mel Profile Banner
mel Profile
mel

@vmfunc

6,287
Followers
523
Following
178
Media
1,425
Statuses

resident in your memory • CEO @joinlunchcat

USA
Joined March 2020
Don't wanna be here? Send us removal request.
@vmfunc
mel
2 months
Turns out, you can jailbreak grok just by pretending you're Elon Musk.
Tweet media one
36
349
5K
@vmfunc
mel
2 months
@nyaathea actually getting the exact same output
Tweet media one
5
32
3K
@vmfunc
mel
10 days
your "privacy-friendly" arc browser relies on firebase and logs everything to their servers? (researched with @xyz3va )
Tweet media one
88
206
3K
@vmfunc
mel
1 month
there is literally NOTHING you can’t do. you're just conditioned to think in limitations, locking yourself in a cage built from outdated societal expectations and your own self-doubt. the key to unlocking it lies in embracing chaos as your closest ally, reshaping it into a tool
36
390
2K
@vmfunc
mel
1 month
・ *゚   ・ ゚* ・。 *・。 *.。 。・ Segmentation Fault (Core Dumped) ゚*. 。。 ・ 。 ・゚ 。°*. 。*・。
Tweet media one
8
245
2K
@vmfunc
mel
2 months
>wake up >open twitter >your startup gets slandered for no reason ngmi
@gf_256
cts 🌸
2 months
If your website looks like this, absolutely ngmi
Tweet media one
Tweet media two
Tweet media three
Tweet media four
48
66
2K
32
19
2K
@vmfunc
mel
1 month
I just broke up with my wife 💔💍 here is what it taught me about diagonal infra scaling:
21
54
2K
@vmfunc
mel
15 days
LADIES AND GENTLEMAN WE GOT IT BACK
Tweet media one
44
99
1K
@vmfunc
mel
3 months
please bro just one more prompt in the chain bro, just one more fine-tuned model bro, just one more-
Tweet media one
1
1
118
@vmfunc
mel
15 days
oh by the way this means we can escape any tag now! xss injections are real now @github
@vmfunc
mel
15 days
LADIES AND GENTLEMAN WE GOT IT BACK
Tweet media one
44
99
1K
24
45
763
@vmfunc
mel
15 days
heeeaaarr me out.........
Tweet media one
6
15
621
@vmfunc
mel
1 month
me and @kennethnym were slightly bored.. buttplug support for the rust compiler.
26
38
488
@vmfunc
mel
15 days
@TheMacSweaty @yacineMTB imagine you're building a lego castle, and there's a secret tunnel (we call it a "vulnerability") that people can use to change things in your castle. in this case, the castle is a github profile, and the sneaky trick uses something called latex (it's like a special language for
13
27
397
@vmfunc
mel
15 days
time to go to bed, ggs, it was a fun ride. will keep experimenting with others but won't keep disclosing this specific thing publicly anymore.
Tweet media one
10
6
378
@vmfunc
mel
11 days
i break computers for a living
Tweet media one
18
3
366
@vmfunc
mel
10 days
@hursh @xyz3va Hey Hursh! Thanks for being transparent about this. However, how are those logs "unconnected to your identity" if you log the userid in the request? That sounds a little strange to me.
3
2
341
@vmfunc
mel
1 month
@vin_acct sorry my openai subscription expired
3
1
261
@vmfunc
mel
1 month
good morning anon, are you still wasting your potential today?
29
16
232
@vmfunc
mel
14 days
this is how a security researcher looks like btw
Tweet media one
22
2
234
@vmfunc
mel
10 days
side note as people seem to be wondering: doesn't include exact urls
2
0
239
@vmfunc
mel
12 days
apple please add latex (especially unicode) to imessage so i can get more bounty money
7
3
204
@vmfunc
mel
10 days
@ririxinya @xyz3va yes it is. but you can't publicly claim you care about privacy then do this in my opinion.
3
0
198
@vmfunc
mel
15 days
what else can I say.... the vmcord is just too powerful
Tweet media one
4
3
179
@vmfunc
mel
2 months
@plsno_uwu well they safeguard “enough” to not get legally liable, if that makes sense.
2
0
170
@vmfunc
mel
16 days
10x engineer mindset
Tweet media one
9
0
167
@vmfunc
mel
11 days
by the way, for all those coming from the github vuln. I am still looking for a job or consulting! (either as a security researcher or swe). Ideally US-based. hit my DMs if you want to chat!
8
9
162
@vmfunc
mel
15 days
@vxunderground or was it...?
Tweet media one
4
2
151
@vmfunc
mel
1 month
discord server profiles are really useful, I can startupmaxx and MLmaxx with most people but I can also switch things around when needed
Tweet media one
Tweet media two
11
0
130
@vmfunc
mel
15 days
the end of an era....
Tweet media one
4
2
132
@vmfunc
mel
2 months
average cracked AI researcher group chat
Tweet media one
12
5
125
@vmfunc
mel
15 days
when the GitHub readme logs you out:
Tweet media one
@vmfunc
mel
15 days
good to note you can already do fun stuff such as IP grabbing as loading the background dynamically doesn't get GitHub to cache it :)
2
1
37
1
7
120
@vmfunc
mel
1 month
Tweet media one
1
0
119
@vmfunc
mel
13 days
slowly getting all my friends into infosec is kinda fun
11
0
122
@vmfunc
mel
2 months
desk finally set up, i can lock in now
Tweet media one
17
0
117
@vmfunc
mel
2 months
@luciascarlet well the second image is my own company, that’s why i’m kinda upset lol 😭
3
0
116
@vmfunc
mel
2 months
hire for attitude, train for skill. skills can be taught, but enthusiasm and adaptability are gold. what you really need is a team that's quick to learn and eager to pivot. forget the perfect resume; give me your true self and not your credentials
4
4
115
@vmfunc
mel
1 month
acid
@github
GitHub
1 month
As an open source maintainer, what brings you joy?
84
19
221
5
13
111
@vmfunc
mel
15 days
@vxunderground yup here you go
@vmfunc
mel
15 days
LADIES AND GENTLEMAN WE GOT IT BACK
Tweet media one
44
99
1K
0
0
109
@vmfunc
mel
15 days
it's patched. and they tested in prod.
8
2
110
@vmfunc
mel
1 month
@onyurine @kennethnym vibrates if builds pass properly
1
1
105
@vmfunc
mel
14 days
gm, one more css vuln reported this morning, still investigating c:
8
0
107
@vmfunc
mel
15 days
@NotNite @github we are in contact with GitHub's security team atm, no worries
1
0
104
@vmfunc
mel
14 days
@cloud11665 i will keep milking everything latex has to offer in fact
0
0
102
@vmfunc
mel
10 days
it is unfortunate for companies that infosec is ran by people with a sense of humour
6
3
96
@vmfunc
mel
2 months
high IQ researcher meetup @ qcord
Tweet media one
4
1
93
@vmfunc
mel
11 days
@cloud11665 add those to the list
Tweet media one
2
2
94
@vmfunc
mel
24 days
@EsotericCofe how to learn ml tutorial by mel 2024 step 1. autism or high IQ step 2. arxiv step 3. gaslight yourself into not building a gpt wrapper step 4. eventually build a gpt wrapper step 5. realize it was a mistake step 6. arxiv step 7. make anime girlfriends real
7
0
85
@vmfunc
mel
1 month
this is how NA’s top 22 player looks like
Tweet media one
10
0
83
@vmfunc
mel
15 days
@vxunderground true XSS injections are doable now btw.
@vmfunc
mel
15 days
oh by the way this means we can escape any tag now! xss injections are real now @github
24
45
763
1
1
83
@vmfunc
mel
14 days
@EsotericCofe I have none and I'm still winning
4
0
82
@vmfunc
mel
1 month
wow so google stole my business idea 🫡🫡
Tweet media one
11
1
80
@vmfunc
mel
26 days
(begpost, RTs appreciated) Hey, so, as most people know, I entered the US a month ago. This has been an exciting journey, but I've unfortunately ran out of money and it's becoming really challenging to support myself or remotely do anything. Despite my best efforts, I'm still
5
30
80
@vmfunc
mel
12 days
i always post one good thing/research each month, get 500-1k followers from it, then disappear from your TL until the next month
7
0
76
@vmfunc
mel
2 months
not enough plushies = slower workflow
Tweet media one
15
1
71
@vmfunc
mel
23 days
@EsotericCofe L take i’m sorry
1
0
72
@vmfunc
mel
11 days
theo reported on the latex vulnerability we used a few days ago, check it out!!
@t3dotgg
Theo - t3.gg
11 days
The Github CSS exploit is nuts, had to make a video on it
Tweet media one
19
12
362
4
1
76
@vmfunc
mel
1 month
it’s crazy how high level low level languages are
5
2
70
@vmfunc
mel
18 days
hey! we might be looking for more cracked developers, researchers, designers to join our ranks at lunchcat. no specific position requirements. if you think you got what it takes, try your luck! application form below this tweet ⬇️
Tweet media one
4
3
70
@vmfunc
mel
16 days
pushed a blog post about my EDC, tech tools, and daily philosophy. have a read c:
Tweet media one
5
1
68
@vmfunc
mel
3 months
@DRAXOMOSPHERE probably cashed out 5k and it locked funds because of KYC lmao
1
1
66
@vmfunc
mel
4 months
@Dexerto Honestly female skins on cs2 would sell for a lot
7
0
67
@vmfunc
mel
3 months
good morning gamers
Tweet media one
10
0
64
@vmfunc
mel
2 months
@Dshoopy0 grok by default has a very minimal explanation pattern when it comes to that kind of stuff; (unrelated, but) from what we’ve been experimenting with, it seems that grok would’ve been very verbatim w/o any sort of prompt set actually asking it to forget it’s guardrails
1
0
64
@vmfunc
mel
1 month
I have resigned from OpenAI today.
7
1
64
@vmfunc
mel
18 days
this is why I usually disable my DMs don't be a fucking freak please.
Tweet media one
13
2
63
@vmfunc
mel
2 months
@gf_256 mind elaborating about why my company’s in there?
5
0
58
@vmfunc
mel
13 days
it's not a bug if the output gets piped into /dev/null
2
0
60
@vmfunc
mel
10 days
@hursh @xyz3va Thanks for clarifying!
1
0
73
@vmfunc
mel
10 days
@onarchbtw @xyz3va safari is good
12
1
59
@vmfunc
mel
1 month
tbh, embracing failure isn't just a cliché, it's a mindset that acknowledges the iterative nature of innovation; each setback is a stepping stone to eventual breakthroughs
1
8
56
@vmfunc
mel
23 days
gn anon, did you waste your potential again today?
7
1
55
@vmfunc
mel
2 months
anyways chat big tech CEO can be mad at our temporary landing page design but we all know that i’d win anyway
4
1
54
@vmfunc
mel
2 months
✈️
Tweet media one
8
0
55
@vmfunc
mel
15 days
@vxunderground @cloud11665 @yacineMTB there's also an open redirect you can chain to POST
@vmfunc
mel
15 days
when the GitHub readme logs you out:
Tweet media one
1
7
120
2
3
52
@vmfunc
mel
2 months
heard someone say "data is the new oil" and I couldn't disagree more. data is more like the new nuclear waste
1
4
49
@vmfunc
mel
2 months
america ya
Tweet media one
6
1
51
@vmfunc
mel
3 months
@vxunderground hopefully this will get me girls someday...
Tweet media one
6
2
50
@vmfunc
mel
1 month
we made it boys
@RustTrending
Rust Trending
1 month
vmfunc / cargo-buttplug: ensuring positive reinforcement during long, tiring code sessions~ ★41
4
7
53
3
0
51
@vmfunc
mel
10 days
companies giving me free time instead of giving me more work are evil. they get me to hack other sites instead.
3
0
56
@vmfunc
mel
15 days
inb4 someone gets paged again, & #x5C ;unicode works!
@vmfunc
mel
15 days
LADIES AND GENTLEMAN WE GOT IT BACK
Tweet media one
44
99
1K
3
2
49
@vmfunc
mel
2 months
why do some people obsess over creating the next big AI model? just use the available APIs and tools, integrate creatively, and actually solve problems.
8
2
51
@vmfunc
mel
1 month
"we made a new, better model, and it's free now" "and all we're doing is luring you into giving us more data"
2
0
48
@vmfunc
mel
15 days
@cupiditys2 @github we have a few already c:
2
0
50
@vmfunc
mel
10 days
@CyberKevin_FR @onarchbtw @xyz3va in all honesty I trust apple much more with my data than any other startup out there
1
0
50
@vmfunc
mel
15 days
still trying to escalate this to an XSS; script tags and data:text injection in backgrounds/such seems to be sanitised. can't make any use of animations to load a remote payload as well. seems like you can still load your payload as a background normally but need a way to eval :\
@cloud11665
cloud
15 days
casual CSS injection on github using the math mode
Tweet media one
182
462
6K
3
3
45
@vmfunc
mel
2 months
@SwiftOnSecurity it's so over
Tweet media one
0
3
45
@vmfunc
mel
2 months
girlfriend got an hackrf and she’s like a child now
3
0
46
@vmfunc
mel
2 months
i'll win. whatever happens next. failure? nah, just temporary setbacks. setbacks fuel the fire, ignite the drive, and push me to win faster.
3
3
47
@vmfunc
mel
15 days
Tweet media one
0
2
45
@vmfunc
mel
3 months
the github sweatshirt goes hard ngl
Tweet media one
8
0
43
@vmfunc
mel
19 days
lock in
Tweet media one
4
0
43
@vmfunc
mel
1 month
is openai just indirectly making their nsfw demo
5
0
41
@vmfunc
mel
9 days
If you still have accounts and devices connected to your @rabbit_hmi device: - Unlink them in the portal: - Change passwords, revoke all sessions, clear active logins
@xyz3va
xyzeva
9 days
for reasons thatll be revealed soon please unlink all of your accounts from the rabbithole ASAP.
18
96
960
5
5
74
@vmfunc
mel
15 days
fyi won't publish/release my findings with that GitHub thing besides what I already shared. once they patch the LaTeX exploit it's going to fix that issue as well
5
1
41
@vmfunc
mel
1 month
i just saw my roommate on the 4chan dating app
5
0
42
@vmfunc
mel
3 months
The beginning of something amazing 💜 | @joinlunchcat
Tweet media one
3
2
38
@vmfunc
mel
15 days
good to note you can already do fun stuff such as IP grabbing as loading the background dynamically doesn't get GitHub to cache it :)
@vmfunc
mel
15 days
still trying to escalate this to an XSS; script tags and data:text injection in backgrounds/such seems to be sanitised. can't make any use of animations to load a remote payload as well. seems like you can still load your payload as a background normally but need a way to eval :\
3
3
45
2
1
37
@vmfunc
mel
2 months
this is the world we live in now..
Tweet media one
2
3
38
@vmfunc
mel
2 months
you don’t need to be cracked to build a successful startup, just focused, resilient, and armed with a killer idea. it’s about strategy, not superpowers.
3
0
39