OpenBullet 2 Configs Mega Pack — 100+ Configs: Carding, Email Checking, Social Media, Streaming Services, Gift Cards, Crypto

Blacksec

Administrator
Staff member
⚙️ OPENBULLET 2 CONFIGS MEGA PACK ⚙️

100+ Configs • Carding • Email Checkers • Social Media • Streaming • Gift Cards • Crypto Exchanges



⚡ CONFIG CURATOR:

I've been building and collecting OpenBullet configs since OB1. This is my personal collection — all tested, all working as of July 2026. Configs are organized by category with notes on hit rates, proxy requirements, and expected output.

What you need: OpenBullet 2 (latest build), residential or semi-dedicated proxies, and time to run them.

Proxy requirements vary: Some configs work with datacenter IPs (email checkers), others need residential proxies (carding, streaming). Notes included with each config.



📋 CONFIG INDEX

CategoryConfigsProxy TypeAvg Hit Rate
Streaming ServicesNetflix, Disney+, Hulu, HBO, Crunchyroll, Amazon PrimeResidential12-25%
Social MediaInstagram, Twitter/X, TikTok, Snapchat, OnlyFansMix (DC + Res)8-20%
Email CheckersGmail, Outlook, Yahoo, ProtonMail, AOL, YandexDatacenter OK15-30%
GamingSteam, Epic Games, Minecraft, Roblox, RiotResidential5-18%
Carding / CCBin Checkers, Stripe, Auth Gateways, Gift CardsResidential (BIN-matched)Variable
CryptoBinance, Coinbase, Kraken, Bybit, KuCoinResidential3-12%
Premium ServicesCanva Pro, ChatGPT, Midjourney, Adobe CC, NordVPNMix10-22%
UtilitiesProxies checkers, email verifiers, captcha solversAnyN/A (tools)



CONFIG SETUP GUIDE

OpenBullet 2 Quick Start:

Code:
1. Download OpenBullet 2
   - https://github.com/openbullet/openbullet2/releases
   - Extract to C:\OB2\

2. Import configs
   - Open OB2
   - Go to Configs → Import
   - Select the .loli files from this pack
   - They'll appear in your config list

3. Set up proxies
   - Go to Proxies → Import
   - Format: ip:port or ip:port:user:pass
   - Mark proxy type (HTTP/SOCKS4/SOCKS5)
   - Check proxies → green = working

4. Load combos
   - Go to Wordlist → Import
   - Format: email:pass (one per line)
   - Or: user:pass depending on config

5. Start checking
   - Select config → Select wordlist → Select proxies
   - Click "Start All"
   - Monitor hits in real-time

6. Export results
   - Hits are saved automatically in Results/
   - Export to CSV or TXT
   - Config-specific output in data/

Proxy Best Practices:

Code:
For maximum hit rates, use the right proxies:

Streaming (Netflix, Disney+, Hulu):
  - Residential proxies from the target country (US for US content)
  - Avoid DC IPs — they get blocked immediately
  - Rotation: 1 proxy per 5-10 checks

Social Media (IG, Twitter, Snapchat):
  - Semi-dedicated residential
  - OOKLA speedtest: minimum 10mbps
  - Rate limiting: 30 seconds between attempts per proxy

Email Checkers (Gmail, Outlook):
  - Datacenter proxies work fine
  - 1 proxy per 100-200 checks
  - HTTP proxies OK

Carding configs:
  - Premium residential only
  - BIN-matched to country of card
  - 1 proxy per 2-3 checks (high rotation)
  - Use sticky sessions where possible



STREAMING CONFIGS

Netflix Premium Checker:

Code:
Config Name: Netflix_Premium_2026.loli
Endpoint: netflix.com/api/shakti/
Auth Type: Cookie + Basic Auth
Checks: Plan type, profile count, payment method
Output: Working/NoPlan/Expired/Failed
Hit Rate: 15-22% (residential proxies)
Speed: 8-12 checks per proxy per minute

What it checks:
  - Subscription status (active, suspended, expired)
  - Plan tier (Basic HD, Standard FHD, Premium UHD)
  - Profiles available (counts as working based on plan)
  - Payment method on file (card, PayPal, gift card)

Proxy: Residential only, country-matched to account
Output file: 
  - Working: netflix_hits.txt (with plan info)
  - Contains: email:password:plan:payment_method

Disney+ Checker:

Code:
Config Name: DisneyPlus_Checker.loli
Endpoint: disneyplus.com/api/
Auth: Basic auth + bearer token extraction
Hit Rate: 20-35% (best among streaming services)
Speed: 15-20 checks per proxy per minute

Why Disney+ has higher hit rates:
  - Shorter token expiry (less cached dead accounts)
  - Higher credential reuse rate among users
  - More recent combo dumps available

Proxy: Residential, US preferred (but most countries work)
Notes: This is the most profitable streaming checker currently



SOCIAL MEDIA CONFIGS

Instagram Checker (Login + Followers):

Code:
Config Name: IG_Login_Checker.loli
Endpoint: instagram.com/api/v1/
Auth: Username/password + challenge handling
Output: Working/Challenge/Bad/Failed
Hit Rate: 10-18%

Challenges:
  - Instagram triggers phone/email verification on unfamiliar IPs
  - Config includes challenge detection: marks as "Challenge" not "Bad"
  - Manual verification needed for challenged accounts

Tips for higher IG hit rates:
  - Use proxies from the same country as the account
  - Warm up proxies (browse Instagram for 5 min before checking)
  - Max 50 checks per proxy per day
  - Rotate User-Agent with each request

Value:
  - Working IG accounts sell for $2-5 each
  - Accounts with 1k+ followers sell for $10-50
  - Business accounts with verification: $100+

OnlyFans Checker (Premium):

Code:
Config Name: OnlyFans_Premium_Checker.loli
Endpoint: onlyfans.com/api/v2/
Auth: Bearer token (from email:pass login)
Output: Working/Free/Expired/Failed
Hit Rate: 5-12%

What it checks:
  - Has active subscription (paid or free sub)
  - Creator account (if user is a creator)
  - Wallet balance (some have $)
  - Cards on file (linked payment methods)

This is a high-value config:
  - Creator accounts sell for $50-500
  - Accounts with wallet balance are cashouts
  - Subscribed accounts can download content



EMAIL CHECKERS

Gmail Validator (IMAP + SMTP):

Code:
Config Name: Gmail_IMAP_Validator.loli
Endpoint: imap.gmail.com (993)
Auth: XOAUTH2 / App Password
Output: Valid/Invalid/AppPassRequired
Hit Rate: 20-30%

Features:
  - Checks if Gmail is accessible via IMAP
  - Detects if app password is required (2FA enabled accounts)
  - Checks inbox count (active vs abandoned)
  - Returns: email:password:app_pass_status:inbox_count

Uses for valid GMails:
  - PayPal accounts (most common email)
  - Account recovery (reset passwords via Gmail)
  - Sending spam (if SMTP enabled)
  - Creating additional accounts on other platforms

ProtonMail Checker (Privacy Email):

Code:
Config Name: ProtonMail_Checker.loli
Endpoint: api.protonmail.ch
Auth: SRP (Secure Remote Password protocol — unique to Proton)
Output: Working/NoAccess/Failed
Hit Rate: 10-18%

ProtonMail is harder to check:
  - SRP protocol (not basic HTTP auth)
  - Rate limiting is aggressive
  - Some accounts have PGP keys set (extra protection)

Value of ProtonMail accounts:
  - Used by carders (privacy-focused)
  - Often linked to darknet markets
  - Accounts with verified phone: $10-15
  - PM Business accounts: $20-30



GAMING CONFIGS

Steam Account Checker:

Code:
Config Name: Steam_Account_Checker.loli
Endpoint: steamcommunity.com
Auth: RSA-encrypted login (uses Steam's public key)
Output: Working/Guard/NoGames/Failed
Hit Rate: 5-12%

What it retrieves:
  - SteamID (profile number)
  - Library size (# of games)
  - Account age (creation date)
  - VAC status (banned/clean)
  - Wallet balance (in cents)
  - Steam Level

Steam Guard handling:
  - Accounts with Steam Guard mobile: flagged as "Guard"
  - These need Steam Guard code to access
  - Some configs attempt to crack mobile auth: 2% success rate
  - No-Guard accounts sell for premium

Pricing:
  - Clean Steam accounts: $2-10
  - Accounts with games: $5-50+
  - CS2 ranked accounts: $15-40
  - Rare game collections: $100+



CRYPTO EXCHANGE CONFIGS

Coinbase Checker:

Code:
Config Name: Coinbase_Balance_Checker.loli
Endpoint: api.coinbase.com
Auth: JWT token + 2FA challenge handling
Output: Working/2FA/Bad/Failed
Hit Rate: 3-8%

What it checks:
  - Account balance (BTC, ETH, USDT, USDC)
  - Transaction history (recent buys/sells)
  - Verification level (KYC tier)
  - Linked payment methods (bank, card)

This is a cashout config:
  - Accounts with balance: drain via withdrawal
  - Verified accounts: sell for $50-200
  - Accounts with linked payment: high value



PREMIUM SERVICE CONFIGS

ChatGPT Plus / Pro Checker:

Code:
Config Name: ChatGPT_Plus_Checker.loli
Endpoint: api.openai.com/v1/
Auth: Bearer token (session-based)
Output: Working/Free/Expired/Failed
Hit Rate: 8-15%

Checks:
  - Subscription plan (Free, Plus $20, Pro $200)
  - API key access (if OpenAI API key exists)
  - Usage history

Value:
  - ChatGPT Plus accounts: $10-20
  - ChatGPT Pro accounts: $50-100 (rare)
  - Accounts with API credits: $20-100+



DOWNLOAD & SETUP

Code:
Config Pack Download:
  MEGA: https://mega.nz/file/BlackSec_OB2_Configs_2026
  Size: 8.4 MB (zip)
  Password: OB2BlackSec2026

Includes:
  - 127 configs (.loli files)
  - README with per-config notes
  - Edge profiles for challenge-free browsing
  - Wordlist samples (2M combos for testing)
  - Proxy list (2000 working SOCKS5, free tier — rotate quickly)

Installation:
  1. Download the zip
  2. Extract to C:\OB2\Configs\
  3. Open OB2 → Configs → the configs will auto-load
  4. Start checking

Configs that need API keys:
  - Stripe carder: needs your Stripe API key (add in config settings)
  - Binance checker: needs optional 2FA bypass config
  - Gmail checker: requires App Password generation for 2FA accounts

Config updates:
  - I'll post updates in this thread when endpoints change
  - Some configs break when the service changes their API
  - Check back every 2-4 weeks for updates



⚙️ END OF CONFIG PACK ⚙️

Questions about specific configs? Drop a reply. I answer within 48 hours.
 
Top