity theft for the whole family. You can frisbee stolen identities to strangers
It's free identity theft for the whole family. You can frisbee stolen identities to strangers
π€©77π€£27β€14π―7π’1
If you're a person who has been a victim of a data leak and/or company compromise we have tips on how to protect yourself.
We know changing passwords can only go so far. If you're a noob and want some tips read below!
1. Change your full name. You need to change your first name, middle name, and last name. If you don't have a middle name, get one.
2. Physically destroy your cell phone. Ideally you should catapult it into an active volcano. Once this has been accomplished, get a new cell phone provider, cell phone number, and cell phone model.
3. Change your profession. If you have a job as a result of a university education, then too bad. Go back to school or go into blue collar work.
4. Get plastic surgery. You need to be unrecognizable to friends, family, and co-workers (your old co-workers).
5. Move to a different state and/or country.
With these 5 simple tips you won't have to worry about cyber breaches!
We know changing passwords can only go so far. If you're a noob and want some tips read below!
1. Change your full name. You need to change your first name, middle name, and last name. If you don't have a middle name, get one.
2. Physically destroy your cell phone. Ideally you should catapult it into an active volcano. Once this has been accomplished, get a new cell phone provider, cell phone number, and cell phone model.
3. Change your profession. If you have a job as a result of a university education, then too bad. Go back to school or go into blue collar work.
4. Get plastic surgery. You need to be unrecognizable to friends, family, and co-workers (your old co-workers).
5. Move to a different state and/or country.
With these 5 simple tips you won't have to worry about cyber breaches!
π«‘76π30π€£22β€5π4π€2π1π€©1
vx-underground
If you're a person who has been a victim of a data leak and/or company compromise we have tips on how to protect yourself. We know changing passwords can only go so far. If you're a noob and want some tips read below! 1. Change your full name. You need toβ¦
Oh, I forgot the 6th "step". This step is optional, but if all else fails you could commit suicide. If you're dead you'll be in 50% LESS breaches. Your identity will still be stolen, but without being online it'll happen less often (hopefully).
π38π€£24β€7π₯°3π₯2π1
vx-underground
Oh, I forgot the 6th "step". This step is optional, but if all else fails you could commit suicide. If you're dead you'll be in 50% LESS breaches. Your identity will still be stolen, but without being online it'll happen less often (hopefully).
For the autistic people, Germans, Australians, emotionally stunted, and old confused people: this is satire. Don't kill yourself.
π63π€£21π’8π€―7β€4β€βπ₯4π3π€3π«‘1
I downloaded over 7,000,000 Windows drivers. I put them on a fancy computer. I am running them all through a fuzzer (IOCTLance).
It's showing stuff like this on some files. What does it mean?
It's showing stuff like this on some files. What does it mean?
π€£42π€8β€6π€4π₯1π’1π€©1
vx-underground
I downloaded over 7,000,000 Windows drivers. I put them on a fancy computer. I am running them all through a fuzzer (IOCTLance). It's showing stuff like this on some files. What does it mean?
Also, I GREATLY underestimated how long it would take to fuzz 7,000,000 files. It's been 12 hours, it's only done.... 200-ish...
π€£60π±12π8β€2π₯1π’1
Shout out to me.
Accidentally ran a recursive file cleaner in the wrong directory. Nuked all my files and important documents.
Fuck my life
Accidentally ran a recursive file cleaner in the wrong directory. Nuked all my files and important documents.
Fuck my life
π’85π«‘32π€£12β€8π±2π1π€―1π1π1π€1
vx-underground
Shout out to me. Accidentally ran a recursive file cleaner in the wrong directory. Nuked all my files and important documents. Fuck my life
Ran this bad boy in the wrong directory: "Get-ChildItem -File -Recurse | Where-Object { $_.Extension -ne ".sys" } | Remove-Item -Force"
RIP "My Documents" folder.
RIP "My Documents" folder.
π’63π€£16π«‘12β€7π2π2
Fuck computers.
Getting off for the day. I'd post a cat picture reaction but I accidentally deleted them.
/me flips desk
Getting off for the day. I'd post a cat picture reaction but I accidentally deleted them.
/me flips desk
π’74β€19π«‘8π±4π1
vx-underground
Fuck computers. Getting off for the day. I'd post a cat picture reaction but I accidentally deleted them. /me flips desk
Pressing the up key over and over until you find the previous command is illegal and for nerds.
π€54π15π«‘7β€6π―4π2π1
vx-underground
Shout out to me. Accidentally ran a recursive file cleaner in the wrong directory. Nuked all my files and important documents. Fuck my life
UPDATE: Cat pictures and sensitive documents have been successfully restored.
Bunch of other shit is still missing, but whatever, fuck it
Bunch of other shit is still missing, but whatever, fuck it
π₯64β€11π₯°6β€βπ₯5π’1
Currently pushing 7,000,000+- drivers through IOCTLance (Windows Driver fuzzer) to look for vulnerabilities*.
All drivers are signed. Hence, the number may be significantly lower. I suspect the actual number to be closer to 2,000,000.
As the project continues I will be uploading and sharing the results online. I don't know if I'll share it on vx-underground or a different website.
I'm not an exploit guy, so I don't know why I'm doing this. I was inspired by eversinc33 to do this project. It's been really fun so far. Computers are fun.
I asterisk vulnerabilities* because even if the fuzzer indicates the driver is vulnerable, that may not necessarily be true. Additionally, even if it is indeed vulnerable, that may not reflect the level of skill required to exploit the vulnerable driver.
If you have any suggestions let me know.
-smelly
All drivers are signed. Hence, the number may be significantly lower. I suspect the actual number to be closer to 2,000,000.
As the project continues I will be uploading and sharing the results online. I don't know if I'll share it on vx-underground or a different website.
I'm not an exploit guy, so I don't know why I'm doing this. I was inspired by eversinc33 to do this project. It's been really fun so far. Computers are fun.
I asterisk vulnerabilities* because even if the fuzzer indicates the driver is vulnerable, that may not necessarily be true. Additionally, even if it is indeed vulnerable, that may not reflect the level of skill required to exploit the vulnerable driver.
If you have any suggestions let me know.
-smelly
π33β€18π₯6π4π’1π1π€1π1
"Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram.
I can't confirm or deny if it's an actual 0day, I have no way to test or confirm anything. However, it is fully weaponized.
I've uploaded it to VXUG
https://vx-underground.org/tmp
I can't confirm or deny if it's an actual 0day, I have no way to test or confirm anything. However, it is fully weaponized.
I've uploaded it to VXUG
https://vx-underground.org/tmp
π±34π11β€6π3π₯3π’1
This media is not supported in your browser
VIEW IN TELEGRAM
β€68π₯13π11β€βπ₯1π1π’1