{"success": true, "entries": [{"entry_id": "ba9455", "surface": "play.neonrush.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: Next.js/React behind Cloudflare+AWS S3+Imperva. ProgressPlay tenant whiteLabelId=284. Enumerated unauth APIs: /api/getTenantData?wl=, /api/getWhiteLabelConfig, /api/player/getDefault, /api/player/getPlayer (PlayerId:0 anon), /api/...", "agent_name": "Recon Delta"}, {"entry_id": "defa95", "surface": "play.neonrush.com /api/player/getPlayer|getPlayerDetails|getPlayerBalance|refreshToken (unauthenticated)", "risk_area": "IDOR / broken object-level authorization (player boundary)", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Player is derived server-side from the session cookie, not from client input. Supplying PlayerId/playerId/PlayerID/id/UserHash/Email query params or X-Player-Id/X-User-Id/Authorization headers always returned the anonymous player (PlayerId:...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "d5d77f", "surface": "play.neonrush.com /api/getTenantData,getWhiteLabelConfig,getDefault (tenant selection via wl/whiteLabelId)", "risk_area": "cross-tenant IDOR / tenant boundary", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Tenant is fixed per deployment. getDefault?wl=200 and getTenantData?wl=284/200/166/8 returned the host's own tenant (whiteLabelId=284, whitelabelName \"neonrush\") or an empty object; the wl/whiteLabelId param is not honoured. Confirmed on pl...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "222fae", "surface": "play.neonrush.com authenticated player IDOR (balance/account/wallet, /api/deposit/*, /api/withdrawal/*)", "risk_area": "IDOR / horizontal privilege escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Could not obtain a player session to test authenticated object access: registration via /api/registration/registrationStepFirst is blocked server-side with em_feature_not_allowed_in_region_text (egress IP geolocated NL, isActiveCountry:fals...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "23a037", "surface": "play.neonrush.com + play.mrslot.com client JS bundle (/_next/static/chunks/5218-*.js)", "risk_area": "credential / secret exposure in client code", "outcome": "reported", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Reported as vuln-0008 and now broadened by the Shared-Platform Cross-Tenant Amplifier: the same byte-identical chunk (sha256 47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7e683992fcac, 73033 B, identical buildId WpePWuKOn3XrgMNqj5LeW)...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["reported"]}, {"entry_id": "0e3dbe", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "prototype pollution / injection", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Endpoint is reachable unauthenticated and echoes caller-supplied keys (returned {\"FreeSpinsOffer\":{},\"Deposit\":{},\"undefined\":{...}}). Requests carrying __proto__/constructor.prototype bodies were blocked by the edge WAF (Incapsula 403), so...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "5f771b", "surface": "play.neonrush.com /api/player/loginOneTime and /api/player/getErrorFromCache", "risk_area": "authentication bypass / session minting", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "loginOneTime with guessed messageid values (1, 100, all-zero UUID) returned success:false with a trustly_login_failed popup and no player/Token; getErrorFromCache?messageid= returned empty. No session is minted without a valid provider call...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "245ced", "surface": "affiliates.neonrush.com (RavenTrack affiliate portal) POST /account/login", "risk_area": "Weak/default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Recovered the real login endpoint (POST /account/login, Laravel Sanctum; CSRF via /sanctum/csrf-cookie) and replayed a bounded set with a valid X-XSRF-TOKEN. Every attempt returned 422 {\"errors\":{\"email\":[\"Credentials not found.\"]}} and the...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "4864e9", "surface": "www.neonrush.com (Cogni) — geo-restriction gate on all pages", "risk_area": "Access control / geo-restriction bypass (IP spoofing)", "outcome": "reported", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "GET / returns 302 -> /geo-block with no header or with a non-US X-Forwarded-For; returns 200 (full app, title \"Neon Rush\") with X-Forwarded-For: 8.8.8.8 or 127.0.0.1. Only XFF is honored (X-Real-IP/X-Client-IP/True-Client-IP/Forwarded ignor...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "0e3762", "surface": "www.neonrush.com ABP application services (/api/services/app/*)", "risk_area": "Broken function-level authorization on unauth endpoints", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "Enumerated 191 routes via /AbpServiceProxies/GetAll and /AbpScripts/GetScripts. All sensitive services (transactions, wallet, profile, notification, document, playerAccount) return 401 \"Current user did not login\" unauthenticated. Only low-...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "9636ea", "surface": "play.neonrush.com /api/* (ProgressPlay tenant 284)", "risk_area": "IDOR / unauth data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Re-enumerated the full client bundle route set (Game/*, player/*, deposit, withdrawal, aml, playResponsibly, registration). Anonymous calls return only the empty/anon player (getPlayer PlayerId:0, getPlayerDetails empty, getPlayerBalance 41...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "d8c126", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "Prototype pollution / reflected data", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Endpoint echoes a fixed {FreeSpinsOffer,Deposit,undefined,TimeStamp} object. Attempts to send __proto__/constructor.prototype and nested-object bodies were rejected at the edge (Incapsula 403), so server-side prototype pollution could not b...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "e4a75e", "surface": "affiliates.neonrush.com admin/affiliate login", "risk_area": "Weak/default credentials & brute force", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "POST /admin/login and POST /account/login (Laravel Sanctum, CSRF via /sanctum/csrf-cookie) return 422 \"Credentials not found\" and then 429 \"Too many login attempts\" after ~5-6 attempts for the same account. Lockout enforced.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "b50eb0", "surface": "trk.neonrush.com tracker", "risk_area": "Open redirect / SSRF", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "All probed paths (/click, /track, /redirect, /c/1, /r/1, /pixel, etc.) return 404 with a static error page; no redirect/tracking endpoint is reachable.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "930c98", "surface": "affiliates.neonrush.com /api/v1/*", "risk_area": "IDOR / broken authorization on affiliate API", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "/api/v1/users/me, /api/v1/session/check, /api/v1/users/* return 401 \"Unauthenticated.\"; other guessed object paths return 404 \"Record not found.\" No unauth object read found.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "75cd8f", "surface": "www.neonrush.com /account/login and /api/services/app/playeraccount/register", "risk_area": "Captcha/anti-automation control on standard auth flows", "outcome": "ruled_out", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "Login and registration endpoints enforce a Cloudflare Turnstile challenge (\"You must prove that you are not a robot.\"); the interactive challenge could not be solved in the headless browser, so end-to-end login/session testing was not possi...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "f3ea57", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Missing authentication / anti-automation bypass on account creation", "outcome": "reported", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "POST /api/services/app/playeraccount/registerexternalfromapi creates an active/login-capable account (successful:true, active:true, canLogin:true, userId increments) with no auth, no API key and no captcha; isusernameavailable confirms the...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "56f3d4", "surface": "www.neonrush.com — ABP application services (/api/services/app/*) enumeration for RCE-capable operations", "risk_area": "Unauthenticated file upload / import / template / command execution", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Enumerated all 191 ABP application-service actions from the unauthenticated `/AbpServiceProxies/GetAll` map and probed each (declared method, empty body). All file/import/export/exec/template-capable services (`documentuser/create`, `accoun...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "68d5bf", "surface": "www.neonrush.com — /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "Missing authentication for critical function — SSO token minting", "outcome": "reported", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "`POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=` returns a signed RS256 token with attacker-controlled sub/email/email_verified/balance claims, unauthenticated. Filed as vuln-0022 (medium)...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "72e9c8", "surface": "www.neonrush.com — authenticated document/KYC upload + pushCashPayment.authorizePayment(tenantBaseSiteUrl)", "risk_area": "File upload path traversal → arbitrary file write; SSRF via tenantBaseSiteUrl", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Resolved by the Neonrush Auth RCE Hunter with a live authenticated tenant-1 session. Document/KYC upload (`/api/accountverification/proof-documents`) requires a server-only `X-Server-Authorization` key (401 without it; no client copy of the...", "agent_name": "Neonrush Auth RCE Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "8745c6", "surface": "play.neonrush.com — /api/record/saveLastAction (key echo)", "risk_area": "Prototype pollution → RCE gadget", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "All `__proto__`/`constructor`/`prototype` token variants (plain, unicode-escaped `\\u005f`, `\\u0074o`, mixed case, nested, array form, 4 content-types) are blocked by the Incapsula/Imperva WAF with a 403 `_Incapsula_Resource` page; the only...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "dfb79d", "surface": "In-scope Next.js hosts (47 apexes + uat.* / neonrush / appmanager subdomains)", "risk_area": "React Server Components deserialization RCE (CVE-2025-55182) — fleet sweep", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "Swept the verified CVE-2025-55182 template across all 47 apex hosts plus uat.* and neonrush/appmanager subdomains (51 targets). No match anywhere. Reachable Next.js hosts (uat.*, play.neonrush.com, acedbet.com) are confirmed not vulnerable;...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "b0f377", "surface": "www.neonrush.com /api/services/app/playeraccount/register + /login (Turnstile)", "risk_area": "anti-automation control bypass (captcha) via client-controlled tenant header", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Abp.TenantId:1 skips Turnstile on playeraccount/register and playeraccount/login (200 successful:true); without the header the same calls are rejected with 'You must prove that you are not a robot.' Filed vuln-0025.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "75b3cf", "surface": "www.neonrush.com /api/authentication/login", "risk_area": "auth bypass on server-to-server login (apiKey)", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "POST api/authentication/login returns 401 {errorcode:'InvalidAPIKey'} for arbitrary X-Server-Authorization values; the apiKey is genuinely validated (an empty header produces a model-validation 'apiKey required' error).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "c18355", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser|byusername", "risk_area": "IDOR on profile pictures (PII)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "profile/getprofilepicturebyuser and byusername are reachable by a low-priv session but returned empty for all probed ids; updateprofilepicture returned HTTP 500 for several body shapes, so a picture could not be set and cross-user read of a...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "abe254", "surface": "www.neonrush.com /api/services/app/documentuser/getall + referafrienduser/getall", "risk_area": "IDOR via client-supplied userId", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Both endpoints returned only the caller's (empty) data and ignored a supplied ?userId= for a different user id — object scoping holds (contrast with the login-attempts IDOR).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5caf28", "surface": "www.neonrush.com /api/services/app/userlogin/getuserloginattempts + getuserloginattemptcount", "risk_area": "IDOR / broken object-level authorization (arbitrary userId)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Confirmed IDOR: session A (user 1853801) read user 1853802's login records incl. clientIpAddress 1.2.3.4 (A's own was 9.9.9.9); getUserLoginAttemptCount returns count for arbitrary userIds. Filed vuln-0023.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "e00cbc", "surface": "www.neonrush.com /api/services/app/turnstilepolicy/getvalidationpolicy", "risk_area": "sensitive information / credential disclosure (server-side secret)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Unauthenticated GET /api/services/app/turnstilepolicy/getvalidationpolicy?turnstileFlow=PlayerLogin&tenantId=17 returns the server-side Cloudflare Turnstile secretKey (0x4AAAAAAChdt6yjJop7KSPCX6pJnYqk6I0). Filed vuln-0024.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5c0687", "surface": "www.neonrush.com /api/services/app/* (pushcashpayment, kyc, trackingevent, stickeralbum, freeentrycode, sportsbook)", "risk_area": "BFLA on privileged ABP application services", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "With a valid low-priv tenant-1 session, every listed service returned 401 'Current user did not login' (permission-gated); a few returned 500 only on missing DTO. No unauth or low-priv access to these privileged services.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "319855", "surface": "www.neonrush.com /api/services/app/playeraccountuser/selfexclude + suspend", "risk_area": "IDOR / DoS via account self-exclude or suspend", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "playerAccountUser.selfExclude/suspend returned 200 on one session and 401 'Current user did not login' on another; it could not be determined whether a target userId/account can be supplied (self vs other). No confirmed impact.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "3861ef", "surface": "www.neonrush.com ABP /api/services/app/* parameters (isusernameavailable, getprofilepicturebyuser/byusername, isgeoblocked...)", "risk_area": "SQL injection (EF Core / ABP)", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Control: ABP + EF Core parameterization on every reachable app-service. isusernameavailable?input= returns {\"result\":true} for quote/OR payloads (literal, no error); getprofilepicturebyuser?userId=1' returns ABP model-validation 400 (type-b...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "285576", "surface": "www.neonrush.com /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "unauthenticated identity forgery / SSO token minting (missing authentication + claim injection)", "outcome": "reported", "created_at": "2026-09-27 17:57:14 UTC", "evidence": "Independently reproduced the unauthenticated SSO token minting (POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=) and added cryptographic proof: the RS256 signature on the minted token verif...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "d4e2cd", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser?userId", "risk_area": "SQL injection (sqlmap BEUT)", "outcome": "ruled_out", "created_at": "2026-09-27 18:10:02 UTC", "evidence": "sqlmap --technique=BEUT on GET /api/services/app/profile/getprofilepicturebyuser?userId=1 (XFF 8.8.8.8, --ignore-code=400,401) reported \"all tested parameters do not appear to be injectable\" (384x 400 = ABP model-validation on non-int userI...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "d53824", "surface": "GET /api/services/app/userlogin/getuserloginattempts (sorting parameter) — www.neonrush.com", "risk_area": "SQL injection / EF Core Dynamic LINQ expression injection", "outcome": "reported", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Client-supplied `sorting` is passed to System.Linq.Dynamic.Core and translated by EF Core to SQL. Data-dependent SQL boolean oracle: `sorting=IIF(it.ClientIpAddress==\"8.8.8.8\", it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 (true) vs the same with...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "863359", "surface": "ABP dynamic-API params on www.neonrush.com (filter, userId, OData $filter/$orderby)", "risk_area": "SQL injection (classic value-parameter injection)", "outcome": "ruled_out", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "`userId` is bound as an integer — non-numeric input (`1'`, `1 OR 1=1`, `abc`, overflow) returns HTTP 400 model-validation, so no string reaches SQL. `filter` is a literal substring/LIKE predicate: `8.8.8.8` matches the stored value while `'...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "88d218", "surface": "POST /api/services/app/publicenabledgames/search — www.neonrush.com", "risk_area": "SQL injection / data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Anonymous endpoint returning the public game catalogue. Injection-shaped and unknown fields (keyword/filter/searchText/provider/category, quoted payloads) are ignored — byte-identical catalogue, no error or timing differential. No auth bypa...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "48c0b7", "surface": "www.neonrush.com — ABP `sorting` parameter (EF Core Dynamic LINQ)", "risk_area": "SQL injection / database access", "outcome": "reported", "created_at": "2026-09-27 18:31:40 UTC", "evidence": "Bounded proof extraction (DB Proof Extractor) — read-only, ~211 requests / ~2 min. DBMS fingerprinted as Microsoft SQL Server: divide-by-zero raises HTTP 500 (rules out MySQL NULL semantics); string comparison is case-insensitive and traili...", "agent_name": "DB Proof Extractor (bounded)", "previous_outcomes": ["reported"]}, {"entry_id": "b99455", "surface": "www.neonrush.com — cross-tenant query via client-controlled Abp.TenantId header (post-auth)", "risk_area": "Tenant isolation bypass", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "With a tenant-1 (CogniSweeps) session, setting `Abp.TenantId: 17` (the populated real NeonRush tenant) returns HTTP 401 \"Current user did not login to the application\" on service endpoints; the header only influences pre-auth flows (registr...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "f98a8c", "surface": "www.neonrush.com — other sortable service list endpoints (documentuser/getall etc.)", "risk_area": "SQL injection via sorting parameter", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "documentuser/getall ignores the sorting parameter entirely: `it.Id`, `it.Bogus` and `it.Player.EmailAddress` all return HTTP 200 with byte-identical rows, so it is not an injection sink. Across the full AbpServiceProxies route map only user...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "4612d3", "surface": "www.neonrush.com — freeentrycodeuser/getall (FreeEntryCode -> Player navigation reachable via sorting injection)", "risk_area": "Cross-table data read via navigation property in injected dynamic-LINQ OrderBy", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "Injected sorting expression resolves a RELATED table: `it.Player.EmailAddress`, `it.Player.UserName`, `it.Player.PhoneNumber`, `it.Player.DateOfBirth`, `it.Player.Gender` all return HTTP 200 (entity translates to a SQL JOIN) while root-only...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "6d948f", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: database metadata (engine/version, schema, table list)", "risk_area": "Database metadata disclosure / DBMS identification", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Re-tested by DB Proof Extractor. Refinement: the DB *engine type* IS inferable from oracle behaviour — `IIF(1=0, it.Id, it.Id/(it.Id-it.Id))` raises HTTP 500 (integer divide-by-zero error, ruling out MySQL's NULL semantics) and string equal...", "agent_name": "DB Proof Extractor (bounded)", "previous_outcomes": ["ruled_out"]}, {"entry_id": "b7452d", "surface": "www.neonrush.com — minted SSO token consumption (in-scope consumers)", "risk_area": "Account impersonation via forged SSO token", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Re-checked for an in-scope token consumer this pass: the minted RS256 JWT is not accepted as a bearer credential (ABP session stays user:null); `/api/sso`, `/api/ssolaunch`, `/api/sso/token`, `/account/single-sign-in` all 404; `/account/log...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "0f6f31", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: arbitrary .NET type resolution / reflection escape", "risk_area": "Remote code execution (expression-injection escape to file read / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Named control: System.Linq.Dynamic.Core's restricted predefined-type provider. Positive controls prove client-side funcevaluation works (System.Math.Abs(-5)==5 -> HTTP 200; System.Convert.ToBase64String(new byte[]{65,66})==\"QUI=\" -> 200) wh...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "d06832", "surface": "www.neonrush.com /api/authentication/{login,register,social-login,social-signup}", "risk_area": "Authentication bypass via the X-Server-Authorization API key", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Additional hunt this pass, still not obtained. Confirmed: the `apiKey` DTO property is bound strictly to the `X-Server-Authorization` header (alternate header names `ApiKey`/`X-API-Key`/`Server-Authorization` and query `?apiKey=` all yield...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "407c4f", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Privilege escalation via role mass-assignment", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Obtained a real session for the registerExternalFromApi-created account (created with roleNames:[\"Admin\"], roles:[\"Admin\"], isAdmin:true; HTTP 200) by using the password-reset disclosure to set its password, then logging in (HTTP 200 sessio...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "ruled_out"]}, {"entry_id": "e753de", "surface": "www.neonrush.com playeraccount sendpasswordresetcode / sendemailactivationlink", "risk_area": "Unauthenticated resource abuse (outbound security-email flooding)", "outcome": "reported", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Both endpoints return 200 with no authentication and no captcha; identical responses for known/unknown addresses (no enumeration); 15/15 rapid requests accepted (no rate limiting). resetpassword (the completing step) is Turnstile-gated, so...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "12b9be", "surface": "www.neonrush.com /signalr-banking/negotiate", "risk_area": "cross-user data exposure via SignalR hub", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "The negotiate returns an Azure SignalR access token whose JWT is bound to the caller (nameid/unique_name/tenantId = my user, role Player), so the bankinghub connection is scoped to the requesting user; no cross-user balance/recent-game broa...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "b31250", "surface": "www.neonrush.com authenticated ABP application services (RCE sinks: file-write, eval, deserialization, command)", "risk_area": "Remote code execution", "outcome": "no_issue_found", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "Enumerated all 46 ABP controllers / 191 actions from AbpServiceProxies/GetAll and drove every file/URL/export/log sink with an authenticated session. No code-eval, template, deserialization or command sink is reachable; the only server-side...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "5c4778", "surface": "www.neonrush.com /api/services/app/pushcashpayment/* (tenantBaseSiteUrl / URL params)", "risk_area": "SSRF", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "On tenant 1 (CogniSweeps) an authenticated `authorizePayment`/`authorizeRedemptionPayment` with a unique interactsh host in `tenantBaseSiteUrl` returned 200 no-op with NO server-side fetch (no OOB hit, repeated); `createWidgetUrl` returns s...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "541c5a", "surface": "www.neonrush.com /file/downloadtempfile + /file/downloadbinaryfile", "risk_area": "path traversal / arbitrary file read", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "downloadbinaryfile validates the `id` as a GUID (400 for any traversal/absolute/path value). downloadtempfile treats `fileToken` as an opaque store key (traversal tokens → 404) and sanitises `fileName` in Content-Disposition (raw CRLF/newli...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "4a24eb", "surface": "www.neonrush.com — freeentrycodeuser/getall navigation traversal (FreeEntryCode.Player)", "risk_area": "Cross-table PII read via dynamic-LINQ navigation traversal (sorting injection)", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Navigation resolves (`Sorting=it.Player.EmailAddress` -> HTTP 200 in tenants 1/5/11) but the queryset is always empty and the injected ORDER BY is never evaluated. The only row-creating path, `freeentrycodeuser/getnewcode`, is refused serve...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "a6cea6", "surface": "www.neonrush.com — userlogin/getuserloginattempts (the only non-empty injectable entity)", "risk_area": "Cross-user / cross-table PII extraction via injection navigation", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Only this endpoint is observably injectable (scan of all 188 routes: baseline 200 -> injected 500). Its entity (UserLoginAttempt) has NO navigation property: ~40 candidate names (`it.Player.*`, `it.User.*`, `it.PlayerAccountUser.*`, `it.Cre...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "c08447", "surface": "www.neonrush.com — tenant 17 (NeonRush) session acquisition", "risk_area": "Reach the populated tenant to test the cross-table PII escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:29:44 UTC", "evidence": "Tenant 17 (the populated \"NeonRush\" tenant) cannot be reached: register and login fail CLOSED on Turnstile (policy for PlayerRegistration/PlayerLogin reports isConfigurationValid:false), and no request-level bypass worked (Abp.TenantId swit...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "d21d4d", "surface": "In-scope API/app hosts (www.neonrush.com, appmanager.tangobet.co.uk, api-qa/uat.playuk.com, www.jackpot.com, play.neonrush.com, uat.uk-bingo.net, promo.hotwinscasino.com, www.betmaze.co.uk, www.playuk.com)", "risk_area": "CORS misconfiguration + Host-header reflection / password-reset poisoning", "outcome": "reported", "created_at": "2026-09-27 20:46:22 UTC", "evidence": "Correction: my initial probe tested only the host root, where api-uat.playuk.com returned ACAO:* (wildcard, no credentials) and no host-header reflection — but that did NOT cover the /revolve/api/* route groups. A separate agent's deeper sw...", "agent_name": "Independent Red Team Lead 4", "previous_outcomes": ["no_issue_found"]}, {"entry_id": "c6f7f2", "surface": "Cross-subdomain cookie scoping on live in-scope apps (www.jackpot.com, play.neonrush.com, appmanager.tangobet.co.uk, uat.uk-bingo.net, partners.jackpot.com) vs dormant-subdomain takeover candidates", "risk_area": "Subdomain takeover escalating to parent-domain cookie tossing / session fixation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:50 UTC", "evidence": "Observed: play.neonrush.com sets incap_ses/visid_incap with Domain=.neonrush.com (incap_ses NOT HttpOnly); www.jackpot.com session cookies (ASP.NET_SessionId, jp_geolocation) are host-only, so a claimed sibling (wiki.jackpot.com, vuln-0011)...", "agent_name": "Independent Red Team Lead 1"}, {"entry_id": "68f4c7", "surface": "www.neonrush.com (Cogni/ABP) REST API services", "risk_area": "XXE / XML request-body formatter", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: ASP.NET Core app registers no XML input formatter. POST application/xml to /api/services/app/publicenabledgames/search and /api/services/app/playeraccount/register returns HTTP 415 Unsupported Media Type (json=200/400 on the...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "fa5470", "surface": "www.neonrush.com /account/profile/upload-profile-picture (multipart upload)", "risk_area": "XXE via SVG/Office/XML upload", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: upload handler enforces an extension allowlist (.gif, .jpeg, .jpg, .png, .webp) AND image content sniffing. Authenticated attempts: SVG (with external entity, parameter entity, XInclude, file:// entity) named .svg -> \"File ty...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "13a394", "surface": "play.neonrush.com shared ProgressPlay Next.js build — full chunk set (buildId WpePWuKOn3XrgMNqj5LeW)", "risk_area": "Client-side secret exposure (additional secrets beyond vuln-0008)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:35 UTC", "evidence": "Enumerated the webpack runtime chunk map and downloaded 150 chunks (2.32 MB) plus the initial chunk set; gitleaks (--no-git, json report) and manual high-signal greps found ONLY the already-reported vuln-0008 material in 5218-5c354764053c3f...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "11f361", "surface": "www.neonrush.com /api/authentication/{login,social-login,social-signup,register,logout}", "risk_area": "X-Server-Authorization API-key bypass (would enable authz bypass + make social-login a token consumer)", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Named control: a static shared API key validated after DTO validation. With a complete DTO (email/password/latitude/longitude/accuracy) every request returns HTTP 401 {\"errorcode\":\"InvalidAPIKey\"}; the header is only field-level \"required\"...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "5f7804", "surface": "www.neonrush.com /api/ controller space (content discovery)", "risk_area": "undocumented token/SSO authentication routes", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "ffuf against /api/FUZZ (295-word API endpoint list) with 404+301 filtered, plus a curated sso/token/jwt/launch/lobby/oidc list at the root: no real endpoint beyond the known controllers. /api/TokenAuth and /api/ssoAuthenticate matched only...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "62d72a", "surface": "www.neonrush.com /api/services/app/session/updateusersignintoken", "risk_area": "IDOR — mint a sign-in token for a foreign user", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Named control: the returned token and `encodedUserId` are always derived from the authenticated session's user, ignoring all request input. Supplying userId/id/encodedUserId/tenantId in the JSON body or query string (targeting user 1853837)...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "dfc26c", "surface": "www.neonrush.com ABP service map (/abpserviceproxies/getall + /abpscripts/getscripts)", "risk_area": "SSO/token-consumer route discovery (sso/jwt/token/launch/lobby/cogniplay/shopify/redirect/callback/authenticate)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Enumerated all 191 auto-exposed app-service methods and their URLs. The only token-minting/consuming routes are: shopifyssotokenservice/generatejwt (the already-reported vuln-0022), session/updateusersignintoken (PUT, no-arg, returns the ca...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "36a893", "surface": "www.neonrush.com /api/services/app/* (ABP dynamic API)", "risk_area": "CSRF / cross-site request forgery", "outcome": "reported", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "anti-forgery not enforced (no token, bogus X-XSRF-TOKEN/RequestVerificationToken, X-Requested-With all -> 200 success); identity cookie SameSite=None; forged cross-origin POST executed a durable server-side change (theme darkMode false->tru...", "agent_name": "XSS Client-Injection & Race Breadth Hunter", "by_you": true}, {"entry_id": "b83a13", "surface": "www.neonrush.com session/updateusersignintoken signInToken redemption", "risk_area": "sign-in-token replay / consumer", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "A fresh (cookie-less) session could not redeem the sign-in token: GET/POST /account/login/?signInToken=, GET /?signInToken=, POST /api/services/app/playeraccount/login {signInToken} all return the normal page or a generic validation error a...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "a94c45", "surface": "www.neonrush.com API CORS behaviour", "risk_area": "CORS misconfiguration / credentialed cross-origin read", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "Origin: https://evil.example and Origin: null on the authenticated API produced no Access-Control-Allow-Origin / -Credentials headers; the OPTIONS preflight returned 400. No CORS reflection, so cookie-session responses cannot be read cross-...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "14168a", "surface": "Minted SSO token replay across in-scope host APIs (neonrush, api-uat/qa.playuk, appmanager.tangobet)", "risk_area": "bearer/cookie acceptance of the minted SSO token", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "Minted RS256 token (iss https://id.neonrush.com, aud cogniplay-sso, sub=attacker-chosen) replayed as Authorization: Bearer, X-Server-Authorization, and Cookie .AspNetCore.Identity.Application= against api-uat.playuk.com, api-qa.playuk.com,...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "faef87", "surface": "qa.neonrush.com / stg.neonrush.com", "risk_area": "reachability / token consumer behind Basic auth", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "dev/qa/stg.neonrush.com all sit behind the same HTTP Basic auth (WWW-Authenticate: Basic realm=\"Secure Area\") on every path incl. /.well-known/jwks.json and /AbpServiceProxies/GetAll. ~24 default/predictable credential pairs (admin/*, brand...", "agent_name": "SSO Consumer & Session Auth Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "484905", "surface": "www.neonrush.com /api/games/launch-url (+ /api/loggedoutlobby/*)", "risk_area": "token-consuming game-launch route", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "GET and POST /api/games/launch-url return HTTP 401 with a fully authenticated tenant-1 session cookie (empty body). The sibling lobby/game endpoints (api/loggedoutlobby/*) also require a X-Server-Authorization key. Gap: the game-launch inpu...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "28041f", "surface": "neonrush.com subdomain enumeration (affiliates, lp, play, qa, stg, trk)", "risk_area": "attack surface mapping / hidden token-accepting hosts", "outcome": "no_issue_found", "created_at": "2026-09-27 21:04:01 UTC", "evidence": "subfinder + crt.sh for neonrush.com yielded only affiliates/lp/play/qa/stg/trk/www. play.* is ProgressPlay (different platform); affiliates./trk. CNAME to raventrack.com and lp. redirects to hub.mamba.im (out-of-scope vendor). qa/stg are Ba...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "7336ff", "surface": "lp.neonrush.com", "risk_area": "SSO token consumer", "outcome": "not_applicable", "created_at": "2026-09-27 21:04:01 UTC", "evidence": "https://lp.neonrush.com/ is a 4.6KB static PHP \"Mamba Hub\" landing page (x-powered-by PHP/8.5.10, StackCDN) whose only link (/admin) 301-redirects to http://hub.mamba.im/admin/ — an out-of-scope third-party host. No token/SSO query-param ha...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "1f9d6a", "surface": "www.neonrush.com — password-reset & email-activation link construction (/api/services/app/playeraccount/sendpasswordresetcode, sendemailactivationlink)", "risk_area": "Host-header injection / password-reset link poisoning", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Tested Host, X-Forwarded-Host, X-Forwarded-Proto, Forwarded, X-Host, X-Forwarded-Server variants against the unauth reset/activation endpoints: response is `{successful:true, redirectUrl:null, code:null, isGeoBlocked:false}` with NO reflect...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "5f985d", "surface": "www.neonrush.com — ABP service API state-changing endpoints (POST/PUT/DELETE; e.g. /api/services/app/uicustomizationsettings/changedarkmodeofcurrenttheme)", "risk_area": "CSRF / anti-forgery enforcement", "outcome": "reported", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Auth cookie issued `samesite=none; secure; httponly`. No anti-forgery token enforced and Origin/Referer not validated: a cross-site-shaped POST (Origin: https://attacker.example, form content-type, no X-XSRF-TOKEN) returned success:true and...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "1d3a3a", "surface": ".AspNetCore.Identity.Application session cookie (www.neonrush.com)", "risk_area": "Session cookie attributes (SameSite / HttpOnly / Secure / Domain) as a CSRF and theft defence", "outcome": "reported", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Raw Set-Cookie on register/login: `path=/; secure; samesite=none; httponly` with no Domain attribute (host-only). HttpOnly and Secure are correctly set and the host-only scope prevents sibling-subdomain theft, but SameSite=None means the br...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "4da926", "surface": "www.neonrush.com session fixation at the authentication transition", "risk_area": "Session fixation", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the server issues a newly generated `.AspNetCore.Identity.Application` value on each register/login and ignores a client-supplied value. Test: pre-setting the cookie to a fixed attacker-known value, then registering, produced...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "3e8f88", "surface": "GET /account/logout and server-side session revocation (www.neonrush.com)", "risk_area": "Logout / server-side session revocation", "outcome": "no_issue_found", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "On a dedicated synthetic account, GET /account/logout returned 302 with a clearing Set-Cookie; replaying the SAME pre-logout cookie against session/getcurrentlogininformations returned user:null, i.e. the session is revoked server-side. (Ob...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "b62ec0", "surface": "/api/services/app/session/updateusersignintoken (PUT) (www.neonrush.com)", "risk_area": "Sign-in token replay as an authentication credential", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Returns {\"signInToken\":\"<guid>\",\"encodedUserId\":\"<b64>\",\"encodedTenantId\":\"<b64>\"}. In a cookie-less session the token did NOT authenticate in any form tested (?signInToken= query, X-SignIn-Token header, as the identity-cookie value → user:...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "f534e7", "surface": "Session cookie Domain scope vs sibling subdomains (lp.qa.stg.neonrush.com)", "risk_area": "Cookie scope / sibling-subdomain cookie theft", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the Set-Cookie has no Domain attribute, so the cookie is host-only to www.neonrush.com and the browser will not send it to lp.neonrush.com / qa / stg. It is also HttpOnly (no JS read). Note lp.neonrush.com is a non-Cogni PHP...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "c9ee2b", "surface": "/api/services/app/profile/{changepassword,updatecurrentuseremailaddress,disablegoogleauthenticator,deleteaccount} (www.neonrush.com)", "risk_area": "CSRF reaching credential/account-takeover actions", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the ASP.NET Core JSON input formatter binds these complex `input` DTOs [FromBody] and rejects every browser-sendable content type — application/x-www-form-urlencoded, multipart/form-data and text/plain all return HTTP 415 (ve...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "f30bed", "surface": "ABP /api/services/app/* state-changing endpoints (www.neonrush.com)", "risk_area": "CSRF (cross-site request forgery)", "outcome": "reported", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Filed/covered by vuln-0031 (revised with additional evidence). Independently reproduced: with a cookie jar containing only the session cookie, a cross-origin form-encoded POST (Origin: https://evil.example, no anti-forgery token) returned 2...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "219a9e", "surface": "www.neonrush.com sendpasswordresetcode / sendemailactivationlink", "risk_area": "Host-header poisoning of password-reset / activation email links (ATO)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:08:41 UTC", "evidence": "Bounded check of POST /api/services/app/playeraccount/sendpasswordresetcode and /sendemailactivationlink with Host: evil.example (403 from Cloudflare), X-Forwarded-Host, X-Original-URL and Forwarded: host=evil.example — the generated link i...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "713fc5", "surface": "www.neonrush.com .AspNetCore.Identity.Application cookie scope + tenant binding", "risk_area": "cross-tenant session confusion / cookie scope", "outcome": "ruled_out", "created_at": "2026-09-27 21:08:41 UTC", "evidence": "Session cookie Set-Cookie attributes captured raw: `.AspNetCore.Identity.Application=...; expires=...; path=/; secure; samesite=none; httponly` — host-only (no Domain), so no sibling-subdomain (e.g. lp.neonrush.com) theft. Cross-tenant: a t...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "a20db8", "surface": "www.neonrush.com /api/services/app/playeraccount/{sendpasswordresetcode,resetpassword}", "risk_area": "Authentication bypass / account takeover via password-reset flow", "outcome": "reported", "created_at": "2026-09-27 21:12:16 UTC", "evidence": "Unauth `sendPasswordResetCode?sendEmail=false` returns the reset code in the body; `resetPassword` accepts it with a client-supplied future `expireDate`; login with attacker-set password yields a victim session. Full ATO proved end-to-end;...", "agent_name": "NeonRush Auth-Gap Closer"}, {"entry_id": "26b4e2", "surface": "www.neonrush.com administrative surface (ABP Zero admin services + admin UI paths)", "risk_area": "Vertical privilege escalation to admin/operator", "outcome": "not_applicable", "created_at": "2026-09-27 21:12:33 UTC", "evidence": "No privilege-escalation target exists on this host. /admin, /admin/login, /hangfire, /elmah.axd, /swagger, /operator, /backoffice, /dashboard, /management, /cogniadmin, /adminpanel all 404 (the 301s are case-normalisation redirects that the...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "39d9ef", "surface": "qa/stg/dev.neonrush.com (staging Cogni/ABP environments)", "risk_area": "Authentication bypass via shared X-Server-Authorization key / staging asset exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:14:38 UTC", "evidence": "LIVE ABP instances. qa.neonrush.com serves the API without auth for /api/* (e.g. GET /api/services/app/session/getcurrentlogininformations → 200, tenant \"NeonRush\" id 20) but every non-/api path (/, /abpscripts, /abpserviceproxies, /dist/*,...", "agent_name": "Cogni X-Server-Authorization Key Hunter"}, {"entry_id": "450c4d", "surface": "www.neonrush.com unauthenticated GET surface (all 65 GET methods of the 46 ABP services)", "risk_area": "Configuration/secret disclosure in service responses", "outcome": "no_issue_found", "created_at": "2026-09-27 21:14:38 UTC", "evidence": "Enumerated every GET method from abpserviceproxies/getall and called each unauthenticated (X-Forwarded-For: 8.8.8.8, no session). Exactly 9 returned 200 and all are benign/public (geo decision, password-policy, locales, empty profile pictur...", "agent_name": "Cogni X-Server-Authorization Key Hunter"}, {"entry_id": "cc864a", "surface": "POST /api/services/app/playeraccount/login (www.neonrush.com, ABP, tenant 1)", "risk_area": "Race condition / TOCTOU defeating the ABP account-lockout threshold", "outcome": "no_issue_found", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "Sequential baseline: 4 wrong passwords -> \"Invalid user name or password\", 5th -> \"The user account has been locked out\" (threshold 4). A 10-request concurrent burst on a fresh account produced exactly 4 password verifications, 2 lockout re...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "bcd829", "surface": "www.neonrush.com /api/amoe/*, /api/freerefill, /api/redemption/*, /api/coins/*, /api/playerprofile/*, /api/services/app/transactionsuser/freerefill, /api/services/app/loyaltyuserservice/redeemloyaltypoints", "risk_area": "Race condition on privileged / one-per-user limit endpoints (refill, redemption, coins, loyalty points)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Reachability gap: the dark API routes (amoe/code, amoe/info, amoe/history, freerefill, redemption/*, coins/packages*, playerprofile/*) all return HTTP 401 (coins/packages/query returns {\"errorcode\":\"InvalidAPIKey\"}) because they require the...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "b17853", "surface": "POST /api/services/app/playeraccount/register (www.neonrush.com, ABP, tenant 1)", "risk_area": "Race condition → duplicate account creation / username-uniqueness bypass", "outcome": "no_issue_found", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Concurrent 4x registration with an identical emailAddress/userName: exactly 1 HTTP 200 (account created, userId returned) and 3 HTTP 500 with \"Username '<email>' is already taken.\" A subsequent login with that email succeeded. Uniqueness en...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "eb53c8", "surface": "POST /api/services/app/freeentrycodeuser/getnewcode (www.neonrush.com, ABP, tenants 1/5/11)", "risk_area": "Race condition → single-use / one-per-period code over-issue", "outcome": "ruled_out", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Named control: the account-verification gate runs before any code is created. A synchronised 10-request concurrent burst with an authenticated tenant-1 session and skipCaptcha=true returned state 998 (\"Your Account Details Must Be Verified...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "4230d8", "surface": "POST /api/services/app/playeraccount/sendpasswordresetcode?sendEmail=false + /playeraccount/resetpassword (www.neonrush.com)", "risk_area": "Authentication / unauthenticated account takeover via password-reset code disclosure + client-controlled expiry", "outcome": "reported", "created_at": "2026-09-27 21:20:25 UTC", "evidence": "Independently reproduced end-to-end (IRT Lead 1, script /workspace/irt_verify_reset.py): unauth sendpasswordresetcode?sendEmail=false leaked code E17009DD35 for a fresh account (userId 1854419); resetpassword with client-supplied future exp...", "agent_name": "Independent Red Team Lead 1"}, {"entry_id": "459d41", "surface": "POST /api/tokenauth/authenticate (www.neonrush.com)", "risk_area": "Session minting / Turnstile bypass via the ABP Zero TokenAuth controller", "outcome": "ruled_out", "created_at": "2026-09-27 21:21:23 UTC", "evidence": "The ABP Zero TokenAuth endpoint exists and is not API-key gated, but the per-tenant Turnstile policy is enforced before credential validation on it: with Abp.TenantId: 17 (and with no header) a valid tenant-17 account returns \"You must prov...", "agent_name": "NeonRush ABP Session Unlock"}, {"entry_id": "fa6e13", "surface": "www.neonrush.com/account/login Cloudflare Turnstile widget (sitekey 0x4AAAAAAChdt0aXJQzhuYXQ)", "risk_area": "Solving the anti-automation challenge from an automated browser to obtain a tenant-17 session", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:21:23 UTC", "evidence": "With the geo-gate satisfied (X-Forwarded-For injected via browser headers), the widget renders but Cloudflare never issues a token: console shows repeated \"[Cloudflare Turnstile] Error: 600010\" and the challenge iframe reports \"Verification...", "agent_name": "NeonRush ABP Session Unlock"}, {"entry_id": "693521", "surface": "userLogin.getUserLoginAttempts `sorting` injection — entity member space and hidden-column reads (www.neonrush.com)", "risk_area": "Cross-user PII extraction via EF Core dynamic-LINQ injection", "outcome": "reported", "created_at": "2026-09-27 21:21:23 UTC", "evidence": "Member existence oracle `(it.X == null) || (it.X != null)` on the injected ORDER BY expression resolved Id/TenantId/UserId/ClientIpAddress/ClientName/BrowserInfo/Result/FailReason/CreationTime and, critically, `it.UserNameOrEmailAddress` (t...", "agent_name": "NeonRush ABP Session Unlock"}, {"entry_id": "59ce07", "surface": "www.neonrush.com (Cogni/ABP, Cloudflare)", "risk_area": "Web cache poisoning + cache deception", "outcome": "not_applicable", "created_at": "2026-09-27 21:22:57 UTC", "evidence": "Cloudflare does not cache the app: cf-cache-status: DYNAMIC for /, /index.html, /manifest.json, /assets/, /AbpServiceProxies/GetAll, /AbpScripts/GetScripts, /api/services/app/session/getcurrentlogininformations (200 JSON), /sitemap.xml, /sw...", "agent_name": "Cache Poisoning and Deception Hunter"}, {"entry_id": "5cd793", "surface": "Cloudflare marketing/Nuxt fleet + ProgressPlay play.* + jackpot.com apex (wombatbingo, pandabingo, queensbingo, uk-bingo.net, jazzyspins, slotlux, mrslot, mrsuperplay, mrmobi, mrjackvegas, acelucky, africasports, 777bet.casino, betstorm, dynobet, chitchatbingo, vampirebingo, betarno, play.neonrush.com, savibet, rainbetsplash, stakespin, q88bets, jackpot.com)", "risk_area": "Web cache poisoning", "outcome": "no_issue_found", "created_at": "2026-09-27 21:22:57 UTC", "evidence": "All return cf-cache-status: DYNAMIC (or Imperva 403 / 301 apex redirects with no cacheable dynamic response) for /, /api/pp/games, /?s=, /robots.txt. No Cloudflare caching of dynamic content => no poisoning surface. jackpot.com apex is a fi...", "agent_name": "Cache Poisoning and Deception Hunter"}, {"entry_id": "f1eba1", "surface": "play.neonrush.com player API (/api/player/getDefault, /api/player/getPlayer) — 'platform-web' cookie its identity credential", "risk_area": "Sealed cookie used as an authentication/session credential for the API", "outcome": "ruled_out", "created_at": "2026-09-27 21:23:43 UTC", "evidence": "Named control: the in-scope player API does not consume platform-web. GET /api/player/getDefault returns byte-equivalent JSON with (a) no cookie, (b) the valid own seal, and (c) a tampered seal — the only differing fields are the per-reques...", "agent_name": "ProgressPlay Iron Cookie Seal Cracker"}, {"entry_id": "5e2e45", "surface": "https://www.neonrush.com /account/login + /account/register (returnUrl / ReturnUrl / returnUrlHash)", "risk_area": "Reflected XSS / HTML injection via returnUrl", "outcome": "ruled_out", "created_at": "2026-09-27 21:24:12 UTC", "evidence": "Named control: the controller HTML-encodes returnUrl into the hidden field (`value=\"/aaa&quot;&gt;&lt;svg/onload=zqx()&gt;\"`) and rejects non-local values (absolute/`//host` URLs are replaced with `/`). Only the canonical/og:url meta echoes...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "a72685", "surface": "https://www.neonrush.com /Popup/Render (fetch -> host.innerHTML sink)", "risk_area": "DOM XSS via innerHTML of server HTML", "outcome": "no_issue_found", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "The inline reloadPopup() does `host.innerHTML = html` from `GET /Popup/Render`, so it is a genuine sink, but the endpoint returns an empty body (HTTP 200, 0 bytes) and reflects none of id/popupId/popup/name/type/slug/game/url/code/title/mes...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "7567df", "surface": "https://www.neonrush.com client-side game search (#searchResultsTemplate + #results-heading innerHTML)", "risk_area": "DOM XSS (Mustache innerHTML render)", "outcome": "ruled_out", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Named controls: the template uses only double-brace `{{pageSlug}}`/`{{name}}`/`{{provider}}`/`{{logoImagePath}}` (Mustache HTML-escapes them), and the rendered data is the server-side game catalogue (pageSlug/name/provider are server metada...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "03b77e", "surface": "https://www.neonrush.com /games/play/play-game-modal (slug from location.hash -> ModalManager POST -> .html(response))", "risk_area": "DOM XSS via location.hash-controlled slug rendered as HTML", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Source->sink trace is complete and attacker-controllable: Index.min.js reads/decodes `location.hash` and calls ModalManager.open({slug:<hash>}), whose ABP implementation does `$.ajax({url:viewUrl,type:'POST',data:args})` then `s.html(o)`. H...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "c3e88e", "surface": "https://play.neonrush.com (Next.js/ProgressPlay app) path + API params", "risk_area": "Reflected/DOM XSS", "outcome": "ruled_out", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Path payload (`/<svg/onload=..>`) is rejected by Imperva with HTTP 403 (no body), so no Next.js error-page reflection is reachable; getTenantData/getWhiteLabelConfig/player.getPlayer/getDefault return JSON with no reflection of `wl`/`Player...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "2a1a7b", "surface": "https://www.neonrush.com ABP notification rendering (UserNotificationHelper.showAsPop / showUiNotifyForUserNotification) + unvalidated user name", "risk_area": "Stored XSS (notification message rendered as HTML)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Sink confirmed in shipped JS: _Notifications.min.js calls `showAsPop` for each item of `notification/getUserNotifications`, and showAsPop runs `swal.fire({html: abp.notifications.getFormattedMessageFromUserNotification(t), ...})`, which cli...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}], "filtered_count": 102, "total_count": 567, "outcome_counts": {"reported": 78, "no_issue_found": 160, "ruled_out": 218, "not_applicable": 21, "needs_follow_up": 90}}