My first experience with penetration testing involved identifying a critical vulnerability in a Roblox experience with over 10 million visits.
The issue stemmed from an unsecured RemoteEvent, which would allow attackers to pass a player’s body part as argument. Doing so led to irreversible data loss for all players in the server.
Tech Used: SynapseX, DarkDex
Outcome: Reported findings to developer, collaborated on securing back-end.
Reward: $200
This project involved building an automated player for rhythm games, specifically for Vertical Scrolling Rhythm Games (VSRGs), using hardware and software integration. I utilized solenoids connected to a Raspberry Pi to physically hit the notes on my keyboard.
The system was programmed using Python, where I created a script to read the screen in real-time and trigger the solenoids at the correct moments based on the note receptors. This allowed the script to physically "play" the game, with a mechanical response to on-screen note inputs.
Tech Used: Raspberry Pi, Python, Solenoids
Outcome: Successfully built a functional autoplayer capable of setting inhumanly accurate scores in rhythm games on a physical keyboard.
"The only day you're going to fail, is the day you accept defeat."
< GeoGuessr Preferences >
Hey, I'm Lua! Cybersecurity Major, Freelance Pentester, Semi-Pro Karter, GeoGuessr Enthusiast, Fursuiter and Cosplayer!
I basically love breaking things (ethically) and finding vulnerabilities in systems.
You can often find me participating in hackathons and htb/ctf events as well!
Happy hacking!