Author

Topic: DaDice.com - Next Gen Social Gambling Dice Experience | Progressive Jackpot - page 119. (Read 257856 times)

sr. member
Activity: 252
Merit: 250
DaDice Administration
So Dadice was Hacked yesterday. Albeit a chat hack, but it turns out (according to what the dev guy said in chat) the hack was not just a unicode or otherwise, it was a direct change to server side variables that store usernames. This means it is like no other chat hack on other dice sites. On other sites it is basically a client side rendering issue - the server was not infiltrated. On DaDice the username was actually changed on the server via a very simple web socket parameter change.

...

Thanks for your insights!

Problems happen, technology is evolving every minute... This was not a hack just a minor exploit, other sites had their fair share of hacks, DaDice also suffered what we can call a real hacking attempt hours after its launch, but at least we correct the issues in a timely manner and get to the root cause of it. So the chat exploit has been sorted.

The other issues you've mentioned will be addressed by our developer later today. Fortunately they are more or less based on ignorance and we will document this here!
full member
Activity: 154
Merit: 100
No longer does the statement "It's just a simple chat hack" make a difference. They have yet to fix it! If it was so simple, why did it take so long!

Well, I reported a security related vulnerability 4-5 days ago, they replied 15h later, but it is still not fixed. This issue should take literally 30 seconds to fix. Obviously I won't abuse nor share the issue before it's fixed. But it is really silly and I cannot really imagine having this on a btc related site. Although nor the site nor the players can directly lose coins with it, still I wouldn't recommend playing here at least until this issue is fixed. Also I would personally hope a dice site would take things like this issue more serious.

Hi NLNico. Thank you again for the heads up on that. The issue has indeed been corrected by our Dev
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
No longer does the statement "It's just a simple chat hack" make a difference. They have yet to fix it! If it was so simple, why did it take so long!

Well, I reported a security related vulnerability 4-5 days ago, they replied 15h later, but it is still not fixed. This issue should take literally 30 seconds to fix. Obviously I won't abuse nor share the issue before it's fixed. But it is really silly and I cannot really imagine having this on a btc related site. Although nor the site nor the players can directly lose coins with it, still I wouldn't recommend playing here at least until this issue is fixed. Also I would personally hope a dice site would take things like this issue more serious.
legendary
Activity: 3500
Merit: 1354
The stats are going pretty slow,as well as the commision only 370k satoshi won from affiliates
really wierd

I think you would not say like that if you know how the affiliate program works.
The stats is not going slow, because it is calculated and paid once per day.
It is not weird if someone only got 370k satoshi even less because the commission is based on his level and his referral losses.
You can get more details about the affiliate system by clicking the affiliate tab in the bottom of the page http://prntscr.com/747qmv



member
Activity: 106
Merit: 10
So Dadice was Hacked yesterday. Albeit a chat hack, but it turns out (according to what the dev guy said in chat) the hack was not just a unicode or otherwise, it was a direct change to server side variables that store usernames. This means it is like no other chat hack on other dice sites. On other sites it is basically a client side rendering issue - the server was not infiltrated. On DaDice the username was actually changed on the server via a very simple web socket parameter change.

Why is this significant. The moderators will tell you it was just a hack to the chat system and was not in anyway an issue to the security of the site. To me it is more than that. It is the site's controls over web sessions that are now in question. Why is it possible to change any details of a web session on the server?  The server and only the server should be monitoring this and ensuring the username used to log in and the session cannot be changed. In this case, it demonstrates that this site could have some more serious vulnerabilities.

No longer does the statement "It's just a simple chat hack" make a difference. They have yet to fix it! If it was so simple, why did it take so long!
DenseCrab also complained he lost access to his account and logged in as CenseDrab due to this access issue. And he was also the first to be targeted in chat.



How was it done.. Well after inspecting the code, one thing is very obvious.

The site made it easy with the client telling the server who it was, and the server didn't have any checks of who it actually was.
A variable object that defined the user looked like this:

socket_handshake_gameplay_token = {
    "token": "1111|1984798bc3ed82374f|11.11.11.11",
    "user": {
        "id": "1111",
        "username": "username",
        "cm": "false"
    }
}

Change the username in the variable above and then log back in:

socket.emit("online", socket_handshake_gameplay_token)

You now have someone else's username. No server side checks or anything!

Because this actually changed server side variables, it is considered a serious issue. I have read through more of the code and found a few more instances of poor coding like this.

As for the lag on the site. It has so many DOM updates it is ridiculous. What this means is the browser is constantly updating elements on the page - even some that do not need to be updated. This in turn causes your browser to use a lot of CPU and memory because it is quite slow at updating the DOM. The other issue is, the socket.io is prefering to use ajax over websockets. Ajax long polling causes the browser to do a lot of work and is not really the way forward when running a site like a gambling site. DaDice should force websocket and only websocket. If you have a 2 year old browser then stiff, upgrade or don't use the site.

My recommendation is to steer clear of this one. It is clearly coded by opportunists and not bitcoin / web coder types. It is therefore probably suffering from many security risks.

If you do continue, It should be a good ride as hackers eventually work out a method to steal coins. Or maybe they already are and the owners are unaware... how many times have we seen this happen to new unsuspecting victims. Stick with the trusted and tested sites that have lasted over 2 years. You have lower risk at these sites.

If you want to try it. After loading the website, press F12. In the console paste the code below and press enter. You will get an input box in the top menu and you can change your name to any other user and chat using their name.

$('.header-inner').append('');
var changeName = function(){
   if ($('#newName').val()){
      socket_handshake_gameplay_token.user.username=$('#newName').val();
      socket.emit("online", socket_handshake_gameplay_token);
   }
}



I took a snap shot of the entire chat from when it started as it is quite amusing but hard to follow as the attacker uses everyone's name.

DenseCrab:
i saw azreal without mod before it

Psychedelic:
told you what to do to solve this

DenseCrab:
a few minutes ago

Psychedelic:
first enable 2fa and then change your pass

DenseCrab:
ok, but i have to stroke my dick first
 TIP:
DreamStage sent a tip of 0.00050000 BTC to DDBank

DenseCrab:
after licking a 10inch cock I always have to stroke mine.

Psychedellic:
Me too

Psychedelic:
fake Dense do us a favor and go fuck yourself.

Psychedelic:
lol

Psychedelic:
so someone found a way to change the chat name..

Psychedelic:
Dense you were not hacked..

Staff dadice_dev:
nobody is hacked. this is a small trick

Psychedellic:
you hear me.. go fuck yourself!

Psychedelic:
Psychedellic with 2 ll not me

Psychedellic:
Whats the trick?

Psychedelic:
changing your name obviously in chat

Psychedellic:
is your code shit?

Psychedelic:
not mine

saurav:
or he used dense.crab at the username

dadice_dev:
its crap code all right!

saurav:
something like that gmail trick

saurav:
whats happenening here man

DenseCrab:
no.. its all about butt magic

Psychedelic:
lol..

Psychedelic:
it's simple..

Psychedelic:
someone found a way to change his name in the chat

saurav:
Well we gathered that. but IT guy doesn't know how or he would have stopped it by now..

Staff dadice_dev:
No he has basically connected to sockets directly and emitting simple "chat" status, thinking he is very big smart ass

Laimu:
Hello

Laimu:
i read about the hacks

Staff dadice_dev:
nothing has been hacked so nothing to worry about regarding this clown

Staff dadice_dev:
It will be taken care of shortly

Laimu:
how much coin they take

dadice_dev:
Its a bit too easy

Psychedelic:
it's easy to stop..

dadice_dev:
can we do other things over this socket?

Staff dadice_dev:
oh boy he wishes

Mod Azrael:
Thank you Sid.

Staff dadice_dev:
yes... it will be stopped soon

dadice_dev:
oh look........ bitcoin!!!

Staff dadice_dev:
let me have my coffee first

Laimu:
ok better put out a statement on reddit and/or forum

Laimu:
get this situation contained nicely

Staff dadice_dev:
I am not really that worried about this troll / clown

Psychedelic:
haha enjoy dev

Laimu:
coo.. I hope you get your coin back

Laimu:
good idea

Laimu:
I hate it when people steal my coin.

Laimu:
is there a safe place to dice these days?

Mod Azrael:
No coin has been taken Laimu.

Laimu:
pocketrocketscas is proven

Laimu:
Not yet.. but this site is pretty poorly coded.

Mod cavetroll:
Laimu what are you on about?

Laimu:
Hurry up and fix it!!!

Staff dadice_dev:
There is nothing to hurry up about

Staff dadice_dev:
there is just a troll in chat.

Stichedupsmile:
Must be a pretty good poorly coded site if so many people go on it.

Stichedupsmile:
Logic is 10/10

Staff dadice_dev:
your acccounts are all secure

Stichedupsmile:
Ahh ok

dadice_dev:
don't panic its all undercontrol

dadice_dev:
We can't stop server side actions from happening and don't look at session controls.. but don't panic.

Stichedupsmile:
This kids obviously got nothing better to do ^

CenseDrab:
i got hacked

CenseDrab:
dev

CenseDrab:
im the real densecrab btw

dadice_dev:
Bord shitless

CenseDrab:
i cant login on it anymore

Psychedelic:
lol no you are not

DenseCrab:
Sorry DenseCrab.. try again

CenseDrab:
ah dev also hacked

DenseCrab:
Entire site hacked!

DenseCrab:
Run for the hills

Mod cavetroll:
Shut up you little pissant

CenseDrab:
child

Mod cavetroll:
Site has not been hacked this is just a pissy little child at work

DenseCrab:
indeed

Bazza:
I'm more of a bored executive.

Mod cavetroll:
Oh so you're confessing?

Bazza:
Someone has to steal all the bitcoin left in the open.. right?

Mod cavetroll:
If that's how you sort your borredom how sad is your life?

Bazza:
yeah

Bazza:
pretty sad... but funny how poorly coded this is

Mod cavetroll:
yeah what

CenseDrab:
Maybe you should just suicide sir "DenseCrab"

Zemzz:
Hello guys

cavetroll:
Yeah DenseCrab.. suicide

Zemzz:
Hi

Mod cavetroll:
Bazza that says far more about you than even you realise. pathetic sad and ppointless

Zemzz:
I want to play with cavetroll's balls

Mod cavetroll:
Hey Zemzz

Lewie:
Don't we all

Zemzz:
lol

Zemzz:
lighten up fellas

Zemzz:
I'm sure we have a laugh

Mod cavetroll:
surprises me that people with this mentality still exists

Psychedelic:
welcome to the internet

Psychedelic:
you have seen nothing

Zemzz:
Why, you need people to keep you honest
sr. member
Activity: 252
Merit: 250
DaDice Administration
LATEST STATS!

And here we go, tonight's top 3 on the leaderboard in line for some awesome prizes!

Rank      Username   Commission
1       bank            0.00377858
2       LNMH            0.00324142
3      williamho            0.00186441



The top 3 from the previous week have been toppled for this whole new set of front runners! However the rest of May remains and as we've seen, anything can and does happen

Hop on over here for more details : https://bitcointalksearch.org/topic/dadice-referral-competition-1046626
The stats are going pretty slow,as well as the commision only 370k satoshi won from affiliates
really wierd

Don't understand your comment at all Huh Do you understand how our referral system is working?
legendary
Activity: 3794
Merit: 1030
The Best Tipster on the Forum!!
LATEST STATS!

And here we go, tonight's top 3 on the leaderboard in line for some awesome prizes!

Rank      Username   Commission
1       bank            0.00377858
2       LNMH            0.00324142
3      williamho            0.00186441



The top 3 from the previous week have been toppled for this whole new set of front runners! However the rest of May remains and as we've seen, anything can and does happen

Hop on over here for more details : https://bitcointalksearch.org/topic/dadice-referral-competition-1046626
The stats are going pretty slow,as well as the commision only 370k satoshi won from affiliates
really wierd
full member
Activity: 154
Merit: 100
LATEST STATS!

And here we go, tonight's top 3 on the leaderboard in line for some awesome prizes!

Rank      Username   Commission
1       bank            0.00377858
2       LNMH            0.00324142
3      williamho            0.00186441



The top 3 from the previous week have been toppled for this whole new set of front runners! However the rest of May remains and as we've seen, anything can and does happen

Hop on over here for more details : https://bitcointalksearch.org/topic/dadice-referral-competition-1046626
sr. member
Activity: 252
Merit: 250
DaDice Administration
Why dadice is so laggy again?  Undecided Yesterday my roll was very fast, 1 sec per roll, but it has been 5-10 sec per roll since 20 hours ago, and I saw other guys complaint it in the chatting room, I think it's not my internet issue, must be cloudflare sucks again?? Angry
Same here.. It is really slow today. Also be aware that users have found a way to change their name (that appears on chat) so be careful and verify that you are talking with the individual that you intend to chat.

Yep we were under maintenance, thus such glitches. We changed a few things and rolls are now faster than ever!
hero member
Activity: 546
Merit: 500
Why dadice is so laggy again?  Undecided Yesterday my roll was very fast, 1 sec per roll, but it has been 5-10 sec per roll since 20 hours ago, and I saw other guys complaint it in the chatting room, I think it's not my internet issue, must be cloudflare sucks again?? Angry
Same here.. It is really slow today. Also be aware that users have found a way to change their name (that appears on chat) so be careful and verify that you are talking with the individual that you intend to chat.
hero member
Activity: 840
Merit: 1000
Why dadice is so laggy again?  Undecided Yesterday my roll was very fast, 1 sec per roll, but it has been 5-10 sec per roll since 20 hours ago, and I saw other guys complaint it in the chatting room, I think it's not my internet issue, must be cloudflare sucks again?? Angry
sr. member
Activity: 252
Merit: 250
DaDice Administration
DaDice when will you update your servers?The site is still really slow,even the lite mode makes things a little better
but not enough.Please make it better


The roll is not slow, it is because of your connection. The lite version is enough if you got a good connection. I got 1 roll for each 1 second so that is enough for now. Dadice have other things to do for now, they cant keep on upgrading the server

Really? I had no idea. I assumed some dice sites put a delay or limit the rolling speed. Didn't know it was the connection. Where is this site hosted? Somewhere in Asia?

Nope, in Europe.

I wonder why gambling sites never hosted their site in US ?
Is it because US have regulation about bitcoin & gambling ?

For us it is rather a matter of principles. After Snowden I would not even host a blog about my model car collection in the US.
sr. member
Activity: 252
Merit: 250
DaDice Administration
DaDice when will you update your servers?The site is still really slow,even the lite mode makes things a little better
but not enough.Please make it better


The roll is not slow, it is because of your connection. The lite version is enough if you got a good connection. I got 1 roll for each 1 second so that is enough for now. Dadice have other things to do for now, they cant keep on upgrading the server

Really? I had no idea. I assumed some dice sites put a delay or limit the rolling speed. Didn't know it was the connection. Where is this site hosted? Somewhere in Asia?

Nope, in Europe.
legendary
Activity: 3808
Merit: 1723
DaDice when will you update your servers?The site is still really slow,even the lite mode makes things a little better
but not enough.Please make it better


The roll is not slow, it is because of your connection. The lite version is enough if you got a good connection. I got 1 roll for each 1 second so that is enough for now. Dadice have other things to do for now, they cant keep on upgrading the server

Really? I had no idea. I assumed some dice sites put a delay or limit the rolling speed. Didn't know it was the connection. Where is this site hosted? Somewhere in Asia?
full member
Activity: 154
Merit: 100
I would like to add my thanks as well to everyone for making the 100 millionth roll a success! And huge congratulations to our winners!
hero member
Activity: 896
Merit: 1000
congratulation to all winners from this awesome competition and great to see everybody got paid on time from this, dadice has the best campaign to make it to the best dice site ever, i am waiting for next competition announcement hope this time will get luck to hit the prize.
legendary
Activity: 1540
Merit: 1016
DaDice when will you update your servers?The site is still really slow,even the lite mode makes things a little better
but not enough.Please make it better


The roll is not slow, it is because of your connection. The lite version is enough if you got a good connection. I got 1 roll for each 1 second so that is enough for now. Dadice have other things to do for now, they cant keep on upgrading the server
legendary
Activity: 1876
Merit: 1005
100,000,000 milestone achieved ,congratulation to Dadice.com for entering in 100 millionth club. Congratulations to the winner that is awesome bounty 0.675BTC.I was trying too but luck was in someone else favor today. Next time will try for next bounty.


that is cool to see a bounty winner of 100 mil rolls so congratz to Elizabeth Wink i would like to hear from that if he/she on forum, i missed that just 10 rolls away but great to see dadice achieved that milestone  Grin cheers for dadice Wink
oh well when i went to sleep dadice had like 98 million rolls and when i woke up it already had passed, a bit sad right now


I am a bit skeptical.
skeptical about what? are you just trying to get your post count up?

Im pretty sure he means that he is skeptical about the fairness of this, he probably thinks that dadice staff does something to roll the 100 million roll themselves if you know what i mean, i dont think thats possible right?
Be serious mate ! This can not even be thought . Dadice is professional site they can not do any act of this type just to save 0.675BTC.This was 100% fair bounty. They are giving more than this money just in different giveaways.
legendary
Activity: 1008
Merit: 1000
Roll #100,000,000 BTC Bounty Winner Announcement :





Once again a huge thank you to all who helped us roll the 100,000,000 rolls we needed to get here!
Without you there would be no winner and no bounty to claim.
We have 1 winner for the roll and 3 winners for the date prediction.
The results were as follows :
 
                                 
Won 0.675 BTC #100,000,00 - @Elizabeth - paid to 1AV5qH9mnGKEVdDRdEy7ZWYCbdJFJNRLcC

Massive congratulations there!

The 0.1 btc winners for the predictions were as follow:

For The BTC talk Prediction:

buddu - 10/05/2015   - 1Cm7rRTdgNoZrgg11diuYJcoMw5tE6gD57

For The FaceBoook Prediction:

Sana Malik   - 10/05/2015 - 112RmTNf3myreQBeR8vX3qadqydKCxSky3

And for Twitter:

boopy - 10/05/2015 - 1KaaCNSKQnsdyzZHei2J7nGiEX1fT5d2EK


Once again huge Congratulations to our winners!

We hope you all had fun as we counted down to the Roll Bounty!
Keep Rollin’
Congratulation to everyone who won prizes.All this was great fun even rolling dice for 100,000,000 bet.One of the best campaign so far and waiting for the announcement for next campaign of 200,000,000 rolls. This will be more amazing and twisting , I think so.

congratz to all winners from this nice competition and once dadice team proves they are the best team in dice gambling so much dedicated and professional person, dadice has bright future and soon going to be the top dice site. Smiley
hero member
Activity: 952
Merit: 516
100,000,000 milestone achieved ,congratulation to Dadice.com for entering in 100 millionth club. Congratulations to the winner that is awesome bounty 0.675BTC.I was trying too but luck was in someone else favor today. Next time will try for next bounty.


that is cool to see a bounty winner of 100 mil rolls so congratz to Elizabeth Wink i would like to hear from that if he/she on forum, i missed that just 10 rolls away but great to see dadice achieved that milestone  Grin cheers for dadice Wink
oh well when i went to sleep dadice had like 98 million rolls and when i woke up it already had passed, a bit sad right now


I am a bit skeptical.
skeptical about what? are you just trying to get your post count up?

Im pretty sure he means that he is skeptical about the fairness of this, he probably thinks that dadice staff does something to roll the 100 million roll themselves if you know what i mean, i dont think thats possible right?
Jump to: