[ home / overboard ] [ soy / qa / raid / r ] [ ss / craft ] [ int / pol ] [ a / an / asp / biz / mtv / r9k / tech / v / sude / x ] [ q / news / chive / rules / pass / bans / status ] [ wiki / booru / irc ][Options]

A banner for soyjak.party

/soy/ - Soyjaks

doctos i just got epi'd
Catalog
Email
Subject
Comment
SelectFile / Embed / Oekaki / Tegaki / JS Paint / Voice / Poll
File
Select/drop/paste files here
Password (For file deletion.)

[–]

File (hide): carbjak-army.png 📥︎ (528.61 KB, 864x1237) ImgOps

 14985245[Last 50 Posts][1][2][Quote] [Voice Chat]>>14986155>>14986453

+=OVU.MOE RAID=+

YOU CAN JUST SPAM REPORTS AT https://ovu.moe/api/report

There is no cloudflare, no captcha, no nothing. You can use bots to automate posting on this site.

The same goes for https://ovu.moe/login. (You could try and bruteforce the admin passwords.)

There is no ratelimiting or security measures of any kind.

>Marge? What is ovu.moe?

It's a site for "people" to track the ovulation cycles of female Vtubers.

 14985252[Quote]

You can also spam their "evidence" section (https://ovu.moe/track) with false evidence or some other raisin

 14985261[Quote]

File (hide): 1679928198544.png 📥︎ (38.84 KB, 1000x1000) ImgOps

>VTuber Ovulation Tracker

 14985340[Quote]

File (hide): ClipboardImage.png 📥︎ (37.36 KB, 752x350) ImgOps

new vtuber dropped

 14985401[Quote]


 14985434[Quote]

File (hide): ClipboardImage.png 📥︎ (37.43 KB, 507x381) ImgOps


 14985438[Quote]

File (hide): 1768131878237k.png 📥︎ (132.77 KB, 1024x1024) ImgOps

>Making a website to track the ovulation cycles of female Vtubers

 14985461[Quote]>>14985488

File (hide): ClipboardImage.png 📥︎ (32.23 KB, 410x346) ImgOps

File (hide): ClipboardImage.png 📥︎ (555.4 KB, 603x595) ImgOps


 14985482[Quote]

okay but really this shit is freaky

 14985488[Quote]>>14985493>>14985507

>>14985461
Annoying Orange trooned out retard

 14985493[Quote]

>>14985488
nophono cares it's still geggy, stop mcwhining

 14985507[Quote]

>>14985488
seperate the fart from the autist or something

 14985531[Quote]>>14985548>>14985557

File (hide): gem.gif 📥︎ (240.92 KB, 64x32) ImgOps

https://ovu.moe/new
you can literally upload any sort of file on here including svg files
and you can also embed javascript into svg files with xml..
teens are you soying what im soying?

 14985548[Quote]>>14985557

>>14985531
also why the fuck is this site so pajeet coded geg
there is no css nor any ui
definetely vibecoded using jeetgpt or something

 14985557[Quote]>>14985742>>14985797

>>14985531
/hack/GODS get in here
>>14985548
gooners are mentally handicapped geg

 14985663[Quote]

DEPLOY BABY BOT ON THIS SITE NQVV

 14985693[Quote]>>14985704

I've been stealthily adding links to nigger scat and prolapse porn and shit under random vtumors

 14985704[Quote]>>14985712


 14985712[Quote]

>>14985704
so gooners click on it hoping to find ovulation info and then vomit at the sight GEG

 14985734[Quote]>>14986076

If you go to https://ovu.moe/api/idol/list it sends you the entire database. It also takes a second or so to do it, as opposed to sending reports which take around 500 ms. This means it is somewhat resource intensive. I'm currently sending quite a bit of requests their way. Not a single rate limit so far.

 14985742[Quote]>>14985744>>14985756

File (hide): Anonymous.jpg 📥︎ (2.03 MB, 4032x2268) ImgOps

File (hide): Anonymous.jpg 📥︎ (6.26 KB, 255x219) ImgOps


 14985744[Quote]>>14985755


 14985755[Quote]


 14985756[Quote]>>14985768

>>14985742
Nice. What's the software called?

 14985768[Quote]>>14985780


 14985779[Quote]>>14985847

File (hide): 1765793857351i.png 📥︎ (83.13 KB, 2446x1298) ImgOps

GEEEEEEEEEEG WHICH ONE OF YOU ALREADY ADDED COBSON and oreos

 14985780[Quote]


 14985787[Quote]

Its based and Vocaloid pilled or something

 14985797[Quote]>>14985800>>14985803

>>14985557
I'M GOING TO TRY TO CREATE THE PAYLOAD IM NOT SURE IF THE SHARTY ALLOWS SVG FILES BUT HOPEFULLY IT WORKS

 14985800[Quote]>>14985828

>>14985797
good luck saar if it doesnt then send n catbo

 14985802[Quote]

x award

 14985803[Quote]

>>14985797
by the time you get the admin's cookie it will be snca though

 14985809[Quote]>>14985812

I can't add evidence or new vtumors. I think VPNs might be blocked but I'm not sure. I even made an account but that didn't help

 14985812[Quote]>>14985816>>14986027

File (hide): 1769246809863k.png 📥︎ (4.68 KB, 401x63) ImgOps

>>14985809
I think VPNS are blocked

 14985816[Quote]

>>14985812
You can still send reports though

 14985828[Quote]

>>14985800
i'm trying to add a frog laugh to it too but it doesn't fucking work

 14985846[Quote]

up

 14985847[Quote]

>>14985779
that was me geg

 14985856[Quote]>>14985896


 14985896[Quote]


 14985897[Quote]

File (hide): 1768989803968f.png 📥︎ (37.11 KB, 657x602) ImgOps

reporting the omori bus to our brave vtuber sisters

 14985918[Quote]>>14986006

try inserting HTML tags in the vtuber descriptions or in the evidence

 14986006[Quote]>>14986159

File (hide): 1765443098712n.png 📥︎ (90.3 KB, 902x766) ImgOps

>>14985918
it's just giving me this

 14986027[Quote]

>>14985812
I think somephono snitched

 14986039[Quote]

Saar why is this site so shit i can't do anything

 14986056[Quote]

File (hide): Ultra_geg.mp4 📥︎ (1.65 MB, 720x720) ImgOps [play once] [loop]

>a site for "people" to track the ovulation cycles of female Vtubers.

WHAT THE FUCK GEEEEEEEEEEEEEEEEG

 14986076[Quote]

>>14985734
I got rate-limited after trying to log into admin's account

 14986115[Quote]

up

 14986126[Quote]

up

 14986155[Quote]

>>14985245 (OP)
Cloudflare is present on the site though. The site is behind kikeflare

 14986156[Quote]

vp

 14986159[Quote]>>14986172

>>14986006
probably some form of basic sanitization?
you could try looking into the script to see if img tags are blocked
try using iframes

 14986172[Quote]>>14986178

>>14986159
no, i cant add evidence or vtubers at all. I used to be able to do it but I got blocked, somephono snitched or it's because I spammed 1488 requests to login

 14986173[Quote]

bump

 14986178[Quote]

>>14986172
well vpns are blocked so..
try using a vpn and a hardened browser like librewolf

 14986200[Quote]>>14986354

if you search https://ovu.moe/api/idol/search/', the server experiences a fatal internal error

 14986292[Quote]

up

 14986300[Quote]

up and oreos

 14986310[Quote]

File (hide): ClipboardImage.png 📥︎ (80.35 KB, 1269x423) ImgOps

COBSON IS FERTILE

 14986314[Quote]>>14986320

btw if you add cobson to your favorites we can get him on the trending vtubers tab

 14986320[Quote]>>14986331


 14986331[Quote]>>14986342

File (hide): ClipboardImage.png 📥︎ (41.43 KB, 797x327) ImgOps

>>14986320
go to https://ovu.moe/v/cobson
make sure you're logged into an account
click "add to favorites"

 14986342[Quote]>>14986383

>>14986331
i got nished, do this for me
Nate:Higgers1488

 14986354[Quote]>>14986363

>>14986200
someone try and get SQL injection to work

 14986356[Quote]

bump

 14986363[Quote]

>>14986354
It's not working, it just returns an empty json

 14986370[Quote]

come on nusois this is an easy target you can do it

 14986383[Quote]>>14986399

File (hide): ClipboardImage.png 📥︎ (37.19 KB, 517x344) ImgOps


 14986398[Quote]

File (hide): ClipboardImage.png 📥︎ (20.57 KB, 330x341) ImgOps


 14986399[Quote]>>14986403

>>14986383

but is he ovulating

 14986403[Quote]

>>14986399
that's a fifteen year old doctos

 14986417[Quote]>>14986453

go up this is actually fucking disgusting nigger

 14986418[Quote]>>14986423

Btw ovu.moe is being talk about in 'Farms if that matter.

 14986423[Quote]


 14986427[Quote]

File (hide): natsoc doctos.png 📥︎ (637.85 KB, 968x778) ImgOps


 14986431[Quote]

File (hide): Anonymous.png 📥︎ (62.57 KB, 900x132) ImgOps

They have htmlspecialchars() on vtumor descriptions

 14986453[Quote]>>14986458>>14986474

File (hide): IMG_0457.jpeg 📥︎ (223.99 KB, 1206x1284) ImgOps

>>14986417
>>14985245 (OP)
groypers btfo

 14986454[Quote]>>14986462

File (hide): Anonymous.png 📥︎ (337.67 KB, 2454x640) ImgOps

same with "evidence"

 14986458[Quote]

>>14986453
btw this is a 'farms screenshot

 14986462[Quote]>>14986477>>14986482

File (hide): 1765364525019o.png 📥︎ (15.4 KB, 777x679) ImgOps

>>14986454
niggers know how to code

 14986471[Quote]>>14986512

can we gem this one up by adding evidence that just links to pictures of froot's 'jak or something
https://ovu.moe/v/froot

 14986474[Quote]


 14986476[Quote]>>14986489

File (hide): IMG_0458.jpeg 📥︎ (221.46 KB, 1206x1316) ImgOps

somephono do a whois

 14986477[Quote]>>14986479

>>14986462
for xss to even work, you need it to render a text content as innerHTML (example document.innerHTML = "fuck niggers")
I don't really think it would be possible to perform xss even if this site is extremely shitty but then again any type of file is allowed for vtubers so we could upload svg files

 14986479[Quote]

>>14986477
vtuber uploading*

 14986482[Quote]>>14986502

>>14986462
there's not an httponly flag on der cookies. We need to try injecting script tags into report forms and grabbing the admin cookie

 14986484[Quote]

File (hide): 1768323278344p.png 📥︎ (35.58 KB, 255x247) ImgOps

someone add cordsonbraps to this geeegggy

 14986489[Quote]


 14986490[Quote]

File (hide): jsid.png 📥︎ (15.58 KB, 598x800) ImgOps

bvmp, annihilate these specimens

 14986502[Quote]>>14986530>>14986559

File (hide): bleedfurfag.mp4 📥︎ (44.38 MB, 3790x2160) ImgOps [play once] [loop]

>>14986482
isn't there sanitization when it comes to user input?
good luck with that ig

 14986512[Quote]>>14986549

File (hide): ClipboardImage.png 📥︎ (25.39 KB, 1191x82) ImgOps

File (hide): ClipboardImage.png 📥︎ (676.45 KB, 735x649) ImgOps

>>14986471
did a stealthy one
the link leads to this geg

 14986530[Quote]

File (hide): Anonymous.png 📥︎ (66.62 KB, 512x512) ImgOps


 14986532[Quote]

File (hide): ClipboardImage.png 📥︎ (12.94 KB, 954x103) ImgOps


 14986536[Quote]>>14986558

we could attempt sql injection again using the report form. The ID and the drop down options arent sanitized and you can use >>>'<<< to cause a internal error like with the search api o algo

 14986549[Quote]>>14986582

>>14986512
did you find a way to mask urls or something?

 14986558[Quote]>>14986584

File (hide): 1765568500487m.png 📥︎ (5.2 KB, 601x313) ImgOps

>>14986536
is this normal

 14986559[Quote]>>14986604

>>14986502
Domain Name: ovu.moe

Registry Domain ID: REDACTED FOR PRIVACY

Registrar WHOIS Server: https://porkbun.com/whois

Registrar URL: www.porkbun.com

Updated Date: 2025-10-21T13:10:11Z

Creation Date: 2025-08-22T13:10:10Z

Registry Expiry Date: 2026-08-22T13:10:10Z

Registrar: Porkbun

Registrar IANA ID: 1861

Registrar Abuse Contact Email: abuse@porkbun.com

Registrar Abuse Contact Phone: +1.5038508351

Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited

Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited

Registry Registrant ID: REDACTED FOR PRIVACY

Registrant Name: REDACTED FOR PRIVACY

Registrant Organization: Private by Design, LLC

Registrant Street: REDACTED FOR PRIVACY

Registrant Street: REDACTED FOR PRIVACY

Registrant Street: REDACTED FOR PRIVACY

Registrant City: REDACTED FOR PRIVACY

Registrant State/Province: NC

Registrant Postal Code: REDACTED FOR PRIVACY

Registrant Country: US

Registrant Phone: REDACTED FOR PRIVACY

Registrant Phone Ext: REDACTED FOR PRIVACY

Registrant Fax: REDACTED FOR PRIVACY

Registrant Fax Ext: REDACTED FOR PRIVACY

Registrant Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.

Registry Admin ID:

Admin Name:

Admin Organization:

Admin Street:

Admin Street:

Admin Street:

Admin City:

Admin State/Province:

Admin Postal Code:

Admin Country:

Admin Phone:

Admin Phone Ext:

Admin Fax:

Admin Fax Ext:

Admin Email:

Registry Tech ID: REDACTED FOR PRIVACY

Tech Name: REDACTED FOR PRIVACY

Tech Organization: REDACTED FOR PRIVACY

Tech Street: REDACTED FOR PRIVACY

Tech Street: REDACTED FOR PRIVACY

Tech Street: REDACTED FOR PRIVACY

Tech City: REDACTED FOR PRIVACY

Tech State/Province: REDACTED FOR PRIVACY

Tech Postal Code: REDACTED FOR PRIVACY

Tech Country: REDACTED FOR PRIVACY

Tech Phone: REDACTED FOR PRIVACY

Tech Phone Ext: REDACTED FOR PRIVACY

Tech Fax: REDACTED FOR PRIVACY

Tech Fax Ext: REDACTED FOR PRIVACY

Tech Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.

Name Server: curitiba.ns.porkbun.com

Name Server: salvador.ns.porkbun.com

Name Server: fortaleza.ns.porkbun.com

Name Server: maceio.ns.porkbun.com

DNSSEC: unsigned

URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

>>> Last update of WHOIS database: 2026-01-27T04:47:47Z <<<

 14986582[Quote]>>14986629

>>14986549
on xitter you can replace the username in the URL with anything and it'll still link to the same post
so for example, I can replace
https://x.com/Coobsun/status/2016210707130315159
with
https://x.com/LichVtuber/status/2016210707130315159
and both will lead to the same post

 14986584[Quote]>>14986625

>>14986558
yes, thats the normal. I can't get anything but that and "[]" to return THOUGH

 14986592[Quote]>>14986607

Can we dox vtubers instead

 14986604[Quote]

>>14986559
THE SERVERS ARE LOCATED IN BRAPZIL GEG

 14986607[Quote]

>>14986592
both should be done

 14986621[Quote]

alright 'teens let the 'ox begin

 14986625[Quote]

>>14986584
My observations:
' > error
'' > error
''' > error
'''' > []
' > error
'; <SQL_statement>;– > error
<any_text_here>'; <SQL_statement>;– > []

 14986629[Quote]

>>14986582
oh okay thanks for the explanation saar

 14986661[Quote]

vp

 14986679[Quote]

up

 14986725[Quote]

File (hide): ClipboardImage.png 📥︎ (150.61 KB, 1277x641) ImgOps

geg o algo

 14986749[Quote]

Make Cobson fetile again or something

 14986810[Quote]

File (hide): ClipboardImage.png 📥︎ (32.17 KB, 429x345) ImgOps

though

 14986818[Quote]>>14986828

File (hide): ClipboardImage.png 📥︎ (281.54 KB, 1477x804) ImgOps

kiwisisters found cobson geg

 14986828[Quote]


 14986914[Quote]

looks like a neutralraid for now

 14986916[Quote]

up

 14986948[Quote]

last bump before it slides

 14986951[Quote]

can't post screencaps for obvious reasons but someone uploaded DNB as a vtuber under like 20 different names

 14986967[Quote]

nusois can't /hack/

 14987017[Quote]>>14987023>>14987024


 14987023[Quote]>>14987090

File (hide): 1769204241017u.png 📥︎ (26.01 KB, 600x871) ImgOps


 14987024[Quote]

>>14987017
janny woke up

 14987042[Quote]

File (hide): ClipboardImage.png 📥︎ (53.45 KB, 1293x605) ImgOps

geg

 14987050[Quote]>>14987089


 14987089[Quote]>>14987096

>>14987050
WINRAIDERALD

 14987090[Quote]>>14987265

>>14987023
with just how much stealth shit I uploaded combined with how shit the site is I imagine the janny will still be finding hidden links to 'jaks and nigger scat + pages for fake vtubers for literal years to come (pretending that the site will still exist then, which it won't). it'll be like glitter or something geg

 14987096[Quote]

>>14987089
Wait falsenvke it's back up again

 14987108[Quote]>>14987133

does someone have a script to spam it yet

 14987111[Quote]

File (hide): 1766204306564o.gif 📥︎ (2.93 MB, 250x250) ImgOps

>>>14987023 (You)
>with just how much stealth shit I uploaded combined with how shit the site is I imagine the janny will still be finding hidden links to 'jaks and nigger scat + pages for fake vtubers for literal years to come (pretending that the site will still exist then, which it won't). it'll be like glitter or something geg

 14987115[Quote]

I'm scrolling through the site right now this is some vile shit

 14987133[Quote]

>>14987108
tutorial
>f12
>network tab
>click report or search or whatever
>right click the request
>copy as cURL
>import into Insomnia
>remove some of the unneeded http headers
>edit the body to say what you want it to say
>send request / send request on interval (lowest delay is 1 second)

If you want to spam faster, you need to click add the request to a task list, set the iteration count, and there you can set the delay to 0ms.

 14987265[Quote]>>14987329

>>14987090
I don't want to dissapoint you but since we fastburned all your stealth gemmies can be reverted by looking at access log + timestamps

 14987270[Quote]

disappoint*

 14987309[Quote]>>14987333

File (hide): ClipboardImage.png 📥︎ (7.21 KB, 713x54) ImgOps

GEEEEEEEEEEEEEEEEEEEEG

 14987329[Quote]

>>14987265
that's okay, it was fun while it lasted anyway
xhey just took the site down for the next few hours because of our spam so I consider this a winraid

 14987333[Quote]


 14987395[Quote]

Geeeeeg they shut it down



[1] [2]
[Return][Catalog][Go to top][Expand all images][Post a Reply]
Delete Post [ ]
[Update] ( Auto) 2
134 replies | 39 images | 34 UIDs | Page 2
[ home / overboard ] [ soy / qa / raid / r ] [ ss / craft ] [ int / pol ] [ a / an / asp / biz / mtv / r9k / tech / v / sude / x ] [ q / news / chive / rules / pass / bans / status ] [ wiki / booru / irc ]
Style: