Bitcoin Forum
May 26, 2024, 01:31:16 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 »  All
  Print  
Author Topic: MagicalDice - Need beta testing [Bounty for bugs]  (Read 2903 times)
Stars (OP)
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
August 29, 2015, 12:58:30 AM
Last edit: September 01, 2015, 03:37:37 PM by Stars
 #1

Hey guys,

After many months of www.magicaldice.com being in development we are finally excited to announce we're close to the finish line and expecting to launch on the 1st of September! We plan to be doing A LOT of giveaways and crazy signature campaigns so make sure you keep a look out!

Firstly before we can do any of that, we need your guys help. We'll be opening up our website for beta-testing for 2-3 days. This will be the time-frame we have to fix any issues and make improvements. So go on over and take a look at our website. If you can find any bugs/improvements that we like then shoot me a pm and we'll be sure to send you some BTC.

There isn't a set bounty for each bug you find. Depending on how severe the bug is we will accommodate you accordingly. Same applies to how good your improvement idea is Smiley

If you want some fake bitcoins to play around with then post your MD username below (You can't withdraw these coins) Wink

Our website - Www.magicaldice.com

Bounties paid so far -
-NLNico
-Monoko
-Everaja
-Discovercebu
-



Mediator
Legendary
*
Offline Offline

Activity: 1442
Merit: 1001


View Profile
August 29, 2015, 02:43:02 AM
 #2

Balace error ,
I claim 500 satoshi and bet 500 sat , balance becomes 1 BTC Cheesy

Stars (OP)
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
August 29, 2015, 02:52:28 AM
 #3

Balace error ,
I claim 500 satoshi and bet 500 sat , balance becomes 1 BTC Cheesy



Haha that's because I set your balance to 1 BTC Tongue

Mediator
Legendary
*
Offline Offline

Activity: 1442
Merit: 1001


View Profile
August 29, 2015, 03:04:38 AM
 #4


Quote
Haha that's because I set your balance to 1 BTC :

My bet is always to win , what this part of the promotion Cheesy
katerniko1
Legendary
*
Offline Offline

Activity: 966
Merit: 1000


View Profile
August 29, 2015, 04:32:38 AM
 #5

sure i want some free btc Cheesy
katerniko1
regards.
-Katerniko1
katerniko1
Legendary
*
Offline Offline

Activity: 966
Merit: 1000


View Profile
August 29, 2015, 04:37:29 AM
 #6

at bottom of your site there is bitcointalk button witch should lead to your thread i think.
and it lead only to gambling section...
Smiley
regards.
-Katerniko1
Stars (OP)
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
August 29, 2015, 04:41:15 AM
 #7

at bottom of your site there is bitcointalk button witch should lead to your thread i think.
and it lead only to gambling section...
Smiley
regards.
-Katerniko1

Yeah that will be changed when we officially launch which will hopefully be 1st of September if we don't run into any problems during this beta test Smiley

NLNico
Legendary
*
hacker
Offline Offline

Activity: 1876
Merit: 1289


DiceSites.com owner


View Profile WWW
August 29, 2015, 04:56:42 AM
 #8

Probably found a serious security vulnerability, will PM.

everaja
Hero Member
*****
Offline Offline

Activity: 490
Merit: 500


~ScapeGoat~


View Profile
August 29, 2015, 05:00:08 AM
Last edit: August 29, 2015, 12:43:12 PM by everaja
 #9

Hi Stars !!  There are lots of security Vulnerability in your site a Rouge Coder can ******** Your site as they did with Luckybit earlier (No hard feeling).

Just Found Two Run Time Errors taht can be fatal from Point of view of your business.
#Bug 0:(noobs Bug)
Bet can be placed even the bet amount is zero  Lips sealed
#Bug 1:

I would like you to take you back to few months back may be much more , i guess all guys reading this may remember that once the blockchain.info "latest Transaction" were filled with transactions of Luckybit Blue or red or green...
They were all because before luckybit coders used Instance variable rather than class variables to make a Bet and stored them in Tables(DB) as a instance variables , Instance variables are easy to inject and can be spoof the database for ,say 1-2 seconds to even 3-4 hours until the database refresh(If another guy make a bet after me in "t" time then the database will refresh in "t" time) , assume if it is night and no one is playing on your site means the database is not refreshing and someone rouge comes to your site and played that trick then he has a lot of time to withdraw as no one is playing n your site and the withdraw(if auto) then you can loose a big amount , i remember that some one withdrew 65 btc from Luckybit with this method and im sure he might be reading this.
How i found this in your site with that method:

#Bug 2:
I had initially 0.000005 Btc from Faucet , I played Two bets but Your database is showing Just 1 bet placed and it is showing my balance 0.000003 , How it can be Posiible , if i played only one bet that was default worth 0.000001BTC , then my balance must be 0.000004 btc not 0.000003 btc , i Guess this error is due to
Code:
Enableviewstate="True"

1. I went to your site and got registered.

2.I went to faucet and claimed 0.000005 btc

3.I payed two times but your database is showing only one time , in which runtime error occured and it deduced the balance but didn't put the bet in bet history table and deduced the 0.000001 btc x2 , The current bet section showed i won but the roll under/above showed that i lost , How two things are possible but as soon as the other guys placed the bet the database was refreshed and i was again showed lost.




direct image link:   http://postimg.org/image/vpcxpfqnb/
See bet 12206 roll was under but it stated i won , after some time it was corrected as others put their betting after me.



My balance shows 0.000003 btc but i played only one bet according to your bet history table(of 0.000001), then where is the another 0.000001 btc ,this is because of enableviewstate i already mentioned it in above.


I guess if user Ecuamobi can Put some light here then it will be much appreciated, as he same from the coding background.

I guess i have said and given two bug reports:
Let me know if You are on your words.

wikenpp
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500



View Profile
August 29, 2015, 06:18:59 AM
 #10

username:Jamest




This new shit, I'll play here, hopefully this can form the best place
neochiny
Hero Member
*****
Offline Offline

Activity: 756
Merit: 503


Crypto.games


View Profile WWW
August 29, 2015, 06:26:40 AM
 #11

hi.. i want to try the free btcs.
 username :tetay14

████  ███████  ███
██████████
███      ███████
███      ███████████
██████████████████
████████
███   ████  ███████████
███ ███████████████
█████████
█████████████████
███  ███████
██████████████
███        ████████
███████████▀▀███▀▀███████████
██████▀▀     ███     ▀▀██████
████▀   ▄▄█████████▄▄   ▀████
████▄▄▄███▀  ▀█▀  ▀███▄▄▄████
██▀▀▀██▀      ▀      ▀██▀▀▀██
█▀  ▄██               ██▄  ▀█
█   ████▄▄         ▄▄████   █
█▄  ▀██▀             ▀██▀  ▄█
██▄▄▄██▄             ▄██▄▄▄██
████▀▀▀███▄ ▄█ █▄ ▄███▀▀▀████
████▄   ▀▀███▄█████▀▀   ▄████
███████▄     ███     ▄███████
███████████▄▄███▄▄███████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
..PLAY NOW..
███  ███████  ████
██████████
███████      ███
███████████      ███
██████████████████
████████
███████████  ████   ███
███████████████ ███
█████████
█████████████████
███████  ███
██████████████
████████        ███
yolanda123
Newbie
*
Offline Offline

Activity: 35
Merit: 0


View Profile WWW
August 29, 2015, 06:35:57 AM
 #12

name magicaldice :yolanda
 Grin

i like .magicaldice
NLNico
Legendary
*
hacker
Offline Offline

Activity: 1876
Merit: 1289


DiceSites.com owner


View Profile WWW
August 29, 2015, 07:26:26 AM
 #13

Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.

zeraTunerse
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile
August 29, 2015, 07:32:47 AM
 #14

Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.

I guess all that site including all JS to load simultaneously at the background while the user only see a splash-screen as the dev of Primedice have done.
neochiny
Hero Member
*****
Offline Offline

Activity: 756
Merit: 503


Crypto.games


View Profile WWW
August 29, 2015, 07:33:19 AM
 #15

hi.. admin, settings in chat like this..

 Show my big wins in chat

 Show my big losses in chat

i disable it but still showing in my chat box. pls check it. thanks.

████  ███████  ███
██████████
███      ███████
███      ███████████
██████████████████
████████
███   ████  ███████████
███ ███████████████
█████████
█████████████████
███  ███████
██████████████
███        ████████
███████████▀▀███▀▀███████████
██████▀▀     ███     ▀▀██████
████▀   ▄▄█████████▄▄   ▀████
████▄▄▄███▀  ▀█▀  ▀███▄▄▄████
██▀▀▀██▀      ▀      ▀██▀▀▀██
█▀  ▄██               ██▄  ▀█
█   ████▄▄         ▄▄████   █
█▄  ▀██▀             ▀██▀  ▄█
██▄▄▄██▄             ▄██▄▄▄██
████▀▀▀███▄ ▄█ █▄ ▄███▀▀▀████
████▄   ▀▀███▄█████▀▀   ▄████
███████▄     ███     ▄███████
███████████▄▄███▄▄███████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
..PLAY NOW..
███  ███████  ████
██████████
███████      ███
███████████      ███
██████████████████
████████
███████████  ████   ███
███████████████ ███
█████████
█████████████████
███████  ███
██████████████
████████        ███
NLNico
Legendary
*
hacker
Offline Offline

Activity: 1876
Merit: 1289


DiceSites.com owner


View Profile WWW
August 29, 2015, 07:46:44 AM
 #16

Mostly non-security related, but still important:

- New account, "Login link" doesn't work. If this is already fixed, make sure to hide and disable the "Login link" for people who have a password. Ideally you have a 2FA option too.
- The popups/iframes like user/bet info, provably fair, tip history, etc. also load all the JS. This means they are also loading all the AJAX requests for bets/stats every second etc. (while these frames don't need that data.) You should save both you and the user some resources/bandwidth by not making these useless requests Wink
- You should force SSL.

I guess all that site including all JS to load simultaneously at the background while the user only see a splash-screen as the dev of Primedice have done.
Not sure what you mean. On MagicalDice most popups actually load a new page in an iframe. This iframe contains all the Javascript files that also load all the bets/stats/etc through AJAX. This iframe however, does not need this data. I was wrong about "user/bet info" actually, but still many popups do this: Account setting, Provably fair, My transcactions, My tips, Chat Settings, ...

orryde
Sr. Member
****
Offline Offline

Activity: 476
Merit: 500


Re-Evolution


View Profile
August 29, 2015, 07:47:51 AM
 #17

Just registered there
My username: orryde

Thank you



                                                                    ▄▄▄▄▄▄▄▄▄
                                                                   ▄█████████                  ██████
                                                                   ███    ███                 ██   ██
         ████████████████████████████████████████████████████████████    ██████████████████████   ████████▀
        ██            ▄█          █▄                 █▄          ███            █▄          █        ▄██▀
       ██            ██           ███                ██   ▄▄▄▄▄  ███            ██   ▄▄▄▄▄  ██   █████▀
       ██   █████    ██   ████   ████   ██     ██    ██   ▀▀▀▀   ██    ██████   ██   ▀▀▀▀   ██   ████▀
      ██    █████   ██    ████   ████   ██     ██   ██          ███   ██████   ██          ██   ████▀
      ██            ██           ███   ███    ███   ██    ▀▀▀▀▀▀███            ██    ▀▀▀▀▀▀██   ▀▀▀████
      ███           ██▄            █   ██     ██    ██▄          █             ▀█▄          ██      ███
       █████████   ████████████████████████████████████████████████████████████████████████████████████
      ██           ██
    ██▀           ███
  ████████████████▀
Betting on e-Sports with Steam Items & Crypto
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
■■■■■ GBT Loyalty Reward Program Steam Marketplace Sportsbetting ■■■■■
trafficolaa
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
August 29, 2015, 08:17:24 AM
 #18

I have just created my account there but there no faucet so how to get free coins to test this brand dice site,
Edit : faucet button right down in the balance.

Username : trafficolaa
Stars (OP)
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
August 29, 2015, 08:23:00 AM
Last edit: August 29, 2015, 09:39:19 AM by Stars
 #19

I appreciate everybody that has found bugs/actively looking for bugs. You will be paid a bounty once our dev has fixed the bug(s). Thanks Smiley

boopy265420
Legendary
*
Offline Offline

Activity: 1876
Merit: 1005


View Profile
August 29, 2015, 08:37:09 AM
 #20

I came to know about bug bounty after having registered under username '' boopy'' I am trying to test and finf the bug.Everyone best of luck to help the OP by finding bugs and win.
Pages: [1] 2 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!