ON-X Casino
Collection of security findings discovered during testing.
Findings
01 — KYC upload without authentication
A KYC upload flow was reachable without an authenticated session.
02 — makeRebill without auth guard
The identified makeRebill functionality lacked the expected authentication guard.
03 — Payout IDOR
Payout-related object access exposed an insecure direct object reference condition.
04 — Bonus balance IDOR
Bonus balance functionality exposed an object-level authorization issue.
05 — retryPaymentUrl IDOR
The retryPaymentUrl flow exposed an object-level authorization issue.
06 — Negative loyalty points
The loyalty-point functionality accepted negative values.
07 — Race conditions
Race-condition behavior was identified in application flows during testing.
08 — WebSocket without token
A WebSocket flow was reachable without the expected token check.
This page intentionally describes the findings at a high level and does not publish exploit payloads, credentials, tokens, or other sensitive data.