Author

Topic: DaDice.com - Next Gen Social Gambling Dice Experience | Progressive Jackpot - page 115. (Read 257856 times)

member
Activity: 106
Merit: 10
I, and a few other users, have raised some very legitimate reasons not to invest here. Not because I am scared they will take over the world of dice. I'm pretty sure they wont, which is based on how well legitimate concerns are turned into "you are an idiot troll" statements. I am concerned for the people who are miss led to thinking this site is good. I had the same concern over dicebitcoin which ran with, or lost, thousands of bitcoin. I have never attacked other dice sites which seem ok and are not arrogant to the community issues raised. The developer has a chip on his shoulder and this is problematic when considering a site that holds hundreds of thousands of dollars (we don't know because they wont show the cold wallet).
Instead of acknowledging issues and concerns, the Dev goes off claiming the negativity is trolling, or the comment is made due to the person backing another dice site. I do not own or run a gambing site, so I don't care who is the number 1 dice site. I do care about all these crooks starting dice sites with the least amount of effort in the attempt to steal as much bitcoin as possible. It ruins bitcoin and the honest gambling site owner reputation.

Lets face it, this site suffers a bucket load of issues and it is a fact. Not speculation, it is 100% fact.

The owners and developers are quite ignorant, or devious, if they believe this site will ever grow to beat the other players in this market. For one, the web interface is unusable due to coding issues. But instead of trying to fix it, they just blame it on the user's computer and internet connection. They fail to understand all these same users can use other gambling sites no problem at all, even on their phones. Instead of taking on the criticism and making things better they spend more time and money trying to cover it up with shill accounts on this forum. To me this is a big wide open display of scam activity. Any anyone investing should go elsewhere as the risk here is too high.

I will keep posting these as long as I have to, as a public service to bitcoin investors who are not aware of this risk.

I await to be told I'm a troll.. again... And look forward to the next condescending image posted by the developer.
full member
Activity: 154
Merit: 100
DON"T FORGET!!! FROM TOMORROW AT 0H00!!!!! BE THERE!!!!!!!!!!


TITLE BOUT TO END ALL BOUTS!!!

MAYWEATHER VS PACQUIAO HERE ON DADICE!!!!




Three contestants will battle it out for the JABBA title this weekend! Some extensive training has been taking place in all camps.


The Current Champion @Scotch! Tough, strong and with a roundhouse bankroll known to level the opponents...

The Challenger @SemenFlower! Fast, edgy and with a surprise uppercut in his balance....

And now! A possible third contender! @Creweer! The underdog, Hungry, dedicated, and with ligtning fast BTC jabs!


Who will win the title? Who will face ignominy!

Find out this weekend on DaDice

The highest rolling player for the weekend will win the coveted title! The Lowest will be their SlaveLeiea!



Watch this space for more details and how you can participate in this landmark event! And Keep Rollin'!
legendary
Activity: 1876
Merit: 1005
CoinBuzz has recently reviewed us and had a chat with Steve.

http://www.coinbuzz.com/review/dadice-next-generation-social-gambling/

We'd like to thank CoinBuzz for such a fantastic review and we look forward to working with everyone in keeping DaDice the best Dice site on the web
Nice share and good to be reviewed by some trusted and well known analysts as these prove more fairness and make sites more trustworthy.Dadice is one of the fastest growing dice site,I have seen ever.Technical issues are with every type of online business but good, is to fix and resolve them sooner as possible.Good to see more and more positive about Dadice day by day.
newbie
Activity: 48
Merit: 0
So since it took 5 days for an email to reach the developer, I am wondering if the development is outsourced or is DaDice truly 1 team that worked together before? Also since there supposed to be 500+ coins invested, I am wondering if there is already a public cold bitcoin address? Thanks.

No, it reached me properly but got burried with lots of other stuff as you are aware we are constantly working on new features for site too. So it was totally my fault and to overcome this I have joined here as well as others measures have been take, all important requests (such as yours) will now be starred/flagged to top of the list.
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
So since it took 5 days for an email to reach the developer, I am wondering if the development is outsourced or is DaDice truly 1 team that worked together before? Also since there supposed to be 500+ coins invested, I am wondering if there is already a public cold bitcoin address? Thanks.
full member
Activity: 154
Merit: 100
CoinBuzz has recently reviewed us and had a chat with Steve.

http://www.coinbuzz.com/review/dadice-next-generation-social-gambling/

We'd like to thank CoinBuzz for such a fantastic review and we look forward to working with everyone in keeping DaDice the best Dice site on the web
member
Activity: 106
Merit: 10
We are runnign a casino here, we are not stupid! Wink


Obviously!!!!
legendary
Activity: 3556
Merit: 9709
#1 VIP Crypto Casino


now regarding the email display issue, it was a real bug, a bounty could have been rewarded but they choose to rather abuse it.

Ending note: Up till now all known bugs reports, technical/security issues and etc have already been fixed!



I am with you on this one Da Dice! Like they say "What doesn't kill you, only makes you stronger!"... Da Dice will certainly be #1 dice game in 2015


agreed with you DaDice getting stronger and more stronger day by day because they have very supportive staff so always you get timely response on every issue and one of other dice has very very poor support section where you have to wait for couple of weeks to get response, other plus point DaDice has the healthy ongoing competitions.

The competitions are cool & the payouts/winnings are great.
I would never slate any other site or gambling page by name but some of the competition prizes on other sites I've seen are quite poor.
Well done & thanks to everybody at DaDice for such a great set up.
full member
Activity: 154
Merit: 100
OUR REFERRAL LEADERS!!!!!!!!

Good morning all! Here are the top three leaders in our referral commission competition as of this mornings Stats.


Rank               Username   Commission
1                   bank            0.00552999
2                   LNMH       0.00383705
3                   williamho    0.00280744


Remember the prizes at stake are 1 BTC for first, 0.6 BTC for second and 0.4 BTC for third! And as always keep an eye on the standings here: https://stats.dadice.com/#
hero member
Activity: 896
Merit: 1000


now regarding the email display issue, it was a real bug, a bounty could have been rewarded but they choose to rather abuse it.

Ending note: Up till now all known bugs reports, technical/security issues and etc have already been fixed!



I am with you on this one Da Dice! Like they say "What doesn't kill you, only makes you stronger!"... Da Dice will certainly be #1 dice game in 2015







agreed with you DaDice getting stronger and more stronger day by day because they have very supportive staff so always you get timely response on every issue and one of other dice has very very poor support section where you have to wait for couple of weeks to get response, other plus point DaDice has the healthy ongoing competitions.
legendary
Activity: 2254
Merit: 1140
I really like the unique twist on dice.   The interface is pretty nice and the design of the site itself is just great overall.  Everything really pops and stands out nice.   Also, the site loads fast and there is never any noticeable delay doing anything at all.  Good work.
newbie
Activity: 48
Merit: 0
now regarding the email display issue, it was a real bug, a bounty could have been rewarded but they choose to rather abuse it.

The fact that this works makes the DaDice operators in this thread look super cringeworthy since it's been revealed before on multiple occasions.

Instead of posting condescending images, consider fixing your site guys. Roll Eyes

This has been corrected as well, no I am not going to post any offensive memes for you nor I have taken any offence there mate! You are partially correct but as I have apologised to Nico for a similar complain and I have promised everyone that I will be around to deal with such bug requests directly myself and with my team.

We have a bug bounty hunter program so if a bug is reported there we will go ahead and correct it and reward the reporter. We have never said that we are 100% fool proof and neither anybody else is! The PocketRocketCasino guy who I think thinks he got his site developed right from "God's IT minions" have had even severe technical issues and some references suggest they still have but we are not there at their thread bragging about it Smiley Go there https://bitcointalksearch.org/topic/gamble-at-prc-at-your-own-risk-779932 and start following the trial of never ending glitches, bugs and issues with PocketRocketCasino... And then there is PrimeDice, who is not aware of robinhood and hufflepuff issues? Infact they also have a bug bounty program.

We officially consider PD and some other dice sites as seniors (which is the fact) and we have looked up to them when planning / developing / marketing Da Dice. And yes we are competiting with everyone on top too but in a good way. Healthy competiton is good, bad marketing tactis is the worst! and not good for anyone.

So we appreciate any bugs reported! There will be no delay in handling them rest assured Smiley

Ending note: Up till now all known bugs reports, technical/security issues and etc have already been fixed!



Ending note: Up till now all known bugs reports, technical/security issues and etc have already been fixed!
newbie
Activity: 48
Merit: 0
Normally i would assume that you already know this, but i would also assume that you know GET requests shouldnt be used sensitive operations (like withdrawals) so I'll make an exception: mac addresses arent transmitted on the network. There is literally no possible way you could know my mac. If you correctly know it, hand-on-heart ill give you everything back

anyway, your whole story is silly. you just got pwnd and now like to present yourself as the victor? Maybe you should put some more memes again. Seems to me someone hasnt yet learnt their lesson.



I have already explained about CSRF and why it was like that, and CSRF preventation was already in place and I have had been monitoring your accounts before you played that "PvP roll" between both of your accounts and were curiously checking all functions of site. We are runnign a casino here, we are not stupid! Wink

You are right that retriving the mac address is not possible but we can label any device (just google there are number of methods of marking a device) and then we check the useage of Da Dice from it. Smart, eh? Cheesy so we might not know the actual mac ID of device but we infact know that it is the same device since it has had been marked Wink

Between, since you have admitted of sending a malicious & infected link here on forum, I will report you and hope you will be banned. Thinking of the next username already I guess?

For me the, the cue was the moment you set iteration to start with 5 BTC, I knew what was going to happen next Wink You have been trampled very hard this time my friend! take your "pot of bullshit" and go somewhere else.

For everybody: GET requests were temporarily allowed because API keys are not yet distributed among members, and all API call (regardless of which site and etc) are either GET/POST and that is why it was enabled but we were monitoring the use of it. And preventation was already in place which we triggered as we found appropriate moment for it Tongue we log each and every action and we keep the logs!
newbie
Activity: 48
Merit: 0
...

Wow, so this must be one of those "should have been more humble" scenarios.  Well you found a bug or 3 guess you get bounty?

He must be literally weeping tears right now 0.1 BTC + 0.1 BTC + 5 BTC and look at his recovery! And I am laughing so hard!!! 90% of transactions are his own the a couple mbtcs are mine and rest 0.001 from a couple of faucet players that have already been named.

Btw... there is no bounty when the bug is abused, and now since they know they can't attack system directly now they are desperate enough to "try to" steal change from users!!! We pay more then that in contests, activities and to our faucet miners Wink
hero member
Activity: 560
Merit: 500
For anyone wondering what really happened, look no further than two pages back. Instead of fixing issues, DaDice thought it'd be fun to post offensive images and call the bug reports trolling, while having the audacity to slander a highly established site that has never lost anyones ever money. Even after what should be a humbling lesson, they continues to spread lies.  The affected users is presumedly lot more than just fauceters, and the 5 BTC story is pure fantasy to make them seem like the victors LOL.

To start the attack I used the leaking of private information that had already been brought to DaDice's attention. With this it became simple to compile a large list of all players email addresses, some of who I'd select to target. This was made easy, as all need to do is make a get request to select them.

The next part was the easy part. DaDice uses no csfr protection, and uses GET requests for all sensitive information. So all I had to do was create a website that issued withdrawals, and made divestments. This is as sample as using an image, or in my case just an iframe. I didn't have much time, so I just had the script loop through and do divestments and then make a withdrawal to one of a couple addresses.

After that, all I had to do was send the email to the players I targetted and dropped the link on irc to help me spread it.

Although the script made thousands of requests, most didn't go through due to the hot wallet instantly becoming empty. Most didn't go through because of hot wallet size, but I did manage a enough pocket change to make the hour worth while:

Code:
0db176c63e5f0d8e7f8b61465a8385355ea75cd756341bc925becca1d999bc3c
774e885edfb91b4f0a790f4d0acf26e906178fc4116810ac21f6fbe7f0968cc5
5b7a06ddee5a710ea0d8009583123655b1a29cd119683b9a21013dfcfb22d76c
9650d6c55a548475a2ec0fe30789cb68eba3e0ec2c66e3e31d650c1a5551a3ee
bcc4d6229d5dfb8dcc702fe1562105b7910cabce615373bc0c50137ccbaa22ab
2e4ab9d5087e6312ee561f0a4c001fb50ed2eed20999fcfde97d90fd064cc1df
a65abb1b969c31a43455ecd83765fc4af45dbc689f5805e5530dc89efa888c47
b65dcaf225e792a2accac1f4433fd4a8ccc03257c17d1a93be3fb56a8620b25e
d3071bf52cbf7c77de44fd878dd202e02ac0d36463e2f820f8f76ae4a0dc969b
2df2fca0797f5ae607f492f75732bd56f43a0dee4793de74566579abe10d1aae
5550fb012b9f89d5e8193542ec38b7d9703daa701340b6e6f2c2ac4c92ef5797
f1880e2e69ccf38eaebba0dc9ddcfefcdf183f591689fe75d8dfeef4aa599d34
4f2ac987727b9633082655938cf1352285492bf5f4f613e3dcc7ee0204fd68a9
a1b291a6c8035b651eb1a22664ebebda53a54705af11c0ad20dd931c6e9e9430
4074e6d2f3b6149ba3c0d3746a3c7fe6e4d6ded968bf2a91fccd582329c196e0
17a99f4a32430a4dc200cfbe9dafba7b1bb014d5be48788c8040f6ecbacddeea
3c44d154afbfc1394ee60714163c79aa1e10b9130ad46dbf419ceb4a49d74add
eba752feceac0a6bdb15838a6bea0f8a46456b51537b62a4f8b4d5d57edc7f6d
766d2c48b5144a3254e24c8e3d3870f9a608e5e1b6d24d5913c7fa42eac4c1e8
b87ab3595d0b33b4b8ac7066e6fdf02df9916ee3793757590d8769a41d9a5a35
0a4d8a369a939f8cbd187293d38a0a3e0fadbafc4179299210a8ddcf7f57b449
ace00c363e1cccbae8031e082f6413aca019ec0698447d2e7f2332442701d047
5f65fb8326af0f300619a4ba12d9b9c0ee4f6bac513ce9e6a1b58ddc11547ef1
0cf7f4947f67298944675d3501d3fb66af31407889b98b0a087fe5707dab9841
8d22474a26d41ed28d370e340ea2133e8ddc378257a00aa3a10509f004315309
0d237f5f9544c869a7f57d243fcf9f8564388e50db2dc40498a31c8cddcbb6c3
62452757234b7ce84da1f89e44e0922b2a6c9038b73b9ec11cebedca8f05ef00

If your withdrawal history contains one of those, please contact support and I'm sure they'll give you a refund. If not, let me know here and I will.


The moral of the story, you should spend time fixing your site instead of criticizing others.

Wow, so this must be one of those "should have been more humble" scenarios.  Well you found a bug or 3 guess you get bounty?
newbie
Activity: 48
Merit: 0
DaDice uses no csfr protection,
...
For anyone wondering what really happened, look no further than two pages back. Instead of fixing issues, DaDice thought it'd be fun to post offensive images and call the bug reports trolling, while having the audacity to slander a highly established site that has never lost anyones ever money. Even after what should be a humbling lesson, they continues to spread lies.  The affected users is presumedly lot more than just fauceters, and the 5 BTC story is pure fantasy to make them seem like the victors LOL.

The moral of the story, you should spend time fixing your site instead of criticizing others.

90% of the transactions from above are from your own accounts (both of them), that you had while you were busy in your agenda. You had deposited 0.1 x 2 so it doesn't matter you took most of your own money out. Oh yes, I lost some from my personal account (since I volunteered) too but it was all for a good cause Tongue hush you goof! Anyway I am glad we successfully traped your 5 BTC deposit, lose and cry scheme... I hope admin will confiscate it since we traced it with the same Mac.

between its called csrf not csfr Wink

newbie
Activity: 48
Merit: 0
The fact that this works makes the DaDice operators in this thread look super cringeworthy since it's been revealed before on multiple occasions.

Instead of posting condescending images, consider fixing your site guys. Roll Eyes

This has been corrected as well, no I am not going to post any offensive memes for you nor I have taken any offence there mate! You are partially correct but as I have apologised to Nico for a similar complain and I have promised everyone that I will be around to deal with such bug requests directly myself and with my team.

We have a bug bounty hunter program so if a bug is reported there we will go ahead and correct it and reward the reporter. We have never said that we are 100% fool proof and neither anybody else is! The PocketRocketCasino guy who I think thinks he got his site developed right from "God's IT minions" have had even severe technical issues and some references suggest they still have but we are not there at their thread bragging about it Smiley Go there https://bitcointalksearch.org/topic/gamble-at-prc-at-your-own-risk-779932 and start following the trial of never ending glitches, bugs and issues with PocketRocketCasino... And then there is PrimeDice, who is not aware of robinhood and hufflepuff issues? Infact they also have a bug bounty program.

We officially consider PD and some other dice sites as seniors (which is the fact) and we have looked up to them when planning / developing / marketing Da Dice. And yes we are competiting with everyone on top too but in a good way. Healthy competiton is good, bad marketing tactis is the worst! and not good for anyone.

So we appreciate any bugs reported! There will be no delay in handling them rest assured Smiley

Ending note: Up till now all known bugs reports, technical/security issues and etc have already been fixed!

newbie
Activity: 48
Merit: 0
Da Dice IT team has discovered and eliminated an important security related bug.

As we are all aware that Da Dice is soon going to release its API, in fact the current structure of our website (i.e. AJAX calls and etc) are all JSON based which in fact could be use as an API it self. We have had a few testers runnings, and for this period we had to remove a couple of checks (i.e. http referer and auth. key) and therefore only protection in place during this while was sessions only. As you are all aware that at any site when you are logged in, and then open a link from inside in a new tab, default behaviour is that you will not be asked to login again and requested page will be shown or action will be performed. i.e. A kind of cross-site attack.

The link to a *.wix.com site above is INFECTED. If opened in the same browser (as tab) where you're logged in to Da Dice, it is going to send withdrawals command from to a BTC address of attacker. However no fix was required for this, since we only had to set a couple of variable to "true" to cripple the "goof's" entire operation.

Since we are running in a secure and monitored environment, there were NO VICTIMS except for my self (for which I volunteered Cheesy) and a couple of our faucet-only players. Oh yes! and the pretty goof himself with his multiple accounts Smiley The attempts started from withdrawing of 5 BTC and kept going down as a process of iteration.

P.S. We don't only monitor your IP address, we also label the PC (oh I mean Mac Wink) you are using and all the accounts associated with it. This was fun but we have caught you red handed there and since the attacker had deposited 5 BTC and then pretend to be a vicitim himself. I can confirm he has a bit old bitcointalk account that he was going to use for this purpose. I think I am going to convience our admin to hold on to that Wink don't bother posting or claiming it here.

newbie
Activity: 41
Merit: 0
The fact that this works makes the DaDice operators in this thread look super cringeworthy since it's been revealed before on multiple occasions.

e.g. just two pages ago: https://bitcointalk.org/index.php?topic=973765.1380

Instead of posting condescending images, consider fixing your site guys. Roll Eyes
legendary
Activity: 3556
Merit: 9709
#1 VIP Crypto Casino
I've documented my experience with this PROVABLY UNFAIR site: http://mothocacho.wix.com/dadice

Go away!
This is clearly a troll post made by somebody with an agenda but I wouldn't like to make any allegations without serious proof.
DaDice are the best bitcoin integrated dice game around imo, stop trolling & wasting everybody's time with futile efforts to try & damage an already blossoming gambling site.
Keep up the good work DaDice admin & team, you deserve far better than pathetic attention like this.
Jump to: