1xSlots Casino
Collection of security findings discovered during testing.
Findings
01 — No rate limit on login
Login requests did not have an effective rate limit, allowing repeated authentication attempts.
02 — Telegram 2FA without rate limit
The Telegram-based 2FA flow could be repeatedly queried without an effective rate limit.
03 — Negative transfer amounts
The transfer functionality accepted negative amount values, creating an unexpected business-logic condition.
04 — Session IDOR
Session-related functionality exposed an insecure direct object reference condition.
05 — Password reset returns 500
The password-reset flow could be forced into an HTTP 500 error condition.
06 — Change withdrawal details
Withdrawal details could be changed through the identified application flow.
07 — Disable 2FA without old code
The 2FA disable flow did not require the previous 2FA code.
08 — Giveaway creation
A giveaway-creation functionality was identified during testing.
This page intentionally describes the findings at a high level and does not publish exploit payloads, credentials, tokens, or other sensitive data.