Mat Rollings
@stealthcopter
Followers
784
Following
199
Media
20
Statuses
119
Bug bounty hunter, AppSec engineer and CTF player. Developer of PortDroid, deepce, Nexus Revamped and some other junk
Joined December 2009
That time of year again, another totally human Black Friday / Cyber Monday for PortDroid: 💸>50% off Lifetime 🔍Port Scanner for Android 👨💻I wrote it 🍺Share it somewhere useful and I'll buy you a drink Buy it, capitalism demands it. Or don't https://t.co/OPMB2MUW8c
portdroid.net
Your Networking Swiss-army Knife
0
0
1
Since starting my training I've lost over 7kg, dropped 6% body fat, got 4 new Hawaiian shirts, and taken >5mins off my 5k time. Am I ready? No. But I'll get through it by thinking about the post-run takeaway and bubble bath 🛀 Last chance to donate🙏 https://t.co/FCKJWihg3u
justgiving.com
Help Mat Rollings raise money to support Cool Earth
0
0
3
REGEXSS: How .* Turned Into over $6k in Bounties Overly-greedy regex replacements can break HTML sanitisation & lead to XSS. Includes a live demo you can try exploiting it yourself! https://t.co/xfN95R9dUo
#BugBounty #BugBountyTips #XSS #AppSec
sec.stealthcopter.com
Overly-greedy regex replacements can break HTML sanitisation and lead to XSS. I’ve already pulled in over $6k from this bug class, and there are plenty more out there. Live demo included so you can...
1
41
212
Last week I found two regex bugs using regex → unauth XSS → 2× $2k = $4k in bounties 🥳 If you’ve been putting it off, learn regex. Seriously. /regex\+xss/\$4k/ #BugBounty #BugBountyTips
3
7
103
Physically & emotionally drained after the rollercoaster that was @yeswehack’s #LHE at #NullconBerlin2025
@TeamViewer was a tough target & I nearly gave up but pushed through to snag 10th place overall 🥳 Thanks to @yeswehack for the support & awesome hosting! #BugBounty
5
0
48
aww yis 🥳thanks @yeswehack, pretty sure it was the vuln title that did it 😉
🏆 Dojo #43 – CCTV Manager is officially closed, and we have our winners! This challenge revolved around a predictable token combined with insecure YAML deserialization - leading to RCE and... flag capture 🏁 Here's the write-up 👉 https://t.co/p4mfjNGv5U
#CTF #BugBounty
3
0
15
Really enjoyed these AI hacking challenges by HackAIcon, the last one had some fun little twists: https://t.co/UVDpm7IcZl
#ctf
1
0
10
Passed the CBBH exam! Instead of spending £60 on the certificate and a t-shirt I'd never wear I decided print it myself and to go out for french toast and a breakfast shake to celebrate🥳 #BugBounty #CyberSecurity #WillHackForFrenchToast
8
1
58
🚀New plugin in the Caido Store! Introducing "Exploit Generator" by @stealthcopter Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL. Check out more details:
1
19
92
🚀 Just released a new Caido plugin: Exploit Generator 💣 Generate clean, working, customizable PoC exploit scripts instantly in Python, JS, Bash/cURL (more langs & frameworks coming soon) Live now in the Caido Plugin Store: https://t.co/ObxP3XGKaJ
#Caido #BugBounty
github.com
Contribute to stealthcopter/CaidoExploitGenerator development by creating an account on GitHub.
1
3
23
Survived the Bristol Half Marathon (2hr40). Then immediately got a kebab and cheesecake because I am an athlete 💪 Next: 25km Bath to Bristol for @CoolEarth. Please donate so the rainforest wins and I continue to question my life choices 🌍💚 👉 https://t.co/FCKJWihg3u
3
0
16
New update for the Caido CSRF plugin! Release 1.0.4: Added HTML encoding for parameter values with double quotes. Big thanks to @stealthcopter for the contribution! #bugbounty #bugbountytips
🛡️✨ Another addition to the Caido Store! Introducing "CSRF PoC Generator" by @Tur24Tur. Generate various types of CSRF PoC payloads from requests. Check it out: https://t.co/TcsoqNWL2k
1
6
30
Check out my awesome Hawaiian shirt with my dog on it 🥳 also an interview with @palmiak_fp for @patchstackapp😉 #BugBounty
We had a talk with one of the @patchstackapp Alliance #ethical #hackers community legends - @stealthcopter
1
1
10
Just received the coolest #ctf prize ever from @patchstackapp, signed Hackers memorabilia and swag! 💾HACK THE PLANET! 🌍 #BugBounty #HackThePlanet #Infosec #Hackers
5
3
33
Thank you 🙏 to everyone who's helped me reach NOT_FOUND, can we make it to SERVICE_UNAVAILABLE?
1
0
5
And for anyone wanting to learn some more PHP tricks 🪄, here's my other two write ups for the Patchstack #wcasia2025 CTF, Blocked 🛑 https://t.co/rjvjpTZxid
#CTF #WordPress #Hacking
sec.stealthcopter.com
Explore how creative tricks in PHP and WordPress allow you to bypass restrictions in a fun Patchstack CTF (S02E01) challenge and uncover neat tricks with filters and file paths!
1
2
7
I will run so fast for you*🥲 * Within reason for a person of my mass and ability
I don’t usually share donation posts, but when I do, it’s because I believe in the person behind them. @stealthcopter is basically a superhero packed with knowledge and goodwill, making a real impact in communities everywhere. Support Mat on his mission! 🤘
1
0
3
I'm running 25k to raise money for Cool Earth. This will be the furthest I’ve ever run, and it’s going to be incredibly difficult! Any donations are massively appreciated! 🙌 Even if you don’t donate, check out the FAQ on my page, it’s worth a read! https://t.co/FCKJWihg3u
justgiving.com
Help Mat Rollings raise money to support Cool Earth
0
1
9