Open Side Menu Go to the Top
Register
Scammed while playing on Twitch because of ACR software flaw Scammed while playing on Twitch because of ACR software flaw

08-10-2019 , 07:44 PM
Quote:
Originally Posted by BringThePain
My first thought was also the url but I have watched this recorded stream from 3:00 and at 3:09 he is pissed off that somebody is login him out from that game he is playing. Than he is telling about the pw he showed on the stream.

https://www.twitch.tv/videos/464726297
If you attempt to login from another computer, WPN lets you -- the existing connection is simply terminated (at least, this has been my experience). So, they could go back and forth just booting each other off.
Scammed while playing on Twitch because of ACR software flaw Quote
08-11-2019 , 03:10 PM
Quote:
Originally Posted by JamesYang
Someone else can just copy paste your casino session URL into their browser and gamble your bankroll and the client doesn't even care that another IP is logged into the same account? What?
I cannot believe that this is true, like surely not.
Scammed while playing on Twitch because of ACR software flaw Quote
08-11-2019 , 03:14 PM
Quote:
Originally Posted by FutureInsights
Still watching, he streamed for over 10 hours, I skipped ahead to where it disappeared. Did he ever get something to eat?
What about the sweet tea?
Scammed while playing on Twitch because of ACR software flaw Quote
08-11-2019 , 05:06 PM
Quote:
Originally Posted by .isolated
When you go to casino, you use a web browser. The URL provided is your URL. If you share it, people can just type it/paste it and gamble your money. Someone from the stream saw the link, went to it, bet $750/hand on BJ and lost $2700, twice.
Wow, if true.
Scammed while playing on Twitch because of ACR software flaw Quote
08-11-2019 , 05:23 PM
Quote:
Originally Posted by ArtyMcFly
Wow, if true.
They hit 15, other hands until they bust. Saw the screenshot sent to Mitch/David at the end.
Scammed while playing on Twitch because of ACR software flaw Quote
08-11-2019 , 09:26 PM
Quote:
Originally Posted by JamesYang
Someone else can just copy paste your casino session URL into their browser and gamble your bankroll and the client doesn't even care that another IP is logged into the same account? What?
Yes, this is what happened. Funny thing is ACR sponsored him but didnt tell him to hide the url...
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 12:42 AM
All those blaming him, what if he had buds over for drinks, and lolz while degening it up in the casino. Someone wants to record big win (we do it all the time), wala, they have his token. THAT, my friends, is a security problem. Is there anywhere from the past that shows can not have casino browser open in front of other people? They require keep password, etc, safe, no one said anything about browser url. What about recs?
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 01:12 AM
Quote:
Originally Posted by FutureInsights
Someone wants to record big win (we do it all the time), wala, they have his token.
I think the word you're looking for is "voila"
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 01:38 AM
Quote:
Originally Posted by GhoulPatrol
I think the word you're looking for is "voila"
lol. wala works for moi.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 05:36 AM
Quote:
Originally Posted by CantStopCalling
Yes, this is what happened. Funny thing is ACR sponsored him but didnt tell him to hide the url...
I genuinely cannot believe that their "security" is so awful that anyone with the URL can gain access to the account. The idea that an adult human professional would program this in this manner is completely bananas to me - it obviously implies that they have no encryption of your login if you can simply copy it in plain text like this. That's completely nuts, and if true, is newsworthy as an epic security fail, not just in the online poker world.

Can someone please do the below?

Quote:
Originally Posted by JamesYang
Casino Security Experiment:

1. Log onto your account and open up casino, copy the URL

2. Find a second computer/device with a different IP and paste the URL

3. Attempt to play casino games with the second device

4. Post findings
A YouTube video or similar would be best!
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 07:10 AM
Agreed. I can guarantee that Ignitions encryption is really good (though I am sure someone could hack it, but copy and paste no work).
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 07:23 AM
Quote:
Originally Posted by Josem
I genuinely cannot believe that their "security" is so awful that anyone with the URL can gain access to the account. The idea that an adult human professional would program this in this manner is completely bananas to me - it obviously implies that they have no encryption of your login if you can simply copy it in plain text like this. That's completely nuts, and if true, is newsworthy as an epic security fail, not just in the online poker world.

Can someone please do the below?



A YouTube video or similar would be best!
jesus. I can confirm I just did this and it allowed me to play straight away. no video though sorry.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 07:55 AM
Quote:
Originally Posted by Josem
I genuinely cannot believe
Then my advice is don't forward anyone a GG bet email with a button linking to a promotion.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 07:56 AM
I highly doubt that you can access the account by just putting in the URL. That would be absolutely ridiculous.

Somebody posted that he had a password from a different login visible during the stream and that one worked for his ACR, too. That explanation sounds more likely to me.

Either way, it should be easy to find out who is responsible for that. I am curious how ACR would react if it was his fault. There should be serious consequences if you broadcast your login data and allow for underage/barred viewers to access your account. If it’s ACRs fault, I hope they refund him the money and fix that situation immediately.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 08:07 AM
Quote:
Originally Posted by madlex
I highly doubt that you can access the account by just putting in the URL. That would be absolutely ridiculous.

Somebody posted that he had a password from a different login visible during the stream and that one worked for his ACR, too. That explanation sounds more likely to me.

Either way, it should be easy to find out who is responsible for that. I am curious how ACR would react if it was his fault. There should be serious consequences if you broadcast your login data and allow for underage/barred viewers to access your account. If it’s ACRs fault, I hope they refund him the money and fix that situation immediately.
well I literally just did this. I opened it up on my phone after e-mailing myself the URL from my computer. My phone was not on WiFi, just cellular network. and I was not logged in to the ACR website on my phone (I don't even know if they have a mobile site for it). But it popped up straight away and allowed me to choose games and then told me my balance and everything.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 08:31 AM
Wow, thats unbelivable!
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 09:34 AM
Quote:
Originally Posted by .isolated
Someone from the stream saw the link, went to it, bet $750/hand on BJ and lost $2700, twice.
[ ] math checks out.


I'm with josem. kind of hard to believe. even on a crap site like ACR
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 10:53 AM
Quote:
Originally Posted by PTLou
[ ] math checks out.


I'm with josem. kind of hard to believe. even on a crap site like ACR

Yeah. Seems too crazy to be true, but it is true. I was shocked when I was able to use the link on another device to open the casino.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 11:56 AM
Quote:
Originally Posted by Josem
I genuinely cannot believe that their "security" is so awful that anyone with the URL can gain access to the account. The idea that an adult human professional would program this in this manner is completely bananas to me - it obviously implies that they have no encryption of your login if you can simply copy it in plain text like this.
I believe it doesn't necessarily imply that the user/pass is not encrypted. If you wanted to program horribly, when you first login through the client (which presumably is encrypted), the client could create a unique sessionID or something and send that sessionID to the server. Then when you click to open the sports betting/casino area, it would verify that the sessionID your client passes matches an existing sessionID from a logged in user. Now obviously doing only this and passing the sessionID in the URL is ridiculously stupid. At a very minimum, you'd want to also make sure the IP address from the logged in user matches the IP address from the person accessing the sports betting page. This still wouldn't be enough (but at least better), but I'm mainly trying to show that the user/password could still be encrypted. You might be aware of this, but I was hoping to provide better explanation of what might be happening.

BTW, nobody should blame mitch Jones, as it's completely unreasonable to expect that a url is enough to gain access to your account.

Last edited by Ten5x; 08-12-2019 at 12:22 PM.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 12:43 PM
Quote:
Originally Posted by Ten5x
but I'm mainly trying to show that the user/password could still be encrypted
I agree that that is possible (even likely?), separately from what I was getting at before.

I've now learned that TLS/HTTPS does encrypt the URL, so at least a potential hacker would need to view your screen (in some detail) rather than just be on the same/upstream network from you.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 01:12 PM
He would be thanking him had he went on a BJ heater
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 02:49 PM
girlfriend - "you lost all your money? you got scammed!"
guy that just got scammed - "stfu dumbass it's not a scam!"
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 09:16 PM
Quote:
Originally Posted by ScotchOnDaRocks
He would be thanking him had he went on a BJ heater
The scammer was intentionally losing the money.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 09:23 PM
Add this as reason #147637467565 to not ever contribute rake or action of any sort to WPN. Seriously degens, nut up and go to a different site or start live crushing.
Scammed while playing on Twitch because of ACR software flaw Quote
08-12-2019 , 10:20 PM
Quote:
Originally Posted by PTLou
[ ] math checks out.


I'm with josem. kind of hard to believe. even on a crap site like ACR
Um, they kept hitting on every hand until bust Someone emailed him screen shot in video. It shows how they kept hitting every hand until bust.

It is 750 a hand if you play 3 spots for $250. The screen shot clearly shows this. Around 11:16 in video.
Scammed while playing on Twitch because of ACR software flaw Quote

      
m