Bitcoin Forum
November 10, 2024, 01:50:45 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: LuckyBitcoinCasino.com Hack  (Read 583 times)
lucky34 (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
November 12, 2013, 08:30:07 PM
 #1

(Feel free to quote or link this post in the LuckyBitcoinCasino.com Thread)

"Hacker" here. In short, I manipulated a game on LuckyBitcoinCasino.com to let me bet coins I didn't actually have. The API for the roulette game accepted negative bets. E.g. I was able to bet 100 coins on black, 100 coins on red and -199 coins on the number 34. This cost me exactly 1 coin, with the likely outcome that I would win 199.
   
The site also has a number of other security issues that I detailed via the support form to the site's owner, including the "right" way to fix them. So far, they have failed to acknowledge these flaws.

Just as an example, a blatant XSS flaw:
https://www.luckybitcoincasino.com/forgot.php?message=%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
(Note that many modern browsers will now actually filter out JS passed via the URL. However, it's a bad idea to rely on this.)

I also noticed a number of SQL injection flaws around the site. The codebase seems to be very inconsistent in what is filtered and what isn't.

tl;dr: contrary to what the author(?) of the site proclaims, there's no such thing as "bug free code".
flooraccount
Full Member
***
Offline Offline

Activity: 157
Merit: 100


View Profile WWW
November 12, 2013, 11:07:01 PM
Last edit: November 12, 2013, 11:27:32 PM by flooraccount
 #2

Hey Lucky34. Just because you are a thief doesn't mean everyone else wants to be. My understanding this was patched 2 days ago while YOU were in game play.
If it wasn't, you would still be out robbing people wouldn't you?
There are some small XSS issues however nothing to "Hack". If you are not a thief you have no problem returning the 2.8 Bitcoins you stole from us eh?

smeagol
Legendary
*
Offline Offline

Activity: 1008
Merit: 1005



View Profile
November 12, 2013, 11:36:37 PM
 #3

Hey Lucky34. Just because you are a thief doesn't mean everyone else wants to be. My understanding this was patched 2 days ago while YOU were in game play.
If it wasn't, you would still be out robbing people wouldn't you?
There are some small XSS issues however nothing to "Hack". If you are not a thief you have no problem returning the 2.8 Bitcoins you stole from us eh?

You should return the bitcoins.  They may give you some for finding the bug though.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!