1exbug_
← back to portfolio
WRITE-UP / 02

ON-X Casino

Collection of security findings discovered during testing.

TargetON-X
AreaWeb / API / WS
Researcher1exbug
Reward75 000 ₽

Findings

01 — KYC upload without authentication

A KYC upload flow was reachable without an authenticated session.

02 — makeRebill without auth guard

The identified makeRebill functionality lacked the expected authentication guard.

03 — Payout IDOR

Payout-related object access exposed an insecure direct object reference condition.

04 — Bonus balance IDOR

Bonus balance functionality exposed an object-level authorization issue.

05 — retryPaymentUrl IDOR

The retryPaymentUrl flow exposed an object-level authorization issue.

06 — Negative loyalty points

The loyalty-point functionality accepted negative values.

07 — Race conditions

Race-condition behavior was identified in application flows during testing.

08 — WebSocket without token

A WebSocket flow was reachable without the expected token check.

Disclosure note

This page intentionally describes the findings at a high level and does not publish exploit payloads, credentials, tokens, or other sensitive data.