Bitcoin Forum
May 05, 2024, 06:48:05 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [WARNING] Wolf.bet security is bad  (Read 214 times)
victorsspy (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
December 29, 2019, 03:17:11 PM
Last edit: December 29, 2019, 08:01:53 PM by victorsspy
 #1

FIXED
1714934885
Hero Member
*
Offline Offline

Posts: 1714934885

View Profile Personal Message (Offline)

Ignore
1714934885
Reply with quote  #2

1714934885
Report to moderator
"Bitcoin: the cutting edge of begging technology." -- Giraffe.BTC
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714934885
Hero Member
*
Offline Offline

Posts: 1714934885

View Profile Personal Message (Offline)

Ignore
1714934885
Reply with quote  #2

1714934885
Report to moderator
1714934885
Hero Member
*
Offline Offline

Posts: 1714934885

View Profile Personal Message (Offline)

Ignore
1714934885
Reply with quote  #2

1714934885
Report to moderator
1714934885
Hero Member
*
Offline Offline

Posts: 1714934885

View Profile Personal Message (Offline)

Ignore
1714934885
Reply with quote  #2

1714934885
Report to moderator
nakamura12
Hero Member
*****
Offline Offline

Activity: 2268
Merit: 669


Bitcoin Casino Est. 2013


View Profile
December 29, 2019, 03:32:34 PM
 #2

I'm here to warn everyone that WOLF.Bet's security is NOT GOOD.

When logging in the site connects to this url
https://wolf.bet/api/v1/login
it sends this json payload {"login":"User","password":"Pass"}


As you can see, they have no tokens, no password encryption.
You can crack accounts very easy using Openbullet or programs alike.
I made a working account cracker < 3 minutes.

However, their API is private which is somewhat good I suppose and when I tried making my program withdraw I got unauthorized but I am sure if I spent more than 5 minutes I could automatically make it withdraw to my BTC address.

To wolf.bet:
- Add Recaptcha to your site
- Encrypt passwords before they get sent to your server
- use CSRF tokens, etc. (these are quite useless but they help somewhat)
Since you're not jr. member rank yet so i'll quote your post to show the images you provide to warn those who use this site. You did a good job sharing this vital information that this doesn't have tight security and this site may git hacked if not taken action. Many people who already been using this site might lose their money.

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
victorsspy (OP)
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
December 29, 2019, 07:01:30 PM
 #3

Since you're not jr. member rank yet so i'll quote your post to show the images you provide to warn those who use this site. You did a good job sharing this vital information that this doesn't have tight security and this site may git hacked if not taken action. Many people who already been using this site might lose their money.
And I just found a way to withdraw BTC, their security is very bad
Steamtyme
Legendary
*
Offline Offline

Activity: 1540
Merit: 2036


Betnomi.com Sportsbook, Casino and Poker


View Profile WWW
December 29, 2019, 07:42:16 PM
 #4

It's unclear from your post but I'm hoping you went directly to their support before posting here. I say this as it doesn't appear to be a malicious step on their part, so warning them to protect their user base first is paramount, followed by posting here to warn users directly.

I have to admit I only get what you did at a surface level, but if you didn't notify Wolf.bet first then you could also be exposing their user base to risk should one of the many shady characters here decide to use your post as a roadmap.


░░░░░▄▄██████▄▄
░░▄████▀▀▀▀▀▀████▄
███▀░░░░░░░░░░▀█▀█
███░░░▄██████▄▄░░░██
░░░░░█████████░░░░██▌
░░░░█████████████████
░░░░█████████████████
░░░░░████████████████
███▄░░▀██████▀░░░███
█▀█▄▄░░░░░░░░░░▄███
░░▀████▄▄▄▄▄▄████▀
░░░░░▀▀██████▀▀
Ripmixer
░░░░░▄▄██████▄▄
░░▄████▀▀▀▀▀▀████▄
███▀░░░░░░░░░░▀█▀█
███░░░▄██████▄▄░░░██
░░░░░█████████░░░░██▌
░░░░█████████████████
░░░░█████████████████
░░░░░████████████████
███▄░░▀██████▀░░░███
█▀█▄▄░░░░░░░░░░▄███
░░▀████▄▄▄▄▄▄████▀
░░░░░▀▀██████▀▀
nakamura12
Hero Member
*****
Offline Offline

Activity: 2268
Merit: 669


Bitcoin Casino Est. 2013


View Profile
December 29, 2019, 07:54:16 PM
 #5

It's unclear from your post but I'm hoping you went directly to their support before posting here. I say this as it doesn't appear to be a malicious step on their part, so warning them to protect their user base first is paramount, followed by posting here to warn users directly.

I have to admit I only get what you did at a surface level, but if you didn't notify Wolf.bet first then you could also be exposing their user base to risk should one of the many shady characters here decide to use your post as a roadmap.
I agree that wolf.bet should be the priority to let them know first before sharing this problem to everyone. As Steamtyme it is posdible that hacking wolf.bet might happen (who knows) to them and many more users will be at risk because of this post you have and shady people use this opportunity.

And I just found a way to withdraw BTC, their security is very bad
Did you contact their support team before posting this info?

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
Drai
Sr. Member
****
Offline Offline

Activity: 567
Merit: 270



View Profile
December 29, 2019, 07:56:35 PM
 #6

I have posted this on the wolf.bet ANN thread and just incase you haven't reported it to their support yet, they would see it from their ANN thread and tackle the issue before it actually becomes an issue. You can see my report here- https://bitcointalk.org/index.php?topic=5167730.msg53473402#msg53473402

edmundduke
Legendary
*
Offline Offline

Activity: 1624
Merit: 1007


View Profile
December 29, 2019, 08:03:54 PM
 #7

Since you're not jr. member rank yet so i'll quote your post to show the images you provide to warn those who use this site. You did a good job sharing this vital information that this doesn't have tight security and this site may git hacked if not taken action. Many people who already been using this site might lose their money.
And I just found a way to withdraw BTC, their security is very bad

I would like to say im shocked but security in the crypto gambling space really has been whack since the beginning. This however is bad beyond that lmao
veleten
Legendary
*
Offline Offline

Activity: 2016
Merit: 1106



View Profile
December 29, 2019, 08:22:36 PM
 #8

you should message their admin , probably will get rewarded if it is a security issue they overlooked
I wonder how on earth you were the first one to discover it
did you manage to hack one of the accounts too? maybe it is not as bad as you are describing it
wolf bet is already a few months old  , should be taking security risks seriously
if your account is not safe there , use 2fa or even consider playing elsewhere until it is fixed
lets see if admin says something about it

          ▄▄████▄▄
      ▄▄███▀    ▀███▄▄
   ▄████████▄▄▄▄████████▄
  ▀██████████████████████▀
▐█▄▄ ▀▀████▀    ▀████▀▀ ▄▄██
▐█████▄▄ ▀██▄▄▄▄██▀ ▄▄██▀  █
▐██ ▀████▄▄ ▀██▀ ▄▄████  ▄██
▐██  ███████▄  ▄████████████
▐██  █▌▐█ ▀██  ██████▀  ████
▐██  █▌▐█  ██  █████  ▄█████
 ███▄ ▌▐█  ██  ████████████▀
  ▀▀████▄ ▄██  ██▀  ████▀▀
      ▀▀█████  █  ▄██▀▀
         ▀▀██  ██▀▀
.WINDICE.████
██
██
██
██
██
██
██
██
██
██
██
██
████
      ▄████████▀
     ▄████████
    ▄███████▀
   ▄███████▀
  ▄█████████████
 ▄████████████▀
▄███████████▀
     █████▀
    ████▀
   ████
  ███▀
 ██▀
█▀

██
██
██
██
██
██
██
██
██
██
██
██
     ▄▄█████▄   ▄▄▄▄
    ██████████▄███████▄
  ▄████████████████████▌
 ████████████████████████
▐████████████████████████▌
 ▀██████████████████████▀
     ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
     ▄█     ▄█     ▄█
   ▄██▌   ▄██▌   ▄██▌
   ▀▀▀    ▀▀▀    ▀▀▀
       ▄█     ▄█
     ▄██▌   ▄██▌
     ▀▀▀    ▀▀▀

██
██
██
██
██
██
██
██
██
██
██
██
                   ▄█▄
                 ▄█████▄
                █████████▄
       ▄       ██ ████████▌
     ▄███▄    ▐█▌▐█████████
   ▄███████▄   ██ ▀███████▀
 ▄███████████▄  ▀██▄▄████▀
▐█ ▄███████████    ▀▀▀▀
█ █████████████▌      ▄
█▄▀████████████▌    ▄███▄
▐█▄▀███████████    ▐█▐███▌
 ▀██▄▄▀▀█████▀      ▀█▄█▀
   ▀▀▀███▀▀▀
████
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
  ██
████


▄▄████████▄▄
▄████████████████▄
▄████████████████████▄
███████████████▀▀  █████
████████████▀▀      ██████
▐████████▀▀   ▄▄     ██████▌
▐████▀▀    ▄█▀▀     ███████▌
▐████████ █▀        ███████▌
████████ █ ▄███▄   ███████
████████████████▄▄██████
▀████████████████████▀
▀████████████████▀
▀▀████████▀▀
iePlay NoweiI
I
I
I
[/t
mk02
Newbie
*
Offline Offline

Activity: 15
Merit: 0


View Profile
December 29, 2019, 08:31:00 PM
 #9

there is a similar problem on almost every site
encryption met only on bc.game/nanogames.io

this is what the primedice authorization looks like:

[{"operationName":"RequestLoginUserMutation","variables":{"name":"user","password":"password","captcha":"RECAPTCHA_RESPONCE"},"query":"mutation RequestLoginUserMutation($name: String, $email: String, $password: String!, $captcha: String) {\n  requestLoginUser(name: $name, email: $email, password: $password, captcha: $captcha) {\n    loginToken\n    hasTfaEnabled\n    user {\n      id\n      name\n      __typename\n    }\n    __typename\n  }\n}\n"}]
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!