Author

Topic: Vulnerability in mmcFE Manual Withdrawal Logic (Read 525 times)

member
Activity: 112
Merit: 10
To: Any pool operator using mmcFE or any one of a dozen derivative forks.

A vulnerability has been discovered in the Manual Withdrawal logic that can allow Withdrawals to be duplicated.

The vulnerability is in accountdetails.php.

Essentially firing off several withdrawal requests in less than a second can sometimes allow multiple withdrawals to be processed.

Resulting in duplicate payments being sent before the first one completes and the users account balance is set to 0.

You should disable manual withdrawal until you can code a work around.

Details here : https://bitcointalksearch.org/topic/m.2416246

Moderator : you might want to make this thread a sticky as there are tons of pools based upon this code.
Jump to: