Bitcoin Forum
May 30, 2024, 08:57:39 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 »  All
  Print  
Author Topic: [NEW] FreeDice - Pre-Launch Bonus 0.005 BTC for free [only for 100 first users]  (Read 2355 times)
Patatas
Legendary
*
Offline Offline

Activity: 1750
Merit: 1115

Providing AI/ChatGpt Services - PM!


View Profile
August 11, 2015, 02:49:56 PM
 #41

.esy.es? This seems a sub domain from a free hosting site (hostinger)
I don't want to judge OP , but why?
Scaccomatt0
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000


https://cryptoworld.io


View Profile WWW
August 11, 2015, 02:53:49 PM
 #42

And if all password are stored in cleartext.. it means two things:
1) really newbie coder (kid?)  Huh
2) scam, phishing website..  Huh

Never store sensitive data in cleartext.

Am I wrong? Smiley

Please, fix your website

       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
               ______
          __███████████████_      █████         █████          █████           █████
       _█████████████████████      █████         █████        █████           █████
     _███████¯¯¯     ¯¯██████       █████         █████      █████           █████
   _██████¯            ¯████¯        █████         █████    █████           █████
  ██████¯                             █████          ██████████            █████
 ██████                               █████          ██████████            █████
 █████                                 █████         ██████████            █████
█████                                  █████          ████████            █████
█████                                  █████           ██████             █████
█████                                  █████           ██████             █████
█████                                  █████           ██████            █████    
█████                                   █████          ██████          █████    
 █████                                  █████          ██████          █████
 ██████                                 █████          ██████        █████
  ██████_                                █████         ██████        █████
   ¯██████_            _████_            █████        ████████       █████
     ¯███████___     __██████            █████      █████  █████     █████
       ¯█████████████████████             █████    █████    █████   █████
          ¯¯███████████████¯               ████████████      ███████████
               ¯¯¯¯¯¯                      ¯¯¯¯¯¯¯¯¯¯         ¯¯¯¯¯¯¯¯¯¯
|
  
FAUCET
ICO
ANDROID
       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
mcfom
Legendary
*
Offline Offline

Activity: 1260
Merit: 1001


View Profile
August 11, 2015, 02:55:38 PM
 #43

Will see how this dice site works just submitted some info there.
Sarthak
Hero Member
*****
Offline Offline

Activity: 518
Merit: 501

Error 404: there seems to be nothing here.


View Profile
August 11, 2015, 03:27:44 PM
 #44

This site seriously sucks  Angry

Firstly the sql error:
Code:
Error: INSERT INTO Login(Username, Password, Email) VALUES ('admin' OR 1=1', 'admin' OR 1=1', ' admin' OR 1=1')
You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '', 'admin' OR 1=1', ' admin' OR 1=1')' at line 2

Secondly.. Just type in <script>alert('XSS')</script> in any of the registering field like Username...An popup appears saying "XSS"!
Also vulnerable to XSS! Website security = 0

Scaccomatt0
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000


https://cryptoworld.io


View Profile WWW
August 11, 2015, 04:08:44 PM
 #45

For who sent registrations details, pay attention.. your credentials are available to all  Cool

Who used as password, the same for the email address, CHANGE immediately the mail password!

       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
               ______
          __███████████████_      █████         █████          █████           █████
       _█████████████████████      █████         █████        █████           █████
     _███████¯¯¯     ¯¯██████       █████         █████      █████           █████
   _██████¯            ¯████¯        █████         █████    █████           █████
  ██████¯                             █████          ██████████            █████
 ██████                               █████          ██████████            █████
 █████                                 █████         ██████████            █████
█████                                  █████          ████████            █████
█████                                  █████           ██████             █████
█████                                  █████           ██████             █████
█████                                  █████           ██████            █████    
█████                                   █████          ██████          █████    
 █████                                  █████          ██████          █████
 ██████                                 █████          ██████        █████
  ██████_                                █████         ██████        █████
   ¯██████_            _████_            █████        ████████       █████
     ¯███████___     __██████            █████      █████  █████     █████
       ¯█████████████████████             █████    █████    █████   █████
          ¯¯███████████████¯               ████████████      ███████████
               ¯¯¯¯¯¯                      ¯¯¯¯¯¯¯¯¯¯         ¯¯¯¯¯¯¯¯¯¯
|
  
FAUCET
ICO
ANDROID
       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
FreeDice (OP)
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
August 11, 2015, 04:35:23 PM
 #46

Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price
2012
Legendary
*
Offline Offline

Activity: 1526
Merit: 1003


View Profile
August 11, 2015, 04:50:14 PM
 #47

After get fixed this security issue will try this dice site.
lastuser
Full Member
***
Offline Offline

Activity: 204
Merit: 100


View Profile
August 11, 2015, 04:55:07 PM
 #48

Sucessful. Wait for official launch soon. Thanks!
FreeDice (OP)
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
August 11, 2015, 05:04:09 PM
 #49

I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
Redones
Sr. Member
****
Offline Offline

Activity: 320
Merit: 261


Web developper


View Profile
August 11, 2015, 06:35:02 PM
 #50

I can help fixing all security issues you have in your website,PM me
allyouracid
Legendary
*
Offline Offline

Activity: 2320
Merit: 1292


Encrypted Money, Baby!


View Profile
August 11, 2015, 07:33:07 PM
Last edit: August 11, 2015, 07:46:03 PM by allyouracid
 #51

Beware!

Newbie account with a suspicious login form asking for username, pw and email. Then nothing happens after registering. This has all the makings of a phishing page.  "submit query" is the default name of a form submit button without a name and the page code is abysmal.  

If you entered your info, and you re-use passwords across multiple sites, I'd suggest you change them now.

Code:
<br>Password:&nbsp;  <input type="password" name="password" />
<br>Email:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<input type="text" name="email" />
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<input type="submit">
</form>
It certainly is a phishing site.
Try to send the form over and over with the same values; even using "foobar" in user, password and email doesn't a) cause an error saying email has wrong format and b) at the second time using those values, there's no complaint about those values already being used.


.edit:
Just thought about writing a script spamming his database with nonsense values. ^^

.edit 2:
To kind of prove that this is a malicious site: I just checked the SQL injection, and the error (shown above) shows that the database only has username, password and email fields. There is no way around a user table of a serious dice game having more fields than just those three.

Don't visit my shitcoin blog: OCOIN.DEV
Use cointracking.info for tax declaration & tracking of your trades!
Redones
Sr. Member
****
Offline Offline

Activity: 320
Merit: 261


Web developper


View Profile
August 11, 2015, 08:35:36 PM
 #52

BEWARE ITS A PHISHING PAGE

There are no password/email checking and confirmation
No database double information checking
No vulernabilities protection

Note: I sended a Pm to OP to fix all his page issues he is online and he didn't reply,you know what does mean that ....
tennozer
Sr. Member
****
Offline Offline

Activity: 322
Merit: 250


Bonus Claim Url: http://betonline.wager.bz


View Profile WWW
August 11, 2015, 08:59:22 PM
 #53

Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

tygeade
Legendary
*
Offline Offline

Activity: 2128
Merit: 1059



View Profile
August 11, 2015, 09:07:01 PM
 #54

Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes

vervolioman
Hero Member
*****
Offline Offline

Activity: 493
Merit: 500



View Profile
August 11, 2015, 09:11:22 PM
 #55

Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes

Either way it is a waste of everyones time and a can be a danger to some of you guys that just love re-using passwords lol

OP should name and shame the so called "coder"

What use is a signature?
Scaccomatt0
Legendary
*
Offline Offline

Activity: 1120
Merit: 1000


https://cryptoworld.io


View Profile WWW
August 11, 2015, 09:17:13 PM
 #56

I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
if you don't change "coder" the website will be available when mining BTC end  Grin

       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
               ______
          __███████████████_      █████         █████          █████           █████
       _█████████████████████      █████         █████        █████           █████
     _███████¯¯¯     ¯¯██████       █████         █████      █████           █████
   _██████¯            ¯████¯        █████         █████    █████           █████
  ██████¯                             █████          ██████████            █████
 ██████                               █████          ██████████            █████
 █████                                 █████         ██████████            █████
█████                                  █████          ████████            █████
█████                                  █████           ██████             █████
█████                                  █████           ██████             █████
█████                                  █████           ██████            █████    
█████                                   █████          ██████          █████    
 █████                                  █████          ██████          █████
 ██████                                 █████          ██████        █████
  ██████_                                █████         ██████        █████
   ¯██████_            _████_            █████        ████████       █████
     ¯███████___     __██████            █████      █████  █████     █████
       ¯█████████████████████             █████    █████    █████   █████
          ¯¯███████████████¯               ████████████      ███████████
               ¯¯¯¯¯¯                      ¯¯¯¯¯¯¯¯¯¯         ¯¯¯¯¯¯¯¯¯¯
|
  
FAUCET
ICO
ANDROID
       


████
████
████
████
████
████
████
████
████
████
████
████
████
████
████
tygeade
Legendary
*
Offline Offline

Activity: 2128
Merit: 1059



View Profile
August 11, 2015, 09:24:46 PM
 #57

Hmm, anyone here is a good coder and can help me fixing this security issues? (my coder said he can't do it well)

Pm me with your price

what is that? Change your coder.

Yeah, sure "coder".. lol

Seems like a kid coded that website and not a real coder or he got that "coder" from a freelancer website.  Roll Eyes

Either way it is a waste of everyones time and a can be a danger to some of you guys that just love re-using passwords lol

OP should name and shame the so called "coder"

Well, maybe he is the so called "coder"  Roll Eyes

I want to say sorry for all about this security problems

We'll delay a little our official launch, we are trying to fix this security problems first, as soon we fix it i'll back
if you don't change "coder" the website will be available when mining BTC end  Grin

Hahaha made my day!  Grin  Grin  Grin

bitcircle
Legendary
*
Offline Offline

Activity: 1540
Merit: 1002


View Profile
August 11, 2015, 09:27:20 PM
 #58

Coder is really funny person and OP still calling him Coder Roll Eyes what a joke Grin
tspacepilot
Legendary
*
Offline Offline

Activity: 1456
Merit: 1078


I may write code in exchange for bitcoins.


View Profile
August 11, 2015, 09:30:15 PM
 #59

I checked it out and was eventually able to get it to work using the tab button.  But on firefox the headline "freedice signup" is written on top of the box where you submit a username so it's kinda broken.

Might wanna fix this!

btcfinans
Full Member
***
Offline Offline

Activity: 216
Merit: 100



View Profile
August 11, 2015, 10:37:27 PM
 #60

username : btcfinans, let me try this

Pages: « 1 2 [3] 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!