Canada 🇨🇦 · EST · 15 · full stack

Corbin

I write code and decompile stuff. Been doing it for years.

evil · Pumpppet · rival

11 projects ↓

About

Full stack developer. Most of my time goes into decompiling programs and figuring out how they work under the hood.

Android APKs, web APIs, infrastructure. If it runs, I've probably opened it up. Some of that got me in trouble. I learned my lesson. Parental controls on all my devices now.

I don't recommend an email provider that isn't Gmail. Gmail has decent spoofing protection to stop people from faking sender addresses — they can still spoof if they get SMTP access, but it's harder. Proton Mail, Apple, Discord, and a lot of others are more vulnerable to spoofing, and some setups can even accept mail that looks like it's to themselves.

So in theory someone could use a proton.me-style address without signing up, use a fake From, and harass a provider or even email the police and get an innocent mailbox tangled up in reports. That wastes everyone's time. Don't do that.

If you're worried about privacy, Tuta Mail is a solid pick — but that alone won't save you. Opsec is habits, not just the inbox. For Tor-only mail, I'd look at Mail2Tor: a Tor hidden-service email provider that runs on the network without a normal clearnet site. Still not magic; you have to use it like you mean it.

VPN tier list

Personal ranking — not sponsored.

  1. Mullvad

    Top pick. Fast servers, kill switch. No email — you get a randomly generated account number.

  2. ProtonVPN

    Decent. They claim no logs — I don't buy that. Requires email and phone number.

  3. NordVPN

    Fast servers, nice UI. Shows up in data breaches too often — wouldn't recommend. Requires email.

  4. Windscribe

    Slow. Requires email.

  5. Surfshark

    Slow. Requires email.

Swatting

Swatting is the biggest loser shit.

Ever wondered how big streamers get swatted? This is the dumb playbook people use — so you know what to lock down, not so anyone copies it.

How they try to find you

What happens on their side (losers)

They want something live so they can watch the reaction. Often it's streamed on a Discord stage while others record and clip. They hide behind VPNs, Tor, and throwaway numbers, then place fake emergency reports — sometimes routing through non-911 lines because 911 isn't always an option from their setup. When police show, chat spams garbage like "LMAOOO" because cruelty is the point.

Why they do it: sometimes they don't even need a stream — they just don't like you, dig through breaches until they have enough to send police to your door, and hope you get hurt. To them it's entertainment. It's not a prank. It's criminal.

Report a swatting

If a swat already happened, send what you have. Paste a link to video evidence (clip, VOD, screen recording). Reports go to me for review — not to police.

Link only — no file upload here. If the file isn't online, note that below and include your email.

Projects

11 builds I still remember.

01 / 11

Unofficial Norwood Fair website

Redesign of norwoodfair.com for the 158th Norwood Fair. Built to feel like a big exhibition site (think CNE scale), not a small-town flyer.

Unofficial student project. Banner at the top says so. Official tickets and info still live on norwoodfair.com.

Design

  • Orange fair poster look, sunburst background, flag bunting, prize ribbon badges
  • Animated Ferris wheel (SVG), cars stay level, blinking lights
  • Bold condensed poster lettering
  • Attraction tiles with their own patterns: rays, dots, stripes, gingham
  • Responsive on phone, tablet, desktop
  • Light and dark mode follows the device

Animations

  • Click anywhere: bubble gum bubble pops, splatter, drip (canvas)
  • Gum bubbles float behind the hero
  • Flip-clock countdown to opening day
  • Sections slide in on scroll; history years outline then fill in
  • Scrolling banner of fair highlights
  • Respects prefers-reduced-motion

Features

  • Full 3-day schedule with times and locations, day tabs, filters (Horses, Livestock, Music, Family)
  • Live music lineup with days, times, stages
  • Ticket prices as ticket stubs
  • 2024 stats: 45,000+ visitors, 23,718 single-day record
  • History timeline from 1868
  • Visitor FAQ (parking, accessibility, pets, ATM)
  • Google map + directions
  • Get involved: fair book, animals, Fair Ambassador, outdoor stage, volunteering
  • Contact + fair office details, link to unofficial student TikTok

Stack

React, TypeScript, Vite, Tailwind CSS, Motion, HTML Canvas (gum), SVG (Ferris wheel), Phosphor Icons. Hosted on Cloudflare. Dates, hours, prices, and schedule pulled from the official site and local news; copy lives in one file for easy updates. SEO and social meta included.

Screenshots

Next: SnoreGuard ↓
02 / 11

SnoreGuard

Keep your website online, even under attack. guard.snore.pw

SnoreGuard sits in front of your site on a global edge network. It filters attacks from layer 3 to layer 7, hides your origin IP, and balances clean traffic across your servers.

Global CDN & caching

Requests hit the edge closest to the visitor. Uploaded sites and static assets cache at each location, so pages load fast worldwide with nothing extra to configure.

Manage it with AI MCP

Built-in Model Context Protocol server so Claude, ChatGPT, Cursor, and other assistants can add sites, upload hosting, verify DNS, change protection, block visitors, and read stats. Scoped API tokens (read-only or full access), every change audited, revoke anytime.

Network request protection

HTTP request smuggling and malformed requests get rejected at the edge. Clients can't forge IP, origin secret, or internal headers. You can lock a site to specific HTTP methods.

How it works

DNS points at the SnoreGuard edge. Attacks stop there; only clean traffic reaches your origin. Visitors include real users, verified search bots, floods, scanners, and exploit attempts.

  • Gateway + 9 edge servers, instant failover
  • L3/L4 filtering, WAF, rate limits, challenge, firewall rules, request armor, CDN cache
  • Origin: your servers or SnoreGuard hosting; origin IP never exposed

Setup

  1. Add your site — Free account, then name.snore.pw or your own domain.
  2. Point DNS — CNAME to edge.snore.pw. DNS scan shows exact steps for your provider.
  3. Tune and monitor — Sensible defaults on day one. Adjust rules and watch live stats in the dashboard.
Next: SnoreClient ↓
03 / 11

SnoreClient

Discord, but cozier. Fork of Equicord (fork of Vencord). Keeps the full plugin set and adds SnoreClient-specific stuff. GitHub

About this project

I was bored and wanted to make a Discord client. I don't claim the code Claude AI wrote. I put it together and debugged issues.

SnoreClient cloud

Settings, QuickCSS, and plugin data sync between devices through the SnoreClient cloud at snore.pw.

Look & front end

  • New logo
  • Redesigned settings landing panel
  • Polished cards
  • Matching web front end on the same server
Next: Solara ↓
04 / 11

Solara

Worked on getsolara.dev for a couple months. At the time it was the most popular Roblox executor going.

People started calling it malware. It wasn't. Rumors spread anyway and usage dropped off.

Discord

The Solara Discord vanity URL got banned over and over. When someone still had the vanity on their server, I'd join that server and get permissions in it stupid fast so we could keep a home for users and updates.

Next: Roblox Map Design ↓
06 / 11

GeometryMod

Minecraft gameplay inside Geometry Dash. GitHub

Made fully by Claude. I take no credit.

Passthrough mod pair, inspired by the Minecraft-in-Elden-Ring trend. You play Geometry Dash, but Minecraft comes with you.

  • Hotbar, hearts, hunger, armor, XP on screen with real Minecraft sprites
  • Mine and place real blocks in any GD level; stand on them
  • Mobs walk the level, hurt you, can be fought
  • Redstone, water, lava, sand, doors, levers, chests, TNT work (real Minecraft)
  • GD spikes cost hearts instead of instant death; eat food to heal
  • What you build stays in that level next time you play
Next: BellaAI ↓
07 / 11

BellaAI

AI-powered penetration testing assistant. GitHub

Used to run on a dedicated server. I can't afford to renew hosting. You can still self-host from the repo.

Required accounts

  • OpenRouter (AI models)
  • OpenAI (content moderation)
  • E2B (isolated cloud execution in Agent mode)
  • Convex (database and backend)
  • WorkOS (auth and user management)
  • Trigger.dev (durable runtime for agent tasks)

Optional

  • Amazon S3 (files instead of Convex storage)
  • Perplexity (web search)
  • Jina AI (URL content retrieval)
  • Redis / Upstash Redis (stream resumption, rate limiting)
  • PostHog (analytics)
  • Stripe (payments)

Getting started

  1. Clone — git clone https://github.com/AABABABABABABBABAABABABABABBA/BellaAI.git
  2. Install — cd BellaAI, then pnpm install, then pnpm run setup
  3. Dev — pnpm run dev (Next.js + Convex), or pnpm run dev:next and pnpm run dev:convex in two terminals
  4. Trigger.dev worker — Agent mode needs a third terminal: pnpm dev:trigger. Put tr_dev_… in .env.local as TRIGGER_SECRET_KEY. Add worker env vars in the Trigger.dev dashboard (Convex URL, service role key, OpenRouter, OpenAI, sandbox provider, etc.)
Next: Live Sports ↓
08 / 11

Live Sports

Live sports streaming. Uses a free pay-per-view provider with all live sports. You can request something and I'll add it.

Public version: elitestreams.lol

There's also a private family deployment. I don't list the domain here, but you can find that version easily if you look. I don't care — I'm not trying to hide it or lock down endpoints on the sports site.

No ads. Playback starts right away. We run 8+ edge CDNs on the private stack.

Cloudflare live inputs

  • Maple default
  • Comet highest
  • Bolt full bitrate
  • Turkey lighter
  • Fish mobile
  • Light low bandwidth
  • Coral stable
  • Breeze standard
  • Mist lowest latency
  • Pebble mid quality
Next: CatWiki ↓
10 / 11

Cheat storefront

Worked on a cheating website for video games — shop, keys, status page, signup, the whole storefront. Provider name is redacted in the screenshots below. I stopped working on it because they weren't keeping their cheats updated.

Database (local dev)

Every page that hit the database took exactly 10 seconds. Not approximate — exactly ten, every time. The database host was unreachable from my PC. A raw TCP probe to the DB port timed out, so each request sat there until the connection attempt gave up. Every page.

Screenshots

Brand name blurred in the captures on purpose.

Next: fell.pics ↓
11 / 11

fell.pics

Hosting company I built and ran at fell.pics. It was online for a solid two or three months — not a weekend project, actually shipped and kept running.

Best site design I've done. Still proud of how that front page looked.

Infrastructure

  • Main box on an OVH dedicated server
  • Game and bot nodes spread across a bunch of cheap providers — whatever had the best price that week

What we hosted

  • Free Discord bot hosting — self-bots allowed
  • Minecraft servers
  • Other game servers
  • Miscellaneous VPS-style stuff people asked for
End of projects · Work history ↓

Worked on thousands of other things too. I can't list all of it — I don't remember it all.

Work

Canvas

Found the infrastructure path that got Canvas breached.

meemup.com

Flooded stores with orders, fake order descriptions, that kind of thing. Did it twice. Won't do that again. Parental controls on every device I use.

Instagram font method

Decompiled the Android Instagram app. Font-based auth bypass. Any account without 2FA was vulnerable.

Because of this, if you search Corbin anywhere you'll pull up news articles. The name is easy to find in two seconds if you want it. I'm still keeping it blurred here.

I deleted most of my photos and posts about it. News sites and archives still have the story. Tim Sweeney even weighed in.

Tim Sweeney on X

"Surely 2FA should prevent this."

Meta AI support chat

Screenshot from the flow. Name in the chat is redacted in the image too.

Video

Original tweet is gone. This is the clip URL from a news embed (Twitter CDN). If it stops working, the articles usually still describe the same demo.

Open stream (.m3u8)

TikTok font method

Made it so you could get any username. TikTok's API was public on GitHub the whole time. GitHub is where devs put source code. Someone left it open.

Meccha Chameleon

First person to make a cheat for Meccha Chameleon. Got sued the next day. Ignored it and sold the cheat's source code for 500 euros in cryptocurrency.

Was staff for Meccha Chameleon after that. Not anymore — I quit.

Skills

Now

SilentNet RAT blocker

Working on a program to block RAT infections from an upcoming builder called SilentNet. I know how these tools work. Trying to stop them before they spread.

Contact

Email any address below — tell me why you're writing.

I'll respond when I can.

  • If you use swag@aster.cx and don't say why, I'll assume it's about Live Sports (elitestreams.lol).
  • feet@aster.cx — still say why you're emailing. No context and I won't know what you want.
Top ↑