Thanks for spamming the registration and bringing that to our attention. Should have asked for bug bounty
But what you failed to see what all the accounts vanish shortly after. 10 seconds of my life wasted
Also your other post. Posting the includes setup just for users to think its real. Well done haha
getElementsByClassName('dashed')[0]
You really have to render the circles captcha as image, in backend and overlay the clickable areas. Like this you might as well remove it.
The text captcha is sovable by implementing some otr package
YES WE. Literally everyone on here knows you are on a few profiles. Get a grip because you have an issue with Demonic take it else where. Your going to lose this one
their so called rate limit has no use except showing this error message " You have reached the maximum failed attempts. Please restart Tor to try again. " and trusting the end user to restart their tor.
I've come across plenty of trolls, but you, /u/valor98, have really raised the bar. Instead of working with the market to help fix potential issues, you’re out here trying to publicly undermine them, like that somehow makes you look impressive.
In truth, all you’ve done is exploit a mass registration bug, which they already fixed. I've explored the site thoroughly, both as a user and a vendor, and it’s actually quite solid. So really, all you’re accomplishing is making yourself look like a misguided fool.
It's okay bro I have no identity. I don't see any issue in becoming a fool till their reputation is going down. Tell me with full honestly you really think their admin and mods are capable of running DNM market, do you see any sort of professionalism in their messages or the way they operate?
Ive spoken to the admins of the site. These are not kids, they know what they are doing. Unless they are given time to run who are you to question them. You found an includes page for gods sake.
This is a captcha bypass vulnerability please review the code carefully. The website uses single captcha logic everywhere in the site and anyone can easily bypass it. For example I just did.
Exactly what I was about to comment, by writing this entire script out and now publicly ridiculing the market, admin and testers. You look stupid and have gained nothing? /u/valor98
I'm sorry, where's the vulnerability? All you did was prove you could annoy the shit out of the market admin by automating account signups with a captcha bypass? OH how will Tabriz ever recover from this devastatingly incredible vulnerability.
Straight, this is my one and only reply to this thread, I have never, and will never test for something so fucking gay and wasteful of my time.
Hopefully these markets keep getting hacked before LE has an opportunity to look at it