sleepy__dev Profile Banner
sleepy Profile
sleepy

@sleepy__dev

Followers
5K
Following
8K
Media
180
Statuses
2K

my sink leaks memory

Joined September 2018
Don't wanna be here? Send us removal request.
@sleepy__dev
sleepy
3 years
Once is luck, twice is
Tweet media one
@sleepy__dev
sleepy
4 years
🎥.Off white on me, left n rite
Tweet media one
26
20
320
@sleepy__dev
sleepy
9 days
RT @ArciumHQ: It’s only after we’ve encrypted everything that we’re free to do anything. <e/acc>.
0
55
0
@sleepy__dev
sleepy
25 days
RT @camolNFT: BREAKING NEWS: PumpFun $PUMP presale contract has no withdrawal function. This effectively means the $500M raised is locked….
0
302
0
@sleepy__dev
sleepy
1 month
I have some crazy sneakers cook outs stories but I just can't tweet it or we getting in court 🤣.
3
0
39
@sleepy__dev
sleepy
1 month
RT @sleepy__dev: So, how did Shinobi clean full stock on LVR across multiple releases? 👀.Let me break it down — this one's wild. 🧵.Most dev….
0
6
0
@sleepy__dev
sleepy
1 month
Here’s a real code snippet straight from Shinobi 🥷. You can see how the token gets used and how we could accept the gift without ever logging into the actual email or extracting any link manually. The result?. Seamless, fast checkouts — no friction, no delays. 🚀. Sometimes all
Tweet media one
1
0
10
@sleepy__dev
sleepy
1 month
However… the bypass wasn’t that simple. 😅.Using the "Send a Gift" button would actually trigger an email to the recipient with a claim link. Not exactly what you want when you're trying to speedrun a checkout. 🏃‍♂️💨. But then —. BINGO, again. 😁. I noticed the first request to
Tweet media one
1
0
4
@sleepy__dev
sleepy
1 month
The first request didn’t hit /myarea/bag/add like a normal ATC. Instead, it went to a completely different endpoint.🔀.Different route. Different request body. Same result. 🧠 BINGO. The logic behind this is simple — but let me break it down so anyone can follow. 👇.In most
Tweet media one
1
0
4
@sleepy__dev
sleepy
1 month
So, how did Shinobi clean full stock on LVR across multiple releases? 👀.Let me break it down — this one's wild. 🧵.Most devs working LVR drops knew this:. Global rate limits were set per PID (product ID). Once a product got ~20 "Add to Cart" requests, boom 💥 — LVR rate-limited
Tweet media one
5
6
102
@sleepy__dev
sleepy
1 month
damn I got this badge.
@lauriewired
LaurieWired
1 month
If you see a github user with this badge it’s because they have code ~1,000 feet underground in the Arctic Circle. 5 years ago Github took a snapshot of all public repos, stored it on photographic film (essentially big QR codes), and stuck it in a mining tunnel.
Tweet media one
Tweet media two
0
0
5
@sleepy__dev
sleepy
1 month
RT @MrMassi24: Back at it with another CDN bypass 🔓.Akamai was blocking desktop traffic on all Eventim group sites:.Eventim DE, NL, UK, Tic….
0
1
0
@sleepy__dev
sleepy
1 month
RT @MrMassi24: Bypass is patched now so here it is:🔓.on event pages, Incapsula blocked GET without a valid reese84….
0
2
0
@sleepy__dev
sleepy
1 month
Sneaker dev open sourcing continues!.Small thread 🧵. So during 2022, Footlocker globally started the Call & Collect release method 👀. You basically had to call at your local store and make them reserve a limited pair of sneakers for you to later pick up instore. The release
Tweet media one
8
2
123
@sleepy__dev
sleepy
1 month
Good read 👀.
@MrMassi24
Valerio
1 month
around the same time I started flipping sneakers.and fell into the web3 rabbit hole. but the turning point came in 2023 when I met @sleepy__dev.
1
0
13
@sleepy__dev
sleepy
2 months
I also managed to keep millions of requests on 2 100$ servers (EU, US) and a simple load balancer with simple express js infra, cachegoose . once my NDA is over I could OS everything, if you guys are interested I’m open to share some old bypasses and methods from time to time.
@sleepy__dev
sleepy
2 months
I was managing the queue for a big sneaker store in EU. Wanted to share how I managed to block Cybersole from getting valid sessions. I would simply check if the client ever requested the website favicon.ico file, no full request bot ever requests the favicon, also the session
Tweet media one
9
0
119
@sleepy__dev
sleepy
2 months
Also if you're curious, what about selenium bots?. You can add a simple verification layer with a PoW challenge, so running many tasks on a machine will consume all the RAM and CPU,. Of course the selenium sessions will still be valid, but very limited.
0
0
23
@sleepy__dev
sleepy
2 months
I was managing the queue for a big sneaker store in EU. Wanted to share how I managed to block Cybersole from getting valid sessions. I would simply check if the client ever requested the website favicon.ico file, no full request bot ever requests the favicon, also the session
Tweet media one
14
8
265
@sleepy__dev
sleepy
2 months
Simple method to find rats, open sourcing this simple project to our fellow creators on discord 🔜.
@MrMassi24
Valerio
2 months
@sleepy__dev and I cooked the hardest drop in the game. @AkariCorp officially mirror-free — zero misses, 100% locked in. Past week? 8 rats banned & reported. Keep playin dirty, we’ll keep cleanin up. 🧹🕵️‍♂️.software dropping for everyone very soon. Stay tuned.
Tweet media one
2
0
8
@sleepy__dev
sleepy
2 months
Discord server mirrors:.dualles (764505186407678002) .rase (1051806893921808434).Ronie (733814042258309200) .IOWEJ (446676538918699008). If you own a private group on discord, consider banning these guys.
0
2
18
@sleepy__dev
sleepy
2 months
bro lost 100M $ and started shilling his ref link to make few bucks 😭😭.CT is insane.
@JamesWynnReal
James Wynn
2 months
HIGH STAKES PERPS 🎰 💹. No KYC required • Join Below 👇 . This link will save you $$$ on trading fees. Use code ‘WYNN’ & save $$$! 🔥. Trade responsibly. Seek advice from a financial advisor. Follow proper risk management. Wear your big boy.
1
0
4
@sleepy__dev
sleepy
2 months
RT @authcookie: Hiring Engineers at Blackboard Studio! [Europe only 🇪🇺]. We're a software holding company (B2B & B2C) building the next gen….
0
1
0