Bitcoin Forum
December 05, 2016, 10:28:59 AM *
News: To be able to use the next phase of the beta forum software, please ensure that your email address is correct/functional.
 
   Home   Help Search Donate Login Register  
Pages: « 1 [2]  All
  Print  
Author Topic: 5 BTC Bounty - break site and help community (and earn 5 coins!)  (Read 2433 times)
anisoptera
Member
**
Offline Offline

Activity: 98



View Profile
July 20, 2011, 06:08:00 AM
 #21

Thanks for the BTC, but the kind of problem that I was describing is a kind of attack on users running firefox and chrome browsers: I can make them not have buttons in a first-to-act situation every time.

In other words, I'm running an opera browser, and "stealing" the small blind of a user who is waiting at a table is very easy. The browser featured on screen in the video is firefox, I make the firefox browser have no buttons by running opera on a separate computer.

I'm sure I can make the first person to act in a full ring game that is already running not have buttons just by sitting down with an opera browser.

Have you actually successfully stolen a blind with this? You claim it's "easy", but you don't demonstrate it.

I couldn't repro this bug at all, myself, let alone steal a blind.

I looked at your screencast. At no time is action on you with no buttons showing. There is a bug here - Opera's not responding properly to the blind request - but once the player times out, the game proceeds as normal. During the time you have no buttons, the action is actually on the other player. That's why the timeout bar is on their name and not yours.

The server has asked that player "Do you want to post a blind?" and the client is meant to automatically respond to that request. It's not, for whatever reason - but that doesn't affect anyone but that client. When you refresh the FF client, nothing happens, because the action isn't on you in the first place. We're waiting for the other player. When you refresh Opera, it "fixes" it because for some reason refreshing makes Opera respond to the blind request properly.

I tried hacking a client to not respond to the blind request, and when it times out, the SB is returned to the player.



That said - thanks for submitting such a detailed bug report. If it weren't for the screencast I wouldn't have any clue what was happening at all. Smiley

online poker, bitcoin style - https://betco.in/
feeling tipsy? 1Q7ktWPwu4Q8MivKdmYxnmsGaBeauMTGwU
1480933739
Hero Member
*
Offline Offline

Posts: 1480933739

View Profile Personal Message (Offline)

Ignore
1480933739
Reply with quote  #2

1480933739
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1480933739
Hero Member
*
Offline Offline

Posts: 1480933739

View Profile Personal Message (Offline)

Ignore
1480933739
Reply with quote  #2

1480933739
Report to moderator
1480933739
Hero Member
*
Offline Offline

Posts: 1480933739

View Profile Personal Message (Offline)

Ignore
1480933739
Reply with quote  #2

1480933739
Report to moderator
ChloeST
Newbie
*
Offline Offline

Activity: 11


View Profile
July 20, 2011, 03:31:19 PM
 #22

Sorry for stating that the small blind could be stolen without verifying completely. I've played so much heads up poker that it became automatic for me to think that if the small blind doesn't do anything they lose. I was also trying to emphasize that I had found a bug, but if nobody can reproduce the missing buttons bug (not the blind stealing) then I guess it's a moot point. I've tried to reproduce the situation just today, but I cannot after two tries, maybe the code on the server has changed since then?
anisoptera
Member
**
Offline Offline

Activity: 98



View Profile
July 20, 2011, 03:34:29 PM
 #23

I've tried to reproduce the situation just today, but I cannot after two tries, maybe the code on the server has changed since then?

hippich says he could repro it right after you submitted this report. I don't think any code changes went in, but two days later none of us could repro it. Very odd.

online poker, bitcoin style - https://betco.in/
feeling tipsy? 1Q7ktWPwu4Q8MivKdmYxnmsGaBeauMTGwU
hippich
Hero Member
*****
Offline Offline

Activity: 546


View Profile
July 20, 2011, 03:52:00 PM
 #24

yeah. i will try it another time. since i am worried about it.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!