Bitcoin Forum
May 08, 2024, 04:18:30 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 [126] 127 128 »
2501  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: December 03, 2014, 02:59:32 PM
Crap. What an awful day to sleep in. It was a pretty basic DoS on the site, triggering a case that I haven't hardened for.  I have the game back up and running, with the offending ips banned. I'm working on preventative measure to stop that being able to happening again, and to automatically pause the game when things are going haywire instead of marching on creating a awful mess.

Right now there's 27 unterminated games, and several dozens of cashouts that were not able to be applied. Please no one worry, over the next couple of hours I'll get to restoring everything and making sure no one was disadvantaged by this.
2502  Economy / Gambling / Re: So I gambled 3 bitcoin on a dice site and won 5 back. Any other good ones? on: December 03, 2014, 04:18:44 AM
Poker and moneypot are the main two games that I know of that make +EV bitcoin gambling possible. If you want any strategy (and not just a fancy skin on top of a RNG) you will need to play something with a player-vs-player aspect, as no casino is going to wittingly accept -EV play.
2503  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: December 03, 2014, 03:41:08 AM
I've finally completely ripped out the coinbase dependency and all deposits and withdrawals are directly using bitcoin core. I've watched the last dozens of transactions and the migration seems to have gone rather seemlessly without interrupts or delays. If anyone has any problems or issues, please let me know.
2504  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: December 02, 2014, 10:08:31 PM
i know of a major bug !   Smiley  yet you refuse to pay the bounty !!! your credibility is shit .. lmfao

I guess this would be you?

look do you want the ranting to stop ? send me the the ten bitcoins and the owl will go home to roost. The bug is something i discovered that allows players to crash each other.... lets resolve this
2505  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: December 02, 2014, 10:00:56 PM
I do not believe it was stealing, as many times I've openly offered bounties of that order of magnitude. He merely pulled it from me, rather than wait on me to push it to him. And that's fine by me, what he found was clearly worth a lot more than that.

In my experience it is hard to get paid properly for an exploit, so he helped himself to what he considered his work to be worth. That's questionable morally, of course, but he put a lot of work into developing the exploit code and wanted to make sure he was suitably rewarded for it. He reported it to MoneyPot in a responsible manner, and shared his exploit code once it was fixed.

I'm not sure what motivates him, but if he ever wants to claim credit and add it to his list of achievements, I wanted to be clear that I bear no ill will, nor do I feel wronged (but rather the contrary).
2506  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: December 02, 2014, 07:04:29 PM
Does this mean he got was able to withdraw and keep 5 btc on account of the exploit?

Yes. He had used the exploit to get somewhere in the order of over 30 BTC in profit. He did withdraw his original deposit, plus 5 BTC as a bounty for finding the exploit. Had he wanted, he would have been allowed to withdraw up to 25 BTC which was the contents of the hot wallet. But being a decent guy he didn't even make an attempt to do so, something that I am very grateful for.
2507  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 30, 2014, 02:56:59 AM
Great explanation, as always, Dooglus. The only thing missing is the adding that one reason for the complexity in the exploit was that the game ticks are scheduled using a setTimeout after the last game tick, as opposed to on fixed intervals or at particular game multipliers. When enough people cash out at a particular point in time, it actually makes an extremely large (~50ms?) impact on the game tick. Since it's using non-blocking IO, I'm not quite sure why this is. But regardless there's quite a bit of work involved in just figuring out when the game ticks will run to be able to abuse the exploit.

I'm really impressed by the person who abused this bug. Not only due to the complexity of the exploit, but the fact he only took 5 of the 25 BTC in the hot wallet. He likely could have slowly abused the bug leading the eventual shutdown of MP, but instead was a class act. I'm really thankful for that and working on better security measures so I won't need to rely on the kindness of strangers as much.
2508  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 30, 2014, 02:30:30 AM
How is the code exploitive? I am new to this like a lot of others too.

It requires quite an in-depth understanding of moneypot source to understand. But the high level of it is that money pot's game_end event was leaking information (or more precisely the lack of money pot's game_end event) which could be abused by taking advantage of dynamically moving the autocashout amounts (something that is now disabled).

Because it was so timing sensitive, the code had to be rather complex taking into consideration network latency to decide how and when to act.
2509  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 29, 2014, 12:37:34 AM
Foo has provided me with his exploit code:

http://privatepaste.com/164b29a720
http://privatepaste.com/9c14190b93
http://privatepaste.com/f4ebeb9b19


Highly impressive stuff! Hats off to you foo!
2510  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 28, 2014, 05:03:47 PM
Yeah, he said he was willing to put the code available online as a lot of work went into it. I'd be extremely interested in seeing it. Some of the timing stuff would be rather challenging to pull off
2511  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 28, 2014, 02:14:53 PM
Remember these guys want you to possibly invest I'm the bankroll in the future also, don't trust shoddy coding.

Had it been the same scenario, it wouldn't have been a big issue: I'd obviously cover such expenses out of my own pocket first. Had the person been less honorable and slowly bleed the site and investors, it'd truly be a nightmare situation. I shudder just thinking about it. But I guess ultimately the price one has to pay to be +EV.

On the plus side, the code is on github for anyone to review and critique, and possibly even pay someone to audit it. If you read how his exploit works, I would argue it a very clever exploit that wasn't the result of shoddy coding, but using a non-obvious and clever way to leak information. Either way, I will slow things down and do a more comprehensive security audit and hardening of everything, including adding some non-public alarms and triggers for suspicious behavior.
2512  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 28, 2014, 01:48:39 PM
Sorry guys, I was asleep! Thanks for letting me know. Foo did find an exploit, and was kind enough to reveal it. I have quickly pushed up a fix, and purged Foo's games from the database to preserve meaningful stats.

Foo used quite a clever exploit in some what should be dead code: http://privatepaste.com/354dae40cd

I'd like to thank him for not abusing the bug further, or slowly bleeding me over time. I'm extremely thankful for that, that would have been a nightmare situation. Thanks Foo!

Sorry about all the drama people, please enjoy the game.
2513  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 25, 2014, 02:01:59 AM
Why the hate? That site is awesome. You have a faucet there, it's a fun game, awesome for some boredom and the guys in the chat room are insane. Cheesy Never really got anything but it sure was a lot of fun.

I wasn't aware there was any hate? Cheesy Glad you enjoyed the game too!
2514  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 17, 2014, 04:59:55 AM
Big thanks to CSM for his contribution to MP, bringing the goodness of 2FA, which is now live!
2515  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 16, 2014, 05:12:38 AM
In the chat we were discussing different chART, here's my favorite:



the reverse martingale!
2516  Economy / Gambling / Re: BitDice.me 1%, >1000฿ INVESTED. >41฿ MAX PROFIT. OPEN SINCE FEB 2014. on: November 14, 2014, 11:53:53 PM
Guys, got another extort email Smiley Server under DDoS now.

Interesting. A message with the same language was sent to MoneyPot.com, but asking for 5 BTC (and doubling to 10) and with an attack said to last 4 days. I guess the guy is A/B testing his extortions.
2517  Economy / Gambling / Re: ChairmanMeow Sports Picks on: November 14, 2014, 11:47:57 PM
You should consider getting a blog or twitter account for these picks. It'll make it a lot easier to follower your picks, and less noisy for people who aren't. Or if you insist on using the forums, the "Game and rounds" is much more suitable for this sort of thing.
2518  Economy / Service Discussion / Re: Beware of 7bit.com on: November 14, 2014, 11:18:13 PM
Did you claim that 50% deposit bonus, which appears to be opt-in and says:

Quote
Simply make a deposit of 200mBTC or more and you will be entitled to a 50% bonus on your qualifying deposit up to a maximum of 2000mBTC. Please note you will need to play through your deposit and bonus 30 times prior to making a withdrawal. Other terms apply.

or did they apply the restriction to your account, without you claiming that bonus?

2519  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 14, 2014, 12:48:41 AM
Check out our latest release, with a totally rewritten strategy tab that also supports easy bet progressions. All custom strategies will need to be modified from using  .onGameCrash  to  .on('game_crash', ...)  and a few other mechanical 1:1 changes. This is to allow far more compossible strategies (e.g. using an autobet, while sniping)
2520  Economy / Gambling / Re: MoneyPot.com -- The Social Gambling Game on: November 13, 2014, 09:42:41 PM
People wander the forums making one-line content-free posts simply to "level up" and get paid more for their signature spam.

Nailed it, and why I discontinued the MoneyPot.com signature program. MP will get less visibility now for sure, but at least it should do so for the right reasons.
Pages: « 1 ... 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 [126] 127 128 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!