Pages:
Author

Topic: Looking for testers with positive trust (Read 1971 times)

sr. member
Activity: 336
Merit: 250
February 22, 2016, 08:00:36 PM
#27
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Thank you. Smiley

Hi there, i was linked here by Lutpin and asked if i could help. Your details are a bit vague. What kind of testing would you like? Will you provide the source or you just like us to check the demo site and find bugs?

Anyway, i did checked your dice demo site, and immediately found this bug. As you can see on the screenshots, i was able to 'dupe'/'repeat' my rolls using the same seed/nonce, and thus,it gives me the same result.

1st try


2nd try


3rd try


Uhm, this looks oddly similar to dicebitco.in
legendary
Activity: 1135
Merit: 1002
Developer
February 18, 2016, 05:41:51 PM
#26
Bug fixed. Thanks for letting us know. Smiley

Have you patched up the demo site too? coz i just checked, and its not yet fixed..



Can you provide me more information how you've accomplished that?

-- EDIT --

We had forgotten to update the demo site with a new security update. Could you please test again now?
sr. member
Activity: 428
Merit: 250
February 18, 2016, 01:36:05 PM
#25
Bug fixed. Thanks for letting us know. Smiley

Have you patched up the demo site too? coz i just checked, and its not yet fixed..



Yup its not fixed
sr. member
Activity: 353
Merit: 254
unibtc - Bitsler.com Developer
February 18, 2016, 08:22:02 AM
#24
Bug fixed. Thanks for letting us know. Smiley

Have you patched up the demo site too? coz i just checked, and its not yet fixed..

legendary
Activity: 1135
Merit: 1002
Developer
February 17, 2016, 12:04:26 PM
#23
Bug fixed. Thanks for letting us know. Smiley
sr. member
Activity: 294
Merit: 250
February 17, 2016, 01:49:45 AM
#22
@MillionsBTCdev how did you do this? I could not find a provably fair button on their site, or even a button that allows you to change your client seed.
sr. member
Activity: 428
Merit: 250
February 17, 2016, 01:48:25 AM
#21
If it has been known, why OP has not fixed it yet? or He doesnt know that this exist? Anyway, I do apologized if this was already known or given, its my first time to visit the demo site and just did some simple tests without the knowledge of this being known already. =)

I don't think he knows how to fix it? Its been around for like a year. Not much people know about the exploit unless you're from alphabay.

It was kept on the down low but yeah some scripts have fixings that needs to be done but its entirely up to him if he wants to acknowledge it.
sr. member
Activity: 353
Merit: 254
unibtc - Bitsler.com Developer
February 17, 2016, 01:38:12 AM
#20
If it has been known, why OP has not fixed it yet? or He doesnt know that this exist? Anyway, I do apologized if this was already known or given, its my first time to visit the demo site and just did some simple tests without the knowledge of this being known already. =)
sr. member
Activity: 428
Merit: 250
February 16, 2016, 09:01:27 PM
#19
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Thank you. Smiley

Hi there, i was linked here by Lutpin and asked if i could help. Your details are a bit vague. What kind of testing would you like? Will you provide the source or you just like us to check the demo site and find bugs?

Anyway, i did checked your dice demo site, and immediately found this bug. As you can see on the screenshots, i was able to 'dupe'/'repeat' my rolls using the same seed/nonce, and thus,it gives me the same result.

1st try


2nd try


3rd try


This has been known for about a year under a certain community but was kept secret lol
sr. member
Activity: 428
Merit: 250
February 16, 2016, 08:58:10 PM
#18
Wow, you look how buggy your stuff and this is proves that people were buying overpriced buggy scripts from you.

1BTC for this kind of work. Well done

Coins dice has been known to have many exploits but was kept a secret from people so when they host their scripts they would go in and blindly rob people. I know a certain dev who can make something like coin dice for twice as cheap and more secure but he is working on a chess project

All in all the point of this thread is because he wants people to test for exploits right?

I know a few people who have no trust or are in the red feedback that has way more programming skills than majority of positive feedback but always remember just because you have green rep or red it doesn't matter which side your on because even then that doesn't prove their skills it's just a e-penis if you ask me.

Hell there are people here who buys accounts just to plus or negative feedback here and nothing people can do to stop it
hero member
Activity: 574
Merit: 500
February 16, 2016, 07:17:20 PM
#17
Wow, you look how buggy your stuff and this is proves that people were buying overpriced buggy scripts from you.

1BTC for this kind of work. Well done
legendary
Activity: 1135
Merit: 1002
Developer
February 16, 2016, 02:13:56 PM
#16
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Thank you. Smiley

Hi there, i was linked here by Lutpin and asked if i could help. Your details are a bit vague. What kind of testing would you like? Will you provide the source or you just like us to check the demo site and find bugs?

Anyway, i did checked your dice demo site, and immediately found this bug. As you can see on the screenshots, i was able to 'dupe'/'repeat' my rolls using the same seed/nonce, and thus,it gives me the same result.

1st try


2nd try


3rd try


Hello,

could you provide more info on how is it possible to use the same seed? Did you just made the bets so quick that the server didn't change nonce?
sr. member
Activity: 353
Merit: 254
unibtc - Bitsler.com Developer
February 16, 2016, 12:46:18 PM
#15
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Thank you. Smiley

Hi there, i was linked here by Lutpin and asked if i could help. Your details are a bit vague. What kind of testing would you like? Will you provide the source or you just like us to check the demo site and find bugs?

Anyway, i did checked your dice demo site, and immediately found this bug. As you can see on the screenshots, i was able to 'dupe'/'repeat' my rolls using the same seed/nonce, and thus,it gives me the same result.

1st try


2nd try


3rd try
legendary
Activity: 1135
Merit: 1002
Developer
February 15, 2016, 11:58:39 AM
#14
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Thank you. Smiley
copper member
Activity: 1876
Merit: 1874
Goodbye, Z.
February 15, 2016, 11:57:41 AM
#13
Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
I don't know about his preferences, but this might be something for MillionsBTCdev (that's the only one that came to my head in the short time).
I've sent him a message regarding this topic, maybe he can help you out.

Edit:
He also got a thread about his programming here.

Services Offered:
✧ Web programming ( php, html5, js, nodejs, etc )
✧ Security check ( I will give you a report regarding your site's security: sqli attack, xss attack, clickjacking, etc.)
legendary
Activity: 1358
Merit: 1003
Designer - Developer
February 15, 2016, 11:56:14 AM
#12
What scripts are these John?

I had run a number of your scripts in the past and set them up for clients but found security less than perfect.
Many injection attacks were apparently doable in both the blackjack and the dice script I saw.

I'd be interested to see if the holes I found were fixed or not.

CoinWheel, CoinDice, CoinJack and CoinSlots.

You can check demos at:
wheel.coindemo.tk
dice.coindemo.tk
jack.coindemo.tk
slots.coindemo.tk

Let me know about your findings. Smiley

Thanks for the links sir. I'll have a whack at breaking the scripts later. Will report back here.
legendary
Activity: 1135
Merit: 1002
Developer
February 15, 2016, 11:55:10 AM
#11
What scripts are these John?

I had run a number of your scripts in the past and set them up for clients but found security less than perfect.
Many injection attacks were apparently doable in both the blackjack and the dice script I saw.

I'd be interested to see if the holes I found were fixed or not.

CoinWheel, CoinDice, CoinJack and CoinSlots.

You can check demos at:
wheel.coindemo.tk
dice.coindemo.tk
jack.coindemo.tk
slots.coindemo.tk

Let me know about your findings. Smiley
legendary
Activity: 1358
Merit: 1003
Designer - Developer
February 15, 2016, 11:52:40 AM
#10
What scripts are these John?

I had run a number of your scripts in the past and set them up for clients but found security less than perfect.
Many injection attacks were apparently doable in both the blackjack and the dice script I saw.

I'd be interested to see if the holes I found were fixed or not.
legendary
Activity: 1135
Merit: 1002
Developer
February 15, 2016, 11:49:06 AM
#9
We have casino scripts and we would like to make clear that our script our safe. I think positive trust is kind of moving this forum.
So you're looking for someone to check and verify your code, right?
Having positive trust doesn't mean someone has the necessary coding skills to perform that task.
You should probably look for a (trusted) developer instead of some "tester with positive trust".

I agree with Lutpin, what language are the scripts written in? You might get someone to respond if they know what they will be looking at.

Thanks for the tips guys. Smiley Scripts use php, js, css, mysql and html.
copper member
Activity: 1498
Merit: 1499
No I dont escrow anymore.
February 15, 2016, 06:55:52 AM
#8
We have casino scripts and we would like to make clear that our script our safe. I think positive trust is kind of moving this forum.
So you're looking for someone to check and verify your code, right?
Having positive trust doesn't mean someone has the necessary coding skills to perform that task.
You should probably look for a (trusted) developer instead of some "tester with positive trust".

I agree with Lutpin, what language are the scripts written in? You might get someone to respond if they know what they will be looking at.
Pages:
Jump to: