Pages:
Author

Topic: [NEW] FreeDice - Pre-Launch Bonus 0.005 BTC for free [only for 100 first users] (Read 2417 times)

full member
Activity: 154
Merit: 100
are you serious or no, for make a site dice ?
legendary
Activity: 1554
Merit: 1014
I just try to visit a website and it turns hostinger error http://prntscr.com/83m9l7 . it looks like you are not really ready for launching
full member
Activity: 216
Merit: 100
username : btcfinans, let me try this
legendary
Activity: 1456
Merit: 1081
I may write code in exchange for bitcoins.
I checked it out and was eventually able to get it to work using the tab button.  But on firefox the headline "freedice signup" is written on top of the box where you submit a username so it's kinda broken.

Might wanna fix this!

legendary
Activity: 1540
Merit: 1002
Coder is really funny person and OP still calling him Coder Roll Eyes what a joke Grin
legendary
Activity: 2086
Merit: 1058
Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes

Either way it is a waste of everyones time and a can be a danger to some of you guys that just love re-using passwords lol

OP should name and shame the so called "coder"

Well, maybe he is the so called "coder"  Roll Eyes

I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
if you don't change "coder" the website will be available when mining BTC end  Grin

Hahaha made my day!  Grin  Grin  Grin
legendary
Activity: 1120
Merit: 1000
https://cryptoworld.io
I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
if you don't change "coder" the website will be available when mining BTC end  Grin
hero member
Activity: 493
Merit: 500
Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes

Either way it is a waste of everyones time and a can be a danger to some of you guys that just love re-using passwords lol

OP should name and shame the so called "coder"
legendary
Activity: 2086
Merit: 1058
Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes
sr. member
Activity: 322
Merit: 250
Bonus Claim Url: http://betonline.wager.bz
Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.
sr. member
Activity: 320
Merit: 261
Web developper
BEWARE ITS A PHISHING PAGE

There are no password/email checking and confirmation
No database double information checking
No vulernabilities protection

Note: I sended a Pm to OP to fix all his page issues he is online and he didn't reply,you know what does mean that ....
legendary
Activity: 2322
Merit: 1292
Encrypted Money, Baby!
Beware!

Newbie account with a suspicious login form asking for username, pw and email. Then nothing happens after registering. This has all the makings of a phishing page.  "submit query" is the default name of a form submit button without a name and the page code is abysmal.  

If you entered your info, and you re-use passwords across multiple sites, I'd suggest you change them now.

Code:

Password:   

Email:         

                                                      
It certainly is a phishing site.
Try to send the form over and over with the same values; even using "foobar" in user, password and email doesn't a) cause an error saying email has wrong format and b) at the second time using those values, there's no complaint about those values already being used.


.edit:
Just thought about writing a script spamming his database with nonsense values. ^^

.edit 2:
To kind of prove that this is a malicious site: I just checked the SQL injection, and the error (shown above) shows that the database only has username, password and email fields. There is no way around a user table of a serious dice game having more fields than just those three.
sr. member
Activity: 320
Merit: 261
Web developper
I can help fixing all security issues you have in your website,PM me
newbie
Activity: 10
Merit: 0
I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
full member
Activity: 204
Merit: 100
Sucessful. Wait for official launch soon. Thanks!
legendary
Activity: 1526
Merit: 1003
After get fixed this security issue will try this dice site.
newbie
Activity: 10
Merit: 0
Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price
legendary
Activity: 1120
Merit: 1000
https://cryptoworld.io
For who sent registrations details, pay attention.. your credentials are available to all  Cool

Who used as password, the same for the email address, CHANGE immediately the mail password!
hero member
Activity: 518
Merit: 501
Error 404: there seems to be nothing here.
This site seriously sucks  Angry

Firstly the sql error:
Code:
Error: INSERT INTO Login(Username, Password, Email) VALUES ('admin' OR 1=1', 'admin' OR 1=1', ' admin' OR 1=1')
You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '', 'admin' OR 1=1', ' admin' OR 1=1')' at line 2

Secondly.. Just type in in any of the registering field like Username...An popup appears saying "XSS"!
Also vulnerable to XSS! Website security = 0
legendary
Activity: 1260
Merit: 1001
Will see how this dice site works just submitted some info there.
Pages:
Jump to: