Author

Topic: [NEW] the-dice.com - Bitcoin dice game - SSL, instanly transactions - 1% House. (Read 2486 times)

full member
Activity: 229
Merit: 100
However, given the admin's handling of the bug bounty and other bug reports, I wouldn't put too much trust in him or his site now if it even comes back.

I sure hope he does -- with about an hours effort, I've found two more exploitable bugs. One of which is particularly nasty and hard to detect from the servers point of view. paradoxal420's might have found a third, but I'm really not sure how to abuse it (since it's not like you know the outcome before making the server reuse the same seed)

Because if I remember correctly this script uses a horrible checking method and the multiple rolls only get subtracted from your balance once because of the way the requests are processed. But it can get added multiple times. I didn't test it thoroughly, just for like 30 seconds lol. Just going on what I remember from an old version of this script. It might not be the case. Either way I would never deposit on this joke of a site.
member
Activity: 117
Merit: 100
You know, if he wants to give away 100 btc, I think we should let him. Smiley

For what it's worth - while the site appears to be broken now - the site was working better than most which use coindice, and withdrawals worked when the site had enough to pay them. People were a little bit harsh before he actually deserved it. However, given the admin's handling of the bug bounty and other bug reports, I wouldn't put too much trust in him or his site now if it even comes back. Also, any site which offers a bonus on deposits with no terms attached generally can't be trusted - if it could, it would go bust pretty quickly.
full member
Activity: 229
Merit: 100
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.

And you don't want to be rich??? deposit and made it, you will can turn 0.001 btc on 100 btc in some hours.

I really get impressive with some people that don't have qualification to run a project, and try in all ways to destroy other pojects. But no problem, the sensate players are playing.

Good Luck.
Your stupidity actually makes me cringe.
full member
Activity: 229
Merit: 100
1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

Appears to not respond to heartbeat requests.

Quote
2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).

I'd be interested in knowing how you would do so. There's another larger site that you can trigger a very similar issue, but the problem is despite the obvious bug you don't see the result until after it's changed. So the only way I could see to exploit it would be do a double bet, and if you win -- take your winnings, and if you lose complain to support, claim it was a server error not changing the server hash and you want your money back.

Any better ideas?

Doing this but with high multipliers lol.
newbie
Activity: 21
Merit: 0
This bug dont is valid, it not about php stack, you just read our error_log that we forgot to put a forbidden on it.

Nice try.

You're a nonsensical moron.  Honestly, if you were slightly less stupid, I'd spend a bit more time going over the code to your site I attained -- but it's really not worth it. There's not a single sane person who would play on your site after this. And I'd rather leave your piece of shit site to someone less ethical than myself who will part your from your bitcents.



I particularly'm already tired of words, I want to see action. You dont have nothing to show.
I open this thread for support, and such posts i dont will reply anymore.
newbie
Activity: 21
Merit: 0
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.

And you don't want to be rich??? deposit and made it, you will can turn 0.001 btc on 100 btc in some hours.

I really get impressive with some people that don't have qualification to run a project, and try in all ways to destroy other pojects. But no problem, the sensate players are playing.

Good Luck.
newbie
Activity: 21
Merit: 0
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!

This bug dont is valid, it not about php stack, you just read our error_log that we forgot to put a forbidden on it.

Nice try.
member
Activity: 117
Merit: 100
2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.

Funniest joke of the day is your dumb response. Cheesy Look at the highlighted lines in the screenshot - 3 successive bets with the same rolled number. While there is theoretically a 1 in 100000000 chance of that, it's more likely that this happened due to the site allowing additional rolls to be made before the next rolled number has been generated.
sr. member
Activity: 574
Merit: 253
This thread made me laugh.
newbie
Activity: 21
Merit: 0
Site is offline

Thats is a ddos attack, we already start to mitigate it.

thanks
newbie
Activity: 21
Merit: 0
lol @ admin ignoring people that actually have legitimate questions.

1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).


https://i.imgur.com/bl4y5Tl.png


Lol heartbeat? we dont use any info as pass, email.

2 - What you do mean? you hack us? LOOLL man, anyone can bet with 0.0000000 fund, but you dont will win nothing kkkkkk, this is the best joke of the day.
legendary
Activity: 1330
Merit: 1000
You guys ruined the bug bounty. Sad. As soon as it would have been escrowed it would have been mine.
sr. member
Activity: 364
Merit: 250
probably took it down after admin credentials were posted
sr. member
Activity: 294
Merit: 250
***THIS ACCOUNT IS NO LONGER ACTIVE***
copper member
Activity: 1386
Merit: 1000
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!
How much money he have on bankroll?
sr. member
Activity: 364
Merit: 250
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Your rpc username is: 'thedicethedicethe' and the password is 'sjhagst...', you leak it by forgetting to disable PHP stack traces which contain the connection string. Feel free to pay any bounty here: 1M9KYG8rzE3E2DqVbuYZtsEYVhXJDBDpfq

Thanks!

I dont think op has the funds to even pay out this bounty
sr. member
Activity: 350
Merit: 250
Guys dont play this dice Smiley Better try other site's.

what' your suggestion?
and tell we us why?
we are waiting your response Smiley
full member
Activity: 229
Merit: 100
lol @ admin ignoring people that actually have legitimate questions.

1. Your server is running OpenSSL/1.0.1e-fips. I hope you have heartbeat disabled.

2. This is how shitty your script is. I could use this to my advantage and clear your bankroll (the one that doesnt exist).


newbie
Activity: 21
Merit: 0
Can you check the withdrawal system? It just hangs! Thanks for the 45% cashback =)

Hi, try again pls, sometimes our server can lost the comunication with bitcoind daemon.

thanks
full member
Activity: 229
Merit: 100
Guys dont play this dice Smiley Better try other site's.

Oh by example your site?
that you used the script from git? that have too much exploit?

Man i think you is a children with 7 years. Get a life.
Bro YOUR script is from Github. It's actually one of the worst dice scripts in existence.
legendary
Activity: 1330
Merit: 1000
Any luck with my previous questions?

Also, if you hold 5BTC in escrow, I will bet high on your account.  Please set this up.
newbie
Activity: 21
Merit: 0
Guys dont play this dice Smiley Better try other site's.

Oh by example your site?
that you used the script from git? that have too much exploit?

Man i think you is a children with 7 years. Get a life.
I dont have my site:)
I think you are young child who want free and fast money.

Really we all want free and fast money, you no??
If you don't like my site just get out.
copper member
Activity: 1386
Merit: 1000
Guys dont play this dice Smiley Better try other site's.

Oh by example your site?
that you used the script from git? that have too much exploit?

Man i think you is a children with 7 years. Get a life.
I dont have my site:)
I think you are young child who want free and fast money.
sr. member
Activity: 364
Merit: 250
wow this site looks really familiar..
and no mention of provably fair either
newbie
Activity: 21
Merit: 0
Guys dont play this dice Smiley Better try other site's.

Oh by example your site?
that you used the script from git? that have too much exploit?

Man i think you is a children with 7 years. Get a life.
copper member
Activity: 1386
Merit: 1000
Guys dont play this dice Smiley Better try other site's.
newbie
Activity: 21
Merit: 0
Gave the site a try with 100k bits, and lost fairly (I verified the games). I asked support for the  40% refund promotion, but haven't heard back. Meanwhile my account now leads to an infinite loop of alert dialogs (asking for a password, which I never set).

Hi the 40% bonus sent, we have removed the password for your account.

Thanks

your site is pretty buggy, it is the same script as all the scam sites, i wonder why everyone keep using this without thinking to change something at least

Oh sure my site is buggy? Come on empty my hot wallet.
I think you need to learn more about vulnerability.
hero member
Activity: 840
Merit: 1000
Gave the site a try with 100k bits, and lost fairly (I verified the games). I asked support for the  40% refund promotion, but haven't heard back. Meanwhile my account now leads to an infinite loop of alert dialogs (asking for a password, which I never set).

Hi the 40% bonus sent, we have removed the password for your account.

Thanks

your site is pretty buggy, it is the same script as all the scam sites, i wonder why everyone keep using this without thinking to change something at least
newbie
Activity: 21
Merit: 0
Gave the site a try with 100k bits, and lost fairly (I verified the games). I asked support for the  40% refund promotion, but haven't heard back. Meanwhile my account now leads to an infinite loop of alert dialogs (asking for a password, which I never set).

Hi the 40% bonus sent, we have removed the password for your account.

Thanks
sr. member
Activity: 378
Merit: 250
oh wow another pd copy script, actually its crazy how so much people seem to play on this site and are not afraid to loose money
legendary
Activity: 3500
Merit: 1354
How about the deposit bonus?Is there any wagering requirements?


legendary
Activity: 896
Merit: 1000
Well, another clone PD site and that seems the same as other dice site.
copper member
Activity: 1386
Merit: 1000
Show proof. This is same script like your and dont this is not infected.

sorry, no proof. dont will give you our script souce.

But you can test that free script Smiley it not working nothing, and you will have a gift from someone empty your hot address

thanks

Can you please answer my question regarding escrow of the bounty bug?

Also, if you have the chance please sign a bitcoin address with a bitcoin bankroll that's able to handle 25BTC deposits.

You have the bug?
Our bankroll dont have 25 btc. in any moment we talk it.
I dont want your script. Show me backdoor in they script. I use it and never lost. YOu take free script and want make money. Just another scam dice.
hero member
Activity: 770
Merit: 504
(っ◔◡◔)っ🍪
YOu really make dice with free script xD?
Next scam dice..

I would say that site based on open source software could be more trustworthy than one based on "custom" script... especially if you could somehow verify that files used on websites are intact.
legendary
Activity: 1330
Merit: 1000
Show proof. This is same script like your and dont this is not infected.

sorry, no proof. dont will give you our script souce.

But you can test that free script Smiley it not working nothing, and you will have a gift from someone empty your hot address

thanks

Can you please answer my question regarding escrow of the bounty bug?

Also, if you have the chance please sign a bitcoin address with a bitcoin bankroll that's able to handle 25BTC deposits.

You have the bug?
Our bankroll dont have 25 btc. in any moment we talk it.

Deposit any amount from 1 btc btc to 25 btc and enjoy a bonus of more 10%.

Then why would you offer this Promotion 3?

Put up the proper bug bounty in escrow and then we can talk.
newbie
Activity: 21
Merit: 0
Show proof. This is same script like your and dont this is not infected.

sorry, no proof. dont will give you our script souce.

But you can test that free script Smiley it not working nothing, and you will have a gift from someone empty your hot address

thanks

Can you please answer my question regarding escrow of the bounty bug?

Also, if you have the chance please sign a bitcoin address with a bitcoin bankroll that's able to handle 25BTC deposits.

You have the bug?
Our bankroll dont have 25 btc. in any moment we talk it.
legendary
Activity: 1330
Merit: 1000
Show proof. This is same script like your and dont this is not infected.

sorry, no proof. dont will give you our script souce.

But you can test that free script Smiley it not working nothing, and you will have a gift from someone empty your hot address

thanks

Can you please answer my question regarding escrow of the bounty bug?

Also, if you have the chance please sign a bitcoin address with a bitcoin bankroll that's able to handle 25BTC deposits.
newbie
Activity: 21
Merit: 0
Show proof. This is same script like your and dont this is not infected.

sorry, no proof. dont will give you our script souce.

But you can test that free script Smiley it not working nothing, and you will have a gift from someone empty your hot address

thanks
copper member
Activity: 1386
Merit: 1000
Show proof. This is same script like your and dont this is not infected.
newbie
Activity: 21
Merit: 0
YOu really make dice with free script xD?
Next scam dice..

Its not a free script, you can see someone selling it by 1.1 btc where i think.
We paid more 2 btc to a dev audity the script.

well, 3.1 btc for a script is good to you?

thanks
legendary
Activity: 896
Merit: 1000
that's funny
I see bets of Player_130 in All bets list although Player_130 is me and I did not any bet yet Smiley


It can have the same username.
What protect you is your URL thats is unique.

thanks

To test the theory, I try to change my username to Player_130 but it gives me a "This alias is alredy taken :-(" message.
So no we cannot have the same username.
newbie
Activity: 21
Merit: 0
that's funny
I see bets of Player_130 in All bets list although Player_130 is me and I did not any bet yet Smiley


It can have the same username.
What protect you is your URL thats is unique.

thanks
legendary
Activity: 896
Merit: 1000
I quite like the design of the provably fair on this site, although it's probably more suitable for computer-verification than human ... but I'll give it a go with 100k bits. I'll report back here.

There is no client seed, and so you can't affect the roll result, but only verify the roll result doesn't change before and after the bet.
full member
Activity: 182
Merit: 100
★Bitin.io★ - Instant Exchange
that's funny
I see bets of Player_130 in All bets list although Player_130 is me and I did not any bet yet Smiley
copper member
Activity: 1386
Merit: 1000
YOu really make dice with free script xD?
Next scam dice..
full member
Activity: 182
Merit: 100
★Bitin.io★ - Instant Exchange
are you going to add btc-faucet on site?
legendary
Activity: 1330
Merit: 1000
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Can you please put that bounty into escrow?
newbie
Activity: 21
Merit: 0
same coindice script ...again... is this with out without the back door ? lol

Sure the script is fully secured.
We make one security audity on it.

We don't are idiot to spend too much with dedicate server, ssl and other things, to run a site and a hacker come here and stole our funds.

Thanks

you should hire a person with good english..

 Cool Cool Cool
Thats true.  Grin
legendary
Activity: 2018
Merit: 1108
Some effort in the layout wouldn't do bad...
full member
Activity: 812
Merit: 100
same coindice script ...again... is this with out without the back door ? lol

Sure the script is fully secured.
We make one security audity on it.

We don't are idiot to spend too much with dedicate server, ssl and other things, to run a site and a hacker come here and stole our funds.

Thanks

you should hire a person with good english..
newbie
Activity: 21
Merit: 0
same coindice script ...again... is this with out without the back door ? lol

Sure the script is fully secured.
We make one security audity on it.

We don't are idiot to spend too much with dedicate server, ssl and other things, to run a site and a hacker come here and stole our funds.

Thanks
full member
Activity: 140
Merit: 100
same coindice script ...again... is this with out without the back door ? lol
The domain name is pretty good on this one. Op you would make more selling the domain than by having people deposit and play on the sit.e.
hero member
Activity: 602
Merit: 501
same coindice script ...again... is this with out without the back door ? lol
hero member
Activity: 602
Merit: 500
hyperboria - next internet
Hello friends, We like to announce today we are openning our Bitcoind dice game: https://the-dice.com

* Transactions fully instant.
* Deposits added with 6 minutes, Withdraw made within milliseconds.
* Fair.
* SSL Protection

Take a eye on our lauching promotions:

Launching promotion 1###: Until 28 February of 2015 we are giving back %40 from your loses. Just sent a email to [email protected] with your email and we will add the %40 to back to your account. (valid only for the first deposit).

Launching promotion 2###: Deposit any amount from 0.0001 btc to 1 btc and enjoy a bonus of more 5%

Launching promotion 3###: Deposit any amount from 1 btc btc to 25 btc and enjoy a bonus of more 10%.


Let's play and have a good luck.

Another site on a old stupid script? What is exatly the difference from old good dice sites?
You can make house edge less atleast...
newbie
Activity: 21
Merit: 0
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Its nothing about "secure". That exact same script has been used in countless dice sites that all ended up as a scam.

And if you really have such a huge bounty system. Sure you would have some coins to pay someone for a logo? I mean advertising BTC dice by stealing "Tittie Coin" logo ?

You just judge a site by script?

if you have proof that says we are insecure or are a scam, pls show there. Not have speculations

Thanks
legendary
Activity: 1918
Merit: 1018
Hello friends, We like to announce today we are openning our Bitcoind dice game: https://the-dice.com

* Transactions fully instant.
* Deposits added with 6 minutes, Withdraw made within milliseconds.
* Fair.
* SSL Protection

Take a eye on our lauching promotions:

Launching promotion 1###: Until 28 February of 2015 we are giving back %40 from your loses. Just sent a email to [email protected] with your email and we will add the %40 to back to your account. (valid only for the first deposit).

Launching promotion 2###: Deposit any amount from 0.0001 btc to 1 btc and enjoy a bonus of more 5%

Launching promotion 3###: Deposit any amount from 1 btc btc to 25 btc and enjoy a bonus of more 10%.


Let's play and have a good luck.

Good luck with your new dice, it will be hard to compete against the existing dice casinos.
legendary
Activity: 1624
Merit: 1007
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks


Its nothing about "secure". That exact same script has been used in countless dice sites that all ended up as a scam.

And if you really have such a huge bounty system. Sure you would have some coins to pay someone for a logo? I mean advertising BTC dice by stealing "Tittie Coin" logo ?
newbie
Activity: 21
Merit: 0
Our script is very Secure.
We make a full audity on it.

Try yourself to login at our admin page: the-dice.com/admin

We paid a bounty of 5 btc if someone are abe to exploit us.

Thanks
legendary
Activity: 1624
Merit: 1007
Oh look its "That" script again. If you really expect to go somewhere with this dice site then get rid of that awful script.
Its been used in so many scams that noone with even a half a brain will ever play on it.

At least remove the "Tittie Coin" logo from top left.
newbie
Activity: 21
Merit: 0
Hello friends, We like to announce today we are openning our Bitcoind dice game: https://the-dice.com

* Transactions fully instant.
* Deposits added with 6 minutes, Withdraw made within milliseconds.
* Fair.
* SSL Protection

Take a eye on our lauching promotions:

Launching promotion 1###: Until 28 February of 2015 we are giving back %40 from your loses. Just sent a email to [email protected] with your email and we will add the %40 to back to your account. (valid only for the first deposit).

Launching promotion 2###: Deposit any amount from 0.0001 btc to 1 btc and enjoy a bonus of more 5%

Launching promotion 3###: Deposit any amount from 1 btc btc to 25 btc and enjoy a bonus of more 10%.


Let's play and have a good luck.
Jump to: