Pages:
Author

Topic: MagicalDice - Need beta testing [Bounty for bugs] - page 3. (Read 2971 times)

legendary
Activity: 997
Merit: 1002
Gamdom.com
let me try it with your free BTC..
username : nekochan05


tipped
legendary
Activity: 1274
Merit: 1000
let me try it with your free BTC..
username : nekochan05
hero member
Activity: 706
Merit: 519
Official LuckyBit Support
Hi Stars !!  There are lots of security Vulnerability in your site a Rouge Coder can ******** Your site as they did with Luckybit earlier.

Just Found Two Run Time Errors taht can be fatal from Point of view of your business.
#Bug 0:(noobs Bug)
Bet can be placed even the bet amount is zero  Lips sealed
#Bug 1:

I would like you to take you back to few months back may be much more , i guess all guys reading this may remember that once the blockchain.info "latest Transaction" were filled with transactions of Luckybit Blue or red or green...
They were all because before luckybit coders used Instance variable rather than class variables to make a Bet and stored them in Tables(DB) as a instance variables , Instance variables are easy to inject and can be spoof the database for ,say 1-2 seconds to even 3-4 hours until the database refresh(If another guy make a bet after me in "t" time then the database will refresh in "t" time) , assume if it is night and no one is playing on your site means the database is not refreshing and someone rouge comes to your site and played that trick then he has a lot of time to withdraw as no one is playing n your site and the withdraw(if auto) then you can loose a big amount , i remember that some one withdrew 65 btc from Luckybit with this method and im sure he might be reading this.

Just to clarify: LuckyBit has never been exploited or attacked in this way. It's even impossible as you cannot "withdraw" from LuckyBit - this is also why user funds cannot be endangered on LuckyBit: we simply do not hold any bitcoins of our users (the advantages of onchain gambling). You must be confusing sites.
legendary
Activity: 997
Merit: 1002
Gamdom.com
i would like to try find bugs thanks. Username: Pimpsta

tipping everyone who talks in the chat for more testing=)
member
Activity: 86
Merit: 10
i would like to try find bugs thanks. Username: Pimpsta
hero member
Activity: 756
Merit: 503
Crypto.games
guys... i think i saw a bug with the fancy rolling.. i keep on playing on fancy rolling but it does not appear on "MY BETS" i tried it a lot of ties.. but really not apper. hope you can fixed this also.. goodluck.
and i cant see it also in ALL BETS AND HIGH ROLLERS... I TRY BET 1 BTC. I CHECK all but not appear..but my balance is moving. up and down when betting.

When you re-fresh the page does it show up then?

oh yeah i saw it now. but i refresh it. 3  times to see it...  Embarrassed
legendary
Activity: 1008
Merit: 1000
guys... i think i saw a bug with the fancy rolling.. i keep on playing on fancy rolling but it does not appear on "MY BETS" i tried it a lot of ties.. but really not apper. hope you can fixed this also.. goodluck.
and i cant see it also in ALL BETS AND HIGH ROLLERS... I TRY BET 1 BTC. I CHECK all but not appear..but my balance is moving. up and down when betting.

When you re-fresh the page does it show up then?

That problem first i reported in chat why we have to refresh the page to see bet result into my tabs so it need to get fixed to continue uninterpreted betting on the way, i think when we have to stop and refersh the page to see this that break the rhythm of betting. Wink 
sr. member
Activity: 462
Merit: 250
guys... i think i saw a bug with the fancy rolling.. i keep on playing on fancy rolling but it does not appear on "MY BETS" i tried it a lot of ties.. but really not apper. hope you can fixed this also.. goodluck.
and i cant see it also in ALL BETS AND HIGH ROLLERS... I TRY BET 1 BTC. I CHECK all but not appear..but my balance is moving. up and down when betting.

When you re-fresh the page does it show up then?
hero member
Activity: 756
Merit: 503
Crypto.games
guys... i think i saw a bug with the fancy rolling.. i keep on playing on fancy rolling but it does not appear on "MY BETS" i tried it a lot of ties.. but really not apper. hope you can fixed this also.. goodluck.
and i cant see it also in ALL BETS AND HIGH ROLLERS... I TRY BET 1 BTC. I CHECK all but not appear..but my balance is moving. up and down when betting.
member
Activity: 69
Merit: 10
Username limit should be increased else usernams like this will mess the board

full member
Activity: 158
Merit: 100
Who am i ....? ❤❤❤
register there and such a good moderation and site graphics Nice:P

but need to some update on site like when we get tips no notification come on the bottom of the site page.should need to fix a bar for tip notification when we get tip.this will be looking more comfortable when anyone get a tip  and there are one problem is on chat.there are no limit for message.myself message such a big sentence.so should prevent unlimited message space should prevent from spamming.we should easily write a composition on the chat this will made a more spam on there.hope u understand. ty admin.
 
username on MD: showrov1993
thnx Smiley
regards .
sr. member
Activity: 311
Merit: 250
Graphics Design Guru
legendary
Activity: 1876
Merit: 1005
I came to know about bug bounty after having registered under username '' boopy'' I am trying to test and finf the bug.Everyone best of luck to help the OP by finding bugs and win.
sr. member
Activity: 462
Merit: 250
I appreciate everybody that has found bugs/actively looking for bugs. You will be paid a bounty once our dev has fixed the bug(s). Thanks Smiley
legendary
Activity: 1008
Merit: 1000
I have just created my account there but there no faucet so how to get free coins to test this brand dice site,
Edit : faucet button right down in the balance.

Username : trafficolaa
sr. member
Activity: 476
Merit: 500
Re-Evolution
Just registered there
My username: orryde

Thank you
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.

I guess all that site including all JS to load simultaneously at the background while the user only see a splash-screen as the dev of Primedice have done.
Not sure what you mean. On MagicalDice most popups actually load a new page in an iframe. This iframe contains all the Javascript files that also load all the bets/stats/etc through AJAX. This iframe however, does not need this data. I was wrong about "user/bet info" actually, but still many popups do this: Account setting, Provably fair, My transcactions, My tips, Chat Settings, ...
hero member
Activity: 756
Merit: 503
Crypto.games
hi.. admin, settings in chat like this..

 Show my big wins in chat

 Show my big losses in chat

i disable it but still showing in my chat box. pls check it. thanks.
hero member
Activity: 546
Merit: 500
Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.

I guess all that site including all JS to load simultaneously at the background while the user only see a splash-screen as the dev of Primedice have done.
legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.
Pages:
Jump to: