Pages:
Author

Topic: [NEW] the-dice.com - Bitcoin dice game - SSL, instanly transactions - 1% House. (Read 2486 times)

full member
Activity: 229
Merit: 100
However, given the admin's handling of the bug bounty and other bug reports, I wouldn't put too much trust in him or his site now if it even comes back.

I sure hope he does -- with about an hours effort, I've found two more exploitable bugs. One of which is particularly nasty and hard to detect from the servers point of view. paradoxal420's might have found a third, but I'm really not sure how to abuse it (since it's not like you know the outcome before making the server reuse the same seed)

Because if I remember correctly this script uses a horrible checking method and the multiple rolls only get subtracted from your balance once because of the way the requests are processed. But it can get added multiple times. I didn't test it thoroughly, just for like 30 seconds lol. Just going on what I remember from an old version of this script. It might not be the case. Either way I would never deposit on this joke of a site.
member
Activity: 117
Merit: 100
You know, if he wants to give away 100 btc, I think we should let him. Smiley

For what it's worth - while the site appears to be broken now - the site was working better than most which use coindice, and withdrawals worked when the site had enough to pay them. People were a little bit harsh before he actually deserved it. However, given the admin's handling of the bug bounty and other bug reports, I wouldn't put too much trust in him or his site now if it even comes back. Also, any site which offers a bonus on deposits with no terms attached generally can't be trusted - if it could, it would go bust pretty quickly.
full member
Activity: 229
Merit: 100
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.

And you don't want to be rich??? deposit and made it, you will can turn 0.001 btc on 100 btc in some hours.

I really get impressive with some people that don't have qualification to run a project, and try in all ways to destroy other pojects. But no problem, the sensate players are playing.

Good Luck.
Your stupidity actually makes me cringe.
full member
Activity: 229
Merit: 100
1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

Appears to not respond to heartbeat requests.

Quote
2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).

I'd be interested in knowing how you would do so. There's another larger site that you can trigger a very similar issue, but the problem is despite the obvious bug you don't see the result until after it's changed. So the only way I could see to exploit it would be do a double bet, and if you win -- take your winnings, and if you lose complain to support, claim it was a server error not changing the server hash and you want your money back.

Any better ideas?

Doing this but with high multipliers lol.
newbie
Activity: 21
Merit: 0
This bug dont is valid, it not about php stack, you just read our error_log that we forgot to put a forbidden on it.

Nice try.

You're a nonsensical moron.  Honestly, if you were slightly less stupid, I'd spend a bit more time going over the code to your site I attained -- but it's really not worth it. There's not a single sane person who would play on your site after this. And I'd rather leave your piece of shit site to someone less ethical than myself who will part your from your bitcents.



I particularly'm already tired of words, I want to see action. You dont have nothing to show.
I open this thread for support, and such posts i dont will reply anymore.
newbie
Activity: 21
Merit: 0
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.

And you don't want to be rich??? deposit and made it, you will can turn 0.001 btc on 100 btc in some hours.

I really get impressive with some people that don't have qualification to run a project, and try in all ways to destroy other pojects. But no problem, the sensate players are playing.

Good Luck.
newbie
Activity: 21
Merit: 0
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!

This bug dont is valid, it not about php stack, you just read our error_log that we forgot to put a forbidden on it.

Nice try.
member
Activity: 117
Merit: 100
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.
sr. member
Activity: 574
Merit: 253
This thread made me laugh.
newbie
Activity: 21
Merit: 0
Site is offline

Thats is a ddos attack, we already start to mitigate it.

thanks
newbie
Activity: 21
Merit: 0
lol @ admin ignoring people that actually have legitimate questions.

1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).


https://i.imgur.com/bl4y5Tl.png


Lol heartbeat? we dont use any info as pass, email.

2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.
legendary
Activity: 1330
Merit: 1000
You guys ruined the bug bounty. Sad. As soon as it would have been escrowed it would have been mine.
sr. member
Activity: 364
Merit: 250
probably took it down after admin credentials were posted
sr. member
Activity: 294
Merit: 250
***THIS ACCOUNT IS NO LONGER ACTIVE***
copper member
Activity: 1386
Merit: 1000
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!
How much money he have on bankroll?
sr. member
Activity: 364
Merit: 250
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!

I dont think op has the funds to even pay out this bounty
sr. member
Activity: 350
Merit: 250
Guys dont play this dice Smiley Better try other site's.

what' your suggestion?
and tell we us why?
we are waiting your response Smiley
full member
Activity: 229
Merit: 100
lol @ admin ignoring people that actually have legitimate questions.

1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).


newbie
Activity: 21
Merit: 0
Can you check the withdrawal system? It just hangs! Thanks for the 45% cashback =)

Hi, try again pls, sometimes our server can lost the comunication with bitcoind daemon.

thanks
full member
Activity: 229
Merit: 100
Guys dont play this dice Smiley Better try other site's.

Oh by example your site?
that you used the script from git? that have too much exploit?

Man i think you is a children with 7 years. Get a life.
Bro YOUR script is from Github. It's actually one of the worst dice scripts in existence.
Pages:
Jump to: