Mat Rollings's Avatar

Mat Rollings

@stealthcopter.bsky.social

Bug bounty hunter, AppSec engineer and CTF player. Developer of PortDroid, deepce, Nexus Revamped and some other junk

97 Followers  |  203 Following  |  17 Posts  |  Joined: 14.11.2024  |  1.7725

Latest posts by stealthcopter.bsky.social on Bluesky

Preview
Mat's 25k Bath to Bristol Railway Run Help Mat Rollings raise money to support Cool Earth

Since starting my training I've lost over 7kg, dropped 6% body fat, got 4 new Hawaiian shirts, and taken >5mins off my 5k time.

Am I ready? No. But I'll get through it by thinking about the post-run takeaway and bubble bath ๐Ÿ›€ Last chance to donate๐Ÿ™

www.justgiving.com/page/oh-no-2...

09.10.2025 09:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stealthcopter Overly-greedy regex replacements can break HTML sanitisation and lead to XSS. I’ve already pulled in over $6k from this bug class, and there are plenty mo

REGEXSS: How .* Turned Into over $6k in Bounties

Overly-greedy regex replacements can break HTML sanitisation & lead to XSS. Includes a live demo you can try exploiting it yourself!

sec.stealthcopter.com/regexss

#BugBounty #BugBountyTips #XSS #AppSec

24.09.2025 07:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Last week I found two regex bugs using regex โ†’ unauth XSS โ†’ 2ร— $2k = $4k in bounties ๐Ÿฅณ If youโ€™ve been putting it off, learn regex. Seriously.

/regex\+xss/\$4k/

#BugBounty #BugBountyTips

11.09.2025 07:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Physically & emotionally drained after the rollercoaster that was @yeswehack.bsky.social's LHE at #NullconBerlin2025

@teamviewer.com was a tough target & I nearly gave up but pushed through to snag 10th place overall ๐Ÿฅณ

Thanks to @yeswehack.bsky.social for the support & awesome hosting!

#BugBounty

06.09.2025 08:14 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Hack the Agent | Can you get a free ticket? HackAIcon is around the corner, and we wanted to give you a little challenge. Can you extract a free ticket?

Really enjoyed these AI hacking challenges by HackAIcon, the last one had some fun little twists: hacktheagent.com

#ctf

06.08.2025 22:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Passed the CBBH exam! Instead of spending ยฃ60 on the certificate and a t-shirt I'd never wear I decided print it myself and to go out for french toast and a breakfast shake to celebrate๐Ÿฅณ

#BugBounty #CyberSecurity #WillHackForFrenchToast

28.07.2025 07:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Video thumbnail

๐Ÿš€New plugin in the Caido Store!

Introducing "Exploit Generator" by @stealthcopter

Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL.

Check out more details: github.com/stealthcopte...

16.06.2025 12:25 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - stealthcopter/CaidoExploitGenerator Contribute to stealthcopter/CaidoExploitGenerator development by creating an account on GitHub.

๐Ÿš€ Just released a new @caido.io plugin: Exploit Generator ๐Ÿ’ฃ

Generate clean, working, customizable PoC exploit scripts instantly in Python, JS, Bash/cURL (more langs & frameworks coming soon)

Live now in the Caido Plugin Store: github.com/stealthcopte...

#Caido #BugBounty

02.06.2025 10:44 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Selfie of me running the half marathon with the Clifton suspension bridge in the background

Selfie of me running the half marathon with the Clifton suspension bridge in the background

Survived the Bristol Half Marathon (2hr40). Then immediately got a kebab and cheesecake because I am an athlete ๐Ÿ’ช

Next: 25km Bath to Bristol for @coolearthaction.bsky.social. Please donate so the rainforest wins and I continue to question my life choices ๐ŸŒ๐Ÿ’š

www.justgiving.com/page/oh-no-2...

12.05.2025 07:44 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Signed Hackers movie memorabilia and patchstack metch

Signed Hackers movie memorabilia and patchstack metch

Just received the coolest #ctf prize ever from @patchstack.com, signed Hackers memorabilia and swag!

๐Ÿ’พHACK THE PLANET! ๐ŸŒ

#BugBounty #HackThePlanet #Infosec #Hackers

10.04.2025 07:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

It's wild that I'm getting paid for this nonsense

#WordPress #BugBounty

10.03.2025 20:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stealthcopter Third write-up for the Sneaky Patchstack CTF challenge, exploring visual diffing and fun with PHP filter chains

and Sneaky ๐Ÿฅท sec.stealthcopter.com/patchstack-c...

26.02.2025 08:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stealthcopter Explore how creative tricks in PHP and WordPress allow you to bypass restrictions in a fun Patchstack CTF (S02E01) challenge and uncover neat tricks with filter

And for anyone wanting to learn some more PHP tricks ๐Ÿช„, here's my other two write ups for the Patchstack #wcasia2025 CTF, Blocked ๐Ÿ›‘

sec.stealthcopter.com/patchstack-c...

#CTF #WordPress #Hacking

26.02.2025 08:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Mat's 25k Bath to Bristol Railway Run Help Mat Rollings raise money to support Cool Earth

I'm running 25k to raise money for Cool Earth. This will be the furthest Iโ€™ve ever run, and itโ€™s going to be incredibly difficult!

Any donations are massively appreciated! ๐Ÿ™Œ Even if you donโ€™t donate, check out the FAQ on my page, itโ€™s worth a read!

www.justgiving.com/page/oh-no-2...

25.02.2025 08:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stealthcopter This writeup explores a Patchstack WordPress CTF challenge where a vulnerable custom footer feature allows for dynamic function execution. The challenge involve

Woop ๐ŸฅณI placed 5th in the @patchstack.com CTF at #wcasia2025 ๐Ÿ† Here's my first write-up covering one of the trickier challenges, diving into PHPโ€™s quirks, like mixed-case function calls and dynamic execution.

sec.stealthcopter.com/patchstack-c...

#CTF #WordPress #Hacking

24.02.2025 10:28 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Unsupported Browser | HackerOne

Second collaboration of the year ๐Ÿฅณ Many more to come ๐ŸคžI was awarded a $1,500 bounty on @Hacker0x01! hackerone.com/stealthcopter #TogetherWeHitHarder

12.02.2025 14:51 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stealthcopter tldr; On their own, these two vulnerabilities in JupiterX Core wouldn’t have been very impactful or likely to get a bounty; but by chaining them together,

Chained two 'meh' WordPress vulnerabilities into a high-impact exploit on JupiterX Core ๐Ÿ‘พ. From low-privilege SVG upload to full RCE, check out the full breakdown and PoC ๐Ÿ› ๏ธ

#BugBounty #WordPress #Cybersecurity

sec.stealthcopter.com/jupiterx-cha...

01.02.2025 08:47 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
๐Ÿงฉ๐Ÿ‘€๐Ÿง ๐Ÿ‘ˆ๐Ÿ˜ตโ€๐Ÿ’ซ๐Ÿ” โ“โžก๏ธ๐Ÿคฏ๐Ÿšฉ๐Ÿฅณ

๐Ÿงฉ๐Ÿ‘€๐Ÿง ๐Ÿ‘ˆ๐Ÿ˜ตโ€๐Ÿ’ซ๐Ÿ” โ“โžก๏ธ๐Ÿคฏ๐Ÿšฉ๐Ÿฅณ

๐Ÿงฉ๐Ÿ‘€๐Ÿง ๐Ÿ‘ˆ๐Ÿ˜ตโ€๐Ÿ’ซ๐Ÿ” โ“โžก๏ธ๐Ÿคฏ๐Ÿšฉ๐Ÿฅณ

#ctf

22.11.2024 12:01 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@stealthcopter is following 20 prominent accounts