I was immediately struck when I looked down at just the boardwalk how similar it felt to being on LSD. I am continually astounded with how similar these systems end up seeming to how our brain works. May just be happy coincidences but I am pretty sold on there being true parallels that will only become more and more apparent.
HN user
danielwmayer
https://www.mayer.cool
Hey! I have a business inquiry for you but I don't see a contact anywhere on your website. Is there a place I can reach you? Thank you!
SEEKING WORK
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER =====================
Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in/available for contract work as well!
SEEKING WORK
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER =====================
Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in/available for contract work as well!
SEEKING WORK
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER
=====================Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.
In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in/available for contract work as well!
SEEKING WORK
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER
=====================Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.
In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in/available for contract work as well!
Thanks for the tips! I live in the middle of the concrete jungle that is LA so I instead have the kushiest moon-shoes I could find. As for the klondike bar I’ll have to train up my neck :)
SEEKING WORK
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER=====================
Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.
In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in contract work as well!
Location: Los Angeles, CA, USA
Remote: Yes, or local to Los Angeles
Willing to relocate: No
Technologies: Python, C/C++, C#, JavaScript, x86 Assembly, YARA, Snort, Bash/zsh, PowerShell, IDA Pro/Hexrays, x64dbg, DNSpy, Cobalt Strike, Impacket, Mythic, Splunk, XWays, Volatility, Wireshark, Burp Suite, Encase, Microsoft Office/GSuite, AWS, Azure, GCP, Kubectl, IceKube, Jenkins, GitHub Actions, Git
Résumé/CV: https://www.mayer.cool/resume.pdf
Email: dan@mayer.cool
SECURITY ENGINEER/SECURITY RESEARCHER/RED TEAM OPERATOR/REVERSE ENGINEER=====================
Howdy, I'm Dan. I currently am employed as SpecterOps, a premier red team consultancy. I execute bespoke offensive security and application security assessments including binary reverse engineering, vulnerability identification, and attack path assessment via kubernetes and active directory abuse.
In my free time I create video game cheats. You may have seen some of my previous blog posts on the top of Hacker News, emphasis on "hacker" [1][2]!
I will say that I am honestly quite happily employed but I still think it is always worth putting my resume out into the aether.
If my skills seem valuable to your organization, please don't hesitate to reach out - I am very interested in contract work as well!
iMessage automation. I love technologies so ubiquitous that they end up registering in our brain as “real life.”
We spend so much time texting each other that it has become transparent, so one expects a cute little chatbot or small game to show up, and it delights people!
I recently made a framework to allow playing Twine games through iMessage and people really love it:
https://www.mayer.cool/writings/imessage-text-adventure/
Another one that brought a lot of joy was hooking up a friend’s iMessage to immediately respond to all messages with a chatbot. It was before ChatGPT came out, so it was just convincing enough to have people for a few messages, but scuffed enough to have some very funny off-kilter responses. It sowed a lot of chaos in our group chats :)
haha sorry, yes, I just posted it as a comment!
Whoops! Forgot the link! https://www.twitch.tv/danstreams_
Yo Leijurv this is so sick! As a fellow game hacker this sort of stuff is super inspiring.
My girlfriend and I watch all the fitmc videos even though neither of us play minecraft, and love the ones detailing your insane tooling the most.
Ever since we watched the nocom one I’ve wondered what you do professionally - are you in the infosec space?
With the amount of math and computer science knowledge you put into your work I would guess more in algorithmic trading or something like that. No worries if you don’t want to answer, just curious!
Thanks for the shout out Rob :) Great writeup yourself!
They didn't respond to my email so I tried twitter. That got a prompter response! No details about how to actually perform the insta-win are visible in the video so I wasn't too pressed about someone replicating it from the tweet
Pretty nondescript. I just sent them the code and explained how to replicate it. They said they'd patch it and then they did haha. They offered me some in-game currency as a reward (20,000 gems, which I think is equivalent ~115 bucks).
Thank you!
This vulnerability was patched before I wrote the post - I disclosed it to MTG.
In terms of viewing your history, you should check out https://untapped.gg/en. I have talked to them a bit and they essentially do what you want. They take most of their info from MTG's debug log, which you can find in MTGA's application directory, so you could also make your own tracker as well if you want. They talk about it on their site: https://help.hearthsim.net/en/articles/3620440-how-do-i-supp...
The name of this is a reference to the incredibly useful godbolt compiler explorer. If you are interested in this you will likely enjoy the other as well:
Ublock is without a doubt the most valuabe chrome extension. Most people underutilize it as a way of filtering “legitimate portions” of websites as well.
For example, I used it to filer out all recommended content from youtube, as well as comments. My youtube is merely a search bar and the video I wanted to watch, nothing more.
Yeah, check out my response here:
https://old.reddit.com/r/MagicArena/comments/1385b90/heistin...
Aha, thank you! This is why we submit things to HN!
This is awesome!!
You commented this on a site named "Hacker News" run by a venture capital firm
Hey all, author here - it feels pretty surreal to see my work on the front page of HN! I have done some other hacking on MTGA like creating an insta-win bug:
https://twitter.com/dan__mayer/status/1641669864460009472
As others have pointed out there are many games where the items _are_ easily converted back to dollars. Welcome to the beautiful world of game hacking! There are some really great talks about game hacking out there that you should check out, people make bank (and have a lot of fun) with it:
1) https://www.youtube.com/watch?v=ZAUf_ygqsDo 2) https://www.youtube.com/watch?v=QoNdhlLPX-g
It is not all fun and games though, game companies crack down on hackers profiting off of item duping and botting HARD. A bit related is the hacker who sold hardware to help play pirated games for the switch who has to pay Nintendo a third of his salary for eternity:
https://www.videogameschronicle.com/news/switch-hacker-gary-...
So be careful out there. Hack the planet!