(04-28-2013, 02:49 PM)1llusion Wrote: I've done some pentesting and I can't see any hole in the donation system. What exactly was the user doing wrong? There isn't really any information except that he donated HCC and that he had 11 HCC and later 13 HCC.
If you peruse the image I screenshot and then uploaded on page 1, you'll note the User "donated" 4 HCC to at least 4 Members, including me. Except he didn't have the Coins to "donate" (4x4=16) because when he started his "donating", he started with 11 HCC and finished with 13 HCC.
Thus, if it wasn't a vulnerability like I thought, then it was an attempt at Social Engineering with at least 1 successfull target made.
Which is where the charge of "faking a donation" came into play.
Also keep in mind for the public record I made note of his HCC count (11 HCC) before and during the process that the User spammed the "donations", screenshot the events, and gave it no further thought until another Member (ILoveYou) publicly posted the charge, which is what I was awaiting to have the proper means to follow protocol on the matter.
No vulnerability, I'll take your expert word on that with absolute certainty and no doubts thereof. Yet it remains the User accomplished at least 1 successfull endeavor. Which I still think may have been a "bug" in the system as it coincided with the same period of time that Bluedog was pushing updates for install.
Nonetheless, if it was neither of those, then it was a Social Engineering exploit used with the human factor being the weak point.
Additional information: To this very date, no single individual has donated a single HCC to the User, nor has the User at that point in time made a comment to earn HCC (made note of on Page 1).
And I stated at least 4 Members were "donated" to, the exact count is 6 Members who were "donated" to, with-out the User actually having the HCC to "donate" that much (6x4=24).