Bitcoin Forum
June 27, 2024, 10:50:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 7 8 9 10 11 [12] 13 14 15 16 17 18 19 20 21 22 23 24 »
221  Local / 中文 (Chinese) / Re: 大家可能都忘记了Satoshi Nakamoto的团队有超过1百万的bitcoin(和预挖类似,因为当时没&# on: October 26, 2013, 07:16:17 PM
大家可能都忘记了Satoshi Nakamoto的团队有超过1百万的bitcoin。所以比特币的涨幅是有限的。

那是他因得的!不过作为创始人, 他因该比谁都想要比特币发扬光大, 所以你不用担心。
222  Bitcoin / Development & Technical Discussion / Re: How do you know how much transaction fee to deduct before sending the payment? on: October 26, 2013, 07:12:22 PM
You should probably just eat the fee or increase your other fees to compensate for the fees. You should not charge users for the fees caused by their withdrawals because the actual fee depends on transactions that other users are making. If someone funds their account with 100 transactions adding up to 0.2 BTC, the large number of transactions will increase fees for everyone. That transaction you referenced is expensive due to this kind of wallet fragmentation, not because the transaction's value is large.

Quote
I have my fees set to 0.0001 BTC for my customers in the bitcoin.conf file

That's unnecessary. Bitcoin-Qt will never use a too-low fee. Even if you set your fee to 0, you will pay fees.

Thanks, I've raised the transaction fee to 0.0005, but now I'm starting seeing this kind of 0.0015 transaction fees which I'm eating up most of it. it seems quite expensive.

https://blockchain.info/tx/8dc313847cb52e4ea11022341314180f5080f870d617c05a49ea5b6bc7772094

how do I lower these wallet fragmentation to reduce fees?
223  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 06:46:59 PM
Finally, if you intend to help the community, you should disclose the bugs reported after you fix them.

Bug Disclosures:

Christy Philip Mathew found a local XSS bug in the next field entering the name text field. Javascript input was escaped on the server side, but was displayed on the client side in the html without escape, so no code injection could be made other than the attackers own computer.

The following 3 members all reported the same bug about the same time, which is a non severe XSS in the url that could only execute an alert message. document.location and document.cookie could not be executed so we deem this bug to be not severe.
- Issam Rabhi - @Issam_Rabhi
- Anand M
- Siddhesh Gawde

A small bitcoin reward had been sent to all these disclosures as a token of thank you.
224  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 05:30:53 PM
Ok, I will check later, crawl for info and some automate test but is intense for my CPU so I will wait until not in use.

Can you allow all IP?  VPN I use is blocked, if I use home IP ISP can ban me.  Counterproductive to have any IP filter for server running test.  Server may automatic block IP for too many request, we know this works so can you turn it off?



All IP is open, and VPN should be allowed.

I reported your first bugs and you try to throw me under the bus, watch me "test" your real site...lol you want me to?  Grin

I wrote you a letter by the way, you might want to take a look:

https://bitcointalk.org/index.php?topic=318830.0
225  Local / 中文 (Chinese) / Re: 聘请:网上营销 + 社交媒体 + 网上广告, 比特币底薪加提成 on: October 26, 2013, 05:29:56 PM
你这个应该招聘我来做适合,本人做过一年的SEO,有一点点点经验吧。

我只知道国外SEO的方法,但不知道国内的。 听说百度是要给红包才给你放排行到前面。
百度还真不是一般的黑,赌博站给红包它也不会做的,很多国内BBS也不能正常推广的,要另想途径。

我给你发了PM
226  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 05:24:12 PM
Ok, I will check later, crawl for info and some automate test but is intense for my CPU so I will wait until not in use.

Can you allow all IP?  VPN I use is blocked, if I use home IP ISP can ban me.  Counterproductive to have any IP filter for server running test.  Server may automatic block IP for too many request, we know this works so can you turn it off?



All IP is open, and VPN should be allowed.
227  Economy / Scam Accusations / Re: Cease and Desist Letter to ASICSRUS on: October 26, 2013, 05:21:39 PM
Let me get this straight:  You run a gambling site (illegal in US) & plan to prosecute some_guy_on_the_internet, citing US state law?  You don't see a problem here?

"The Unlawful Internet Gambling Enforcement Act of 2006 (UIEGA) did not specifically prohibit online gambling; instead, it outlawed financial transactions involving online gambling service providers."
http://en.wikipedia.org/wiki/Gambling_in_the_United_States#Legal_issues

Currently US law say it's illegal to take credit card for payment for online gambling, it doesn't actually say online gambling is illegal. This means sites that take Bitcoin is not yet illegal until they change the law.

228  Economy / Scam Accusations / Cease and Desist Letter to ASICSRUS on: October 26, 2013, 05:07:13 PM
Background
ASICSRUS is a huge troll who blackmail and spread false rumours to extort for bitcoins. He would come to ice-dice everyday with different account begging for free bitcoins, and make threats. He would reply to every one of my thread telling people I don't pay out and owe him money.

What he is doing is classified as Libel and Slander, aka defamation, which is illegal and if he does not stop, I will be taking legal action against him.

To ASICSRUS:
If you don't stop what you are doing immediately and also delete all your defamatory posts in the past, you will be sure that legal actions would be taken against you. What you are doing is illegal, and there has been successful lawsuits against people like you in the past. People like you had been fined millions previously from law suites. I highly recommend you not to go down that path.

In Varian v. Deflino & Day two former employees had libeled Varian executives by posting more than 14,000 defamatory messages on over 100 different websites. The jury found that the defendants liable for defamation as well as misappropriation of the executives names.

In 2006 a Florida court awarded a plaintiff $11.3 million dollars when the defendant posted numerous comments on message boards defaming the plaintiff and her business reputation. The court did not specify whether the cause of action was based on libel or slander.

- See more at: http://defamation.laws.com/defamation-laws/libel-vs-slander#sthash.5PZjFx8E.dpuf



You have 1 week from today to delete all your defamatory posts and apologize to me before I start seeking legal actions. If you think you can hide behind your internet nickname thinking you are anonymous, you will be in for an surprise how easy your real identity could be tracked down.

Sincerely,

David Lee
229  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 04:42:29 PM
To the guy with IP: 115.242.186.210 from Chennai, India:

So if someone tries to find a vulnerability you post his IP ? This might, or might not, be his actual IP, but aren't you supposed to keep this information (and other you might collect) private ? He/she might be trying to help you after all...  if I had any interest on this, now I would surely never give it a try.

Also, every related program I've seen paid much more than what you're offering. I don't see why anyone not so honest with an actual bug would sell it to you. Be clear about what you would actually pay, "There is no maximum reward" is not clear at all.

Finally, if you intend to help the community, you should disclose the bugs reported after you fix them.

You are right, I had a misunderstanding. At the time I thought he was being malicious and what he was doing looked like a DDOS so I posted his IP. It was a mistake I shouldn't have.

Why not put test site on different server?  Vulnerability scan is intense, what you what the india guy to do, page by page manuall?
Minimum one need to run crawler and catch all file and pages to look at manually.

It is on a different server. You are right I had a misunderstanding. I thought he was being malicious.

PS. This ASICSRUS guy is a troll. just look at his post histories. He blackmails and spread rumours about all the casino owners in order to extort for bitcoins.
230  Local / 中文 (Chinese) / Re: 聘请:网上营销 + 社交媒体 + 网上广告, 比特币底薪加提成 on: October 26, 2013, 10:04:20 AM
你这个应该招聘我来做适合,本人做过一年的SEO,有一点点点经验吧。

我只知道国外SEO的方法,但不知道国内的。 听说百度是要给红包才给你放排行到前面。
231  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 09:38:48 AM
Do not test on the main site, use http://testnet.ice-dice.com only! If you exploit the main site, you will not be eligible for rewards!
232  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 07:18:49 AM
To the guy with IP: (edit: sorry, shouldn't have posted this) from Chennai, India:

You are flooding the server with the same POST request over and over again. The CSRF protection is automatically blocking your submission and what you are doing won't actually find any bugs. It will just waste bandwidth.
233  Bitcoin / Development & Technical Discussion / Re: Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 06:11:11 AM
Christy Philip Mathew - @christypriory found a non-severe bug that will not cause financial loss or data breach. A smaller reward was given to thank him for his effort.
234  Economy / Gambling / Re: [Ice-Dice.com] Free 0.005 BTC | 50% Referral Commission | Invest or Play on: October 26, 2013, 03:31:16 AM
how we get 0.0005 bonus ?

just visit https://ice-dice.com then click on "get free bitcoins"
235  Local / 中文 (Chinese) / Re: 聘请:网上营销 + 社交媒体 + 网上广告, 比特币底薪加提成 on: October 26, 2013, 02:47:22 AM
1,那些赌场服务器都不在国内
2,他们的营销也没有公开到微博或主流网站上。
3,建议你在比特币相关网站和论坛推广即可,如果你想扩大营销范围可能会存在不可知的风险,另外我觉得性价比也不会好

你的建议不错。 你知道一些中文关于比特币的论坛吗?
236  Economy / Services / Looking for hackers and security researchers on: October 26, 2013, 02:39:50 AM
Ice-dice.com launched our bug bounty program, hackers and security researchers can get paid doing what you do best:

See this thread for detail:

https://bitcointalk.org/index.php?topic=318347.0
237  Economy / Securities / Re: [Ice-Dice.com] 0% Investor Commission! | Multiple Languages | Invest or Play on: October 26, 2013, 02:35:20 AM
Just launched our bug bounty program, see this thread for detail:

https://bitcointalk.org/index.php?topic=318347.0
238  Economy / Gambling / Re: [Ice-Dice.com] Free 0.005 BTC | 50% Referral Commission | Invest or Play on: October 26, 2013, 02:34:17 AM
Just launched our bug bounty program, see this thread for detail:

https://bitcointalk.org/index.php?topic=318347.new#new
239  Local / 中文 (Chinese) / Re: 聘请:网上营销 + 社交媒体 + 网上广告, 比特币底薪加提成 on: October 26, 2013, 02:33:18 AM
网络赌博在国内是非法的,微博等公开营销估计会被封禁

但比特币不是人民币, 因该没问题吧。 何况国内不是有好几家比特币赌场了吗?
240  Bitcoin / Development & Technical Discussion / Ice-Dice.com Bug Bounty Program On Testnet Subdomain on: October 26, 2013, 02:30:31 AM
Ice-Dice.com understands the important of security and the safety of our customers and investors bitcoins is very important to us. This is why we are launching our bug bounty program and launched our Testnet subdomain http://testnet.ice-dice.com for security researchers to find vulnerabilities.

We ask all security researchers to:

- Do not test on the main site, use http://testnet.ice-dice.com only! If you exploit the main site, you will not be eligible for rewards!
- Providing us a reasonable amount of time to fix the issue before publishing it elsewhere.
- Making a good faith effort to not leak or destroy any production user data (testnet website is fine)
- Not defrauding Ice-Dice.com users or Ice-Dice.com itself in the process of discovery.
- In order to encourage responsible disclosure, we promise not to bring legal action against researchers who point out a problem provided they do their best to follow the above guidelines.

Rewards

The minimum payout is 0.5 bitcoin for reporting a previously unknown security vulnerability of sufficient severity. There is no maximum reward, and we may award higher amounts based on severity or creativity of the vulnerability found.

We also provide attribution as a thank you.

Eligibility

We reserves the right to decide if the minimum severity threshold is met and whether it was previously reported.

In general, anything which has the potential for financial loss or data breach is of sufficient severity, including:

- XSS
- CSRF
- Authentication bypass or privilege escalation
- Click jacking
- Remote code execution
- Obtaining user information

In general, the following would not meet the threshold for severity:

- Vulnerabilities on sites hosted by third parties unless they lead to a vulnerability on the main website
- Denial of service
- Spamming
- Vulnerabilities in third party applications

To Submit a bug report, please email icedicedavid@gmx.com with the following:

- Description and potential impact
- Steps to reproduce the issue or a proof of concept

Severe Awards
- none yet

Non-Severe Awards (Bugs that will not cause financial loss or data breach)
- Christy Philip Mathew - @christypriory
- Issam Rabhi - @Issam_Rabhi
- Anand M
- Siddhesh Gawde
- Sahil Saif
Pages: « 1 2 3 4 5 6 7 8 9 10 11 [12] 13 14 15 16 17 18 19 20 21 22 23 24 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!