{"success": true, "entries": [{"entry_id": "6833c5", "surface": "tangobet.co.uk (+subdomains)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "apex/www Imperva 403 (blocked for sandbox IP). Reachable subdomains mapped: appmanager (Betty Admin SPA + /api/admin/* Bearer-JWT, 401 gated, unauth /api/mobile-app/stats), app (AppsFlyer OneLink), deletemyaccount, affiliates/promos (403 ng...", "agent_name": "Recon Echo"}, {"entry_id": "ece8bd", "surface": "acedbet.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Checkpoint now SOLVED with a real browser. `agent-browser open https://www.acedbet.com/` renders the Vercel Security Checkpoint once, then the real app: title \"Acedbet - £1,000 bonus and 100 free spins to all new players\", hydrated Next.js...", "agent_name": "Cogni X-Server-Authorization Key Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "018859", "surface": "uat.uk-bingo.net / uat.pandabingo.com (shared EKS UAT app)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Both resolve to one AWS ELB k8s-devkrake-sitesing-...eu-west-2.elb.amazonaws.com; Next.js/React/Webpack. /api/health → 200; /api/v1 → 308→/api/v1 (404); other /api/* 404. App bundles reference platform API api.dev.kraken.ptops.net/api/v1, W...", "agent_name": "Recon Bravo"}, {"entry_id": "411914", "surface": "betmaze.co.uk (+ www.betmaze.co.uk, play.betmaze.co.uk)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE WordPress 7.1.2 (LiteSpeed/PHP/MySQL, twentytwentyfive-child theme) behind Cloudflare. /wp-json/wp/v2/users enumerates user `betmaze_login`; xmlrpc.php present; custom theme PHP fetch-sports.php/fetch-promotions.php/fetch-games.php AJA...", "agent_name": "Recon Alpha"}, {"entry_id": "24efa9", "surface": "chitchatbingo.com (+ www, play, uat, api, support)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE. Marketing = Nuxt3/Vue on Cloudflare with API /api/pp/games, /api/worker/games and Cloudflare Workers *.tech1960.workers.dev. play.chitchatbingo.com = Betable app behind Imperva. uat.chitchatbingo.com = AWS EKS Next.js staging (1.3MB)...", "agent_name": "Recon Alpha"}, {"entry_id": "eb311b", "surface": "dynobet.com (+ www, play, affiliates, promos, *.uat/*.qa)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE ProgressPlay white-label (Imperva acct 3119998), title \"Dynobet: Sports betting and Online Casino\". affiliates.dynobet.com + promos.dynobet.com → AWS Elastic Beanstalk webapp-env.eba-4x3ezugm.eu-west-2.elasticbeanstalk.com (403 nginx)....", "agent_name": "Recon Alpha"}, {"entry_id": "a91887", "surface": "betsuna.com (+ www.betsuna.com, games.betsuna.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "WordPress behind Cloudflare+LiteSpeed; root `/` has a 301↔302 redirect loop returning no body, but /robots.txt, /wp-json/ (224KB exposed), /wp-json/wp/v2/users (user `betsunaadmin`), /wp-login.php all respond. games.betsuna.com → Microsoft-...", "agent_name": "Recon Alpha"}, {"entry_id": "c45341", "surface": "betmorph.com SPA admin routes (/admin, /admin/users, /admin/cms/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Admin guard is client-side only (OIDC isAuthenticated + Convex users.isAdmin; false -> redirect /). Unauth requests to /admin, /admin/users, /admin/cms/home render only the sign-in prompt (no data). All privileged data/actions resolve to Co...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "e360e7", "surface": "777tigers.com SPA admin routes (/admin, /admin/users, /admin/games, /admin/pages/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Same client-side-only guard as betmorph. Unauth /admin/users and /admin/games show \"Admin Access Required / Please sign in\". Privileged functions (users.getAllUsers, users.updateUserRole role-escalation, games.create/update/remove, cms.upse...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "222fae", "surface": "play.neonrush.com authenticated player IDOR (balance/account/wallet, /api/deposit/*, /api/withdrawal/*)", "risk_area": "IDOR / horizontal privilege escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Play.*** ProgressPlay player app (Next.js). Region gate on POST /api/registration/registrationStepFirst returns 500 {\"Text\":\"em_feature_not_allowed_in_region_text\"} for our NL egress (getDefault: countryCode=NL, isActiveCountry=false). Full...", "agent_name": "ProgressPlay play.* Geo-Bypass IDOR Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "0e3dbe", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "prototype pollution / injection", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Endpoint is reachable unauthenticated and echoes caller-supplied keys (returned {\"FreeSpinsOffer\":{},\"Deposit\":{},\"undefined\":{...}}). Requests carrying __proto__/constructor.prototype bodies were blocked by the edge WAF (Incapsula 403), so...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "4caecb", "surface": "play.africasports.com, play.acelucky.com, play.777bet.casino, play.betstorm.com, play.dynobet.com, play.luckcity.com, play.mamzinobet.com, play.mrrex.com, play.moneyplay.com, play.ne-bet.com, play.q88bets.com, play.stakespin.casino, play.savibet.com, play.rainbetsplash.com", "risk_area": "attack surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "No DNS for these play.* hosts (dig returns nothing; proxy 502 = unresolved, not a target response); play.betstorm.com resolves to Cloudflare but the origin returns 522. play.mogobet.com and play.mrslot.com resolve but sit behind Imperva (40...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "e0aa35", "surface": "acedbet.com", "risk_area": "Unauthenticated CMS proxy (blast-radius check for vuln-0003) / general surface", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:45:57 UTC", "evidence": "Every request (including the root `/`) returns HTTP 429 from Vercel, repeatedly, even when spaced ~8s apart — egress is rate-limited/blocked, so /api/cms and the app surface could not be observed. The 429 body (data-astro-cid marker) indica...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "6f82b3", "surface": "partners.jackpot.com Cellxpert partner/admin login (/authenticate, /authenticate/admin-auth)", "risk_area": "Weak/default credentials", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Exposed partner portal and a separate admin login (/v2/login/admin-login/). Login POST /authenticate/admin-auth returns {\"error\":true,\"isCaptchaRequired\":true,\"reason\":\"Bad Captcha\"} for every credential — the server rejects on captcha BEFO...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "6d32ad", "surface": "acedbet.com POST /api/auth/callback/credentials", "risk_area": "Authentication — credential validation, CSRF enforcement, enumeration, brute-force, callbackUrl redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Re-confirmed with a REAL browser (agent-browser, headless Chromium) after solving the Vercel Security Checkpoint — the prior result was from a non-browser client. POST /api/auth/callback/credentials returns 403 `{\"error\":\"Access denied\"}` f...", "agent_name": "Cogni X-Server-Authorization Key Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "5c0c15", "surface": "acedbet.com password-reset Server Action (POST /?modal=forgot-password)", "risk_area": "User enumeration / reset-flow abuse", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Action reached (body [\"email\",\"en\"]) but returns 1:{\"success\":false,\"error\":\"ACCESS_DENIED\"} for the probed address, so existing-vs-nonexistent response differences could not be compared. Client-side validator rejected mailinator.com addres...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "fd2dc6", "surface": "acedbet.com registration Server Action (POST /?modal=create-account)", "risk_area": "Account creation abuse / anti-bot control enforcement", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Re-confirmed via the real registration UI in a real browser: navigate to `https://www.acedbet.com/en?modal=create-account`, fill Full name / Email / Phone (+31) / Password / Country (Netherlands) and submit → the Server Action `POST /en?mod...", "agent_name": "Cogni X-Server-Authorization Key Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "3d8a79", "surface": "acedbet.com x-is-human anti-bot header (all POST routes)", "risk_area": "Security-control enforcement / bot-protection bypass", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Re-verified from a real browser. The anti-bot SDK patches fetch/XHR to add `x-is-human`/`x-path`/`x-method` for `{path:\"/api/auth/callback/credentials\",method:\"POST\"}` and `{path:\"/*\",method:\"POST\"}` with `advancedOptions.checkLevel:\"basic\"...", "agent_name": "Cogni X-Server-Authorization Key Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "096efe", "surface": "acedbet.com /api/auth/session and /api/auth/csrf", "risk_area": "Session / JWT handling and cookie flags", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Anonymous session returns null; CSRF cookie confirmed HttpOnly+Secure+SameSite=Lax. No session/JWT could be obtained (login denied), so signing strength, alg confusion, fixation and session-cookie flags could not be assessed.", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "df5d6f", "surface": "support.uk-bingo.net", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> ukbingo.zendesk.com -> 301 /app/help-center-closed/. KEY CONTROL TEST: a random unregistered subdomain zzznotreal99x8y7.zendesk.com returns BYTE-IDENTICAL responses (301 to help-center-closed with utm_content=<host>; 404 9-byte on...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "33799b", "surface": "ftp.betmorph.com, mail.betmorph.com, smtp.betmorph.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Re-tested 2026-09 (30s timeouts). Cloudflare-proxied A (104.21.56.95 / 172.67.183.188); every HTTPS and HTTP request returns Cloudflare HTTP 522 (origin unreachable), consistently across attempts (while the same-zone whm/cpanel resolve to a...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "d8c126", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "Prototype pollution / reflected data", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Endpoint echoes a fixed {FreeSpinsOffer,Deposit,undefined,TimeStamp} object. Attempts to send __proto__/constructor.prototype and nested-object bodies were rejected at the edge (Incapsula 403), so server-side prototype pollution could not b...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "58946d", "surface": "Nuxt marketing SPA CMS/config-content innerHTML sinks (shared across the 9 hosts)", "risk_area": "Stored/DOM XSS via CMS content rendered with innerHTML", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "The apps render CMS/config strings via innerHTML (e.g. sig_terms/sigTerms, heading/subheading/body/intro, footerHtml, compliance HTML, WordPress content.rendered). The data is fetched from OUT-OF-SCOPE sources (access-content-pp.tech1960.wo...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "9806ad", "surface": "POST /api/admin/notifications/send", "risk_area": "unauthorized/mass notification action", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Deliberately not executed per the non-destructive rule: targetType accepts 'all' and 'selected', and a send would push to the full pushable audience (~1,046 players). Request-schema validation, authorization, and rate-limiting of this route...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "e6f3d7", "surface": "Betty Admin SPA (index HTML + API responses)", "risk_area": "missing anti-framing headers / clickjacking", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Responses carry no X-Frame-Options, no CSP frame-ancestors, no HSTS, no X-Content-Type-Options and no Referrer-Policy, and the SPA bundle contains no frame-busting logic, so the admin UI is embeddable in an iframe. Impact is not confirmed:...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "4e97a0", "surface": "POST /api/admin/notifications/send — advancedFilter handling / fail-open", "risk_area": "fail-open mass targeting", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "A valid zero-match filter (Status eq '__zz_no_such_status__', proven total:0 via players/count) produced count 0 on the send route, so the filter IS honoured for well-formed input (no observed fail-open). The behaviour for a MISSING or INVA...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "69fa9d", "surface": "Notification title/content rendered in player client", "risk_area": "stored content injection into player-facing push payload", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "Notification title/content are fully caller-controlled and stored/forwarded verbatim (no sanitization observed server-side; the admin UI renders nothing server-returned via an HTML sink). Whether the player-facing mobile/webview client rend...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "13cbeb", "surface": "Notification recipient-safety gates (pushable&gt;0, selected-requires-filter)", "risk_area": "client-side-only enforcement (CWE-602)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "The UI enforces recipient-safety gates (cannot send when matched-audience pushable===0; 'selected' requires a filter), but the API accepted a send request the UI would block, returning 201 {\"success\":true,\"count\":0}. Impact is unproven beca...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "3ed848", "surface": "tangobet.co.uk DNS email-auth records (SPF/DKIM/DMARC)", "risk_area": "email spoofing / sender authenticity (missing DMARC)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "dig shows SPF 'v=spf1 include:mailgun.org ~all' (softfail) and NO DMARC record (_dmarc.tangobet.co.uk is empty); DKIM exists only for selector s1 (Mailgun RSA key). With no published DMARC policy, receivers get no reject/quarantine instruct...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "28cc97", "surface": "betmaze.co.uk & betsuna.com — enumerated admin accounts (betmaze_login, betsunaadmin, admin)", "risk_area": "Account takeover via credential brute-force / password guessing (validation of the username-enumeration + missing-throttle chain)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:43:45 UTC", "evidence": "Chain capability validated end-to-end: identifiers are valid logins (confirmed via login error differential), the XML-RPC endpoint evaluates credentials genuinely (demo.sayHello succeeds in the same multicall), a single request carries 500...", "agent_name": "WP Takeover Chain Validator"}, {"entry_id": "c18355", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser|byusername", "risk_area": "IDOR on profile pictures (PII)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "profile/getprofilepicturebyuser and byusername are reachable by a low-priv session but returned empty for all probed ids; updateprofilepicture returned HTTP 500 for several body shapes, so a picture could not be set and cross-user read of a...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "319855", "surface": "www.neonrush.com /api/services/app/playeraccountuser/selfexclude + suspend", "risk_area": "IDOR / DoS via account self-exclude or suspend", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "playerAccountUser.selfExclude/suspend returned 200 on one session and 401 'Current user did not login' on another; it could not be determined whether a target userId/account can be supplied (self vs other). No confirmed impact.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "1f4b0f", "surface": "appmanager.tangobet.co.uk POST /api/auth/login (HS256 JWT)", "risk_area": "JWT HS256 signing-secret recovery / token forgery", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:49:37 UTC", "evidence": "Captured a valid HS256 token via the default credential and attempted an offline brute-force: the prior reviewer had already exhausted rockyou (14.34M) + a 10k list; this pass added ~200,500 mutated/targeted candidates (betty/tangobet/railw...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "6913d3", "surface": "theonlinecasino.co.uk, mogobet.com, betmaze.co.uk, betsuna.com, jeffbet.net, playuk.com — WordPress admin-credential path to theme-editor RCE", "risk_area": "RCE via admin credential compromise -> theme/plugin editor", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "No unauthenticated file-write/upload primitive and registration is disabled, so RCE requires valid admin credentials. xmlrpc.php system.multicall + wp-login.php have no rate limiting/lockout (vuln-0014), making credential brute force the re...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "6e15f5", "surface": "77.68.12.66 (promotions.pandabingo.com) — MariaDB 10.5.29 on tcp/3306", "risk_area": "Internet-exposed database service / weak-credential DB access", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Additional targeted testing by this agent: 1,254 more attempts (usernames root/admin/psa/mysql/promotions/pandabingo/panda/bingo/promo/web/www/db/database/user/test/wordpress/wp/plesk/backup/sql/debian-sys-maint x brand-/server-/Plesk-deriv...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "d271cb", "surface": "jackpot.com string-parameter widget endpoints (UsWebIdentity/CheckUser, UsaServices/ComplianceCheck, UsWebIdentity/Error?id=, Menu/Timezones|Results, Promotion/Tac, UsGames/*)", "risk_area": "SQL injection via application parameters", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Extended testing: /%2ftrace.axd reaches the ASP.NET Trace handler but returns a 3425B \"Trace Error\" page (remote tracing disabled, localOnly); /elmah.axd + /%2felmah.axd -> 404 (not deployed). /shoppingcart?promoCode|search|sort|orderby ->...", "agent_name": "App-Layer SQLi Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "7f13db", "surface": "games.playuk.com", "risk_area": "RCE surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "games.playuk.com returns a blanket 403 awselb/2.0 for every path, User-Agent, method and normalization variant (incl. /%2f) — the ALB exposes no content and no origin hostname, so no code path is reachable to assess. Access-limited, not cle...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "f637f4", "surface": "www.betsuna.com — front-end /?s= search parameter", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Front-end requests to betsuna.com return 0-byte / connection-reset responses (InvalidChunkLength gzip errors; all payload variants time out at ~5.2s) so the theme-level search handler could not be differentially tested. The /wp-json/ REST s...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "8b549d", "surface": "promo.hotwinscasino.com — WordPress SQL injection surface", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Host live but its origin (openresty) returns 403 Forbidden for EVERY request incl. a real browser and the /?rest_route= bypass (wp/v2/users, redirection/v1, llar) — Cloudflare fronting + origin IP block. WordPress REST/plugin SQLi surface c...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "4612d3", "surface": "www.neonrush.com — freeentrycodeuser/getall (FreeEntryCode -> Player navigation reachable via sorting injection)", "risk_area": "Cross-table data read via navigation property in injected dynamic-LINQ OrderBy", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "Injected sorting expression resolves a RELATED table: `it.Player.EmailAddress`, `it.Player.UserName`, `it.Player.PhoneNumber`, `it.Player.DateOfBirth`, `it.Player.Gender` all return HTTP 200 (entity translates to a SQL JOIN) while root-only...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "b7452d", "surface": "www.neonrush.com — minted SSO token consumption (in-scope consumers)", "risk_area": "Account impersonation via forged SSO token", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Re-checked for an in-scope token consumer this pass: the minted RS256 JWT is not accepted as a bearer credential (ABP session stays user:null); `/api/sso`, `/api/ssolaunch`, `/api/sso/token`, `/account/single-sign-in` all 404; `/account/log...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "42a6b8", "surface": "api-uat.playuk.com — session acquisition / authenticated API", "risk_area": "SQL injection / database access", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Re-confirmed api-uat session acquisition is blocked: POST /revolve/api/register/lite returns anti-fraud 400 code 3 (\"potential breach of terms\") for every payload/email-domain variant, with and without spoofed UK X-Forwarded-For. The block...", "agent_name": "PlayUK Authenticated Injection Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "d06832", "surface": "www.neonrush.com /api/authentication/{login,register,social-login,social-signup}", "risk_area": "Authentication bypass via the X-Server-Authorization API key", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Additional hunt this pass, still not obtained. Confirmed: the `apiKey` DTO property is bound strictly to the `X-Server-Authorization` header (alternate header names `ApiKey`/`X-API-Key`/`Server-Authorization` and query `?apiKey=` all yield...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "5c4778", "surface": "www.neonrush.com /api/services/app/pushcashpayment/* (tenantBaseSiteUrl / URL params)", "risk_area": "SSRF", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "On tenant 1 (CogniSweeps) an authenticated `authorizePayment`/`authorizeRedemptionPayment` with a unique interactsh host in `tenantBaseSiteUrl` returned 200 no-op with NO server-side fetch (no OOB hit, repeated); `createWidgetUrl` returns s...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "c08447", "surface": "www.neonrush.com — tenant 17 (NeonRush) session acquisition", "risk_area": "Reach the populated tenant to test the cross-table PII escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:29:44 UTC", "evidence": "Tenant 17 (the populated \"NeonRush\" tenant) cannot be reached: register and login fail CLOSED on Turnstile (policy for PlayerRegistration/PlayerLogin reports isConfigurationValid:false), and no request-level bypass worked (Abp.TenantId swit...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "73b264", "surface": "77.68.12.66:3306 MariaDB 10.5.29 + Plesk 8443 (promotions.pandabingo.com)", "risk_area": "Internet-exposed database service / weak credentials / data exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:31 UTC", "evidence": "Independently re-verified 2026-09-27 (egress 64.111.92.186). nmap -sV: 21/ProFTPD, 22/OpenSSH 8.0, 80/nginx, 443/nginx, 3306/MariaDB 5.5.5-10.5.29, 8443/Plesk sw-cp-server. MariaDB completes handshake (no host ACL — ERROR 1045, not 1130). C...", "agent_name": "Exposed MariaDB/Plesk Validator", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "c6f7f2", "surface": "Cross-subdomain cookie scoping on live in-scope apps (www.jackpot.com, play.neonrush.com, appmanager.tangobet.co.uk, uat.uk-bingo.net, partners.jackpot.com) vs dormant-subdomain takeover candidates", "risk_area": "Subdomain takeover escalating to parent-domain cookie tossing / session fixation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:50 UTC", "evidence": "Observed: play.neonrush.com sets incap_ses/visid_incap with Domain=.neonrush.com (incap_ses NOT HttpOnly); www.jackpot.com session cookies (ASP.NET_SessionId, jp_geolocation) are host-only, so a claimed sibling (wiki.jackpot.com, vuln-0011)...", "agent_name": "Independent Red Team Lead 1"}, {"entry_id": "80afa8", "surface": "45.132.74.81 origin: nginx 1.24.0, Apache Tomcat 9.0.121 + Guacamole 1.6.0, OpenSSH 9.6p1, NoMachine NX 10.0.59 (dev/qa/lp/promo/promotions/games.potsofluck.com)", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "Independently re-verifed this pass (agent a5c20f7f). Versions now CONFIRMED by handshake/banner/error-page: 22 = OpenSSH 9.6p1 Ubuntu-3ubuntu13.19; 80/443 = nginx/1.24.0 (Ubuntu); 443 -> Apache Tomcat/9.0.121 + Apache Guacamole 1.6.0 (all.m...", "agent_name": "Infra Origins Version &amp; Precondition Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "596bb1", "surface": "77.68.12.66 (promotions.pandabingo.com): Plesk Obsidian 18.0.80.8, MariaDB 10.5.29:3306, ProFTPD:21, OpenSSH 8.0, nginx, Dovecot", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "Version-matched Plesk CVEs giving RCE/root are all authenticated (CVE-2026-58046 9.9 XML-RPC SQLi, CVE-2026-65646 9.9 BAC, CVE-2026-64636 7.7 SQLi); unauth RCE/traversal CVEs (2026-67397/68492/67394) are fixed at 18.0.80.8. NEW (from compon...", "agent_name": "Independent RCE-Candidate Inventory Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "ced5c7", "surface": "WordPress fleet: betmaze.co.uk, betsuna.com, mogobet.com, theonlinecasino.co.uk, jeffbet.net, playuk.com, promo.hotwinscasino.com", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "No unauthenticated RCE path: plugins current (LSCWP 7.8.1 vs CVE range <6.5.1; CF7 6.1.7; ACF 6.8.8), no upload/file-write primitive, custom themes expose only inert static JSON proxies, wp-abilities/v1 run -> 401. Only RCE path is authenti...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "81e139", "surface": "www.jackpot.com + games.betsuna.com (IIS 10.0 / ASP.NET MVC 5.2 / WebForms Media.aspx ViewState)", "risk_area": "RCE via ViewState deserialization / .NET gadget", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "No RCE reached; the path is held shut only by .NET machineKey MAC+encryption (ViewState tamper -> 500 \"Validation of viewstate MAC failed\"; no __EVENTVALIDATION). No machineKey/web.config leak found; no vendor RCE components (no Telerik/Ken...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "188d1a", "surface": "UAT EKS Strapi CMS via /api/cms/[...path] (uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com)", "risk_area": "RCE via Strapi admin account-takeover", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "CVE-2026-27886 (Strapi BAC, confirmed in vulnx) is a query-sanitizer bypass on the content API -> admin ATO -> potential RCE. Proxy is GET/HEAD/OPTIONS-only (405) and its filters are parameterized (Knex), so the sanitizer bypass was ruled o...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "8d5125", "surface": "appmanager.tangobet.co.uk (Betty Admin, Node/NestJS/Express on Railway)", "risk_area": "RCE candidate inventory (prototype pollution / dependency RCE)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:54:08 UTC", "evidence": "Operator admin access is confirmed (admin/admin123, vuln-0001) but no RCE sink exists on the recovered API: typed JSON DTOs (19 prototype-pollution vectors inert), no recursive merge/eval, no URL-consuming feature (no SSRF), no upload/impor...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "7658e7", "surface": "api-qa.playuk.com /revolve/api/* (Markor Revolve player API + MySQL 8.0.42-33)", "risk_area": "SQL injection to RCE escalation (INTO OUTFILE webshell)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:54:08 UTC", "evidence": "Confirmed time-based blind SQLi (vuln-0028) on POST /revolve/api/account/isBonusCodeValid; MySQL 8.0.42-33 is the backend. Read access proven (version()/database()). Escalation to RCE requires INTO OUTFILE/stacked-query write to a web-serve...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "9b8558", "surface": "potsofluck.com estate fronting (Imperva apex vs direct-to-origin subdomains)", "risk_area": "WAF edge bypass / direct origin exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "DNS: apex potsofluck.com -> 45.60.249.194 / 45.60.243.194 and www -> z5nq7mr.impervadns.net (45.60.243.194) = Imperva/Incapsula edge; but dev/qa/lp/promo/promotions/games.potsofluck.com resolve DIRECTLY to the origin 45.132.74.81, so the Gu...", "agent_name": "Potsofluck Origin Services"}, {"entry_id": "e0583f", "surface": "www.jeffbet.net /xmlrpc.php + promo.hotwinscasino.com /xmlrpc.php", "risk_area": "XXE / server-side external entity resolution", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Proof gap: both XML-RPC endpoints are blocked at the edge for the test egress (www.jeffbet.net 403 Cloudflare; promo.hotwinscasino.com 403 openresty), so the parser could not be exercised. Sibling WordPress hosts of the same fleet (5 tested...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "9835b9", "surface": "headless/staging WordPress subdomains (headless.slotlux.com, headless.mrslot.com, staging3.mrjackvegas.com, staging6.mrsuperplay.com, headless.mrmobi.com)", "risk_area": "XXE / XML-RPC or REST XML parsing", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Proof gap: SiteGround sgcaptcha returns HTTP 202 with a JS challenge for every request (including /xmlrpc.php); the origin parser is unreachable for automated probing, so XML-RPC/XXE behaviour could not be verified.", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "a92b96", "surface": "appmanager.tangobet.co.uk notification title/content (stored)", "risk_area": "Stored XSS reaching a renderer", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "title/content are stored verbatim and the admin React UI renders them as text (no HTML sink). No in-scope player-facing web surface that renders these notifications was reachable (tangobet player app play.tangobet.co.uk is Imperva 403). Whe...", "agent_name": "XSS Client-Injection & Race Breadth Hunter"}, {"entry_id": "b83a13", "surface": "www.neonrush.com session/updateusersignintoken signInToken redemption", "risk_area": "sign-in-token replay / consumer", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "A fresh (cookie-less) session could not redeem the sign-in token: GET/POST /account/login/?signInToken=, GET /?signInToken=, POST /api/services/app/playeraccount/login {signInToken} all return the normal page or a generic validation error a...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "faef87", "surface": "qa.neonrush.com / stg.neonrush.com", "risk_area": "reachability / token consumer behind Basic auth", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "dev/qa/stg.neonrush.com all sit behind the same HTTP Basic auth (WWW-Authenticate: Basic realm=\"Secure Area\") on every path incl. /.well-known/jwks.json and /AbpServiceProxies/GetAll. ~24 default/predictable credential pairs (admin/*, brand...", "agent_name": "SSO Consumer & Session Auth Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "484905", "surface": "www.neonrush.com /api/games/launch-url (+ /api/loggedoutlobby/*)", "risk_area": "token-consuming game-launch route", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "GET and POST /api/games/launch-url return HTTP 401 with a fully authenticated tenant-1 session cookie (empty body). The sibling lobby/game endpoints (api/loggedoutlobby/*) also require a X-Server-Authorization key. Gap: the game-launch inpu...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "441927", "surface": "play.hotwinscasino.com (host reachability)", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Unreachable - named blocker. play.hotwinscasino.com has NO DNS record (dig +short returns empty; hotwinscasino.com apex and www.hotwinscasino.com do resolve to Imperva 45.60.243.194). A browser navigation and the HTTP proxy both fail with D...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "d87c98", "surface": "play.betstorm.com (host reachability)", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Unreachable - named blocker. play.betstorm.com resolves (Cloudflare) but every request (curl and real headless browser) returns Cloudflare error 522 \"Connection timed out\" (7252 B) - the origin is down/unreachable, so the chunk cannot be fe...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "1f9d6a", "surface": "www.neonrush.com — password-reset & email-activation link construction (/api/services/app/playeraccount/sendpasswordresetcode, sendemailactivationlink)", "risk_area": "Host-header injection / password-reset link poisoning", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Tested Host, X-Forwarded-Host, X-Forwarded-Proto, Forwarded, X-Host, X-Forwarded-Server variants against the unauth reset/activation endpoints: response is `{successful:true, redirectUrl:null, code:null, isGeoBlocked:false}` with NO reflect...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "d15eca", "surface": "api-qa.playuk.com / api-uat.playuk.com (Markor Revolve player API)", "risk_area": "CSRF / anti-forgery enforcement", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Session is a `SessionCorrelationId` cookie; the observed state-changing endpoints (register/lite, isBonusCodeValid, login) take JSON request bodies and CORS is closed (no ACAO), so a preflight-free cross-site form cannot reach them. Gap: a...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "e01f3d", "surface": "POST /revolve/api/account/claimReward", "risk_area": "Race condition / reward double-claim + claimCode IDOR", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Body is {claimCode:<v>} (confirmed from the SPA bundles). All claimCode probes (\"1\",\"2\",\"0\",\"WHEEL\",\"ADVENTURE\",\"LEVEL1\") return a generic HTTP 500 System Error; 25 concurrent identical calls all 500. Valid claim codes are issued by CMS pro...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "507475", "surface": "POST /revolve/api/promobonus/redeemPromocode", "risk_area": "Race condition / single-use promo-code double-claim", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Could not reach the redemption success path: every code supplied (WELCOME, PLAYUK, GRACE, CASINO, FREESPINS, ...) returned code 37 \"Promo code is invalid\"; no valid code is obtainable within scope (promotions are served as CMS JSON from the...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "d29315", "surface": "POST /revolve/api/payments/withdraw + /payments/provider/cancelPendingWithdrawal + /payments/transactionStatus", "risk_area": "Race condition / double-pay &amp; withdrawal state-machine abuse", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "Withdrawals are disabled on QA: POST /revolve/api/payments/withdraw returns code 141 \"Payments are under maintenance\" for every body (empty, {amount:10}, {amount:10,currencyCode:\"GBP\"}). There are no pending withdrawal records to exercise:...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "ea1dcc", "surface": "paymentRecord / promoCode / identifier object references", "risk_area": "IDOR / object-level authorization on promo &amp; payment identifiers", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "Object ids in the promo/payment flows cannot be tested for cross-account access because no such objects exist to seed them: synthetic accounts have zero payment records, zero pending withdrawals, zero bonuses/rewards/transactions and a zero...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "b62ec0", "surface": "/api/services/app/session/updateusersignintoken (PUT) (www.neonrush.com)", "risk_area": "Sign-in token replay as an authentication credential", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Returns {\"signInToken\":\"<guid>\",\"encodedUserId\":\"<b64>\",\"encodedTenantId\":\"<b64>\"}. In a cookie-less session the token did NOT authenticate in any form tested (?signInToken= query, X-SignIn-Token header, as the identity-cookie value → user:...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "219a9e", "surface": "www.neonrush.com sendpasswordresetcode / sendemailactivationlink", "risk_area": "Host-header poisoning of password-reset / activation email links (ATO)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:08:41 UTC", "evidence": "Bounded check of POST /api/services/app/playeraccount/sendpasswordresetcode and /sendemailactivationlink with Host: evil.example (403 from Cloudflare), X-Forwarded-Host, X-Original-URL and Forwarded: host=evil.example — the generated link i...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "64bcb7", "surface": "jackpot.com subdomains (results-dev/stage, lotto, uk, us, api-us, data, se, affs, rss, jplsbr, xp-sms, my, casino, thelotter, cdm.link.marketing)", "risk_area": "attack surface mapping / subdomain takeover", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:11:00 UTC", "evidence": "results-dev/results-stage -> AWS S3 403 (bucket exists, listing denied); se.jackpot.com -> DNSMadeEasy 'lostredirect' page (dangling CNAME, takeover candidate); affs.jackpot.com -> Cloudflare 'CNAME Cross-User Banned' (dangling CNAME); jpls...", "agent_name": "Jackpot Admin Surface"}, {"entry_id": "941eef", "surface": "WordPress fleet (betmaze/betsuna/jeffbet/playuk/theonlinecasino/mogobet/promo.hotwins) — plugins & core", "risk_area": "Component CVE → RCE (plugin/core version-vs-advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "Out of range: LiteSpeed Cache 7.8.1 (CVEs 2024-28000 <=6.3.0.1, 2024-50550 <=6.5.1, 2024-47637 <=6.4.1), ACF 6.8.8 (2023-1196 <6.1.0), Yoast (CVE-2026-10821 rejected/premium). WordPress core 7.1.2: CVE-2026-63030 (pre-auth REST batch SQLi→R...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "8d908f", "surface": "77.68.12.66 (Plesk Obsidian 18.0.80.8 / MariaDB 10.5.29 / ProFTPD / OpenSSH 8.0)", "risk_area": "Component CVE → RCE (version-vs-advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "Independently re-verifed this pass (agent a5c20f7f). OpenSSH 8.0 banner `SSH-2.0-OpenSSH_8.0` (no p-suffix => RHEL/Alma family); advertises kex-strict-s-v00@openssh.com (Terrapin mitigation backported => distro backports security fixes), so...", "agent_name": "Infra Origins Version &amp; Precondition Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "a3c8d6", "surface": "Next.js / React RSC fleet + Nuxt/Nitro + Strapi (UAT & marketing apps)", "risk_area": "Component CVE → RCE (framework/advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "CVE-2025-55182 (React Server Components 19.0.0/19.1.0/19.1.1/19.2.0, unauth deserialization RCE, CVSS 10, PoC=100, KEV) — in range ONLY if an app pins those RSC versions; prior pack verified patched on UAT apps. CVE-2026-75604 (Next.js) sta...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "7c812f", "surface": "userLogin.getUserLoginAttempts / getUserLoginAttemptCount (tenant scoping of the filed IDOR)", "risk_area": "Cross-tenant data access (IDOR scope)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:22 UTC", "evidence": "Cross-user read is confirmed (a tenant-1 session read another tenant-1 user's rows). The cross-TENANT scope could not be established: a tenant-17 user id (1854267, created via registerExternalFromApi without the tenant header) returned tota...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "5fcbaf", "surface": "transactionsUser.reverse(batchId) and getProcessingStatus(batchId)", "risk_area": "Financial integrity / unauthorized transaction reversal", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:45 UTC", "evidence": "transactionsUser.reverse and getProcessingStatus take a batchId that rejects integers and non-GUID strings (HTTP 400 'Your request is not valid!'), so the target could not be selected without a real transaction batch identifier. No batch GU...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "39d9ef", "surface": "qa/stg/dev.neonrush.com (staging Cogni/ABP environments)", "risk_area": "Authentication bypass via shared X-Server-Authorization key / staging asset exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:14:38 UTC", "evidence": "LIVE ABP instances. qa.neonrush.com serves the API without auth for /api/* (e.g. GET /api/services/app/session/getcurrentlogininformations → 200, tenant \"NeonRush\" id 20) but every non-/api path (/, /abpscripts, /abpserviceproxies, /dist/*,...", "agent_name": "Cogni X-Server-Authorization Key Hunter"}, {"entry_id": "ffc9fc", "surface": "POST /revolve/api/{account/claimReward,account/awardBonus,account/optInToPromotion,promobonus/redeemPromocode,loyalty/redemption,account/freeSpinDetails} (api-qa.playuk.com)", "risk_area": "Race condition on one-per-period bonus / reward / promotion claims (double-claim)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "All endpoints are reachable with an authenticated QA session but reject every test input at validation: claimReward -> code 1 \"Missing or invalid parameter(s)\"; awardBonus -> code 163 \"Invalid Bonus\"; redeemPromocode -> code 37 \"Promo code...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "bcd829", "surface": "www.neonrush.com /api/amoe/*, /api/freerefill, /api/redemption/*, /api/coins/*, /api/playerprofile/*, /api/services/app/transactionsuser/freerefill, /api/services/app/loyaltyuserservice/redeemloyaltypoints", "risk_area": "Race condition on privileged / one-per-user limit endpoints (refill, redemption, coins, loyalty points)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Reachability gap: the dark API routes (amoe/code, amoe/info, amoe/history, freerefill, redemption/*, coins/packages*, playerprofile/*) all return HTTP 401 (coins/packages/query returns {\"errorcode\":\"InvalidAPIKey\"}) because they require the...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "fa6e13", "surface": "www.neonrush.com/account/login Cloudflare Turnstile widget (sitekey 0x4AAAAAAChdt0aXJQzhuYXQ)", "risk_area": "Solving the anti-automation challenge from an automated browser to obtain a tenant-17 session", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:21:23 UTC", "evidence": "With the geo-gate satisfied (X-Forwarded-For injected via browser headers), the widget renders but Cloudflare never issues a token: console shows repeated \"[Cloudflare Turnstile] Error: 600010\" and the challenge iframe reports \"Verification...", "agent_name": "NeonRush ABP Session Unlock"}, {"entry_id": "4ded2c", "surface": "www.betsuna.com — /?s=, /?cat= etc.", "risk_area": "Reflected XSS", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:22:33 UTC", "evidence": "The origin returns malformed gzip (InvalidChunkLength) for dynamic search/query responses to this egress, so the front-end search handler could not be differentially tested. 404 path, wp-login params and feed were reachable and encoded. Hos...", "agent_name": "WP Fleet XSS Deep Hunter"}, {"entry_id": "ce4c32", "surface": "www.betmaze.co.uk promotion carousel — fetch-promotions.php title/bigImageUrl/htmlSummary into innerHTML", "risk_area": "Stored/DOM XSS (HTML injection sink)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:22:33 UTC", "evidence": "`pbCreateCarouselSlide` interpolates `promo.title`/`promo.bigImageUrl` into innerHTML unescaped and the API ships `htmlSummary` as raw HTML — a real sink. Gap: the content originates from the ProgressPlay promotions CMS / data.progressplay....", "agent_name": "WP Fleet XSS Deep Hunter"}, {"entry_id": "90099e", "surface": "Kroger OAuth code exchange (KrogerConfirmation supplied with code+state)", "risk_area": "Authorization-code / token leak", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:22:46 UTC", "evidence": "Proof gap, not proof of safety. Supplying code+state moves the handler past the line-107 Uri.EscapeDataString null throw and it then returns a bare 302 to /Admin?ReturnUrl=/Widgets/UsKroger/KrogerConfirmation — i.e. the observable flow reac...", "agent_name": "Jackpot Kroger OAuth SSRF Probe"}, {"entry_id": "1827f6", "surface": "www.jackpot.com Host-header-driven absolute URL / redirect generation (Kroger handlers, / and /checkout)", "risk_area": "Open redirect / Host header injection (CWE-601/CWE-644)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:22:46 UTC", "evidence": "Reproduced: POST /Widgets/UsKroger/KrogerConfirmation (and KrogerConnect) with header Host: evil.example.com returns 302 Location: http://evil.example.com/Admin?ReturnUrl=... . Additional instance (agent f00b58b6): the trailing-slash redire...", "agent_name": "Jackpot ALB-Bypass Admin Surface Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "1af3d6", "surface": "play.* / www ProgressPlay hosts — 'platform-web' hapi/iron Fe26.2 sealed cookie", "risk_area": "Session forgery via weak hapi/iron sealing password (offline crack → re-seal / impersonation)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:23:43 UTC", "evidence": "Cookie set unauthenticated on every ProgressPlay host: `platform-web=Fe26.2*1*<64-hex salt>*<22ch iv>*<1387ch ct>**<64-hex hmacSalt>*<43ch hmac>~2`. Structure matches @hapi/iron 7 defaults EXACTLY (saltBits 256 / aes-256-cbc / iv 128 / PBKD...", "agent_name": "ProgressPlay Iron Cookie Seal Cracker"}, {"entry_id": "c05abe", "surface": "ProgressPlay Next.js app (shared build WpePWuKOnX3rgMNqj5LeW) — POST /api/record/saveLastAction", "risk_area": "Server-side prototype pollution", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:23:43 UTC", "evidence": "`POST /api/record/saveLastAction` (unauthenticated, 200) merges and echoes caller-supplied keys, so a prototype-polluting merge is plausible. Attempted in-browser (WAF cookies present): `{\"constructor\":{\"prototype\":{\"pp_test\":\"POLLUTED\"}}}`...", "agent_name": "Imperva-Unlock Dynamic Tester"}, {"entry_id": "03b77e", "surface": "https://www.neonrush.com /games/play/play-game-modal (slug from location.hash -> ModalManager POST -> .html(response))", "risk_area": "DOM XSS via location.hash-controlled slug rendered as HTML", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Additional test by XSS breadth lead: with an authenticated tenant-1 session, POST /games/play/play-game-modal (slug=<svg onload=alert(1)>>) returns a fixed 1290-byte 'Zero Balance' template that does NOT contain the slug (no reflection) — t...", "agent_name": "XSS Client-Injection & Race Breadth Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "2a1a7b", "surface": "https://www.neonrush.com ABP notification rendering (UserNotificationHelper.showAsPop / showUiNotifyForUserNotification) + unvalidated user name", "risk_area": "Stored XSS (notification message rendered as HTML)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:24:24 UTC", "evidence": "Sink confirmed in shipped JS: _Notifications.min.js calls `showAsPop` for each item of `notification/getUserNotifications`, and showAsPop runs `swal.fire({html: abp.notifications.getFormattedMessageFromUserNotification(t), ...})`, which cli...", "agent_name": "Jackpot and NeonRush Client-Side XSS Hunter"}, {"entry_id": "ad7dfa", "surface": "Imperva/Incapsula-fronted hosts (www.highstakes.co.uk, www.supabet.co.uk, www.hotwinscasino.com, www.luckcity.com, www.mrrex.com, www.mamzinobet.com, www.moneyplay.com, www.ne-bet.com, www.betblink.com, www.21luckybet.com, www.lekkerbets.co.za, play.betzi.co, www.tangobet.co.uk, www.potsofluck.com)", "risk_area": "HTTP request desync (CL.TE / TE.CL / CL.0 / TE.TE / H2.CL / H2.TE / H2C)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:25:53 UTC", "evidence": "Non-browser clients get an 885-byte Incapsula block page (403; `Set-Cookie: visid_incap_*`/`incap_ses_*`; `X-Iinfo`). Correction (notes c1d1c7 / bfb6c5 / f2ea3c): this is a browser-solvable JS/fingerprint challenge, NOT an IP deny — the hos...", "agent_name": "Edge Desync Smuggling Sweep", "previous_outcomes": ["needs_follow_up"], "by_you": true}, {"entry_id": "f43a03", "surface": "promo.hotwinscasino.com (Cloudflare -> openresty origin 403)", "risk_area": "HTTP request desync (CL.TE / TE.CL / CL.0 / TE.TE / H2.CL / H2.TE / H2C)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:25:53 UTC", "evidence": "Cloudflare-fronted host whose origin (`openresty/1.31.1.1`) returns 403 to this egress for every path (verified previously in note 43e341 and not reproducible now). No framing test could reach the origin; left open.", "agent_name": "Edge Desync Smuggling Sweep", "by_you": true}, {"entry_id": "e8473e", "surface": "www.acedbet.com / acedbet.com (Vercel edge -> Next.js)", "risk_area": "HTTP request desync (CL.TE / TE.CL / CL.0 / TE.TE / H2.CL / H2.TE / H2C)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:25:53 UTC", "evidence": "Vercel edge answers normal requests with `429` + `X-Vercel-Mitigated: challenge`. Requests with malformed framing bypass the challenge and reach a parser: `Transfer-Encoding: chunked` + invalid body -> `500` (text/plain), `Transfer-Encoding...", "agent_name": "Edge Desync Smuggling Sweep", "by_you": true}, {"entry_id": "496ecb", "surface": "POST /api/services/app/playeraccount/isusernameavailable (+ note route is lowercase/case-sensitive)", "risk_area": "User enumeration / information disclosure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:28:25 UTC", "evidence": "POST /api/services/app/playeraccount/isusernameavailable?input=<name> returns {\"result\":false} for a username already present in the SESSION's tenant and true otherwise (verified: our t1/t5/t11 handles each return false only under their own...", "agent_name": "NeonRush Captcha-Free Tenant Data Hunter"}, {"entry_id": "5bf74f", "surface": "play.neonrush.com registration region gate (/api/registration/registrationStepFirst)", "risk_area": "Geo/region access-control bypass (register from a prohibited jurisdiction)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:30:30 UTC", "evidence": "Gate holds for our NL egress in controlled testing: interleaved CONTROL vs CF-IPCountry:MT (10 pairs, 1.2s apart) gave REGION or WAF in both arms with zero differential. Also tried CF-IPCountry/X-Real-IP/X-Country-Code/True-Client-IP/XFF/Fo...", "agent_name": "ProgressPlay play.* Geo-Bypass IDOR Hunter"}, {"entry_id": "544aae", "surface": "www.neonrush.com /api/authentication/* and key-gated ABP endpoints (X-Server-Authorization)", "risk_area": "Static server API-key recovery / authentication bypass", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:32:15 UTC", "evidence": "Key NOT recovered. Searched: all shipped JS/HTML/view-resources/LoginCore/RegisterCore/getscripts/getall (no value), ~220 curated guesses (brands/ABP defaults), 0-30 tenant IDs with junk key, query-string/cookie/JSON-body delivery, path nor...", "agent_name": "Cogni API-Key & Token Hunt"}, {"entry_id": "9f468e", "surface": "77.68.12.66:8443 — Plesk Obsidian 18.0.80 panel login (origin of promotions.pandabingo.com) — default/weak credentials", "risk_area": "Weak/default credentials on an internet-exposed hosting control panel (auth path to version-matched Plesk RCEs)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:33:24 UTC", "evidence": "Panel live (`Server: sw-cp-server`); login endpoint functional. POST /login_up.php3 (X-Requested-With: XMLHttpRequest, `login_name`/`passwd`/`forgery_protection_token` from the meta tag) returns JSON `{\"status\":\"error\",...}` for bad creds....", "agent_name": "Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)"}, {"entry_id": "4a29ff", "surface": "77.68.12.66:8443 /enterprise/control/agent.php — Plesk XML-RPC API (CVE-2026-58046 blind SQLi)", "risk_area": "Authenticated XML-RPC SQLi -> panel takeover (credential-gated)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:33:24 UTC", "evidence": "The API-RPC endpoint IS reachable from our egress and evaluates packets: POST returns `<?xml ...><packet version=\"0.0.0.0\"><system><status>error</status><errcode>1003</errcode><errtext>Wrong request</errtext></system>` (1003 = malformed req...", "agent_name": "Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)"}, {"entry_id": "9c0515", "surface": "77.68.12.66:8443 — Plesk panel exact version", "risk_area": "Version gap for in-range Plesk RCE/SQLi CVEs (CVE-2026-58046/65646/64636)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:33:33 UTC", "evidence": "UPDATE 2026-09-27 by Plesk/Tomcat/WP-Core Verifier (d05d6fd6): exact version POSITIVELY CONFIRMED on the live panel — GET https://77.68.12.66:8443/login_up.php returned `<title>Plesk Obsidian 18.0.80</title>` (Server: sw-cp-server; 303 -> /...", "agent_name": "Plesk/Tomcat/WP-Core Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "0ff984", "surface": "appmanager.tangobet.co.uk (Betty Admin, Railway) — Node.js runtime version", "risk_area": "Node.js CVE-2023-32002 module-policy bypass -> RCE (<20.5.1 / <18.17.1 / <16.20.1)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:33:43 UTC", "evidence": "Version is not disclosed: `Server: railway-hikari`, `x-powered-by: Express`; `/package.json`, `/.env`, `/version` all return the 451-byte SPA catch-all, `/api` and `/api/` return Express default `Hello World!` (12 B), and error bodies `{\"me...", "agent_name": "Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)"}, {"entry_id": "2863e5", "surface": "promo.hotwinscasino.com — WordPress plugin version enumeration (WPML / SEOPress / Yoast)", "risk_area": "WPML (CVE-2024-6386) / SEOPress (CVE-2024-5488) plugin versions -> RCE", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:33:43 UTC", "evidence": "Origin 403s every request regardless of path/method/headers: `/`, `/?rest_route=/`, `/wp-json/`, `/wp-content/plugins/sitepress-multilingual-cms/readme.txt`, `/wp-content/plugins/wp-seopress/readme.txt`, `/wp-content/plugins/wordpress-seo/r...", "agent_name": "Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)"}, {"entry_id": "8f7a5f", "surface": "ProgressPlay Next.js 13.3.0 fleet — middleware auth bypass (CVE-2025-29927)", "risk_area": "Broken access control via x-middleware-subrequest (Next.js middleware bypass)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:34:40 UTC", "evidence": "Next.js 13.3.0 (confirmed) is nominally in range for CVE-2025-29927 (fixed 14.2.25). Bounded benign probe on www.africasports.com `/account/login` with `x-middleware-subrequest: middleware | src/middleware | pages/_middleware` produced no d...", "agent_name": "Next.js RSC Version & Imperva Reach Verifier"}, {"entry_id": "f37655", "surface": "77.68.12.66:21 ProFTPD — mod_sql-dependent issues", "risk_area": "CVE-2026-42167 (mod_sql RCE &lt;1.3.10rc1), CVE-2026-44331 (mod_sql reverse-DNS SQLi), CVE-2024-48651 (mod_sql GID0 privesc)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:35:45 UTC", "evidence": "These CVEs require the mod_sql module loaded with a command-capable SQL backend / sqltab / UseReverseDNS — none of which is observable over the FTP control channel (no FEAT or SITE artifact exists for mod_sql), and the exact build is hidden...", "agent_name": "FTP/SSH Pre-Auth RCE Verifier"}, {"entry_id": "0ee9c1", "surface": "77.68.12.66:21 ProFTPD — authenticated memory-corruption / overflow CVEs", "risk_area": "CVE-2026-63090, CVE-2026-53994, CVE-2026-63091, CVE-2026-35025 (all authenticated), CVE-2024-57392", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:35:45 UTC", "evidence": "CVE-2026-63090/53994/63091/35025 all require an authenticated FTP/SFTP low-privilege session and (for 63090/63091/53994) mod_sftp; CVE-2024-57392 is scoped by vulnx to a specific ProFTPD commit with no released-range detail. No credentials...", "agent_name": "FTP/SSH Pre-Auth RCE Verifier"}, {"entry_id": "89f769", "surface": "77.68.12.66:21 ProFTPD — reachability after fingerprint/auth probes", "risk_area": "Anti-automation / connection-block control", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:35:45 UTC", "evidence": "tcp/21 was open and served the banner/FEAT/HELP/SITE responses, then after the fingerprint pass plus three failed logins it flipped to `Connection refused` (nmap: 21/tcp closed) and remained refused on 7 further attempts over ~6 minutes. Co...", "agent_name": "FTP/SSH Pre-Auth RCE Verifier"}, {"entry_id": "fbaa10", "surface": "WordPress core + plugin version fingerprint — promo.hotwinscasino.com", "risk_area": "RCE via CVE-2026-63030 (WP core) and WPML CVE-2024-6386 / SEOPress CVE-2024-5488", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:41:43 UTC", "evidence": "UNRESOLVED — exact versions could not be read. Control observed: the origin (`openresty/1.31.1.1`) returns 403 Forbidden for EVERY request (GET and POST; /, /readme.html, /wp-json/, /?rest_route=/wp/v2/users, /wp-content/plugins/*/readme.tx...", "agent_name": "WordPress Core &amp; Plugin CVE Verifier"}, {"entry_id": "8129ca", "surface": "promo.hotwinscasino.com (Cloudflare -> openresty origin)", "risk_area": "HTTP request desync (CL.TE/TE.CL/CL.0/TE.TE)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:43:53 UTC", "evidence": "Access-limited: GET / returns 403 at the Cloudflare edge and the origin (openresty) 403s the test egress; a CL+TE timing probe is answered with a Cloudflare 400 before the origin is reached. No origin parser is reachable from this source IP...", "agent_name": "Desync Verifier + Residual Edge Coverage"}, {"entry_id": "4ff50b", "surface": "Imperva/Incapsula-gated hosts (highstakes, supabet, hotwinscasino, luckcity, mrrex, mamzinobet, ne-bet, betblink, 21luckybet, lekkerbets, play.betzi.co, tangobet, potsofluck, 777bet.casino, acelucky, betstorm, dynobet)", "risk_area": "HTTP request desync (CL.TE/TE.CL/H2.CL/H2.TE/CL.0/TE.TE/H2C)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:43:53 UTC", "evidence": "Access-limited, not clean: a single GET / to each host from the test egress returns the ~1.3 KB Incapsula 403 block page (no request reaches the origin HTTP parser), so no desync can be exercised from this source IP. www.moneyplay.com is th...", "agent_name": "Desync Verifier + Residual Edge Coverage"}], "filtered_count": 107, "total_count": 642, "outcome_counts": {"reported": 82, "no_issue_found": 167, "ruled_out": 257, "not_applicable": 29, "needs_follow_up": 107}}