1exbug_
← back to portfolio
WRITE-UP / 01

1xSlots Casino

Collection of security findings discovered during testing.

Target1xSlots
AreaWeb / API
Researcher1exbug
Reward200 000 ₽

Findings

01 — No rate limit on login

Login requests did not have an effective rate limit, allowing repeated authentication attempts.

02 — Telegram 2FA without rate limit

The Telegram-based 2FA flow could be repeatedly queried without an effective rate limit.

03 — Negative transfer amounts

The transfer functionality accepted negative amount values, creating an unexpected business-logic condition.

04 — Session IDOR

Session-related functionality exposed an insecure direct object reference condition.

05 — Password reset returns 500

The password-reset flow could be forced into an HTTP 500 error condition.

06 — Change withdrawal details

Withdrawal details could be changed through the identified application flow.

07 — Disable 2FA without old code

The 2FA disable flow did not require the previous 2FA code.

08 — Giveaway creation

A giveaway-creation functionality was identified during testing.

Disclosure note

This page intentionally describes the findings at a high level and does not publish exploit payloads, credentials, tokens, or other sensitive data.