Show Posts
|
Pages: [1] 2 »
|
I have a great Idea, and it is FREE for the first customer! Here it is: Create a thread and say you are selling an idea. When someone buys it, tell your customer the same idea you are reading right now. It's a bit like ponzi: if noone wants to buy The Idea from you, then you lose your money.
The above is similar to a website, which promises you can make lots of money with a method. To get the method, you need to do a survey. If you do the survey, you get a text file telling you to create a website that gives users the exact same text file for a survey.
|
|
|
There is a bug in your site. It happens when an user retries payment from the failed page.
|
|
|
AutoShun thinks that every AlterVista site is malicious. Google "altervista autoshun", and check the VirusTotal results.
|
|
|
Is this on Bitcoin.SE, SO or an another SE site?
|
|
|
No , "Ponzi" the word itself is not worth of Trust , its main essence is to pay to early investor with the money of late investor and as soon as the total deposit exceed the owner wish(planned) , switch off the site and good bye !!
Did you read? I told that this would be a system where the owner cannot take all of the invested money. The owner simply wouldn't have every private key (and as you know, you cannot spend bitcoins without the private key).
|
|
|
Hi! I got the idea of creating a ponzi experiment where no one can run away with the money. It would be similar to peer-to-peer. But I don't want to waste my time, so I asked this question. What is your opinion?
|
|
|
Don't invest guys, for sure your BTC will be robbed.
dont spam just to earn in sig campaign.. will report you next time when you do that again i will report those who do spam just to earn in sig campaign.. and commenting without reading.. so be careful for those who comment without reading and those who say bad thing without trying.. Maybe he is speaking from experience? Also, if it pays out one time, it doesn't mean you won't get robbed next time.
|
|
|
Let's see who's the biggest fan!  Total time logged in: 17 hours and 36 minutes. --------------------- Updated 8/22/2014: Total time logged in: 16 days, 10 hours and 5 minutes.  4 minutes  Your first post! Total time logged in: 1 days, 12 hours and 46 minutes. According to my quick calculations, and counting since my registration date, this means I spend ~9% of my time here.
|
|
|
It says "LOGO" on the top left corner, and "Copyright PAMHYIP.com 2014" in the footer (bottom). (pamhyip.com seems to be the HYIP script) Broken images on FAQ. Domain expires on June 01 2016. Tried to call them, didn't work. If you have any questions, feel free to call us toll-free Toll-free: 1-234-567-8900 Looks legit. /s
|
|
|
I double-checked, and in my opinion this backdoor is fully intentional. ...strip...
The intention was not to take advantage of a backdoor. Instead it was a silly mistake meant to give the option for the admin to not have to relogin everytime. It has already been fixed and can be checked by faucet owner on the script.As I mentioned in the first post this has been done as a hobby and service is meant to be free. You can now check that it has been fixed. Thank you for bringing this up. My intention is to make honest business and help new faucet creators. I can confirm that the "remember" cookie bug is fixed. Thank you for acting so fast. I thought it's intentional because in the initial commit ( https://github.com/destinybogan/Faucet-Builder/commit/49e11c91812d020b677fe791faffb06e27da706c), there's no setcookie("remember"). This means you either wanted to write some code that sets the cookie but then forgot about it, or you backdoored the script and put a "remember me" checkbox to make it less suspicious. Sorry for accusing you if the former is the case. By the way, this script still has a security vulnerability which allows full write access to the database for everyone who can log in as admin.
|
|
|
Why do we have to use a program that is obfuscated with SmartAssembly and has full access to our computer instead of solving captchas in our web browser? Sounds a bit suspicious...
|
|
|
Which all languages do you know? is it only PHP? Do you know SOCKET.io? I have few scripts written in socket.io which I wanted to get tested.
Yes, I know JavaScript (socket.io is a JavaScript, more precisely NodeJS [EDIT: ofcourse it has client side too] library for real-time applications). Contact me if you have any more questions or just send me the script so I can take a look at it.
|
|
|
Is one $0.5 for 1 month or for what time? 'coz spotify has monthly payment for premium account. And BTW Spotify is giving out free trials. Are you trying to sell trial accounts?
EDIT: It seems to be that Spotify is not giving out free trials in the USA, only in my country. They only have a $0.99 three month offer.
|
|
|
I have an accented character in my last name (an "á" to be exact) and the site does not allow me to enter it. Will it be a problem when I try to verify?
|
|
|
I double-checked, and in my opinion this backdoor is fully intentional. He checks if the cookie called "remember" exists, but that cookie is not set anywhere. This means that the script expects that a human will set that cookie manually, because manually setting it is the only way it can exist.
|
|
|
Because lots of scripts have backdoors which can be used to steal bitcoins, I offer a service.
Send me a script or program, and I will check if it has any vulnerability, accidental or intentional, which can be used to do damage. I can check scripts where the source code is available. I can decompile Java and C# bytecodes.
You will not have to pay if I do not find any backdoors. I would appreciate a tip in that case, but it is optional. I may ask for some caution money depending on the size of the script and your account trust. Of course, I am willing to use escrow. I promise that I will not use the script you send me for any other purpose than checking for vulnerabilities, except if you say otherwise.
If you want me to check a script or program, contact me with your offer.
|
|
|
DO NOT USE THIS SCRIPT!!!EDIT: The OP has fixed the issue below and sent an e-mail to faucet owners. There are still some logic problems in that code but so far every "exploit" requires admin login. I will take a look at the fixed version. This script has a backdoor!!! On this page: https://github.com/destinybogan/Faucet-Builder/blob/master/admin/index.php The code contains:if(isset($_COOKIE['remember'])){ $_SESSION['admin']=true; } This means that if I set a cookie with the name "remember", I AM THE ADMIN! Hackers can set cookies because they are stored client-side and sent to the server in an HTTP header!
You may think that because it only shows the last four characters of your Xapo key, you are safe. But a hacker could increase the referral payout to something insanely high, disable the timeout, take the SolveMedia key and run a bot until all the coins are gone .
So do not use this script!
|
|
|
I'm noob here, but better to be safe. 1HfwxdUnjzr9FZt7JzGEdcR76Gta7nNzGp Text: I'm szgal, but this signature is publicly available, thus not proof in case my account gets stolen. Signature: Hxn88Igzv6u1s54UsQIOjyyte0j6Jf+dqZytPIL5aw6CYpfxhGaFJdOG5Stb4k8u+XzYYCpPpYT8xT28D7j6v1Y=
|
|
|
AFAIK you earn money if you work, not spend money to work...
|
|
|
Well, I'm afraid that if I put a demo, other people will steal it as this is fully client-side. But I am thinking about it. I thought the screenshots will be enough. Working on it.
|
|
|
|