Bitcoin Forum
May 22, 2024, 08:50:23 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 [107] 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 ... 243 »
  Print  
Author Topic: Just-Dice.com : now with added CLAMs : Play or Invest  (Read 454558 times)
flower1024
Legendary
*
Offline Offline

Activity: 1428
Merit: 1000


View Profile
October 23, 2013, 11:30:44 PM
 #2121


If you havn't set a username/password go to the account tab and "You can log into the same account from a different computer or browser using this link."

thanks. i have a username set. so i guess i have to manually login on a different pc.
dree12
Legendary
*
Offline Offline

Activity: 1246
Merit: 1077



View Profile
October 23, 2013, 11:35:23 PM
 #2122

Indeed, I think this is a modified CSRF attack. Someone can put the login link into an invisible iframe on any website, which can not only destroy someone's access to his or her account but also prompt unsuspecting newbies to deposit to a public account.
superresistant
Legendary
*
Offline Offline

Activity: 2142
Merit: 1121



View Profile
October 24, 2013, 03:12:55 PM
 #2123

Indeed, I think this is a modified CSRF attack. Someone can put the login link into an invisible iframe on any website, which can not only destroy someone's access to his or her account but also prompt unsuspecting newbies to deposit to a public account.

OMG can it be fixed ?
dooglus (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
October 24, 2013, 05:13:37 PM
 #2124

Indeed, I think this is a modified CSRF attack. Someone can put the login link into an invisible iframe on any website, which can not only destroy someone's access to his or her account but also prompt unsuspecting newbies to deposit to a public account.

OMG can it be fixed ?

I could make it such that any time you log in using a "secret URL" link, the site pops up a warning message suggesting that you should set a username and password.

That should prevent the attack from working on people who read popup messages.  But that may be quite a small percentage of people.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
GOB
Member
**
Offline Offline

Activity: 94
Merit: 10


Come on!


View Profile
October 24, 2013, 07:42:06 PM
 #2125


I could make it such that any time you log in using a "secret URL" link, the site pops up a warning message suggesting that you should set a username and password.

That should prevent the attack from working on people who read popup messages.  But that may be quite a small percentage of people.

Why even allow users to bypass creating a username and password (and 2FA)?

"Bitcoin is to bank transfers, credit cards & Paypal, as Email is to letters, faxes & FedEx." 1BAMFrk1qJai5u7UnrhDXoBudGwbYynams
dooglus (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
October 25, 2013, 12:09:00 AM
 #2126

Why even allow users to bypass creating a username and password (and 2FA)?

Because casual players want as few barriers between them and the dice as possible.  They want to deposit, play, maybe withdraw winnings, and forget about the account.  Account registration and 2FA is boring.

For people intending to leave coins on their accounts though, it's clearly a good idea to use 2FA.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
Dabs
Legendary
*
Offline Offline

Activity: 3416
Merit: 1912


The Concierge of Crypto


View Profile
October 25, 2013, 08:18:35 AM
 #2127

Dabs Suggestion: Don't use a pop up because it can and probably will be blocked (they won't see it). Make a large red bold sign somewhere near the deposit buttons or near the bet buttons only for those who don't have accounts, where the text can not be missed; where it is easily seen.

Maybe under the ads or something.

b!z
Legendary
*
Offline Offline

Activity: 1582
Merit: 1010



View Profile
October 25, 2013, 11:52:33 AM
 #2128

Dabs Suggestion: Don't use a pop up because it can and probably will be blocked (they won't see it). Make a large red bold sign somewhere near the deposit buttons or near the bet buttons only for those who don't have accounts, where the text can not be missed; where it is easily seen.

Maybe under the ads or something.

I think he means a popup in the page, not an external window.
tunafish
Member
**
Offline Offline

Activity: 95
Merit: 10


View Profile WWW
October 25, 2013, 03:43:50 PM
 #2129

not sure if maybe theres just no message or anything but i'm trying to withdraw and when i input my address and amount and press withdraw nothing happens, no dialog like "withdrawal processing" or similar but its still showing a balance so i'm guessing its not going through. help?

Feeling generous?
BTC: 1MiaKvvzhuCrbWJ2iXA9RceZfRpNDjwJTk
Otoh
Donator
Legendary
*
Offline Offline

Activity: 3024
Merit: 1105



View Profile
October 25, 2013, 03:56:30 PM
 #2130

not sure if maybe theres just no message or anything but i'm trying to withdraw and when i input my address and amount and press withdraw nothing happens, no dialog like "withdrawal processing" or similar but its still showing a balance so i'm guessing its not going through. help?

Make sure that you got the address & amount in the correct boxes, I think I muddled them up once & if C&P to make sure that there is no space before or after either as some sites can't cope with that. Also obvious, I assume you divested, if invested before, so that you have the amount to withdraw in your available balance.

BTC = $c²     My BTC addie = 1otohotohMoQoxHuxLBveQiZcV3Pji3Tc 
Bitstamp Exchange: Referal Code
CHARITY | MY REP | PREDICTION 1 | PREDICTION 2 | PREDICTION 3
tunafish
Member
**
Offline Offline

Activity: 95
Merit: 10


View Profile WWW
October 25, 2013, 04:02:41 PM
 #2131

not sure if maybe theres just no message or anything but i'm trying to withdraw and when i input my address and amount and press withdraw nothing happens, no dialog like "withdrawal processing" or similar but its still showing a balance so i'm guessing its not going through. help?

Make sure that you got the address & amount in the correct boxes, I think I muddled them up once & if C&P to make sure that there is no space before or after either as some sites can't cope with that. Also obvious, I assume you divested, if invested before, so that you have the amount to withdraw in your available balance.

Checked and rechecked, got "bad amount format" first time and fixed that, now button doesn't do anything *shrug*
and yes i'm divested and i tried withdrawing my entire balance shown and less than it, nothing. Using firefox, have adblock and such whitelisted.


edit:
FIXED
I restarted my browser and that seemed to do the trick. Should have thought of that sooner, firefox isn't as good as it used to be with lots of random things, time to switch to chrome methinks

Thanks for the help though.

Feeling generous?
BTC: 1MiaKvvzhuCrbWJ2iXA9RceZfRpNDjwJTk
dooglus (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 1330



View Profile
October 25, 2013, 04:11:24 PM
 #2132

not sure if maybe theres just no message or anything but i'm trying to withdraw and when i input my address and amount and press withdraw nothing happens, no dialog like "withdrawal processing" or similar but its still showing a balance so i'm guessing its not going through. help?

Shortly before your post, one of our early investors withdrew a large amount, leaving the hot wallet almost empty.

When you try to withdraw more than is in the hot wallet, you should see an error message added to the bottom of the withdraw dialog, like this:



At some zoom levels the warning doesn't fit; a scrollbar appears on the dialog and you have to scroll down to see it.  And on some devices, like phones, the display is too small for the error message to be visible.

Either way, I refilled the wallet shortly after it was emptied, so you can just try again.

Just-Dice                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   Play or Invest                 ██             
          ██████████         
      ██████████████████     
  ██████████████████████████ 
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
██████████████████████████████
    ██████████████████████   
        ██████████████       
            ██████           
   1% House Edge
ASICSRUS
Member
**
Offline Offline

Activity: 70
Merit: 10


Expert Computer Geek


View Profile
October 25, 2013, 04:15:35 PM
 #2133

not sure if maybe theres just no message or anything but i'm trying to withdraw and when i input my address and amount and press withdraw nothing happens, no dialog like "withdrawal processing" or similar but its still showing a balance so i'm guessing its not going through. help?

Shortly before your post, one of our early investors withdrew a large amount, leaving the hot wallet almost empty.

When you try to withdraw more than is in the hot wallet, you should see an error message added to the bottom of the withdraw dialog, like this:



At some zoom levels the warning doesn't fit; a scrollbar appears on the dialog and you have to scroll down to see it.  And on some devices, like phones, the display is too small for the error message to be visible.

Either way, I refilled the wallet shortly after it was emptied, so you can just try again.

do you see whats happened to PrimeDice you are next! LOL  Grin have funnn

✰ If You Risk Nothing, You Risk Everything | PrimeDice.com | The New Way To Roll | *Thread*

<3<3:::LOVE^YOUR^NEIGHBOR!!!:::|+i|_33+(((PLEASE)))====>Donate if you like me!~> 157YEcD4WQ9UbhZ7NSC2FpuaYfxHe3JgF2
andrewbadr
Full Member
***
Offline Offline

Activity: 174
Merit: 100

Posts made Jan-March 2017 are not by me


View Profile
October 25, 2013, 08:00:42 PM
 #2134

How can I get in touch with Nakowa?
dree12
Legendary
*
Offline Offline

Activity: 1246
Merit: 1077



View Profile
October 25, 2013, 09:12:13 PM
 #2135

On closer inspection it seems that the best way to resolve the CSRF (which is a CSRF, not just a modified one) is to display a confirmation. "Are you really really sure you want to log in to this secret link?" and have a CSRF token on the confirmation page.
soso
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
October 25, 2013, 10:42:56 PM
 #2136

Hey Dooglus, a poster named BigboyDan at Sbrforum.com has posted this about you.

It's funny you keep putting up smoke screens to this entire BTC ordeal.

Let me be blunt here if I may as the current sting they have underway now to takedown Mr.Nigel and his operations that has plagued the U.S. for many years.


Homeland security is currently sitting on the supposely unknown devoloper "Dooglus" and his associates as well as the BTC platform book, their hub Dowlla and it's roughly $50+ million (was like 33+ million) wagered already and is waiting till more money to be pumped through it before it they shut it down. Now if you or any other SBR poster would like to call the feds and inquire about this info I've provided then please do so because that's what a good reporter like myself would do. Hell, I could go on but I don't think Mr.Meng would appreciate it and does see where I'm going with this. :


Now think logically about this from both sides of the fence:

Not only would the books get burned but the players will get stung so bad that it will ultimate be a big negative on the industry as a whole to the point the players won't send money to any offshore book. The really sad part of it all is the mere fact of just what type of impact it would be on the global offshore marketplace as a whole in Europe, Australia, Asia, CR, Panama, Antigua, ect,ect.

Anything to say about this?
willphase
Hero Member
*****
Offline Offline

Activity: 767
Merit: 500


View Profile
October 25, 2013, 10:47:37 PM
 #2137

Hey Dooglus, a poster named BigboyDan at Sbrforum.com has posted this about you.

It doens't look like BigboyDan has been active on sbrforum for two years.  Do you have a link, or are you just trolling?

Will

organofcorti
Donator
Legendary
*
Offline Offline

Activity: 2058
Merit: 1007


Poor impulse control.


View Profile WWW
October 25, 2013, 11:32:54 PM
 #2138

<snip> Anything to say about this?

Did anything you just posted make any sense at all?

What BTC ordeal? Who is Mr. Nigel? Why is "Homeland security" taking action against a Canadian? Is Canada now a part of the US? Or was your post just a list of random words from other posts?


Bitcoin network and pool analysis 12QxPHEuxDrs7mCyGSx1iVSozTwtquDB3r
follow @oocBlog for new post notifications
soso
Newbie
*
Offline Offline

Activity: 41
Merit: 0


View Profile
October 25, 2013, 11:52:06 PM
 #2139

I am not "trolling". I have no dog in this fight. I do not care one bit.

 bigboydan posted today at 4:45

Go to sbrforum.com and find the "do you use bitbooks?" thread post #37, or don't i don't give a shit.

He made allegations against dooglus that i posted.

organofcorti
Donator
Legendary
*
Offline Offline

Activity: 2058
Merit: 1007


Poor impulse control.


View Profile WWW
October 25, 2013, 11:55:36 PM
 #2140

I am not "trolling". I have no dog in this fight. I do not care one bit.

 bigboydan posted today at 4:45

Go to sbrforum.com and find the "do you use bitbooks?" thread post #37, or don't i don't give a shit.

He made allegations against dooglus that i posted.



Ah, sorry about that - I didn't realise you were quoting someone else.

Bitcoin network and pool analysis 12QxPHEuxDrs7mCyGSx1iVSozTwtquDB3r
follow @oocBlog for new post notifications
Pages: « 1 ... 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 [107] 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 ... 243 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!