Bitcoin Forum

Economy => Services => Topic started by: bitcoinermatt on July 01, 2020, 05:16:08 PM



Title: .
Post by: bitcoinermatt on July 01, 2020, 05:16:08 PM
.


Title: Re: JavaScript knowledge needed! I found a breach in a slots game! (Huge Reward!)
Post by: VoucherS on July 01, 2020, 09:22:11 PM
Its BETA. You can invest real money to play with it or its just DEMO mode?
Btw i see it can be easy to "hack", DEMO atleast.


Title: Re: JavaScript knowledge needed! I found a breach in a slots game! (Huge Reward!)
Post by: Joel_Jantsen on July 01, 2020, 11:17:26 PM
Inspect Element == Client-side stuff. You cannot do anything on the server with the changes on your browser. Unless of course, you're injecting some malicious scripts which don't seem to be the case.


Title: Re: JavaScript knowledge needed! I found a breach in a slots game! (Huge Reward!)
Post by: polypusx on July 02, 2020, 03:05:10 PM
lol very nice conversation between one person with multiple account


Title: Re: JavaScript knowledge needed! I found a breach in a slots game! (Huge Reward!)
Post by: StonerStanley on July 02, 2020, 03:51:54 PM
Inspect Element == Client-side stuff. You cannot do anything on the server with the changes on your browser. Unless of course, you're injecting some malicious scripts which don't seem to be the case.

It depends of how it has been programmed, it could be a HTTP Pollution Parameter vulnerability. I don't do security research in this domain anymore but 2 years ago i was still finding a lot of these vulnerabilities even in some great online games (they are just well hidden and people don't have enough time to check all the parameters, pages, functionnalities)

Hey guys! I found out that the snip microwallet has a slots game which is built with php and javascript, i am already able to change my win percentage just by doing inspect element and i know it is possible to set the minimum win! Help me and serve yourself in Bitcoin! The link for the game is snip Thanks

More details: I am able to change the win percentage in the Sources tab in inspect element
I also know there is some kind of minimum win variable thing


What you are trying to exploit could be a HTTP Pollution Parameter vulnerability and i doubt that there is this kind of vulnerability but it's possible, this vulnerability is mostly foundable in unexpected or unsuspectable parameters.


Anyway i won't help you to do that kind of stuff 8)

Stealing people is bad, more when you don't even know them so you don't even know what they deserve....


Title: Re: JavaScript knowledge needed! I found a breach in a slots game! (Huge Reward!)
Post by: VoucherS on July 03, 2020, 12:46:25 AM
If the script is working and you can get funds, why dont you make it?
Can you send how it works? Its little fishy for me, you advertise a random slot game, how should we know its not your site?
Or maybe they dont even pay, you invest funds and they steal it. Its "BETA" so they can upgrade it later