Live data from Hacker News

Hacking the World Poker Tour: Inside ClubWPT Gold's Back Office

samcurry.net

1–10 of 12 posts

Re: Hacking the World Poker Tour: Inside ClubWPT Gold's Back Office

#7
post #5

What's this 'subs' command being run to enumerate subdomains?

Not sure what it is but certificate transparency logs are a goldmine for this. https://crt.sh/?q=liuxinyi1.cn

Oh got this"

"CONTEXT: PL/pgSQL function web_apis(text,text[],text[]) line 4671 at FOR over EXECUTE statement ERROR: server conn crashed?"

May be pushing a bit too hard on their postgres-rest ?

Re: Hacking the World Poker Tour: Inside ClubWPT Gold's Back Office

#8
post #5

What's this 'subs' command being run to enumerate subdomains?

Not sure what it is but certificate transparency logs are a goldmine for this. https://crt.sh/?q=liuxinyi1.cn

That's interesting. Suppose it doesn't do you any good if you're looking for subdomains that don't have certs though.

Re: Hacking the World Poker Tour: Inside ClubWPT Gold's Back Office

#10
And the biggest question that all of that raises and stays unaddressed is how a US official and regulated gambling website is developped and probably operated directly from China?

Meaning all PII (name, address , id scans, ip, ...) are available to Chinese individuals.

The argument that the dev website is just developped in China doesn't hold as you can see that the prod admin panel is also partially in Chinese.

And what to say about the admin that is really using 123456 as password in production...

Post reply on HN