|
|||
|
|||||||
| Register | All Albums | Member Blogs | FAQ | Members List | Mark Forums Read | |||
| Main Site | CM Casinos | CM Poker | I-Gaming Forum Reps | Rogue Pit | Webcast | Bitchin' Newsletter | News |
| Notices |
| Online Casinos Online Casinos - Information, Experiences, questions and such. This is no place for ads or cloaked promos. Shills and spammers be warned |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||||
|
Quote:
Quote:
Quote:
__________________
|
| The Following User Says Thank You to Sodax77 For This Useful Post: | ||
Pinababy69 (14th July 2007) | ||
| The Following User Says Thank You to Pinababy69 For This Useful Post: | ||
Sodax77 (14th July 2007) | ||
|
|||||
|
Quote:
(You may check standards via google - referring Secunia, etc - It is always to GOOD to give a chance to programmer/etc correct mistakes, before, publicity) ...but this was major reason, why Alan BANNED me But i admit, that this a good casino. Unfortunately i can not recommend iNetBet to everyone. Remember, almost 1200 emails are positive... and only few may have this kind of critic! Plus http://www.casinomeister.com/forums/...hlight=Inetbet ('06) http://www.casinomeister.com/forums/...hlight=Inetbet ('04) http://www.casinomeister.com/forums/...tbet#post99459 ('06) http://www.casinomeister.com/forums/...tbet#post36429 ('04) Etc, etc
__________________
|
|
||||
|
I dont mean to be rude but i have no clue what this is all about.
__________________
paul02085 |
|
|||||
|
I'm pretty lost too Paul, so don't feel bad. I don't really understand the issue, besides the fact that Soda's account has been closed. All I can gather is that he had some "security issue" with the casino, and after that, I don't know.
__________________
I'll promise to be nicer, if you'll promise to be smarter. |
|
|||||
|
Quote:
The point is: MY ACCOUNT IS CLOSED, BECAUSE I SENT DETAILS TO INETBET, WHAT WAS THE SECURITY ISSUE. THIS IS CONFIRMED, DATABASE WAS OPEN - DATASHEET WAS OPEN I SAID I WILL PUBLISH THIS ISSUE, IF THEY DO NOT FIX THIS. REPLY WAS: THEY CLOSED MY ACCOUNT! IS SECURITY ISSUE STILL EXIST, IS IT POSSIBLE TO LOAD DATASHEET - BASED USERNAME/ETC - ANSWER: YES Hopefully capital letters helped you understand... ok, ok... i am F´king pissed... so try to get it... damn it.. or read my over 650 useless posts f´king damn it... pardon my france, i mean Finnish
__________________
Last edited by Sodax77; 14th July 2007 at 07:45 AM. |
|
|||||
|
Quote:
![]() Sounds a bit obsessive & certainly excessive to me. From Soda's posts I think he is saying that a first grade junior computer hacker can access iNetBet's database of all players names, account numbers & other personal details...? ![]() Could be wrong here, but that's my interpretaion... KK
__________________
KK: Reputable casinos turn rogue overnight! See Kasino News. Casinos: New ~ 15 Rivals ~ OK for USA. SB: Slots Stats & Facts: GV, WW, 3Dice, Rival, Wizard. |
| The Following 3 Users Say Thank You to KasinoKing For This Useful Post: | ||
|
|||||
|
Quote:
You have probably got it in one. Looks like an incorrect link was sent out to the player, which instead of linking them to their OWN account, linked them through to the casino administration panel ![]() The link posted (without the /XXXXXXX) simply requires the administrator to log in, clearly hackable, since a good deal of the legwork has been done by giving out the route to this page on the server (a sequence of 20 random letters). I presume that, given an appropriate value for the following /XXXXXX, the link will automatically log into the casino admin area. It seems that sodax is saying that the original link DID INDEED have a value for "/XXXXXXX" that logged straight into the admin area. When sodax tried to make the support staff aware, they simply assumed this was a threat (blackmail - whatever), and reacted by not cooperating with this attempt to assist, but rather brought on a confrontation. The accusation that sodax was attempting to obtain "personal information", seems to be derived from their view that sodax had actually hacked the server, and had sent the resulting spreadsheet not as evidence of the bug, but as a statement of "threat", such as "do this for me, or this information might be misused.) I would hope that all administrator username and password details were immediately changed as soon as they were aware of this breach, but they should also ensure that they are sufficiently secure such that a cracking script attached to this page could not grant easy access. As well as personal details of players, this admin area will probably contain access to the operator "tweaks" to payout tables and slot percentages. Strictly speaking, the login area should not be shown to an IP outside of the range used by apropriate employees. Most websites would simply show "access denied", rather than allow use of the secure page. It may be that the admin page is on the same server as the players use to log into their OWN accounts, and thus cannot be blocked by IP. The fact that sodax originally got in through the link in the E-mail about the withdrawal means this is a pretty serious issue, as the same mistake could well be made in E-mails to other players, they may even just try to log into their player account without really reading the fact this is "administrator", not player, login. The large number of E-mails exchanged between sodax and support simply ensured this issue was looked upon as "oh no, not again!", rather than being properly addressed. This just ensured sodax got the impression they just did not care about the potential security issue, and just wanted sodax to "go away and forget about it" - sodax could not do this until an assurance had been received that management had checked for, and closed, any security issues. I rather get the impression this is an RTG problem, not just this one casino, and is how the RTG software comes when supplied. At the very least, the page should have been reallocated such that it could no longer be reached by the original 20 letter coded link. I expect there are MANY RTG casinos where this happening would be treated with enthusiasm by disaffected players, but fortunately InetBet is not one of them. Disaffected players are probably thinking along the lines of "does this glitch exist at CoolCat". I had not thought that one of the major brands would allow administrative access over the internet with just the protection of two simple codes (user & password). I get the impression that such functions at brands such as Microgaming are performed locally at the offices of the operators by secure links (I could be wrong, operators please do NOT clarify if this is the case, just check it really is secure!). It might be an idea to have Bryan look at all these E-mails that lead to this parting of ways, mainly to see how this developed into a mud-slinging match when sodax tried to report this one security concern. (Or was it already a mud-slinging match BEFORE this particular issue became the "last straw" for support).
__________________
http://www.vinylweatherman.net The unbelievably out of date guide to Fruit Machines on the UK Motorway network. Last edited by Casinomeister; 16th July 2007 at 12:31 PM. Reason: removed URL from screenshot |
| The Following 10 Users Say Thank You to vinylweatherman For This Useful Post: | ||
KasinoKing (16th July 2007), livefree247 (15th July 2007), lojo (17th July 2007), Mike031 (15th July 2007), mysticjoz (16th July 2007), NZmumof4 (28th July 2007), Pinababy69 (15th July 2007), silkprint (15th July 2007), Sodax77 (15th July 2007), trips to win (9th September 2007) | ||
|
|||||
|
Thank you Vinyl (and KK). You have described it in terms that even I can understand. I have zero technical knowledge like I said, and Soda I'm sorry that I couldn't grasp your explanation, and just frustrated you further. No harm done.
That is an excellent post VWM, and something that should be looked at further, IMO.
__________________
I'll promise to be nicer, if you'll promise to be smarter. Last edited by Pinababy69; 15th July 2007 at 06:09 AM. |
| The Following User Says Thank You to Pinababy69 For This Useful Post: | ||
Sodax77 (15th July 2007) | ||
|
|||||
|
I'm surprised iNetbet hasn't commented on this yet.
![]() They are here a lot, and they are here right now actually. |
| The Following User Says Thank You to just play For This Useful Post: | ||
Sodax77 (15th July 2007) | ||
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Letter to Santa So Funny | BingoT | Jokes | 12 | 12th December 2007 11:57 AM |
| Inetbet and Moneybookers withdraw | tiger2006 | Online Casinos | 3 | 21st November 2006 03:53 PM |
| Payouts iNetBet Casino | Zodiac | Online Casinos | 3 | 14th August 2006 01:28 PM |
| Happy Birthday INetbet! | huny2 | Online Casinos | 5 | 9th May 2006 11:47 PM |