Pages:
Author

Topic: [BETA] EXCHANGE.BYTECOIN.IN - page 2. (Read 3487 times)

hero member
Activity: 602
Merit: 500
April 19, 2013, 11:54:00 AM
#27
i got a rpc error somehow and nothing was sent, but amount was 0 after the error

Anyway it was only 0.06 BTC Smiley
newbie
Activity: 37
Merit: 0
April 19, 2013, 11:14:42 AM
#26
Had an error when withdrawing BTC from the platform.. See your PM Smiley
Send me that to me also, i'll investigate your issue.
hero member
Activity: 602
Merit: 500
April 18, 2013, 04:32:06 PM
#25
Had an error when withdrawing BTC from the platform.. See your PM Smiley
sr. member
Activity: 476
Merit: 250
Bytecoin: 8VofSsbQvTd8YwAcxiCcxrqZ9MnGPjaAQm
April 17, 2013, 04:05:37 PM
#24
I notice you also added timestamps to the recent trade data, which is a big improvement, IMO.
legendary
Activity: 1455
Merit: 1033
Nothing like healthy scepticism and hard evidence
April 17, 2013, 03:32:57 PM
#23
We certainly need more exchanges to trade alt coins and, therefore, this initiative deserves praise. However, I think it would have more success with a more general accepted coin, like terracoin or ppcoin. Any plans to accept also these ones?
member
Activity: 70
Merit: 10
April 17, 2013, 06:21:31 AM
#22
DO NOT USE THIS SITE YET
It is vulnerable to cross-site request forgery.

This basically means that if you are logged in to the exchange, any random site you visit can log you out, cancel your orders, possibly create new orders (haven't checked this one yet), or withdraw your money to the attacker's address (I have successfully done this with my own account).

I have an easy solution for the exchange to fix the biggest problem there.

Simply allow users to lock their payment address.
The correct solution is to protect against all CSRF attacks.

I also recommend avoiding this site completely until this critical issue is fixed.  Any site you visit in the same browser could steal your entire balance with absolutely zero interaction from you.

Funny, the first thing I thought of after seeing this site was "it is probably vulnerable to CSRF".

Issue Fixed!

And thanks to all for finding and reporting the bugs. We will continue to improve on it and we are always open to suggestions and feedback. No need to scream it in BIG RED FONT lol Wink
full member
Activity: 238
Merit: 100
April 13, 2013, 12:55:55 PM
#21
exchange.bytecoin.in ?

I assume it's the same owners who have the pool that made my bytecoins go "poof" on withdrawal.
hero member
Activity: 840
Merit: 1000
April 12, 2013, 06:06:40 PM
#20
DO NOT USE THIS SITE YET
It is vulnerable to cross-site request forgery.

This basically means that if you are logged in to the exchange, any random site you visit can log you out, cancel your orders, possibly create new orders (haven't checked this one yet), or withdraw your money to the attacker's address (I have successfully done this with my own account).

I have an easy solution for the exchange to fix the biggest problem there.

Simply allow users to lock their payment address.
The correct solution is to protect against all CSRF attacks.

I also recommend avoiding this site completely until this critical issue is fixed.  Any site you visit in the same browser could steal your entire balance with absolutely zero interaction from you.
EDIT: FIXED

Funny, the first thing I thought of after seeing this site was "it is probably vulnerable to CSRF".
hero member
Activity: 602
Merit: 500
April 12, 2013, 05:05:12 PM
#19
I am buying 3750 BTE! fill my order please.
member
Activity: 70
Merit: 10
April 12, 2013, 04:34:24 PM
#18
Welcome guys!
jhd
member
Activity: 63
Merit: 10
April 12, 2013, 04:17:05 PM
#17
Thanx for it i try it soon Cheesy
legendary
Activity: 1442
Merit: 1000
April 12, 2013, 02:25:20 PM
#16
Deposits and payouts work fine  Smiley
legendary
Activity: 1442
Merit: 1000
April 12, 2013, 01:34:36 PM
#15
Goog morning guys,

We are very happy to announce the release of the exchange (http://exchange.bytecoin.in)

It is still rough but the background is highly functional, but like in all betas, bugs are likely to show up.

Please use this thread to post all your feedback about the exchange and what changes/improvements you would like to see.

Enjoy!

Edit: IT experts, please test the site for security vulnerabilities. We want to make sure the exchange is rock solid. Thanks in advance

nice work Sir Smiley
full member
Activity: 154
Merit: 100
April 12, 2013, 11:47:31 AM
#14
DO NOT USE THIS SITE YET
It is vulnerable to cross-site request forgery.

This basically means that if you are logged in to the exchange, any random site you visit can log you out, cancel your orders, possibly create new orders (haven't checked this one yet), or withdraw your money to the attacker's address (I have successfully done this with my own account).

I have an easy solution for the exchange to fix the biggest problem there.

Simply allow users to lock their payment address.
full member
Activity: 126
Merit: 100
April 12, 2013, 10:47:08 AM
#13

seems I have an emerald to sell - https://bitcointalk.org/index.php?topic=174455.20   Undecided
grc
newbie
Activity: 40
Merit: 0
April 12, 2013, 10:34:47 AM
#12
Wow you're a real jerk considering they asked for help pointing out security vulnerabilities and you go all ape-shit on them with your enormous red font.

Sorry. I just don't want other people to lose money like I did.

How much did you lose?

Post your address

Not much at all. I just used a tiny bit while testing and lost almost most of it, so I wanted to warn others. I apologise if I was rude about it before.
member
Activity: 70
Merit: 10
April 12, 2013, 10:31:23 AM
#11
Wow you're a real jerk considering they asked for help pointing out security vulnerabilities and you go all ape-shit on them with your enormous red font.

Sorry. I just don't want other people to lose money like I did.

How much did you lose?

Post your address
grc
newbie
Activity: 40
Merit: 0
April 12, 2013, 10:30:00 AM
#10
Wow you're a real jerk considering they asked for help pointing out security vulnerabilities and you go all ape-shit on them with your enormous red font.

Sorry. I just don't want other people to lose money like I did.
legendary
Activity: 1204
Merit: 1002
RUM AND CARROTS: A PIRATE LIFE FOR ME
April 12, 2013, 10:25:31 AM
#9
DO NOT USE THIS SITE

It is vulnerable to cross-site request forgery.

This basically means that if you are logged in to the exchange, any random site you visit can log you out, cancel your orders, possibly create new orders (haven't checked this one yet), or withdraw your money to the attacker's address (I have successfully done this with my own account).

Not to mention that in the process of testing it my 0.5 BTE magically turned into 0.005 BTE. I made one order to sell 0.5 BTE at a price of 0.1 (BTC per BTE I presume, but I can't be sure since are no units given for the price, amount or total). When I cancelled it, I only got 0.05 BTE back. I did a similar thing again and it further reduced my balance to 0.005 BTE.

So I'd definitely recommend avoiding this site for now/ever.

Wow you're a real jerk considering they asked for help pointing out security vulnerabilities and you go all ape-shit on them with your enormous red font.
legendary
Activity: 1862
Merit: 1011
Reverse engineer from time to time
April 12, 2013, 10:17:08 AM
#8
DO NOT USE THIS SITE

It is vulnerable to cross-site request forgery.

This basically means that if you are logged in to the exchange, any random site you visit can log you out, cancel your orders, possibly create new orders (haven't checked this one yet), or withdraw your money to the attacker's address (I have successfully done this with my own account).

Not to mention that in the process of testing it my 0.5 BTE magically turned into 0.005 BTE. I made one order to sell 0.5 BTE at a price of 0.1 (BTC per BTE I presume, but I can't be sure since are no units given for the price, amount or total). When I cancelled it, I only got 0.05 BTE back. I did a similar thing again and it further reduced my balance to 0.005 BTE.

So I'd definitely recommend avoiding this site for now/ever.
Best way to fix csrf is to use POST more(with some hidden randomly generated tokens) for most stuff, and less GET requests with dynamic data.
Pages:
Jump to: