Marcel Profile Banner
Marcel Profile
Marcel

@MarcelD505

Followers
2,042
Following
77
Media
409
Statuses
2,023

- Cat lover - AKA ProgrammeerMeneer - Web, App and WebApp developer - Just doing some dumb shit as always - Studying IT at Hanze University of Applied Sciences

The Netherlands
Joined May 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@MarcelD505
Marcel
3 days
My current collection of absolutely deranged android devices
Tweet media one
147
330
5K
@MarcelD505
Marcel
23 days
Ok so people already cracked the rabbit R1 and found out its android. People dumped the apk and i got it working (with root and a few mods) on a standard ass phone lmaoo
306
2K
18K
@MarcelD505
Marcel
14 days
oops
Tweet media one
175
761
13K
@MarcelD505
Marcel
22 days
Without a valid rabbit IMEI, it will now get blocked server site. Still on the looks for the updater tool (and possibly a working IMEI lol)
Tweet media one
@MarcelD505
Marcel
23 days
Ok so people already cracked the rabbit R1 and found out its android. People dumped the apk and i got it working (with root and a few mods) on a standard ass phone lmaoo
306
2K
18K
25
101
3K
@MarcelD505
Marcel
19 days
Guess who’s back on android phones? That’s right! Our little rabbit friend! We have fought through: ⁃ “IMEI checks” We discovered these literally don’t exist and you still can just use any string as IMEI ⁃ Other header checks These are obfuscated across a few files and even
66
190
2K
@MarcelD505
Marcel
9 days
More rabbit shenanigans, got lineage up and running for myself + google play services. Also rooted with magisk! I also bricked it like 3 times in the process but fortunately recovered, however i don’t know what specifically did the trick to unbrick it lol
54
99
981
@MarcelD505
Marcel
14 days
@JackRhysider @thel3l I pinky promise this is not a photoshop, we will do a writeup eventually, here is a short video. Note that this isn't my video and device but from someone in our team. We do all have the knowledge on how to do it.
11
24
605
@MarcelD505
Marcel
23 days
Vision crashes
3
8
578
@MarcelD505
Marcel
23 days
@Michaelbolloz I got the apk from someone that dumped it, rooted and upgraded my phone to android 14. The app only runs on 13 and up and as a system app. I then used a flipper zero to emulate the scroll wheel and set it up with a rabbit account. Now it’s like this lol
10
5
546
@MarcelD505
Marcel
22 days
Spotify works but is a bit glitchy
3
6
519
@MarcelD505
Marcel
13 days
Interesting development on the latest OTA, seems like rabbit fixed terminal mode for other android devices. Previously it would just rotate the small rabbit instead of displaying the terminal. Thanks for fixing it i guess??😅
Tweet media one
8
19
439
@MarcelD505
Marcel
18 days
It no longer lies
8
24
348
@MarcelD505
Marcel
22 days
@maietta There is, they have limited it by checking the IMEI right now!
2
0
241
@MarcelD505
Marcel
2 years
Yo @dbrand @Mrwhosetheboss @MKBHD Thank you for the airpods and the dope tshirt!
Tweet media one
24
13
226
@MarcelD505
Marcel
9 days
Can't even order from an r1 smh @terminaldotshop
10
9
308
@MarcelD505
Marcel
14 days
We will try other things like calling in a bit. I am not the owner of this device but it is someone else in the team which needs to come back from work. What doesn’t work confirmed: The motor for the camera, it’s stuck pointing down, but the camera works. So it’s just only gonna
4
0
196
@MarcelD505
Marcel
15 days
Embedded systems are hard
Tweet media one
7
2
181
@MarcelD505
Marcel
14 days
@KaziAhmedDev @thel3l That’s entirely possible, even in the stock rom if it isn’t updated yet or you prepared and installed overlaying apps before updating.
1
2
179
@MarcelD505
Marcel
22 days
@lucaslain If you have one that isn’t updated/parched, yes. You can break into android. The rabbit runs A13.
4
2
172
@MarcelD505
Marcel
14 days
Tweet media one
3
2
164
@MarcelD505
Marcel
2 years
Apparently i won something and now i have 100 dms asking me to give it away haha i don't even know what i won guys calm
28
2
153
@MarcelD505
Marcel
9 days
This also means we can finally play the ultimate meme game
7
13
220
@MarcelD505
Marcel
19 days
@EricYockey Proving the lies about api security to customers, and proving that it is still able to run with A LOT of tinkering.
2
1
128
@MarcelD505
Marcel
22 days
2
0
122
@MarcelD505
Marcel
19 days
Apk version number to prove it. The full version number of the apk is 20240424.1-1-gc10355b9-dirty and the ota version is rabbit_OS_v0.8.78_2024050219525. You will see this as the first part of the os version in the about screen.
Tweet media one
1
3
118
@MarcelD505
Marcel
14 days
@CameronPak @JackRhysider @thel3l Good call! We haven't tested it yet but i am pretty sure it would work.
0
0
112
@MarcelD505
Marcel
19 days
94f835a8f06f59ec4477325b3a5d915200ec7999df3c2bf249c3e00d2a0d4bda For future reference 👀
1
1
108
@MarcelD505
Marcel
14 days
@hmm1752006 @thel3l MediaTek Helios P35 4gb ram 128gb storage
2
1
109
@MarcelD505
Marcel
13 days
@dnebdal @thel3l Yes, but due to the broken camera motor, we will not be able to scan the QR code. We are trying to figure it out, would be funny.
3
0
103
@MarcelD505
Marcel
21 days
@GokuInnovates @WillHobick @FlutterDev @flutterflow The rabbit servers are real and the apk is definitely real. However this app is probably just connecting to openai instead of rabbit directly. (which is basically the same thing rabbit does lmao)
2
0
103
@MarcelD505
Marcel
2 years
@jacksfilms fortunately i am not a gamer sooo YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY YAIY
6
1
93
@MarcelD505
Marcel
9 days
Calling also works both on lineage and base os.
7
3
136
@MarcelD505
Marcel
10 days
Tweet media one
Tweet media two
10
4
101
@MarcelD505
Marcel
19 days
@uwukko
wukko
19 days
you can navigate menus in rabbit app with a tv remote instead of a scroll wheel! should work on actual device too that’s because the “scroll wheel” sends dpad actions, just like tv remotes, keyboards, or other accessories
8
5
163
1
2
92
@MarcelD505
Marcel
19 days
@savi0joseph We aren't removing a need to buy the product, as said, we will not share files, tutorials or valid credentials.
3
0
92
@MarcelD505
Marcel
23 days
Full setup in glorious twitter compression, setup before this was rooting and having android 13 or higher. Then adding the app to have system level permissions.
@MarcelD505
Marcel
23 days
Ok so people already cracked the rabbit R1 and found out its android. People dumped the apk and i got it working (with root and a few mods) on a standard ass phone lmaoo
306
2K
18K
2
7
91
@MarcelD505
Marcel
11 days
This reminds me of something, can't quite place it
@cakeRND
cake
11 days
Hello World! 🍰📱 We're Cake. Designing products that empower you to focus on what matters most, one connection at a time.
Tweet media one
13
1
26
1
5
87
@MarcelD505
Marcel
10 days
Got my own r1 first batch! And wow this thing is indeed orange 😅 Time to have some more fun with it! From now on all API requests i will do will have my own IMEI attributed instead of the random invalid ones we used before.
Tweet media one
7
1
87
@MarcelD505
Marcel
23 days
@Michaelbolloz *this is a dev/burner phone
1
0
79
@MarcelD505
Marcel
13 days
It also launches fullscreen when it’s trying to establish connection, but then returns to the smol rabbit after it does?
3
2
78
@MarcelD505
Marcel
19 days
@thel3l
Rithwik Jayasimha
19 days
We reversed the Rabbit R1 🐇 and got it to run on our phones! This gives us future OTA updates, access to new features without a device + works perfectly without root/system perms! (Blog post below)
41
149
1K
1
1
71
@MarcelD505
Marcel
19 days
@ChromMob
ChromMob
19 days
Okay, so we've done it again: @rabbit_hmi @jessechenglyu I cracked the final apk but that was only possible with the help of: - @EmilyLShepherd , @MarcelD505 , @thel3l , @uwukko , media: @MishaalRahman
2
4
97
0
2
69
@MarcelD505
Marcel
22 days
@pengubow Someone already managed to do it! But they privated their videos.
1
0
69
@MarcelD505
Marcel
15 days
@meowkoteeq Didn’t even notice that wtf
0
0
69
@MarcelD505
Marcel
19 days
@RKBDI We see, we might have gotten confused with ip bans. Anyways we have it fully patched now so if they decide to check for more specific headers we got them
1
0
66
@MarcelD505
Marcel
2 years
Jongens @NietRickBroers is helemaal niet weg, hij is gewoon hier in de inferno! Helaas wel dood....
Tweet media one
Tweet media two
1
1
60
@MarcelD505
Marcel
20 days
I am ip banned from rabbit's servers, but it doesn't matter as i am on a vacation network and cellular still works so lol.
6
1
58
@MarcelD505
Marcel
19 days
@EricYockey Having a valid news outlet tied to this doesn't prove anything, ok, i will not go into further discourse.
1
0
54
@MarcelD505
Marcel
22 days
If you want more updates, please follow me. We are trying to get it working on the update with a valid imei code.
1
1
52
@MarcelD505
Marcel
14 days
@Kura_io @thel3l It doesn't, we just get an orange screen cause it only points down lol
2
0
52
@MarcelD505
Marcel
22 days
@JEthenoobgamer @lucaslain Yes! But the videos have been privated sadly. I don’t own one so i can’t crack it.
2
0
49
@MarcelD505
Marcel
18 days
Rabbit now also checks if the IMEI is remotely valid, if not, gives the user a delay that is about 5 minutes long before it answers. However, we can still register any IMEI and even used IMEIs because devices are linked to specific user accounts and are not only identified by
5
1
43
@MarcelD505
Marcel
22 days
@AryaTheOpossum The rabbit runs regular android 13. (at least the ASOP variant without all the fancy google apps and things). You could break out of it on the first firmware version but they have patched it. So until someone finds a new exploit you can't currently exit the app on the rabbit.
1
0
43
@MarcelD505
Marcel
14 days
New OTA from 20 minutes ago already secured, dumped and patched. Seemingly the only API security that changed is that the C++ file now outputs a different string, nothing else. Cringe.
Tweet media one
1
4
41
@MarcelD505
Marcel
9 days
0
1
41
@MarcelD505
Marcel
20 days
Confirmed that rabbit just uses openai for their answers or at least in some way. Vision kept working so that might use a different model. But it's slowly all falling apart. Progress on finding a new way to get it running under normal android hasn't lacked too!
Tweet media one
Tweet media two
4
2
34
@MarcelD505
Marcel
3 years
Am i famous now? ew
Tweet media one
4
0
34
@MarcelD505
Marcel
3 years
now doesn't error anymore if you have cookies disabled. The only feature that will be missing is the storage of the light switch state.
1
1
30
@MarcelD505
Marcel
14 days
@gigantinozip We do, and are already figuring out a possible solution. We don't intend to share it unfortunately.
2
0
33
@MarcelD505
Marcel
21 days
@WillHobick @FlutterDev @flutterflow This doesn’t directly communicate with rabbit servers right?
9
0
31
@MarcelD505
Marcel
18 days
Some corrections + additions: We think we are wrong about the certificate pinning part, we can still see requests made by the app but they get blocked by the server if using an http inspector tool. Something else is going on. Our rabbit reponses are currently REALLY slow, mine
@MarcelD505
Marcel
19 days
Guess who’s back on android phones? That’s right! Our little rabbit friend! We have fought through: ⁃ “IMEI checks” We discovered these literally don’t exist and you still can just use any string as IMEI ⁃ Other header checks These are obfuscated across a few files and even
66
190
2K
2
0
31
@MarcelD505
Marcel
20 days
Sorry visitors of this specific vacation home but your r1 will not work while you are here, oops 😅
2
0
29
@MarcelD505
Marcel
22 days
@Bringus_Studios Doom and minecraft have been ran! However the person privated the videos after threats from the rabbit CEO. We are now in a discord server trying to get the updated files working.
3
0
29
@MarcelD505
Marcel
18 days
Rabbit now checks (we think) the JA3 fingerprint on every request via cloudfront, it isn't possible anymore to http inspect the api requests without getting everything EXACTLY right. This is actually a good thing security wise. 😊
3
0
26
@MarcelD505
Marcel
22 days
@rajkoshik Keyboard with arrow up/down
0
0
26
@MarcelD505
Marcel
19 days
Btw with these tweets, i, or the team have no intentions to defame the company. All the things stated in our tweets are directly from our research and compared against statements rabbit has made in the past. We will also not distribute any files including but not limited to the
2
1
23
@MarcelD505
Marcel
21 days
— about the rabbit incident — I will not be sharing files. I have found some great people and we are trying to get things working again. Please don’t ask me or others (if you find them) for apks. Thank you for reading! 🙏
3
0
23
@MarcelD505
Marcel
11 days
Apparently its a case for an apple watch, but it uhh REALLY LOOKS LIKE SOMETHING ELSE
3
0
24
@MarcelD505
Marcel
9 months
@f4micom For anyone interested, these are the Logitech Z-10
0
0
18
@MarcelD505
Marcel
17 days
Good security ideas for the rabbit team:
@MarcelD505
Marcel
17 days
@cheyclough @EmilyLShepherd @rabbit_hmi @AndroidAuth Not even then, you could just use a valid imei in your request anyways, a lot get shared accidentally. The best thing would be is to bind an imei to a user account and MAKE SURE that only that user can use it though that link. But as of now you can use any imei in the known
1
0
6
0
2
18
@MarcelD505
Marcel
22 days
@meowkoteeq It’s just scared of it’s inevitable fate 😅
0
0
18
@MarcelD505
Marcel
9 days
@manaspawar2004 Will definitely do that!
0
0
25
@MarcelD505
Marcel
21 days
Amazing things have been accomplished, that's all i will say for now.
2
0
18
@MarcelD505
Marcel
14 days
Twitter doesn't let me upgrade cause i bought basic while i was on vacation in germany 😅
Tweet media one
3
1
18
@MarcelD505
Marcel
9 months
@0xNefu @TimTimTeemo @catshouldnt He committed multiple warcrimes
1
0
16
@MarcelD505
Marcel
22 days
If anyone gets ahold of the updated rabbit apk or the updater tool, please share it with me.
2
0
16
@MarcelD505
Marcel
21 days
stop, no more, it's perfect
Tweet media one
3
0
16
@MarcelD505
Marcel
11 months
@juwas_Shop Can you eat them when you grow out of them
1
0
16
@MarcelD505
Marcel
2 years
My parents took our family to a computer museum for my dad's birthday. Safe to say they didn't lock down their systems that well. Could ctrl alt delete most of them and shut them down or open task manager lol
Tweet media one
Tweet media two
5
0
15
@MarcelD505
Marcel
19 days
We are also not using IMEIs of real devices. We have generated a random string of numbers to work as a placeholder for an IMEI.
0
1
15
@MarcelD505
Marcel
19 days
We will also not provide tutorials on how to obtain these files yourself, valid server communication details, and any server urls or vulnerabilities we may find.
2
0
15
@MarcelD505
Marcel
22 days
FOUND! Thank you to the great person that sent it, time for more hackenings!
4
0
14
@MarcelD505
Marcel
1 year
@NietRickBroers Man is gewoon levende chatgpt
0
0
14
@MarcelD505
Marcel
19 days
@uwukko Holy shit that one looks like mine but different
0
0
13
@MarcelD505
Marcel
14 days
@JackRhysider And btw if we do find a method to access customer data, we will not post about it but rather report it directly to rabbit.
0
0
14
@MarcelD505
Marcel
22 days
I and a couple other people are now at the same stage @MishaalRahman is in terms of rabbit research. We have the ota image but it is a delta image, not a full rom. We really need someone with an exploitable r1 to continue.
0
2
13
@MarcelD505
Marcel
19 days
@_SilentClubstep Too many failed requests
1
0
13
@MarcelD505
Marcel
22 days
@MishaalRahman I accomplished this too, pretty funny. Vision crashes and notes don't seem to save to rabbithole. With the new update that just came out, i think they are checking IMEI numbers to verify that it can access the online service. But i would need to somehow get the updated app.
1
0
13
@MarcelD505
Marcel
14 days
@JackRhysider The way the API checks for if you actually own an r1 device, and not run the dumped APK like we have been doing on different devices, is to check a few request headers. These headers are set by the app and include device credentials like IMEI, OS version and App version. These
1
0
12
@MarcelD505
Marcel
2 years
Google ads metamask blocked suspended pancakeswap coinbase hacked blocked instagram hacked banned twitch hacked suspended i forgot my private key hardware key password lost help my gmail hacked crypto stolen lost buy bitcoin dogecoin ethereum stolen and lost
16
0
3
@MarcelD505
Marcel
19 days
@foxlllllll We are trying to patch it to display full screen
1
0
12
@MarcelD505
Marcel
18 days
@app_settings No, that would not be responsible. We aren’t sharing any files, guides, or valid credentials. Also it requires A LOT of tinkering if you want to get to the point we are.
1
0
12
@MarcelD505
Marcel
10 months
Samen met @OfficialMorrog heb ik de aller eerste Nederlandse AI TTS gemaakt. Voor nu kun je meerdere stemmen gebruiken waaronder Morrog. In de toekomst willen we nog meer stemmen van streamers toevoegen! Check hier: En hier:
1
2
11
@MarcelD505
Marcel
19 days
@Reelix "I'm using a language model created by rabbit inc."
1
0
11
@MarcelD505
Marcel
18 days
@JackRhysider Yes, if you manage to unlock the bootloader, you can put all sorts of flavours of android on it and possibly a few other things too.
1
0
9
@MarcelD505
Marcel
3 years
no one is allowed to follow me anymore
Tweet media one
2
0
9
@MarcelD505
Marcel
10 months
@NietRickBroers Ik zeg altijd gelijk op nadat de trail ingaat, eigenlijk altijd heb je dan gewoon toegang zolang de trial dat toestaat en hoef je je niet zorgen te maken dat je het per ongeluk niet opzegt.
1
0
9
@MarcelD505
Marcel
9 days
@stephenspencer Maps to dpad up down so does work as a kinda scrollwheel. Ptt button is the power button.
0
1
11