Post
Topic
Board Games and rounds
Re: MagicalDice - Need beta testing [Bounty for bugs]
by
lyco
on 30/08/2015, 13:43:36 UTC

troubleshooting target: fountain (for abuse potential)
exploit found: captcha bypass assuming 0 balance

with any of the three adblock extensions enabled, captcha is checked after simply clicking (no selecting images) so long as balance is 0 - this enables me to use autokey (autohotkey on windows) to continually through automated click-events, claim 500 satoshi and bet it at an absurd multiplier until i essentially steal 55k satoshi by recording a few mouse click events and retiring to the opium den until autokey alerts me that i've succeeded in ripping off your fountain.

http://i.imgur.com/NtI5OnC.png

(difficult to take a screen of something NOT happening, but all i have to do is click the human verification and it accepts as if i had completed a captcha, then allows me to claim)

note that once the balance is over 0 the captcha modal window does appear and does not award additional coin upon completion. it simply allows for an automation scheme if the user bets all 500 satoshi at 1% odds / 99x multiplier.

software tech specs: debian-ish linux running chromium/webkit-based browser using stock adblock plus extension out of chrome app store

ok!

- Lyco / user "harlequence" on magicaldice
- Joshua Ryan Nydel - nydel at ma dot sdf dot org for mail