Bitcoin Forum

Economy => Services => Topic started by: Stunna on August 03, 2014, 07:01:22 PM



Title: Pentest Primedice 3 for bounties!
Post by: Stunna on August 03, 2014, 07:01:22 PM
Looking to grab a few additional pentesters to try and break/glitch primedice 3 prior to launch. If you have pentesting experience please post here instead of PMing and I will contact you if I feel you are suitable. If you aren't selected you will still have the chance to test when the site goes public and the bounties will increase substantially after that point. Bounties will be paid for new unreported issues and rewards will be based off severity.


Thanks


Note: I'm not looking for a normal user to test out the site, I'm looking for hackers with code experience and knowledge on how to find/abuse bugs like XSS/CSRF. Will be back later today to PM details


Title: Re: Pentest PD3 for bounties!
Post by: marcotheminer on August 03, 2014, 07:21:03 PM
Im interested and willing to try it out. Up to you Stunna.


Title: Re: Pentest Primedice 3 for bounties!
Post by: nahtnam on August 03, 2014, 09:22:00 PM
Im interested! :)

EDIT: Although I cant really try to "hack" pd3, I can test for speed and efficiency, as well as js problems.

Let me know if you are interested!


Title: Re: Pentest Primedice 3 for bounties!
Post by: edmundduke on August 03, 2014, 09:23:27 PM
I am interested. I might be a Jr. Member here but i have plenty of experience in testing.


Title: Re: Pentest Primedice 3 for bounties!
Post by: Prez on August 03, 2014, 10:02:28 PM
I'm interested in testing/breaking PD. I can PM you my resume of the sites I have worked on if needed.

I'm confident in my abilities and won't waste your time. Let me know what you would like to see from me.


Title: Re: Pentest Primedice 3 for bounties!
Post by: account4btc on August 03, 2014, 10:17:32 PM
I can test with 90gbps, let me know


Title: Re: Pentest Primedice 3 for bounties!
Post by: factor280 on August 03, 2014, 10:26:04 PM
Hi Stunna,

I'm interested and can help. I code in JS and dice quite frequently. Please let me know if I can be of help.


Title: Re: Pentest Primedice 3 for bounties!
Post by: MICRO on August 03, 2014, 10:30:35 PM
He needs some blackhat hackers not testers :D . U guys don't need to test pd u need to try to break it , abuse it , and exploit it :D .


Title: Re: Pentest Primedice 3 for bounties!
Post by: factor280 on August 03, 2014, 11:27:51 PM
He needs some blackhat hackers not testers :D . U guys don't need to test pd u need to try to break it , abuse it , and exploit it :D .

Absolutely agree with you. But he still needs to find if there are any exploits, including in javascript. If there are, you could manipulate the code or, for example, if the code is poorly written, a few users with bots would overload the server and slow things down considerably. Simple things that shouldn't be overlooked :)


Title: Re: Pentest Primedice 3 for bounties!
Post by: Prez on August 03, 2014, 11:40:22 PM
He needs some blackhat hackers not testers :D . U guys don't need to test pd u need to try to break it , abuse it , and exploit it :D .

Don't you mean whitehat?


Title: Re: Pentest Primedice 3 for bounties!
Post by: serje on August 03, 2014, 11:41:03 PM
I'm an abuser! I like to abuse things! Pick me!


Title: Re: Pentest Primedice 3 for bounties!
Post by: franckuestein on August 03, 2014, 11:46:43 PM
Hi @Stunna!

I'm one of the members of your Primedice Bitcointalk campaigns.
Yes, I can help you with Primedice tests as a hacker.

As well, I think that I have some previous posts on my 'post history' solving problems to some coins on the Spanish sub-forum.

If you need help, just contact with me and we're going to secure PD3!!
:)


Title: Re: Pentest Primedice 3 for bounties!
Post by: Watoshi-Dimobuto on August 04, 2014, 02:06:39 AM
This job is to find vulnerabilities. If you don't know how to find vulnerabilities jobs like this is not for you.


Title: Re: Pentest Primedice 3 for bounties!
Post by: Stunna on August 04, 2014, 02:34:49 AM
Our main developer is asleep at the moment, when he's online I'll send some of the people here site/api details.


Title: Re: Pentest Primedice 3 for bounties!
Post by: wang_yan on August 04, 2014, 07:40:44 AM
I'm interested in doing this, please let me know if I can help.


Title: Re: Pentest Primedice 3 for bounties!
Post by: ranochigo on August 04, 2014, 10:23:54 AM
I can test with 90gbps, let me know
Stunna don't need stressers. He can stress test it himself if he wants to. He is finding people who can exploit the website to gain access to admin panel for example. He would probably be using cloudflare so your ddos won't hurt him a lot too.


Title: Re: Pentest Primedice 3 for bounties!
Post by: gelross2014 on August 04, 2014, 10:27:40 AM
Hi, I can do XSS . Its up to you Stunna if you will hire me :D


Title: Re: Pentest Primedice 3 for bounties!
Post by: Joca97 on August 04, 2014, 11:00:33 AM
hello stunna im intrested

you can check with micro he knows im trusted!!!


Title: Re: Pentest Primedice 3 for bounties!
Post by: Kluge on August 04, 2014, 11:09:18 AM
I'm always up for trying to force data to execute, though IMO, forcing a 100BTC credit to myself is a feature, not a bug. To date, I've only been able to force a small site to accept LTC as BTC, though. Then it was fixed and he never paid the bounty. :D


Title: Re: Pentest Primedice 3 for bounties!
Post by: Rora on August 04, 2014, 03:15:42 PM
Id love to test it out!


Title: Re: Pentest Primedice 3 for bounties!
Post by: DeboraMeeks on August 04, 2014, 06:04:23 PM
Me too! Would be interested :)


Title: Re: Pentest Primedice 3 for bounties!
Post by: BitCoinDream on August 04, 2014, 07:29:41 PM
Our main developer is asleep at the moment, when he's online I'll send some of the people here site/api details.

I might be interested in checking SQL injection.

I'm always up for trying to force data to execute, though IMO, forcing a 100BTC credit to myself is a feature, not a bug. To date, I've only been able to force a small site to accept LTC as BTC, though. Then it was fixed and he never paid the bounty. :D

How come a site accept LTC as BTC ? The Bitcoin daemon is different from the Litecoin daemon. If they check balance to their Bitcoin address that can never be filled with Litecoin !!! I'd like to know what flaw they made... if u please share.


Title: Re: Pentest Primedice 3 for bounties!
Post by: devthedev on August 04, 2014, 10:13:40 PM
Our main developer is asleep at the moment, when he's online I'll send some of the people here site/api details.

I might be interested in checking SQL injection.

It's pretty solid, I don't think you'll find anything in that realm.
Stunna, I've shot you a PM with the results of the pentest.


Title: Re: Pentest Primedice 3 for bounties!
Post by: MICRO on August 04, 2014, 10:28:55 PM
Our main developer is asleep at the moment, when he's online I'll send some of the people here site/api details.

I might be interested in checking SQL injection.

It's pretty solid, I don't think you'll find anything in that realm.
Stunna, I've shot you a PM with the results of the pentest.

Are u tester123 ? Come on pd3 to play around PvP with me.


Title: Re: Pentest Primedice 3 for bounties!
Post by: atinski on August 04, 2014, 10:36:21 PM
me too


Title: Re: Pentest Primedice 3 for bounties!
Post by: Kluge on August 05, 2014, 03:20:18 AM
Our main developer is asleep at the moment, when he's online I'll send some of the people here site/api details.

I might be interested in checking SQL injection.

I'm always up for trying to force data to execute, though IMO, forcing a 100BTC credit to myself is a feature, not a bug. To date, I've only been able to force a small site to accept LTC as BTC, though. Then it was fixed and he never paid the bounty. :D

How come a site accept LTC as BTC ? The Bitcoin daemon is different from the Litecoin daemon. If they check balance to their Bitcoin address that can never be filled with Litecoin !!! I'd like to know what flaw they made... if u please share.
They used deposit accounts which you spent from, which they didn't use a daemon for, just internal accounting. Basically, they accepted everything from their forms as true without checking, but allowed a user to specify "LTC" on a "BTC" form by dinking around with the source html (and they literally used those really obvious currency flags). I had LTC in my account there, so I changed the currency flag from BTC to LTC and was able to spend LTC as if it were valued like BTC. Unfortunately, it was only to buy ads. :'(


Title: Re: Pentest Primedice 3 for bounties!
Post by: 2double0 on August 05, 2014, 08:37:46 AM
Me 3 interested.


Title: Re: Pentest Primedice 3 for bounties!
Post by: eden1 on August 05, 2014, 05:07:40 PM
I am interested, u will need someone who is new to Prime-Dice to test the atmosphere of the site


Title: Re: Pentest Primedice 3 for bounties!
Post by: MCM-Mike on August 07, 2014, 07:45:08 AM
Do you provide a test/dev-environment in order to pentest it and don't break the production system?
If so I would give it a shot if its worth the try.

some facts about me:
http://bitcloudproject.org/w/User:MCM-Mike


Title: Re: Pentest Primedice 3 for bounties!
Post by: BitCoinDream on August 10, 2014, 06:06:38 PM
Hi Stunna... though i was not among the testers, I have found a small UI bug hat u may consider fixing. When I click on the language drop-down, it does not work. It is only showing English as a fixed option.


Title: Re: Pentest Primedice 3 for bounties!
Post by: cookiemonsterwhat on August 11, 2014, 02:42:32 AM
can we still get rewarded if we found bugs?


Title: Re: Pentest Primedice 3 for bounties!
Post by: nahtnam on August 11, 2014, 02:45:29 AM
can we still get rewarded if we found bugs?

Yep. Just email support@primedice.com

If your bug is unique and can be reproduced, you will get a reward!


Title: Re: Pentest Primedice 3 for bounties!
Post by: BitCoinDream on August 11, 2014, 03:48:38 PM
can we still get rewarded if we found bugs?

Yep. Just email support@primedice.com

If your bug is unique and can be reproduced, you will get a reward!

I posted above. The bug has neither been addressed nor I have heard from Stunna. May be he's not checking this thread anymore :'(

Hi Stunna... though i was not among the testers, I have found a small UI bug hat u may consider fixing. When I click on the language drop-down, it does not work. It is only showing English as a fixed option.


Title: Re: Pentest Primedice 3 for bounties!
Post by: nahtnam on August 11, 2014, 03:49:38 PM
can we still get rewarded if we found bugs?

Yep. Just email support@primedice.com

If your bug is unique and can be reproduced, you will get a reward!

I posted above. The bug has neither been addressed nor I have heard from Stunna. May be he's not checking this thread anymore :'(

Hi Stunna... though i was not among the testers, I have found a small UI bug hat u may consider fixing. When I click on the language drop-down, it does not work. It is only showing English as a fixed option.

How is that a bug?

I dont think PD has been translated to any other language yet.


Title: Re: Pentest Primedice 3 for bounties!
Post by: BitCoinDream on August 11, 2014, 05:40:23 PM
can we still get rewarded if we found bugs?

Yep. Just email support@primedice.com

If your bug is unique and can be reproduced, you will get a reward!

I posted above. The bug has neither been addressed nor I have heard from Stunna. May be he's not checking this thread anymore :'(

Hi Stunna... though i was not among the testers, I have found a small UI bug hat u may consider fixing. When I click on the language drop-down, it does not work. It is only showing English as a fixed option.

How is that a bug?

I dont think PD has been translated to any other language yet.

When a drop down is not dropping down but showing the down arrow is not a bug ?


Title: Re: Pentest Primedice 3 for bounties!
Post by: 0xAli on August 11, 2014, 09:09:10 PM
I am interested.


Title: Re: Pentest Primedice 3 for bounties!
Post by: cookiemonsterwhat on August 11, 2014, 10:39:53 PM
whats considered as a bug? cause the withdraw gave me 10,000 satoshi is that one?


Title: Re: Pentest Primedice 3 for bounties!
Post by: rz20 on August 11, 2014, 10:51:35 PM
I sent and talk to edward about the nonce repeat bug when you make a flood query. It gives to all the bets of the same timestamp the same result. In one run I could get 10 bets with the same result.


Title: Re: Pentest Primedice 3 for bounties!
Post by: MasterOwel on August 14, 2014, 12:02:25 AM
I'm good with patterns and logic errors, meaning if there's an issue with the script that runs the site I could root around it figuring out ways to break the odds.


Title: Re: Pentest Primedice 3 for bounties!
Post by: MICRO on August 14, 2014, 12:04:51 AM
I'm good with patterns and logic errors, meaning if there's an issue with the script that runs the site I could root around it figuring out ways to break the odds.

Site is now live , everybody can pentest it . And if u find any bugs email support@primedice.com , if u are first to report it , u will get bounty .


Title: Re: Pentest Primedice 3 for bounties!
Post by: MasterOwel on August 14, 2014, 12:19:45 AM
I'm good with patterns and logic errors, meaning if there's an issue with the script that runs the site I could root around it figuring out ways to break the odds.

Site is now live , everybody can pentest it . And if u find any bugs email support@primedice.com , if u are first to report it , u will get bounty .

It's the same site isn't it? I haven't been able to connect the last few time I've tried.


Title: Re: Pentest Primedice 3 for bounties!
Post by: MICRO on August 14, 2014, 12:27:00 AM
I'm good with patterns and logic errors, meaning if there's an issue with the script that runs the site I could root around it figuring out ways to break the odds.

Site is now live , everybody can pentest it . And if u find any bugs email support@primedice.com , if u are first to report it , u will get bounty .

It's the same site isn't it? I haven't been able to connect the last few time I've tried.

Yeah on primedice.com . U should try using latest version of chrome , there is some issue with ff, should be sorted out rly soon thou .


Title: Re: Pentest Primedice 3 for bounties!
Post by: MasterOwel on August 14, 2014, 01:11:07 AM
I only use chrome, and all I get is an error message for that site.
Nothing is wrong with my internet or anything, the page loads quick and smooth,,,, but to the error.


Title: Re: Pentest Primedice 3 for bounties!
Post by: rz20 on August 15, 2014, 02:36:39 AM
I only use chrome, and all I get is an error message for that site.
Nothing is wrong with my internet or anything, the page loads quick and smooth,,,, but to the error.
It works in firefox and opera aswell.


Title: Re: Pentest Primedice 3 for bounties!
Post by: Kluge on August 30, 2014, 01:07:52 PM
Are all URL arguments disabled? Every time I try to enable poop function (in chat, they confirm it is /?poop=enabled), it hangs on loading screen (or does that happen if IP address is already connected to websocket?).