För er som inte har tillgång till Dread så publicerades detta nyligen gällande Moominmarket som har nämnts i tråden.
Citat:
Moomin Market is now banned and the flaws are as under:
-> Not using Captchas, will allow bad people to mass create accounts or mass create support tickets.
-> Not using CSRF Tokens, i managed to create the accounts with a simple Rust Script, i made in under an hour.
-> Not having any rate limiting or firewall, nothing at all, you can easily ddos them and they will give error 504 because their backend or DB crashed.
-> not using any POW defense on your torrc, it is very simple to add that, its just 1 line that will take not even a minute to add.
-> Their Monero deposits are litterely crediting my account 3x the amount i deposited, i made a test deposit of 0.001 xmr and it credited my account 0.003 xmr lol.
-> Their XMR withdrawal is not working, i tried withdrawing it and its been like 3 hours and nothing on my wallet. (i lost my 30 cents to that market)
-> a few more technical issues...
I have thoroughly verified the claims, and I apologize for the oversight in approving them.
There is no place here for these type of markets. They can and probably will continue running, but they are not welcome or recognized by /d/newmarkets.
No tolerance will be given to these type of markets. I have been trying my best to not approve any questionable markets, and in mod mail, I have banned more than 15 markets so far.
However, this is my mistake, and I accept responsibility for it. I apologize for it.
Thank you, /u/Scarab, for the findings.
- Valor
-> Not using Captchas, will allow bad people to mass create accounts or mass create support tickets.
-> Not using CSRF Tokens, i managed to create the accounts with a simple Rust Script, i made in under an hour.
-> Not having any rate limiting or firewall, nothing at all, you can easily ddos them and they will give error 504 because their backend or DB crashed.
-> not using any POW defense on your torrc, it is very simple to add that, its just 1 line that will take not even a minute to add.
-> Their Monero deposits are litterely crediting my account 3x the amount i deposited, i made a test deposit of 0.001 xmr and it credited my account 0.003 xmr lol.
-> Their XMR withdrawal is not working, i tried withdrawing it and its been like 3 hours and nothing on my wallet. (i lost my 30 cents to that market)
-> a few more technical issues...
I have thoroughly verified the claims, and I apologize for the oversight in approving them.
There is no place here for these type of markets. They can and probably will continue running, but they are not welcome or recognized by /d/newmarkets.
No tolerance will be given to these type of markets. I have been trying my best to not approve any questionable markets, and in mod mail, I have banned more than 15 markets so far.
However, this is my mistake, and I accept responsibility for it. I apologize for it.
Thank you, /u/Scarab, for the findings.
- Valor