Pages:
Author

Topic: [UPDATE] - BetSomeBits is ALMOST LAUNCHING ! - page 4. (Read 5569 times)

member
Activity: 112
Merit: 10
December 04, 2014, 06:16:55 AM
#32
Make a design with better colors,with the modern ( i call it windows 8 ) style with flat colors,most people play on pd cause its UNIQUE!
Im gonna start testing the site,hopefully there arent tons of exploits.

Edit:Refreshing page every bet?Thats bad for people with slow internet.

Edit:I can bet on 100% win chance and earn 1 satoshi everytime.

Yep, ajax will be implemented soon, to prevent the refreshing

Regarding the 100% win bet, how did you accomplish this, as it should refuse rolls at 0% or 100% change..

Thx
member
Activity: 112
Merit: 10
December 04, 2014, 04:06:29 AM
#31
on mobile again: so in short again:

sorrt for the typo. will be fixed.
db is on a diff server. the phpmyadmin you found does not hold the betting data

server setting will be fixed, bet regarding the php session id in the cookie, thats normal ?  same with fb, prime, etc ?

i really dislike the win8 metro look Smiley actually


and regarding the 60% chance and winning 1 satoshi.   is this not the same at prime?  it seems im getting the same results there?  thx
i guess the question is: is 0.00000001 X 1.7.    0.00000001 or 0.00000002


will post more elaborate response when im in the office


edit: looking at previous rolls: lol @ user "test41241' OR 1=1; --". Smiley

edit: how many ti.es the signup bonus, should be required to withdraw ( to prevent abusing the bonus).   at primt its like x200 or something i believe
sr. member
Activity: 1456
Merit: 326
Eloncoin.org - Mars, here we come!
December 03, 2014, 10:04:32 PM
#30
There is a typo -
fixes to fait play algorithm.

It must be:

Fixes to fair play algorithm.

In here u typed it right,but on the site it has a typo.

If you wanna go all Grammar Nazi, it's "Fixed with a fairplay algorithm", or something along those lines.
member
Activity: 70
Merit: 10
December 03, 2014, 07:49:02 PM
#29
There is a typo -
fixes to fait play algorithm.

It must be:

Fixes to fair play algorithm.

In here u typed it right,but on the site it has a typo.
sr. member
Activity: 392
Merit: 268
Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ
December 03, 2014, 07:47:04 PM
#28
    Make a design with better colors,with the modern ( i call it windows 8 ) style with flat colors,most people play on pd cause its UNIQUE!
    Im gonna start testing the site,hopefully there arent tons of exploits.

    Edit:Refreshing page every bet?Thats bad for people with slow internet.

    Edit:I can bet on 100% win chance and earn 1 satoshi everytime.

    Well, 100% doesn't make sense. However, I put in 1 satoshi, set chance to 60% (so payout is 1.64%) and clicked bet a bunch of times. Eventually, I was slowly winning in the long run, due to rounding error. Might be insignificant, until a bot comes along. I do agree on using AJAX instead.

    There are some technical points of interest:

    • PHPSESSID (cookie) is accessible to javascript so if an XSS or something does occur, then JS will be able to steal the session.
    • hxxp colon slash slash betsomebits.com/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 reveals info about the PHP version (estimated by way of author list) and extensions, which is a risk. Set expose_php = Off in php.ini, or rewrite URLs so this is not accessible.
    • Apache 2.2.22 is somewhat out of date. Not sure if there is an issue here yet, though.
    • "PHP/5.4.35-1+deb.sury.org~precise+1" is made known to the world through the X-Powered-By header. If there's an exploit in this specific version, that might be an issue.

    As I find more, I'll post them.[/list]

    Also, I found phpmyadmin. No vulnerabilities as far as I know, though I'm not familiar with it. May I have permission to run a quick portscan from my personal IP?
    member
    Activity: 70
    Merit: 10
    December 03, 2014, 07:43:24 PM
    #27
     I cant get the free satoshi by refreshing the page  Huh Huh

    Make it so it doesnt type 0.0_______ when i dont type all the zero's and make it auto typing the zero's its so annoying.
    sr. member
    Activity: 392
    Merit: 268
    Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ
    December 03, 2014, 07:14:17 PM
    #26
      Make a design with better colors,with the modern ( i call it windows 8 ) style with flat colors,most people play on pd cause its UNIQUE!
      Im gonna start testing the site,hopefully there arent tons of exploits.

      Edit:Refreshing page every bet?Thats bad for people with slow internet.

      Edit:I can bet on 100% win chance and earn 1 satoshi everytime.

      Well, 100% doesn't make sense. However, I put in 1 satoshi, set chance to 60% (so payout is 1.64%) and clicked bet a bunch of times. Eventually, I was slowly winning in the long run, due to rounding error. Might be insignificant, until a bot comes along. I do agree on using AJAX instead.

      There are some technical points of interest:

      • PHPSESSID (cookie) is accessible to javascript so if an XSS or something does occur, then JS will be able to steal the session.
      • hxxp colon slash slash betsomebits.com/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 reveals info about the PHP version (estimated by way of author list) and extensions, which is a risk. Set expose_php = Off in php.ini, or rewrite URLs so this is not accessible.
      • Apache 2.2.22 is somewhat out of date. Not sure if there is an issue here yet, though.
      • "PHP/5.4.35-1+deb.sury.org~precise+1" is made known to the world through the X-Powered-By header. If there's an exploit in this specific version, that might be an issue.

      As I find more, I'll post them.[/list]
      member
      Activity: 70
      Merit: 10
      December 03, 2014, 06:52:03 PM
      #25
      Make a design with better colors,with the modern ( i call it windows 8 ) style with flat colors,most people play on pd cause its UNIQUE!
      Im gonna start testing the site,hopefully there arent tons of exploits.

      Edit:Refreshing page every bet?Thats bad for people with slow internet.

      Edit:I can bet on 100% win chance and earn 1 satoshi everytime.
      sr. member
      Activity: 728
      Merit: 256
      December 03, 2014, 06:43:22 PM
      #24
      I'm willing to do testing of withdrawals. I'm familiar with the Bitcoin network, and I'll try to "cheat" the withdrawal system as well. Anything extremely large that I get, I'll return except for a small bit for finding it Smiley

      Very well, fair enough Smiley


      EDIT: just added link to page to verify your own bets (http://phpfiddle.org/main/code/4071-5c2q)

      Do u have a gambling license ?
      sr. member
      Activity: 1456
      Merit: 326
      Eloncoin.org - Mars, here we come!
      December 03, 2014, 06:28:31 PM
      #23
      im not in the office anymore. so in short:

      betting at 0 or 100% has been fixed. but not yet deployed

      the typos and dutch words will be fixed this evening.

      same with the redirect.

      same with the email

      ill also put an inputmask on the amount input. only allowing correct input.


      in the mean time heres a question:

      how much would an average user consider a "big enough" signup bonus to convince them to give it a go, where they would just bounce if there was no bonus/small bonus ?

      thx again amd keep em coming guys, ill update here when the next version is deployed. hopefully this evening



      edit: when i get to implementing the withdrawals. i will actually have a few people from here (like 5) make real withdrawals to test the system. so keep an eye out ..

      using btc i will donate to your account obviously

      I think a decent amount would be dependent on your funding; there are some sites that offer .0001 - .01 BTC for signing up during the promotional period. Another possibility for the site could be a combination of a faucet, which again is up to you; upon logging in, people could get 500 satoshi, each time once a day or something. It seems like it'd be somewhat easy to abuse the system if the signup bonus is too big though, as there are people with multiple wallets, myself included

      Hmm, i like the idea of combining the site with a faucet, but should i do it like prime does, allow the user the use tha faucet, every x amount of minutes, IF their balance is at zero..

      Or maybe even indeed, give them a bonus, once per day, on the first login of the day, each user, even WITHOUT their balance beeing zero ..    or base the amount of daily bonus given, on the total amount wagered by the user so far, something like that ?

      Thx


      I'm also willing to test withdrawals! The concept of only giving them a certain amount if they're at 0 is more cost-effective for you, but it may be counterproductive for business unless it's a decent amount to gamble with. If you did the daily bonus people could abuse it, but it would attract more loyal customers. Ultimately it's up to you to you around with how you'd want to do it
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 03:45:40 PM
      #22
      I'm willing to do testing of withdrawals. I'm familiar with the Bitcoin network, and I'll try to "cheat" the withdrawal system as well. Anything extremely large that I get, I'll return except for a small bit for finding it Smiley

      Very well, fair enough Smiley


      EDIT: just added link to page to verify your own bets (http://phpfiddle.org/main/code/4071-5c2q)
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 03:26:39 PM
      #21
      im not in the office anymore. so in short:

      betting at 0 or 100% has been fixed. but not yet deployed

      the typos and dutch words will be fixed this evening.

      same with the redirect.

      same with the email

      ill also put an inputmask on the amount input. only allowing correct input.


      in the mean time heres a question:

      how much would an average user consider a "big enough" signup bonus to convince them to give it a go, where they would just bounce if there was no bonus/small bonus ?

      thx again amd keep em coming guys, ill update here when the next version is deployed. hopefully this evening



      edit: when i get to implementing the withdrawals. i will actually have a few people from here (like 5) make real withdrawals to test the system. so keep an eye out ..

      using btc i will donate to your account obviously

      I think a decent amount would be dependent on your funding; there are some sites that offer .0001 - .01 BTC for signing up during the promotional period. Another possibility for the site could be a combination of a faucet, which again is up to you; upon logging in, people could get 500 satoshi, each time once a day or something. It seems like it'd be somewhat easy to abuse the system if the signup bonus is too big though, as there are people with multiple wallets, myself included

      Hmm, i like the idea of combining the site with a faucet, but should i do it like prime does, allow the user the use tha faucet, every x amount of minutes, IF their balance is at zero..

      Or maybe even indeed, give them a bonus, once per day, on the first login of the day, each user, even WITHOUT their balance beeing zero ..    or base the amount of daily bonus given, on the total amount wagered by the user so far, something like that ?

      Thx
      sr. member
      Activity: 392
      Merit: 268
      Tips welcomed: 1CF4GhXX1RhCaGzWztgE1YZZUcSpoqTbsJ
      December 03, 2014, 03:16:35 PM
      #20
      I'm willing to do testing of withdrawals. I'm familiar with the Bitcoin network, and I'll try to "cheat" the withdrawal system as well. Anything extremely large that I get, I'll return except for a small bit for finding it Smiley
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 03:13:36 PM
      #19
      Update :

      more changelog for 3 december 2014:

       d9fd9a5 - input mask (9.99999999) over amount field
       d90065e - layout changes to previous rolls page
       60c6d6d - fixed typo on registration confirmation page
       0427049 - redirect to bet page after login
       ce26655 - added missing login button translation
       5efa4e1 - fixed footer copyright
       455b910 - unallow 0% or 100% bets
      sr. member
      Activity: 1456
      Merit: 326
      Eloncoin.org - Mars, here we come!
      December 03, 2014, 02:21:02 PM
      #18
      im not in the office anymore. so in short:

      betting at 0 or 100% has been fixed. but not yet deployed

      the typos and dutch words will be fixed this evening.

      same with the redirect.

      same with the email

      ill also put an inputmask on the amount input. only allowing correct input.


      in the mean time heres a question:

      how much would an average user consider a "big enough" signup bonus to convince them to give it a go, where they would just bounce if there was no bonus/small bonus ?

      thx again amd keep em coming guys, ill update here when the next version is deployed. hopefully this evening



      edit: when i get to implementing the withdrawals. i will actually have a few people from here (like 5) make real withdrawals to test the system. so keep an eye out ..

      using btc i will donate to your account obviously

      I think a decent amount would be dependent on your funding; there are some sites that offer .0001 - .01 BTC for signing up during the promotional period. Another possibility for the site could be a combination of a faucet, which again is up to you; upon logging in, people could get 500 satoshi, each time once a day or something. It seems like it'd be somewhat easy to abuse the system if the signup bonus is too big though, as there are people with multiple wallets, myself included
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 10:40:32 AM
      #17
      im not in the office anymore. so in short:

      betting at 0 or 100% has been fixed. but not yet deployed

      the typos and dutch words will be fixed this evening.

      same with the redirect.

      same with the email

      ill also put an inputmask on the amount input. only allowing correct input.


      in the mean time heres a question:

      how much would an average user consider a "big enough" signup bonus to convince them to give it a go, where they would just bounce if there was no bonus/small bonus ?

      thx again amd keep em coming guys, ill update here when the next version is deployed. hopefully this evening



      edit: when i get to implementing the withdrawals. i will actually have a few people from here (like 5) make real withdrawals to test the system. so keep an eye out ..

      using btc i will donate to your account obviously
      sr. member
      Activity: 1456
      Merit: 326
      Eloncoin.org - Mars, here we come!
      December 03, 2014, 07:41:21 AM
      #16
      You shouldn't be able to make a bet with 0% probability. If you set the min guess and the max guess to the same value, it still lets you roll the dice, with a 0% chance of earning a payout.

      Correct, i still need to fix this, but it is a known bug, yet i will reward you for it still.



      - CopyRight in the lower left corner could be changed to Copyright  correct Smiley
      - Upon creating a new account, change the / to a ?  Can you explain this, i dont understand what you mean ?


      Out of curiosity, why does everyone get their own e-mail address? This is also something i still need to fix, the underlying database needs a unique email adress for each user, before i get rid of the email altogether, i bypass this by generating random email adresses for each user (as i dont want to ask the user for its real email adress, as i dont feel the need to spam people Smiley )

      Coolio, thanks again! Upon registering a new account,
      "You have received 500 Free Satoshi to play.
      Click here to go to the betting screen, or click BET in the top menu/" is the message provided.

      The "Sign-in" button is currently in Dutch, which is fine, but it might as well be changed to English if the whole site is going to initially be in English.

      Also, after logging into an account, they should be directed to a different Home page/directly to the Bet page; as it is, it's redirecting to the home page and prompting for a name, so that the user can set up a new account, even if it's already logged in.

      This also might not qualify as a bug, but if you bet something like .00004AWEDAJ@ or .00004 or .00004!!!0339-4, it will roll, betting for .00004; maybe disable special symbols in that text area, or give an error message?
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 07:11:40 AM
      #15
      You shouldn't be able to make a bet with 0% probability. If you set the min guess and the max guess to the same value, it still lets you roll the dice, with a 0% chance of earning a payout.

      Correct, i still need to fix this, but it is a known bug, yet i will reward you for it still.



      - CopyRight in the lower left corner could be changed to Copyright  correct Smiley
      - Upon creating a new account, change the / to a ?  Can you explain this, i dont understand what you mean ?


      Out of curiosity, why does everyone get their own e-mail address? This is also something i still need to fix, the underlying database needs a unique email adress for each user, before i get rid of the email altogether, i bypass this by generating random email adresses for each user (as i dont want to ask the user for its real email adress, as i dont feel the need to spam people Smiley )
      sr. member
      Activity: 1456
      Merit: 326
      Eloncoin.org - Mars, here we come!
      December 03, 2014, 07:03:06 AM
      #14
      You shouldn't be able to make a bet with 0% probability. If you set the min guess and the max guess to the same value, it still lets you roll the dice, with a 0% chance of earning a payout.

      If that qualifies as a bug, payment can be accepted here: 1Ch173DuRzf1aDxnbabo1rQhUJa2YkfDZG
      Thanks!

      Couple stylistic changes just to make the site appear more aesthically pleasing:
      - CopyRight in the lower left corner could be changed to Copyright
      - Upon creating a new account, change the / to a ?

      Out of curiosity, why does everyone get their own e-mail address?
      member
      Activity: 112
      Merit: 10
      December 03, 2014, 06:43:12 AM
      #13
      THX? i changed it to "Repeat Password", you where completely right ..

      i also made the registration and login process easier just now, by making it 2 step,   first username,   then pass.

      Pages:
      Jump to: