Mat Rollings's Avatar

Mat Rollings

@stealthcopter

Bug bounty hunter, AppSec engineer and CTF player. Developer of PortDroid, deepce, Nexus Revamped and some other junk

104
Followers
203
Following
18
Posts
14.11.2024
Joined
Posts Following

Latest posts by Mat Rollings @stealthcopter

Preview
Black Friday 2025 Your Networking Swiss-army Knife

It's that time of year again, another totally human Black Friday / Cyber Monday post for PortDroid:

πŸ’Έ >50% off Lifetime
πŸ” Port scanner for Android
πŸ‘¨β€πŸ’» I wrote it Β―\_(ツ)_/Β―
🍺 Share it somewhere useful and I'll buy you a drink

Buy it, capitalism demands it. Or don't.

portdroid.net/black-friday...

14.11.2025 14:42 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Mat's 25k Bath to Bristol Railway Run Help Mat Rollings raise money to support Cool Earth

Since starting my training I've lost over 7kg, dropped 6% body fat, got 4 new Hawaiian shirts, and taken >5mins off my 5k time.

Am I ready? No. But I'll get through it by thinking about the post-run takeaway and bubble bath πŸ›€ Last chance to donateπŸ™

www.justgiving.com/page/oh-no-2...

09.10.2025 09:03 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stealthcopter Overly-greedy regex replacements can break HTML sanitisation and lead to XSS. I’ve already pulled in over $6k from this bug class, and there are plenty mo

REGEXSS: How .* Turned Into over $6k in Bounties

Overly-greedy regex replacements can break HTML sanitisation & lead to XSS. Includes a live demo you can try exploiting it yourself!

sec.stealthcopter.com/regexss

#BugBounty #BugBountyTips #XSS #AppSec

24.09.2025 07:50 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Last week I found two regex bugs using regex β†’ unauth XSS β†’ 2Γ— $2k = $4k in bounties πŸ₯³ If you’ve been putting it off, learn regex. Seriously.

/regex\+xss/\$4k/

#BugBounty #BugBountyTips

11.09.2025 07:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Physically & emotionally drained after the rollercoaster that was @yeswehack.bsky.social's LHE at #NullconBerlin2025

@teamviewer.com was a tough target & I nearly gave up but pushed through to snag 10th place overall πŸ₯³

Thanks to @yeswehack.bsky.social for the support & awesome hosting!

#BugBounty

06.09.2025 08:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Hack the Agent | Can you get a free ticket? HackAIcon is around the corner, and we wanted to give you a little challenge. Can you extract a free ticket?

Really enjoyed these AI hacking challenges by HackAIcon, the last one had some fun little twists: hacktheagent.com

#ctf

06.08.2025 22:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

Passed the CBBH exam! Instead of spending Β£60 on the certificate and a t-shirt I'd never wear I decided print it myself and to go out for french toast and a breakfast shake to celebrateπŸ₯³

#BugBounty #CyberSecurity #WillHackForFrenchToast

28.07.2025 07:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

πŸš€New plugin in the Caido Store!

Introducing "Exploit Generator" by @stealthcopter

Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL.

Check out more details: github.com/stealthcopte...

16.06.2025 12:25 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - stealthcopter/CaidoExploitGenerator Contribute to stealthcopter/CaidoExploitGenerator development by creating an account on GitHub.

πŸš€ Just released a new @caido.io plugin: Exploit Generator πŸ’£

Generate clean, working, customizable PoC exploit scripts instantly in Python, JS, Bash/cURL (more langs & frameworks coming soon)

Live now in the Caido Plugin Store: github.com/stealthcopte...

#Caido #BugBounty

02.06.2025 10:44 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Selfie of me running the half marathon with the Clifton suspension bridge in the background

Selfie of me running the half marathon with the Clifton suspension bridge in the background

Survived the Bristol Half Marathon (2hr40). Then immediately got a kebab and cheesecake because I am an athlete πŸ’ͺ

Next: 25km Bath to Bristol for @coolearthaction.bsky.social. Please donate so the rainforest wins and I continue to question my life choices πŸŒπŸ’š

www.justgiving.com/page/oh-no-2...

12.05.2025 07:44 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Signed Hackers movie memorabilia and patchstack metch

Signed Hackers movie memorabilia and patchstack metch

Just received the coolest #ctf prize ever from @patchstack.com, signed Hackers memorabilia and swag!

πŸ’ΎHACK THE PLANET! 🌍

#BugBounty #HackThePlanet #Infosec #Hackers

10.04.2025 07:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It's wild that I'm getting paid for this nonsense

#WordPress #BugBounty

10.03.2025 20:31 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stealthcopter Third write-up for the Sneaky Patchstack CTF challenge, exploring visual diffing and fun with PHP filter chains

and Sneaky πŸ₯· sec.stealthcopter.com/patchstack-c...

26.02.2025 08:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stealthcopter Explore how creative tricks in PHP and WordPress allow you to bypass restrictions in a fun Patchstack CTF (S02E01) challenge and uncover neat tricks with filter

And for anyone wanting to learn some more PHP tricks πŸͺ„, here's my other two write ups for the Patchstack #wcasia2025 CTF, Blocked πŸ›‘

sec.stealthcopter.com/patchstack-c...

#CTF #WordPress #Hacking

26.02.2025 08:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Mat's 25k Bath to Bristol Railway Run Help Mat Rollings raise money to support Cool Earth

I'm running 25k to raise money for Cool Earth. This will be the furthest I’ve ever run, and it’s going to be incredibly difficult!

Any donations are massively appreciated! πŸ™Œ Even if you don’t donate, check out the FAQ on my page, it’s worth a read!

www.justgiving.com/page/oh-no-2...

25.02.2025 08:49 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stealthcopter This writeup explores a Patchstack WordPress CTF challenge where a vulnerable custom footer feature allows for dynamic function execution. The challenge involve

Woop πŸ₯³I placed 5th in the @patchstack.com CTF at #wcasia2025 πŸ† Here's my first write-up covering one of the trickier challenges, diving into PHP’s quirks, like mixed-case function calls and dynamic execution.

sec.stealthcopter.com/patchstack-c...

#CTF #WordPress #Hacking

24.02.2025 10:28 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Unsupported Browser | HackerOne

Second collaboration of the year πŸ₯³ Many more to come 🀞I was awarded a $1,500 bounty on @Hacker0x01! hackerone.com/stealthcopter #TogetherWeHitHarder

12.02.2025 14:51 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Stealthcopter tldr; On their own, these two vulnerabilities in JupiterX Core wouldn’t have been very impactful or likely to get a bounty; but by chaining them together,

Chained two 'meh' WordPress vulnerabilities into a high-impact exploit on JupiterX Core πŸ‘Ύ. From low-privilege SVG upload to full RCE, check out the full breakdown and PoC πŸ› οΈ

#BugBounty #WordPress #Cybersecurity

sec.stealthcopter.com/jupiterx-cha...

01.02.2025 08:47 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
πŸ§©πŸ‘€πŸ§ πŸ‘ˆπŸ˜΅β€πŸ’«πŸ” β“βž‘οΈπŸ€―πŸš©πŸ₯³

πŸ§©πŸ‘€πŸ§ πŸ‘ˆπŸ˜΅β€πŸ’«πŸ” β“βž‘οΈπŸ€―πŸš©πŸ₯³

πŸ§©πŸ‘€πŸ§ πŸ‘ˆπŸ˜΅β€πŸ’«πŸ” β“βž‘οΈπŸ€―πŸš©πŸ₯³

#ctf

22.11.2024 12:01 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0