Bitcoin Forum
November 09, 2024, 08:25:48 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 [5] 6 »  All
  Print  
Author Topic: [100bit.co.in] Earn up to 0.1 BTC for finding bugs  (Read 7132 times)
btc_enigma
Hero Member
*****
Offline Offline

Activity: 692
Merit: 569


View Profile
April 20, 2015, 01:14:39 PM
 #81

I can register with multiple emailids (sepearated by commas) in registration page

100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 21, 2015, 09:30:20 AM
 #82

what is this? http://www.100bit.co.in/admin , let me know if this helpful.
also maybe in 404 error page you should added text like " the page is not found " or something else

Like every user ID, admin ID can be seen as well. That is no bug.

404 error page is already in place - www.100bit.co.in/error404.php

MoonOfLife
Sr. Member
****
Offline Offline

Activity: 714
Merit: 253


View Profile
April 22, 2015, 10:51:24 AM
Last edit: April 22, 2015, 11:13:21 AM by MoonOfLife
 #83

in seting we cant edit our user id ?
i think you need add this seting ,, cause i cant remember my user id

edit:

and ..
i found this


just click thats image from http://www.100bit.co.in/home.php

if you click thats image from http://www.100bit.co.in/trade.php or anything its back to http://www.100bit.co.in/home.php

but if you click from http://www.100bit.co.in/home.php it say " You are already logged in " its mean thats button for sign in to the site  
100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 22, 2015, 05:56:35 PM
 #84

in seting we cant edit our user id ?
i think you need add this seting ,, cause i cant remember my user id

edit:

and ..
i found this


just click thats image from http://www.100bit.co.in/home.php

if you click thats image from http://www.100bit.co.in/trade.php or anything its back to http://www.100bit.co.in/home.php

but if you click from http://www.100bit.co.in/home.php it say " You are already logged in " its mean thats button for sign in to the site  

User ID is not editable. It is unique for every user. If you forget your User ID, it is always in your email inbox.

You have home button return to the user home page. Logo link is to return to the site's landing page. So, if you are logged in and click that logo, it'll always show you "You are already logged in".

None of the above are bug. Thanks for trying anyway...

MoonOfLife
Sr. Member
****
Offline Offline

Activity: 714
Merit: 253


View Profile
April 23, 2015, 02:15:34 AM
 #85

in seting we cant edit our user id ?
i think you need add this seting ,, cause i cant remember my user id

edit:

and ..
i found this


just click thats image from http://www.100bit.co.in/home.php

if you click thats image from http://www.100bit.co.in/trade.php or anything its back to http://www.100bit.co.in/home.php

but if you click from http://www.100bit.co.in/home.php it say " You are already logged in " its mean thats button for sign in to the site  

User ID is not editable. It is unique for every user. If you forget your User ID, it is always in your email inbox.

You have home button return to the user home page. Logo link is to return to the site's landing page. So, if you are logged in and click that logo, it'll always show you "You are already logged in".

None of the above are bug. Thanks for trying anyway...

i think its a bug , because at other site doesnt like that
here my address : 1JxXDzcnWk1sMR1JiG2agZeELEa6g95pXd  if you want to send some BTC
Albert Hamilton
Full Member
***
Offline Offline

Activity: 128
Merit: 100


View Profile
April 24, 2015, 02:10:47 PM
 #86

in seting we cant edit our user id ?
i think you need add this seting ,, cause i cant remember my user id

edit:

and ..
i found this


just click thats image from http://www.100bit.co.in/home.php

if you click thats image from http://www.100bit.co.in/trade.php or anything its back to http://www.100bit.co.in/home.php

but if you click from http://www.100bit.co.in/home.php it say " You are already logged in " its mean thats button for sign in to the site  

User ID is not editable. It is unique for every user. If you forget your User ID, it is always in your email inbox.

You have home button return to the user home page. Logo link is to return to the site's landing page. So, if you are logged in and click that logo, it'll always show you "You are already logged in".

None of the above are bug. Thanks for trying anyway...

i think its a bug , because at other site doesnt like that
here my address : 1JxXDzcnWk1sMR1JiG2agZeELEa6g95pXd  if you want to send some BTC

To me, these do not appear to be bug. These are more of improvement suggestion...
100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 26, 2015, 07:55:12 PM
Last edit: April 26, 2015, 08:35:06 PM by 100bitcoin
 #87

I can register with multiple emailids (sepearated by commas) in registration page

This one is expected to be fixed now. Please check at your end and let us know. Also, please provide your bitcoin address for a small bounty.

MoonOfLife
Sr. Member
****
Offline Offline

Activity: 714
Merit: 253


View Profile
April 27, 2015, 06:12:35 AM
 #88

suggestion

> add photo profile in seting
> change dashboard [ because your dashnboard is doesnt interesting ]
> add new feature on your site [ like  forum on your site ]
>  can sell LTC
>  enable contac seller for discount or anything *lol



_________

for bug .. i think its doesnt bug in  your site again 

_______
ask

03AHJ_Vuu3FUG45V4jKXui9Csz8rHSgdjqULKk9jIt71lGp1uyeoCJXG8QVr0TBcwRqRA0pjJkJMkXo l2rVc-ahk5Ojl1hzcZ9G0r0MPkvePeJd_AueZwA7wgmcTKhAC039YtGTPiytye6hYJlRRwBt9xSCUG4zO3D7i0aXikE9e64ojGloq7f_Pz-3GWEfxeKgKzvZlVWcCSL078cHcO35cWhgczdocyLm8TgCqxAJdurAAf8N73J9tmQNZgm-9nFyaNtwS2ptNS_kjlbzuMohpV4fcm8tgu1CA

what is that it show  up after in password after write captcha your  site say " please copy this ... "
GiocareHost
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
April 27, 2015, 09:42:04 AM
Last edit: April 27, 2015, 02:39:55 PM by GiocareHost
 #89

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).
2.)Registration form without CSRF protection.
3.)Session cookie is without Secure flag set & HTTP only flag set.
4.)Vulnerable to Click jacking.
In total I have detected 4 Major bugs which can be very harmful for your site.
I can explain them to you,if you want.
I hope you will not break your promise and send me 0.4 BTC to 1FzWfTTy8YCh1fRBBZ9Fuyym85Xoe4qYL8
add one more bug,
user details are transmitted over an unencrypted channel.
That makes it 0.5BTC



 
CoinFriend
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


support.


View Profile
April 27, 2015, 06:08:01 PM
 #90

hey admin, why do you have two different threads?

why is no information about the BETA status on your website?

and why do you provide so less information about your site.

why you didn't answer my questions personally on the other thread?
https://bitcointalk.org/index.php?topic=985796.0

- https://www.cryptopia.co.nz  - your one stop crypto shop  -
Exchange, Mineshaft, Marketplace and much more. Check it out Smiley
Victor Beckham
Full Member
***
Offline Offline

Activity: 243
Merit: 100


View Profile
April 27, 2015, 06:17:36 PM
 #91

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).
2.)Registration form without CSRF protection.
3.)Session cookie is without Secure flag set & HTTP only flag set.
4.)Vulnerable to Click jacking.
In total I have detected 4 Major bugs which can be very harmful for your site.
I can explain them to you,if you want.
I hope you will not break your promise and send me 0.4 BTC to 1FzWfTTy8YCh1fRBBZ9Fuyym85Xoe4qYL8
add one more bug,
user details are transmitted over an unencrypted channel.
That makes it 0.5BTC

LoLz... according to OP, you may get up to 0.1BTC. It is not 0.1BTC per bug. Check about the others who got paid before you. They found more bugs than you have found.

Albert Hamilton
Full Member
***
Offline Offline

Activity: 128
Merit: 100


View Profile
April 27, 2015, 06:53:03 PM
 #92

hey admin, why do you have two different threads?

why is no information about the BETA status on your website?

and why do you provide so less information about your site.

why you didn't answer my questions personally on the other thread?
https://bitcointalk.org/index.php?topic=985796.0

As I can see, the registration page clearly says that the site is in BETA...

www.100bit.co.in/register.php
100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 27, 2015, 10:12:32 PM
 #93

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).
2.)Registration form without CSRF protection.
3.)Session cookie is without Secure flag set & HTTP only flag set.
4.)Vulnerable to Click jacking.
In total I have detected 4 Major bugs which can be very harmful for your site.
I can explain them to you,if you want.
I hope you will not break your promise and send me 0.4 BTC to 1FzWfTTy8YCh1fRBBZ9Fuyym85Xoe4qYL8
add one more bug,
user details are transmitted over an unencrypted channel.
That makes it 0.5BTC

Please note that, maximum payment you may receive is 0.1BTC and you need to provide explanation of your bugs. We have sent you PM regarding this.

100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 27, 2015, 10:19:49 PM
 #94

suggestion

> add photo profile in seting
> change dashboard [ because your dashnboard is doesnt interesting ]
> add new feature on your site [ like  forum on your site ]
>  can sell LTC
>  enable contac seller for discount or anything *lol
_________

for bug .. i think its doesnt bug in  your site again 


Thank you for the suggestions. You can already sell LTC and communicate with seller when the order is in progress. Nice to know that you did not find any bug.


ask

03AHJ_Vuu3FUG45V4jKXui9Csz8rHSgdjqULKk9jIt71lGp1uyeoCJXG8QVr0TBcwRqRA0pjJkJMkXo l2rVc-ahk5Ojl1hzcZ9G0r0MPkvePeJd_AueZwA7wgmcTKhAC039YtGTPiytye6hYJlRRwBt9xSCUG4zO3D7i0aXikE9e64ojGloq7f_Pz-3GWEfxeKgKzvZlVWcCSL078cHcO35cWhgczdocyLm8TgCqxAJdurAAf8N73J9tmQNZgm-9nFyaNtwS2ptNS_kjlbzuMohpV4fcm8tgu1CA

what is that it show  up after in password after write captcha your  site say " please copy this ... "


Can you please provide a screenshot of this ? Also, please let us know when you are getting this and in which browser.

100bitcoin (OP)
Sr. Member
****
Offline Offline

Activity: 860
Merit: 423


View Profile WWW
April 27, 2015, 10:29:01 PM
 #95

hey admin, why do you have two different threads?

why is no information about the BETA status on your website?

and why do you provide so less information about your site.

why you didn't answer my questions personally on the other thread?
https://bitcointalk.org/index.php?topic=985796.0

Extremely sorry for the delay. We were little busy in providing support on the site. We have replied to you in the Active Trader thread as well. This one is for bug bounty. So, there are 2 different threads. Thank you for your interest. Smiley

MoonOfLife
Sr. Member
****
Offline Offline

Activity: 714
Merit: 253


View Profile
April 28, 2015, 01:31:11 AM
Last edit: April 28, 2015, 01:51:58 AM by MoonOfLife
 #96

suggestion

> add photo profile in seting
> change dashboard [ because your dashnboard is doesnt interesting ]
> add new feature on your site [ like  forum on your site ]
>  can sell LTC
>  enable contac seller for discount or anything *lol
_________

for bug .. i think its doesnt bug in  your site again  


Thank you for the suggestions. You can already sell LTC and communicate with seller when the order is in progress. Nice to know that you did not find any bug.


ask

03AHJ_Vuu3FUG45V4jKXui9Csz8rHSgdjqULKk9jIt71lGp1uyeoCJXG8QVr0TBcwRqRA0pjJkJMkXo l2rVc-ahk5Ojl1hzcZ9G0r0MPkvePeJd_AueZwA7wgmcTKhAC039YtGTPiytye6hYJlRRwBt9xSCUG4zO3D7i0aXikE9e64ojGloq7f_Pz-3GWEfxeKgKzvZlVWcCSL078cHcO35cWhgczdocyLm8TgCqxAJdurAAf8N73J9tmQNZgm-9nFyaNtwS2ptNS_kjlbzuMohpV4fcm8tgu1CA

what is that it show  up after in password after write captcha your  site say " please copy this ... "


Can you please provide a screenshot of this ? Also, please let us know when you are getting this and in which browser.

sorry i forget screenshot  
browser :UcBrowser [ mobile browser ]
and can u add :
> converter btc to any currency
>  and currency BTC to $  graph

i will very thx if you donate me / pay me for some btc
1JxXDzcnWk1sMR1JiG2agZeELEa6g95pXd
Albert Hamilton
Full Member
***
Offline Offline

Activity: 128
Merit: 100


View Profile
April 28, 2015, 10:53:21 AM
 #97

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).

I wonder how do u brute-force here ? They are behind CloudFlare. Your loop wont work from browser/iframe/command prompt.
CoinFriend
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


support.


View Profile
April 28, 2015, 11:43:00 AM
 #98

hey admin, why do you have two different threads?

why is no information about the BETA status on your website?

and why do you provide so less information about your site.

why you didn't answer my questions personally on the other thread?
https://bitcointalk.org/index.php?topic=985796.0

Extremely sorry for the delay. We were little busy in providing support on the site. We have replied to you in the Active Trader thread as well. This one is for bug bounty. So, there are 2 different threads. Thank you for your interest. Smiley

thanks for reply.
I am a little bit confused now. I don't understand why you didn't offer the same reward for the active traders, for finding bugs. Does someone who is active not deserve a reward if he found something wrong?

And why is there no information / link about the other thread on each?
Are this both really the only two? Or is there also one where you explain how your site works and what i can do with your site?
I like to know this information before i fill out register form on a site!

And yeah, i understand that you must be busy if you have to manage two threads to support your site^^
Later i have look what you reply in the Active Trader thread as well...

- https://www.cryptopia.co.nz  - your one stop crypto shop  -
Exchange, Mineshaft, Marketplace and much more. Check it out Smiley
GiocareHost
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250



View Profile
April 28, 2015, 02:21:29 PM
 #99

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).

I wonder how do u brute-force here ? They are behind CloudFlare. Your loop wont work from browser/iframe/command prompt.
They have a basic Plan of cloudflare,which couldn't protect them if I use iframe.
Albert Hamilton
Full Member
***
Offline Offline

Activity: 128
Merit: 100


View Profile
April 28, 2015, 03:34:02 PM
 #100

I HAVE A BUG TO REPORT.
1.)Your website is vulnerable to Brute-force attack,since the login form is not asking for Captcha's(No captcha on the home page Login Box).

I wonder how do u brute-force here ? They are behind CloudFlare. Your loop wont work from browser/iframe/command prompt.
They have a basic Plan of cloudflare,which couldn't protect them if I use iframe.

I'm under attack mode is available under free plan only. Moreover they initially had a CAPTCHA on the home page as well as you'll find in the screenshot in OP. May be they are not using it right now for some reason...
Pages: « 1 2 3 4 [5] 6 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!