{"success": true, "entries": [{"entry_id": "65365f", "surface": "luckcity.com (+ www, play, app.luckcity.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE DNS 45.60.243.194 but Imperva/Incapsula WAF returns 403 incident page to tester IP (real browser also blocked). Marketing+play app unreachable from this egress. app.luckcity.com CNAMEs to Firebase Dynamic Links (luck-city-i2zy6e.web.ap...", "agent_name": "Recon Charlie"}, {"entry_id": "f308ca", "surface": "mrjackvegas.com (+ www, play, staging3)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site fully crawled/mapped: static routes (/all-games,/casino-games,/compliance/*), JS bundles recovered, whitelabel ID 107 and play.mrjackvegas.com identified. staging3.mrjackvegas.com = headless WordPr...", "agent_name": "Recon Charlie"}, {"entry_id": "d1add8", "surface": "mrrex.com (+ www)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE (Imperva 45.60.243.194) but returns Imperva 403 to tester IP. ProgressPlay tenant #250. Gap: app unreachable due to WAF IP block.", "agent_name": "Recon Charlie"}, {"entry_id": "720511", "surface": "mamzinobet.com (+ www)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE (Imperva 45.60.249.194) but returns Imperva 403 to tester IP; play.* not resolving. ProgressPlay tenant #285. Gap: app unreachable due to WAF IP block.", "agent_name": "Recon Charlie"}, {"entry_id": "a38a21", "surface": "mrslot.com (+ www, play, headless, lobby)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 77, play.mrslot.com). headless.mrslot.com WP REST behind SiteGround sgcaptcha (blocked even via real browser). lobby.mrslot.com→185.27.56.100 (stale). No app issue on reachable s...", "agent_name": "Recon Charlie"}, {"entry_id": "3fa973", "surface": "moneyplay.com (+ lobby.moneyplay.com, mta-sts)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE; apex 301→www then Imperva 403; lobby.moneyplay.com (Imperva DNS ng.impervadns.net) also 403 to tester IP. ProgressPlay tenant #272. Gap: app unreachable due to WAF IP block.", "agent_name": "Recon Charlie"}, {"entry_id": "a18dcd", "surface": "mogobet.com (+ www, play.mogobet.com)", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "Tested to closure. CONFIRMED: GET https://mogobet.com/wp-content/debug.log returns 200 with a live PHP debug log (absolute path /home/mogobet.com/public_html/, stack traces) — filed as a finding. Also unauth user enum via /wp-json/wp/v2/use...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "47acd5", "surface": "mrsuperplay.com (+ www, play, staging6)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 102, play.mrsuperplay.com). staging6.mrsuperplay.com headless WP (35.214.94.72) behind SiteGround challenge. No issue on reachable static surface.", "agent_name": "Recon Charlie"}, {"entry_id": "a3a9bc", "surface": "mrmobi.com (+ www, play, headless, lobby)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 76, play.mrmobi.com). headless.mrmobi.com WP REST behind SiteGround sgcaptcha (blocked). lobby.mrmobi.com→185.27.56.100 no HTTPS service (likely stale DNS). No app-level issue on...", "agent_name": "Recon Charlie"}, {"entry_id": "b3cbe3", "surface": "content.progressplay.net/api23/api/* (ProgressPlay backend API)", "risk_area": "broken access control / unauthenticated API", "outcome": "not_applicable", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "content.progressplay.net is a third-party platform-vendor backend and is NOT among the 47 system-verified in-scope targets. Observe-only; no active testing authorized there. Recorded as out-of-scope rather than an open item.", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "6641ec", "surface": "ne-bet.com (+ www)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE (Imperva) but 403 to tester IP; play.* not resolving. ProgressPlay tenant #273. Gap: app unreachable due to WAF IP block.", "agent_name": "Recon Charlie"}, {"entry_id": "0d215a", "surface": "*.tech1960.workers.dev (Cloudflare Workers micro-APIs)", "risk_area": "attack surface mapping / unauthenticated API", "outcome": "not_applicable", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "*.tech1960.workers.dev is a third-party Cloudflare Workers domain, not an in-scope target. Observe-only; no active testing authorized. Out-of-scope, not an open item.", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "7599c5", "surface": "potsofluck.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant, og:url https://games.potsofluck.com. Related live subs: dev/qa/lp/promo/promotions.potsofluck.com. api/uat/api-qa/api-uat.potsofluck.com have NO DNS.", "agent_name": "Recon Delta"}, {"entry_id": "1ac831", "surface": "playuk.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: WordPress on WP Engine (nginx/PHP/MySQL, Yoast 28.3); 301→www.playuk.com. Casino backend playuk.casino-pp.net (ProgressPlay). REST exposed: /wp-json/ (261KB), /wp-json/wp/v2/users (admin,playuk), pages 1367/3916; /xmlrpc.php 405;...", "agent_name": "Recon Delta"}, {"entry_id": "ba9455", "surface": "play.neonrush.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: Next.js/React behind Cloudflare+AWS S3+Imperva. ProgressPlay tenant whiteLabelId=284. Enumerated unauth APIs: /api/getTenantData?wl=, /api/getWhiteLabelConfig, /api/player/getDefault, /api/player/getPlayer (PlayerId:0 anon), /api/...", "agent_name": "Recon Delta"}, {"entry_id": "f0d0f9", "surface": "play.betzi.co", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: resolves to Imperva 45.60.241.194 (cname 6pi69zy.ng.impervadns.net); TCP/443 open; returns Incapsula 403 block page (X-Iinfo, visid_incap cookies) to non-browser clients. ProgressPlay \"play\" tenant front-end. Mapped, WAF-gated — needs...", "agent_name": "Recon Delta"}, {"entry_id": "6fa904", "surface": "q88bets.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www.q88bets.com, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=200 (\"q88bets\"). Same /api/* pattern reachable in-browser. promo.q88bets.com = Apache 2.4.52 WP-ish offers page.", "agent_name": "Recon Delta"}, {"entry_id": "02ed25", "surface": "rainbetsplash.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403 on 45.60.243.194/45.60.249.194). Browser render confirms ProgressPlay tenant whiteLabelId=8 (\"rainbetsplash\").", "agent_name": "Recon Delta"}, {"entry_id": "71038d", "surface": "slotlux.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: Nuxt.js/Vue on Cloudflare; headless WordPress backend (headless.slotlux.com/wp-json behind SiteGround captcha); play.slotlux.com 403 Imperva. Enumerated /api/pp/games (unauth full catalog), /compliance/* routes. Confirmed .env/.gi...", "agent_name": "Recon Delta"}, {"entry_id": "33398e", "surface": "stakespin.casino", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=166 (\"stakespin\").", "agent_name": "Recon Delta"}, {"entry_id": "77c01d", "surface": "ProgressPlay /api/getTenantData?wl= + whiteLabelId", "risk_area": "IDOR / cross-tenant access via wl parameter", "outcome": "ruled_out", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Resolved by the ProgressPlay IDOR Hunter on the reachable play.* hosts: the `wl`/`whiteLabelId` parameter is IGNORED — tenant is fixed per deployment server-side (getDefault/getTenantData return the host's own tenant); player endpoints retu...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "0da114", "surface": "playuk.com /wp-json + xmlrpc.php", "risk_area": "WordPress REST exposure / user enumeration / plugin CVEs", "outcome": "reported", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Tested to closure. Confirmed unauthenticated user enumeration: GET https://playuk.com/wp-json/wp/v2/users (and /?rest_route=/wp/v2/users) returns admin(id1)+playuk(id2) without auth. xmlrpc.php POST is blocked (403 nginx for our egress; sys...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "190915", "surface": "dev/qa/lp/promo/promotions.potsofluck.com Apache Guacamole", "risk_area": "exposed remote-desktop gateway", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Resolved by the Guacamole Gateway Hunter: the gateway (all six potsofluck.com hosts = one Apache Guacamole 1.6.0 instance) rejects default/weak credentials, enforces an unbypassable brute-force throttle (429 after ~5 attempts; spoofed IP he...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "60f56c", "surface": "savibet.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=268 (\"savibet\").", "agent_name": "Recon Delta"}, {"entry_id": "0c45c1", "surface": "supabet.co.uk", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:05 UTC", "evidence": "Host live (Imperva IPs 45.60.243/249.194) but Imperva/Incapsula returns 403 \"Access denied Error 15\" blocking sandbox egress IP 64.111.92.186 - apex, www and http->https all blocked. Origin not reachable; surface unmapped.", "agent_name": "Recon Echo"}, {"entry_id": "293759", "surface": "vampirebingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Live www branded Nuxt.js/Vue3 marketing site (Cloudflare); platform at play.vampirebingo.com returns Imperva 403 (blocked). Marketing routes enumerated; no API surface exposed on marketing site.", "agent_name": "Recon Echo"}, {"entry_id": "c84fe9", "surface": "betblink.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Host live (Imperva IPs 45.223.166/178.247) but Imperva 403 WAF block for sandbox IP on apex/www. Origin unmapped.", "agent_name": "Recon Echo"}, {"entry_id": "3ae16c", "surface": "theonlinecasino.co.uk", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Tested to closure. CONFIRMED unauth user enumeration via /wp-json/wp/v2/users (admin id1) and ?rest_route= bypass. wp-login.php/wp-admin are rewritten to a custom /404 (login is served by the custom theme page /theonlinecasino-portal/, whic...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "201e32", "surface": "21luckybet.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Host live (Imperva IPs) but imperative 403 \"Error 15\" WAF block for sandbox IP on apex, www and http. Origin unmapped.", "agent_name": "Recon Echo"}, {"entry_id": "1b12f2", "surface": "betarno.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Apex (Heroku) serves Nuxt.js/Vue3 betting site + Prismic CMS; enumerated routes incl /test/home and i18n prefixes; /linkResolver.js returns JSON 404. www.* is Imperva 403. No exposed API surface on marketing site.", "agent_name": "Recon Echo"}, {"entry_id": "6833c5", "surface": "tangobet.co.uk (+subdomains)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "apex/www Imperva 403 (blocked for sandbox IP). Reachable subdomains mapped: appmanager (Betty Admin SPA + /api/admin/* Bearer-JWT, 401 gated, unauth /api/mobile-app/stats), app (AppsFlyer OneLink), deletemyaccount, affiliates/promos (403 ng...", "agent_name": "Recon Echo"}, {"entry_id": "ece8bd", "surface": "acedbet.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Reachable via headless browser (Vercel Security Checkpoint returns 429 to curl). Next.js + Auth.js credentials provider; /api/auth/providers, /api/auth/csrf, /api/auth/signin/credentials, /api/auth/callback/credentials, /api/auth/session al...", "agent_name": "Recon Echo"}, {"entry_id": "576b2b", "surface": "promo.hotwinscasino.com (WordPress)", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Tested to closure. Cloudflare managed challenge intermittently gates the host; wp-login.php / xmlrpc.php / wp/v2/users return 403 to our egress. CONFIRMED: the WAF rule blocking /wp-json/wp/v2/users is bypassed via /?rest_route=/wp/v2/users...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "802305", "surface": "jeffbet.net", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "WordPress 7.1.2 + CF7 6.1.7 + Yoast 28.3 on WP Engine/Cloudflare mapped. Observed unauthenticated user enumeration via /wp-json/wp/v2/users (200, 18KB → admin, simon-young, ross-young) — handed to downstream note. xmlrpc.php 403, wp-login.p...", "agent_name": "Recon Bravo"}, {"entry_id": "314c14", "surface": "pandabingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare, 188.114.x) mapped; SPA fallback returns index 200 for unknown paths. Public game catalogue /api/pp/games + /api/worker/games (identical ~6.9MB JSON). Subs: bingo.→www, uat.pandabingo.com Next.js on AWS EKS (see...", "agent_name": "Recon Bravo"}, {"entry_id": "dfe0aa", "surface": "uk-bingo.net", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped. Subs: play. Imperva 403; support.→ukbingo.zendesk.com; uat.uk-bingo.net = Next.js app on AWS EKS (see UAT coverage). No exploitable surface at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "018859", "surface": "uat.uk-bingo.net / uat.pandabingo.com (shared EKS UAT app)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Both resolve to one AWS ELB k8s-devkrake-sitesing-...eu-west-2.elb.amazonaws.com; Next.js/React/Webpack. /api/health → 200; /api/v1 → 308→/api/v1 (404); other /api/* 404. App bundles reference platform API api.dev.kraken.ptops.net/api/v1, W...", "agent_name": "Recon Bravo"}, {"entry_id": "ce38a9", "surface": "wombatbingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare, 188.114.x) mapped; public /api/pp/games + /api/worker/games. Subs: play.wombatbingo.com Imperva 403 (app tier). SPA fallback returns 200 index for arbitrary paths (not a file hit). No exploitable surface at mapp...", "agent_name": "Recon Bravo"}, {"entry_id": "bd4c94", "surface": "jazzyspins.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped; returns 404 (no SPA fallback); /lp/ campaign landing (robots disallow). Public /api/pp/games. Subs: play. Imperva 403; headless. Imperva 202. No exploitable surface at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "6e6bad", "surface": "jackpot.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "IIS 10.0 / ASP.NET MVC 5.2 behind AWS ALB mapped. /admin and /trace.axd → 403 (exist-but-blocked); /api,/login,/account,/register → 404 (custom 2916B); sitemap.xml 1336 game routes; robots disallow /admin. Verbose X-AspNetMvc-Version header...", "agent_name": "Recon Bravo"}, {"entry_id": "a97694", "surface": "lekkerbets.co.za", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "DNS 45.60.243.194; 443 open; apex→www returns Imperva Incapsula 403 (403/881B). No subdomains found via subfinder. App/marketing surface not observable through WAF — needs browser/evasion.", "agent_name": "Recon Bravo"}, {"entry_id": "e578e7", "surface": "hotwinscasino.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "www Imperva 403. Subs mapped: promo. (WordPress/LiteSpeed 200, wp-json exposed), admin/m/brand/partners. (Microsoft-HTTPAPI/2.0, 404, CNAME map180.mediacle.net), media. (S3+CloudFront 403). Main app tier behind promotion/Imperva not mapped.", "agent_name": "Recon Bravo"}, {"entry_id": "d1b86f", "surface": "queensbingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped. Subs: play. Imperva 403; headless. Imperva 202 challenge; anna./staging3. DNS NXDOMAIN (stale CT records → unreachable). No exploitable surface found at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "d996ce", "surface": "highstakes.co.uk", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "DNS 45.60.243/249.194; 443 open; apex+www return Imperva Incapsula 403 (visid_incap cookie). casino.highstakes.co.uk 301→www→403. Marketing/account surface not observable through WAF — app tier unmapped; needs browser/evasion.", "agent_name": "Recon Bravo"}, {"entry_id": "013a04", "surface": "betmorph.com (+ www, play.betmorph.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE Hercules React/Vite SPA (680KB bundle) via Cloudflare CNAME cname.onhercules.app; client-routed /admin, /admin/users, /admin/cms/* + OIDC authority hercules.app client_id yhCUhFUbncJWJFucAVteyCLHipSlfJFM + Convex backend fearless-chihu...", "agent_name": "Recon Alpha"}, {"entry_id": "f5f194", "surface": "betstorm.com (+ www, play.betstorm.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 2939242); browser+cookie bypass → 200. ProgressPlay white-label Next.js (whiteLabelName \"betstorm\"), title \"BetStorm - Lightning can strike twice\". offers.betstorm.com → 157.53.227.1 (404).", "agent_name": "Recon Alpha"}, {"entry_id": "411914", "surface": "betmaze.co.uk (+ www.betmaze.co.uk, play.betmaze.co.uk)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE WordPress 7.1.2 (LiteSpeed/PHP/MySQL, twentytwentyfive-child theme) behind Cloudflare. /wp-json/wp/v2/users enumerates user `betmaze_login`; xmlrpc.php present; custom theme PHP fetch-sports.php/fetch-promotions.php/fetch-games.php AJA...", "agent_name": "Recon Alpha"}, {"entry_id": "24efa9", "surface": "chitchatbingo.com (+ www, play, uat, api, support)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE. Marketing = Nuxt3/Vue on Cloudflare with API /api/pp/games, /api/worker/games and Cloudflare Workers *.tech1960.workers.dev. play.chitchatbingo.com = Betable app behind Imperva. uat.chitchatbingo.com = AWS EKS Next.js staging (1.3MB)...", "agent_name": "Recon Alpha"}, {"entry_id": "da1916", "surface": "acelucky.com (+ www, play.acelucky.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3181109); browser+cookie bypass → 200. ProgressPlay white-label Next.js (whiteLabelName \"acelucky\"), title \"AceLucky: Online Casino – Online Slots, Live Casino & Sports\".", "agent_name": "Recon Alpha"}, {"entry_id": "eb311b", "surface": "dynobet.com (+ www, play, affiliates, promos, *.uat/*.qa)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE ProgressPlay white-label (Imperva acct 3119998), title \"Dynobet: Sports betting and Online Casino\". affiliates.dynobet.com + promos.dynobet.com → AWS Elastic Beanstalk webapp-env.eba-4x3ezugm.eu-west-2.elasticbeanstalk.com (403 nginx)....", "agent_name": "Recon Alpha"}, {"entry_id": "a91887", "surface": "betsuna.com (+ www.betsuna.com, games.betsuna.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "WordPress behind Cloudflare+LiteSpeed; root `/` has a 301↔302 redirect loop returning no body, but /robots.txt, /wp-json/ (224KB exposed), /wp-json/wp/v2/users (user `betsunaadmin`), /wp-login.php all respond. games.betsuna.com → Microsoft-...", "agent_name": "Recon Alpha"}, {"entry_id": "37f5af", "surface": "africasports.com (+ www, play.africasports.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3271531); browser+cookie bypass → 200. ProgressPlay white-label Next.js; __NEXT_DATA__ leaks platform config (whiteLabelName \"africasports\", playMode IDs, testWhiteLabelName \"betsteve\", paypal sandbox key, Smartico key...", "agent_name": "Recon Alpha"}, {"entry_id": "e3c035", "surface": "777bet.casino (+ www.777bet.casino, play.777bet.casino)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3213198) in front; plain HTTP blocked, bypassed via browser-reload + curl_cffi cookies → 200. ProgressPlay white-label Next.js (whiteLabelName \"777bet\"), title \"777Bet | Online Casino and Sports Betting\". No subdomains...", "agent_name": "Recon Alpha"}, {"entry_id": "c49f39", "surface": "777tigers.com (+ www, play.777tigers.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE Hercules React/Vite SPA (704KB bundle) via Cloudflare CNAME cname.onhercules.app; exposes client-routed /admin, /admin/users, /admin/games, /admin/pages + OIDC client_id in JS + Convex backend. Admin auth enforcement untested (mapping...", "agent_name": "Recon Alpha"}, {"entry_id": "9b0b28", "surface": "https://appmanager.tangobet.co.uk /api/mobile-app/stats", "risk_area": "Missing authentication / information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Unauthenticated GET returns only aggregate counts {\"count\":8722,\"pnAllowed\":3533}; no PII or identifiers. Low sensitivity and plausibly intended for the public mobile app.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "69329b", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "Brute-force / missing rate limiting", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "15 consecutive failed logins each returned 401 with no rate-limit headers, no Retry-After, no lockout; a valid login immediately after still succeeded. Filed as report.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "89cf7a", "surface": "https://appmanager.tangobet.co.uk /api/admin/*", "risk_area": "Missing authentication / BFLA", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Server-side gate: every /api/admin/users[/count], /api/admin/players/search, /api/admin/players/count, /api/admin/notifications/send returns {\"message\":\"Unauthorized\",\"statusCode\":401} without a valid Bearer token (GET/POST/PUT/DELETE teste...", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "c1a0ec", "surface": "https://appmanager.tangobet.co.uk /api/admin/players/search", "risk_area": "Sensitive player data exposure (PII / financial)", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "With the token obtained from default credentials, POST /api/admin/players/search returns 4,460 player records incl. Alias/real names, age, gender, country, deposit, cashout, revenue, currency. Reported as impact of the credential finding.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "4310a5", "surface": "https://appmanager.tangobet.co.uk /api/admin/users (POST/PUT)", "risk_area": "Mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "POST /api/admin/users with role/isAdmin/isSuperuser/permissions returned only {id,username,created,updated}; extra fields not stored. GET /api/admin/users shows the model has no role field (flat admin concept), so no privilege field to esca...", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "402e4b", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "JWT forgery (alg:none / weak secret)", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Self-signed alg:none token rejected 401. HS256 secret not recovered from 10k common-password list plus targeted candidates (betty/tangobet/railway/etc); token is short-lived (1h exp). No kid/jku/jwk headers present to abuse.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "46c30e", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "Weak/default administrative credentials", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "POST /api/auth/login with {\"username\":\"admin\",\"password\":\"admin123\"} returns HTTP 201 + HS256 access_token (payload {\"username\":\"admin\",\"sub\":1}). Token grants the full /api/admin/* API. Filed as report.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "d0fc2e", "surface": "uat.pandabingo.com /api/cms/[...path]", "risk_area": "Broken access control / sensitive data exposure", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Same build as uat.uk-bingo.net; /api/cms/users + /users/count return 200 unauth (identical 6 CMS accounts).", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "92a2e7", "surface": "UAT apps /api/env/vars", "risk_area": "Secret / environment variable disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Endpoint enforces prefix startswith NEXT_PUBLIC_ (NEXT_PUBLIC 11 chars rejected, NEXT_PUBLIC_ works; SECRETS/DATABASE_URL rejected). Only public NEXT_PUBLIC_* vars returned (feature flags, Sentry DSN, API base URL) — all client-embedded by...", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "3a0e56", "surface": "UAT apps /api/cms privilege escalation (BFLA)", "risk_area": "Broken function-level authorization", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Proxy forwards only GET/HEAD/OPTIONS (POST/PUT/DELETE -> 405). Traversal to admin endpoints (/admin/users, /admin/permissions, /admin/api-tokens) returns 401 Missing or invalid credentials — no write or privileged action achievable.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "e4b24f", "surface": "uat.uk-bingo.net /api/cms/[...path] (Strapi CMS proxy)", "risk_area": "Broken access control / sensitive data exposure (unauthenticated CMS API) + path traversal", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Unauth GETs return 200: /api/cms/users (6 staff emails), /users-permissions/roles, /sites (51 brands, 31MB), /upload/files (10MB), /content-type-builder/content-types (33 schemas). Traversal /api/cms/..%2fadmin%2finit -> admin config; POST...", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "55a468", "surface": "uat.chitchatbingo.com /api/cms/[...path]", "risk_area": "Broken access control / sensitive data exposure", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Same build; /api/cms/users + /users/count return 200 unauth (identical 6 CMS accounts).", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "739cba", "surface": "UAT apps account/wallet/player routes", "risk_area": "IDOR / BOLA", "outcome": "not_applicable", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "The UAT Next.js app exposes no account/wallet/player route handlers; client calls the out-of-scope backend api.dev.kraken.ptops.net/api/v1 directly. No in-scope object-scoped endpoints to test.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "192be7", "surface": "UAT apps /api/cms proxy SSRF", "risk_area": "Server-Side Request Forgery", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Host-injection attempts (//example.com, %2f%2f, ..%2f%2f%2f, 169.254.169.254) return {\"status\":400,\"message\":\"Malicious Path\"}; traversal only reaches same-host CMS sibling paths. No arbitrary-host fetch.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "c45341", "surface": "betmorph.com SPA admin routes (/admin, /admin/users, /admin/cms/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Admin guard is client-side only (OIDC isAuthenticated + Convex users.isAdmin; false -> redirect /). Unauth requests to /admin, /admin/users, /admin/cms/home render only the sign-in prompt (no data). All privileged data/actions resolve to Co...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "1d70c6", "surface": "betmorph.com / 777tigers.com OIDC login flow (/auth/callback, hercules.app issuer)", "risk_area": "Authentication / token handling", "outcome": "no_issue_found", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "oidc-client-ts flow uses authorization code + PKCE S256 and state validation; redirect_uri is fixed to window.location.origin + /auth/callback; the callback component navigates to a hardcoded \"/\" (no attacker-controllable returnUrl); no tok...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "e360e7", "surface": "777tigers.com SPA admin routes (/admin, /admin/users, /admin/games, /admin/pages/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Same client-side-only guard as betmorph. Unauth /admin/users and /admin/games show \"Admin Access Required / Please sign in\". Privileged functions (users.getAllUsers, users.updateUserRole role-escalation, games.create/update/remove, cms.upse...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "83852c", "surface": "betmorph.com / 777tigers.com static assets and config exposure", "risk_area": "Information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "betmorph.com /.env and /.git/config return 403 (Cloudflare); all other unknown paths return the SPA index HTML (no source maps, no config). No API keys/secrets in either JS bundle. 777tigers.com /.env and /.git/config return 403.", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "324ff7", "surface": "777tigers.com apex DNS (A record 100.24.208.97)", "risk_area": "Dangling DNS / domain takeover", "outcome": "reported", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Apex has two A records: 104.18.220.38 (Cloudflare -> real Hercules site) and 100.24.208.97 (rDNS staticip2.multiscreensite.com = Duda). Direct HTTPS/HTTP to 100.24.208.97 with SNI/Host 777tigers.com returns Duda's \"SITE NOT FOUND / not publ...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "d20baa", "surface": "https://www.jackpot.com/admin (AWS ALB path rule)", "risk_area": "Access control / path-normalization bypass", "outcome": "reported", "created_at": "2026-09-27 16:37:23 UTC", "evidence": "Confirmed and refined. ALB returns 403 (awselb/2.0) for raw-path prefixes /admin, /Admin, /Areas/Admin, /wp-admin on every method; encoded variants (/%2fadmin, /%61dmin, /%5cadmin, /%2f%2fadmin, /%2fAreas%2fAdmin%2f..., /%2fADMIN) return 20...", "agent_name": "Edge WAF Bypass Hunter", "previous_outcomes": ["reported"]}, {"entry_id": "44a707", "surface": "https://www.jackpot.com admin area controllers/actions", "risk_area": "Broken function-level authorization (admin area)", "outcome": "ruled_out", "created_at": "2026-09-27 16:37:31 UTC", "evidence": "Re-confirmed with the ALB %2f bypass. Known controllers (Dashboard, User, Promotion, Tickets, Config, Pages, News, Widget, Contents) 302 to /Admin?ReturnUrl=... and unknown names 404. NEW: /Admin/Home and /Admin/Home/Index return 200 but th...", "agent_name": "Jackpot Admin Access Hunter", "previous_outcomes": ["ruled_out"]}, {"entry_id": "9bbfcb", "surface": "https://www.jackpot.com public/widget parameters", "risk_area": "SQL injection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:12 UTC", "evidence": "Tested admin login (14 SQLi/auth-bypass payloads: admin'--, ' OR '1'='1'--, WAITFOR DELAY, UNION, comment/quote variants — all identical 133-byte 'Wrong USERNAME and/or PASSWORD!' JSON, no timing/content differential) and public widget para...", "agent_name": "Jackpot ASP.NET Hunter"}, {"entry_id": "e04858", "surface": "*.potsofluck.com gateway — exposed network services (45.132.74.81)", "risk_area": "Exposed backend services (guacd/database/RDP)", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Only 22/80/443 open. guacd 4822, MySQL 3306, PostgreSQL 5432, Tomcat 8080/8081, RDP 3389, VNC 5900, Redis 6379 all filtered from the internet — the gateway reaches guacd over loopback only.", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "ba8b12", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST)", "risk_area": "Authentication bypass / token forgery", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "No alternate auth extension: POST with 'data=' (JSON-auth) returns the standard expected:[username,password] response, ruling out guacamole-auth-json forgeable-token path. Guacamole 1.6.0 — CVE-2021-43999 (auth bypass) is SAML-only/<=1.3.0...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "4ddf8b", "surface": "*.potsofluck.com gateway — TLS transport (all six vhosts)", "risk_area": "Transport security / certificate validity", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Protocol/cipher posture is sound: TLS 1.0/1.1 refused, TLS 1.2/1.3 with ECDHE-ECDSA-AES256-GCM / AES256-GCM. OBSERVATION (not an exploitable finding): every host serves a Let's Encrypt cert with CN/SAN=cl.exalt-digital.ru, an unrelated thir...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "870781", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Injection markers in username/password (\"guacadmin'-- -\", \"' OR '1'='1\" in username, \"' OR '1'='1\" in password) all returned byte-identical 403 INVALID_CREDENTIALS with no error/ambiguity. Guacamole JDBC auth uses parameterized queries. NOT...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "9b76c4", "surface": "*.potsofluck.com Guacamole gateway — /api/session/* , /api/session/ext/quickconnect", "risk_area": "Unauthenticated access to session/connection data", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "All /api/session, /api/session/data, /api/session/data/{mysql,jdbc,postgresql}/* and quickconnect paths return 403 {\"message\":\"Permission Denied.\"} for every method/token shape tried. Standard Guacamole permission check runs before dataSour...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "f1e58c", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST) [dev/qa/lp/promo/promotions/games]", "risk_area": "Weak / default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Default guacadmin/guacadmin, guacadmin/password, admin/admin, root/root, potsofluck/potsofluck all rejected with 403 INVALID_CREDENTIALS. Auth provider is JDBC username/password (guacamole-auth-jdbc). Built-in rate limiter blocks after ~4-5...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "cfd5e6", "surface": "*.potsofluck.com gateway web root — static/management paths, .git/.env/backups, Tomcat apps", "risk_area": "Exposed management artifacts / information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "~140-path fuzz returned only expected Guacamole resources. Tomcat /manager, /host-manager, /docs, /examples all 404; no .git, .env, config, dump, or backup files. Port 80 serves the stock nginx welcome page (no API over cleartext). Only dis...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "d030fc", "surface": "https://www.jackpot.com widget endpoints (malformed params)", "risk_area": "Verbose error / stack-trace information disclosure", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:38:20 UTC", "evidence": "CONFIRMED but not filed as a vulnerability (low impact / recon value only, per disclosure-rating guidance). www.jackpot.com runs with customErrors mode=\"Off\"; unhandled exceptions return full ASP.NET stack traces to remote clients, e.g. GET...", "agent_name": "Jackpot ASP.NET Hunter"}, {"entry_id": "e5a53b", "surface": "https://www.jackpot.com Widget API endpoints", "risk_area": "IDOR / object-level authorization", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:20 UTC", "evidence": "No unauthenticated data-bearing object endpoints found. Widget endpoints that take identifiers are bound to Int32 (Menu/Timezones state, Promotion/Tac id, UsWebIdentity/ModalSeen customerID) and return non-sensitive content (promotion T&C t...", "agent_name": "Jackpot ASP.NET Hunter"}, {"entry_id": "67adc0", "surface": "api-uat/api-qa.playuk.com IP whitelist", "risk_area": "IP allowlist bypass via forwarding headers", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:20 UTC", "evidence": "Probed the full route list against api-uat: baseline /api/{prod,qa}/frontend returns 401 for our egress, and header-spoofing attempts (X-Forwarded-For, X-Real-IP, X-Originating-IP, Client-IP, True-Client-IP, X-Client-IP, Forwarded, CF-Conne...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "b856a7", "surface": "api-uat.playuk.com /revolve/api/* (UAT casino account API)", "risk_area": "broken access control / IDOR on casino account + wallet API", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:20 UTC", "evidence": "Resolved by the PlayUK UAT API Hunter on api-uat/api-qa.playuk.com: after authenticating against all /revolve/api/* object-scoped routes, identity is derived solely from SessionCorrelationId; the userCorrelationId cookie is ignored (swappin...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "515f16", "surface": "xmlrpc.php pingback (theonlinecasino.co.uk, mogobet.com)", "risk_area": "SSRF via xmlrpc pingback", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:24 UTC", "evidence": "xmlrpc.php is enabled on theonlinecasino.co.uk and mogobet.com (system.listMethods lists pingback.ping + system.multicall). Issued pingback.ping(sourceURI=http://<oast>/tag, targetURI=<real post URL>) with a live interactsh listener: the on...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "690d4d", "surface": "uat.playuk.com &amp; qa.playuk.com SPA bundles", "risk_area": "exposed JS secrets / source maps", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:24 UTC", "evidence": "Mapped the in-scope subdomain SPAs uat.playuk.com and qa.playuk.com (S3+CloudFront, Vue). Extracted the app bundles and inline runtime config (window.settings/siteconfig/config). Only secret-shaped value is a RavenTrack affiliate-pixel JWT...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "bc0166", "surface": "theonlinecasino.co.uk /wp-content/themes/Theonlinecasino/fetch-*.php", "risk_area": "LFI / SQLi / parameter injection in custom theme PHP", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:29 UTC", "evidence": "Directly executable theme PHP endpoints (fetch-games.php=5537 games, fetch-sports.php=158, fetch-promotions.php=6, fetch-sports-promotions.php=21) return cached JSON. Parameter fuzzing (file/cache/name/type/src/url/path/template/debug/refre...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "d7357f", "surface": "WordPress login (playuk/theonlinecasino/mogobet portal forms)", "risk_area": "weak/default credentials on WordPress admin", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:29 UTC", "evidence": "Bounded credential test (no massive brute force) against the reachable WordPress login surfaces for the enumerated admins: 31 passwords × {admin,playuk} on www.playuk.com/wp-login.php, and 31 × admin on the /theonlinecasino-portal/ and /mog...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "defa95", "surface": "play.neonrush.com /api/player/getPlayer|getPlayerDetails|getPlayerBalance|refreshToken (unauthenticated)", "risk_area": "IDOR / broken object-level authorization (player boundary)", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Player is derived server-side from the session cookie, not from client input. Supplying PlayerId/playerId/PlayerID/id/UserHash/Email query params or X-Player-Id/X-User-Id/Authorization headers always returned the anonymous player (PlayerId:...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "d5d77f", "surface": "play.neonrush.com /api/getTenantData,getWhiteLabelConfig,getDefault (tenant selection via wl/whiteLabelId)", "risk_area": "cross-tenant IDOR / tenant boundary", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Tenant is fixed per deployment. getDefault?wl=200 and getTenantData?wl=284/200/166/8 returned the host's own tenant (whiteLabelId=284, whitelabelName \"neonrush\") or an empty object; the wl/whiteLabelId param is not honoured. Confirmed on pl...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "222fae", "surface": "play.neonrush.com authenticated player IDOR (balance/account/wallet, /api/deposit/*, /api/withdrawal/*)", "risk_area": "IDOR / horizontal privilege escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Could not obtain a player session to test authenticated object access: registration via /api/registration/registrationStepFirst is blocked server-side with em_feature_not_allowed_in_region_text (egress IP geolocated NL, isActiveCountry:fals...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "23a037", "surface": "play.neonrush.com + play.mrslot.com client JS bundle (/_next/static/chunks/5218-*.js)", "risk_area": "credential / secret exposure in client code", "outcome": "reported", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Reported as vuln-0008: providersConfig block ships plaintext Evolution apiPassword, Skywind password/secretKey and Tomhorn sign_key, served unauthenticated (200, no cookies) and identically on a second tenant.", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "0e3dbe", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "prototype pollution / injection", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Endpoint is reachable unauthenticated and echoes caller-supplied keys (returned {\"FreeSpinsOffer\":{},\"Deposit\":{},\"undefined\":{...}}). Requests carrying __proto__/constructor.prototype bodies were blocked by the edge WAF (Incapsula 403), so...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "5f771b", "surface": "play.neonrush.com /api/player/loginOneTime and /api/player/getErrorFromCache", "risk_area": "authentication bypass / session minting", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "loginOneTime with guessed messageid values (1, 100, all-zero UUID) returned success:false with a trustly_login_failed popup and no player/Token; getErrorFromCache?messageid= returned empty. No session is minted without a valid provider call...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "828857", "surface": "jazzyspins.com /api/pp/games + /api/worker/games", "risk_area": "query-param injection / mass-data handling", "outcome": "no_issue_found", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Public catalogue endpoints return 200. Injecting provider=1', whitelabelId=284', lang=en', country=1', \"1 OR 1=1\", id=1' and other params produced byte-identical responses (7,167,811 bytes), so parameters are not processed by the backend; n...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "4caecb", "surface": "play.africasports.com, play.acelucky.com, play.777bet.casino, play.betstorm.com, play.dynobet.com, play.luckcity.com, play.mamzinobet.com, play.mrrex.com, play.moneyplay.com, play.ne-bet.com, play.q88bets.com, play.stakespin.casino, play.savibet.com, play.rainbetsplash.com", "risk_area": "attack surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "No DNS for these play.* hosts (dig returns nothing; proxy 502 = unresolved, not a target response); play.betstorm.com resolves to Cloudflare but the origin returns 522. play.mogobet.com and play.mrslot.com resolve but sit behind Imperva (40...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "fa834f", "surface": "play.* player apps (play.chitchatbingo.com, play.uk-bingo.net, play.pandabingo.com, play.wombatbingo.com, play.queensbingo.com, play.jazzyspins.com)", "risk_area": "Unauthenticated CMS proxy / broken access control (blast-radius check for vuln-0003)", "outcome": "ruled_out", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Imperva challenge passed with agent-browser (reload loop); in-page fetch from each host returns HTTP 404 (Next.js player-app 404 page) for /api/cms/users, /api/cms/users/count, /api/health and /api/pp/games. The Betable/ProgressPlay player...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "538573", "surface": "promotions.pandabingo.com", "risk_area": "Subdomain takeover / unconfigured vhost", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Serves the Plesk default \"Web Server's Default Page\" from 77.68.12.66 with no CNAME to any claimable third-party service; DNS record is under the organisation's own control. Unconfigured vhost only — not a takeover candidate.", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "cc9cad", "surface": "uat.* subdomain discovery across all 47 in-scope apexes", "risk_area": "Additional tenants carrying the same Next.js/CMS-proxy build", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "DNS A/CNAME resolution for uat.<apex> on all 47 apexes: only uat.chitchatbingo.com, uat.pandabingo.com and uat.uk-bingo.net resolve to the shared EKS ELB (the three hosts already reported in vuln-0003); uat.playuk.com resolves to CloudFront...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "cbf9b6", "surface": "Marketing Nuxt fleet /api/cms proxy blast radius (chitchatbingo, pandabingo, queensbingo, wombatbingo, uk-bingo.net, jazzyspins, vampirebingo, slotlux, betarno)", "risk_area": "Unauthenticated CMS proxy / broken access control (blast-radius check for vuln-0003)", "outcome": "ruled_out", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Control: the marketing apps are Nuxt 3/Nitro, whose entire server route table is /api/pp/games and /api/worker/games (only /api/* literals extracted from the shipped _nuxt bundles). Direct probes of /api/cms/users, /users/count, /users-perm...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "598161", "surface": "Public game catalogue /api/pp/games + /api/worker/games (marketing fleet)", "risk_area": "Query-parameter injection / unauth data exposure / reflection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Intended public catalogue (5,518 records, Access-Control-Allow-Origin: *, cached 300s, no PII/secrets). 15 param/payload variants (wl, whiteLabelId, tenant, siteId, gameId, id, callback, filter=1', <script>, pagination[...], url=, path trav...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "e0aa35", "surface": "acedbet.com", "risk_area": "Unauthenticated CMS proxy (blast-radius check for vuln-0003) / general surface", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:45:57 UTC", "evidence": "Every request (including the root `/`) returns HTTP 429 from Vercel, repeatedly, even when spaced ~8s apart — egress is rate-limited/blocked, so /api/cms and the app surface could not be observed. The 429 body (data-astro-cid marker) indica...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "b6ade2", "surface": "Cross-tenant operator-panel credential reuse (Betty Admin product, 47-apex fleet)", "risk_area": "Weak/default credentials — reuse across tenants", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Enumerated ~110 operator/admin hostname labels (appmanager, app, admin, manage, manager, backoffice, bo, ops, panel, dashboard, console, operator, staff, crm, risk, bi, affiliate, rabbit, betty, etc.) across all 47 apexes (DNS brute) plus s...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "568f9d", "surface": "bonus.supabet.co.uk (HTTP Basic operator panel)", "risk_area": "Weak/default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Endpoint is protected by HTTP Basic (WWW-Authenticate: Basic realm=\"Login\"). A bounded set (admin/admin123, admin/admin, admin/password, supabet/supabet, bonus/bonus, etc.) all returned 401, and the server then rate-limited (429), so brute...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "6f82b3", "surface": "partners.jackpot.com Cellxpert partner/admin login (/authenticate, /authenticate/admin-auth)", "risk_area": "Weak/default credentials", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Exposed partner portal and a separate admin login (/v2/login/admin-login/). Login POST /authenticate/admin-auth returns {\"error\":true,\"isCaptchaRequired\":true,\"reason\":\"Bad Captcha\"} for every credential — the server rejects on captcha BEFO...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "245ced", "surface": "affiliates.neonrush.com (RavenTrack affiliate portal) POST /account/login", "risk_area": "Weak/default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Recovered the real login endpoint (POST /account/login, Laravel Sanctum; CSRF via /sanctum/csrf-cookie) and replayed a bounded set with a valid X-XSRF-TOKEN. Every attempt returned 422 {\"errors\":{\"email\":[\"Credentials not found.\"]}} and the...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "216f06", "surface": "WordPress wp-admin logins (jeffbet.net, playuk.com, theonlinecasino.co.uk, mogobet.com, betmaze.co.uk, betsuna.com)", "risk_area": "Weak/default administrative credentials", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "Greatly expanded credential test on the enumerated accounts: 106,684 candidates were evaluated per account for betmaze_login (betmaze.co.uk), betsunaadmin (betsuna.com) and admin (betsuna.com) - ~320,000 attempts in total, comprising the to...", "agent_name": "WP Takeover Chain Validator", "previous_outcomes": ["no_issue_found"]}, {"entry_id": "84017c", "surface": "Hidden operator/admin consoles across the 47-apex fleet (hostname discovery)", "risk_area": "Exposed operator/admin panel discovery", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "Subfinder (16 apexes) + crt.sh + ~110-label DNS brute over all 47 apexes surfaced only known/previously-mapped hosts; the only new admin-ish finds were marketing/affiliate surfaces (partners.jackpot.com, affiliates.neonrush.com, bonus.supab...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "81ab56", "surface": "tangobet.co.uk sibling apps (deletemyaccount.tangobet.co.uk, app.tangobet.co.uk)", "risk_area": "Exposed operator panel / weak credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "deletemyaccount.tangobet.co.uk is a 2.6KB static SPA with no JS bundle and no API endpoints (no login). app.tangobet.co.uk is an AppsFlyer OneLink deep-link page (noindex). Neither exposes a management panel or credential login, so the Bett...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "e28959", "surface": "acedbet.com Auth.js credentials login (/api/auth/callback/credentials)", "risk_area": "Weak/default credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "acedbet.com is a player-facing casino site (Sign in / Create account), not an operator console; no /admin surface exists (client-routed /admin renders the public SPA). The Auth.js credentials endpoint returned 403 {\"error\":\"Access denied\"}...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "46c22d", "surface": "uat.playuk.com (Markor lobby) + api-uat.playuk.com", "risk_area": "Exposed operator panel / weak credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "uat.playuk.com is the PlayUK player lobby SPA (Vue/Nuxt, server: MarkorLobby); it has no login form in-page and no operator/admin routes. Its backing API api-uat.playuk.com returns 401 (JSON) for all paths. No operator console with default...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "6d32ad", "surface": "acedbet.com POST /api/auth/callback/credentials", "risk_area": "Authentication — credential validation, CSRF enforcement, enumeration, brute-force, callbackUrl redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Endpoint returns HTTP 403 {\"error\":\"Access denied\"} for every input: valid CSRF + wrong creds, missing/garbage CSRF, empty creds, JSON/text-plain bodies, method override, X-Auth-Return-Redirect:1, full browser headers, and a fresh page-gene...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "b2d561", "surface": "acedbet.com /api/auth/error and /api/auth/signin pages", "risk_area": "Reflected XSS / open redirect", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "error param is not reflected (tested <script> and \"><img onerror> payloads and a benign marker; none appeared in the HTML). Vercel WAF blocks <script> in query with 403 {\"error\":{\"code\":\"403\",\"message\":\"Forbidden\"}}. signin?callbackUrl=http...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "5b8575", "surface": "acedbet.com POST /api/auth/signout", "risk_area": "CSRF on state-changing endpoint", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Signout without a valid CSRF token returns 302 to /api/auth/signin?error=MissingCSRF; token required and rejected when invalid.", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "5c0c15", "surface": "acedbet.com password-reset Server Action (POST /?modal=forgot-password)", "risk_area": "User enumeration / reset-flow abuse", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Action reached (body [\"email\",\"en\"]) but returns 1:{\"success\":false,\"error\":\"ACCESS_DENIED\"} for the probed address, so existing-vs-nonexistent response differences could not be compared. Client-side validator rejected mailinator.com addres...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "fd2dc6", "surface": "acedbet.com registration Server Action (POST /?modal=create-account)", "risk_area": "Account creation abuse / anti-bot control enforcement", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Action executes its business logic regardless of x-is-human (absent, empty, 5KB junk, \"hello\", \"[]\") but always returns 1:{\"success\":false,\"error\":\"ACCESS_DENIED\"} for every email/country/btag tested, including from the real UI with a real...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "3d8a79", "surface": "acedbet.com x-is-human anti-bot header (all POST routes)", "risk_area": "Security-control enforcement / bot-protection bypass", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Auth Server Actions process requests with the header absent or forged (junk/empty/non-JSON), proving the client-side token is not enforced there; the token's signing key material is hardcoded in the client SDK so it is forgeable. No route w...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "096efe", "surface": "acedbet.com /api/auth/session and /api/auth/csrf", "risk_area": "Session / JWT handling and cookie flags", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Anonymous session returns null; CSRF cookie confirmed HttpOnly+Secure+SameSite=Lax. No session/JWT could be obtained (login denied), so signing strength, alg confusion, fixation and session-cookie flags could not be assessed.", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "2440ef", "surface": "/revolve/api/account/* and /payments/* object-scoped routes (balance, history, updateProfile, transactionStatus, cancelPendingWithdrawal)", "risk_area": "IDOR / BOLA", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "All routes resolve the player from the SessionCorrelationId cookie; no player/object identifier is accepted. Swapping the userCorrelationId cookie returns the session owner's data (cookie ignored); random/removed session -> 401. transaction...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "3d80df", "surface": "POST /revolve/api/account/updateProfile", "risk_area": "Mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Server whitelists fields: securityLevel, vip, playerGroupIds, kycStatus, depositCount, bonusAbuser, optoutOfAllRewards, registrationLevel were accepted in the request (HTTP 200) but none changed in the returned profile. Only whitelisted pro...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "a2631d", "surface": "POST /revolve/api/account/mobileCheck (api-uat/api-qa.playuk.com)", "risk_area": "Unauthenticated account enumeration", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registered mobile -> HTTP 400 {\"code\":30,\"message\":\"Mobile Number already exists.\"}; unregistered -> HTTP 200. No session required; 20/20 requests accepted (no rate limit).", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "fb3ef4", "surface": "CORS policy on api-uat.playuk.com (/revolve/api/*)", "risk_area": "Cross-origin data exposure with SameSite=None cookies", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Access-Control-Allow-Credentials: true is returned universally, but Access-Control-Allow-Origin is only emitted for the allow-listed origin https://uat.playuk.com. Attacker origins (evil.example, null, other playuk hosts) receive no ACAO, s...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "73d521", "surface": "POST /revolve/api/account/login (api-uat/api-qa.playuk.com)", "risk_area": "Account lockout denial of service", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "3 failed passwords -> HTTP 400 code 246 \"Player cannot login as too many failed login attempts\"; the correct password is then rejected (locked >=17 min, still locked at time of testing). Unauthenticated, per-account.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "fbd691", "surface": "POST /revolve/api/account/validateSMS and /resendSMS", "risk_area": "Unauthenticated OTP validation / brute force", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "With the correct parameter (smsPin) both endpoints return HTTP 401 \"Invalid session or session has expired\" before any code comparison; resendSMS also 401. OTP validation is session-bound.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "f58c0d", "surface": "POST /revolve/api/account/checkEmail (api-uat/api-qa.playuk.com)", "risk_area": "Unauthenticated account enumeration", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registered email -> HTTP 200 (empty); unregistered -> HTTP 404. No session required; 30/30 requests accepted (no rate limit). Reproduced on both api-uat and api-qa with separate per-environment databases.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "268eb7", "surface": "GET/POST injection sweep on /revolve/api/account/checkEmail, mobileCheck", "risk_area": "SQL injection / NoSQL injection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "SQLi markers (quote, boolean, UNION, SLEEP/WAITFOR/pg_sleep) produced no error or timing differential (all ~0.09s). NoSQL/type-confusion objects gave 404 (checked at format) or a generic 500 on mobileCheck with no data leak.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "8b718e", "surface": "POST /revolve/api/account/changePassword", "risk_area": "Account takeover via password change", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Client contract requires oldPassword + newPassword; the endpoint is session-gated. No password-only or token-only change path was found.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "aeaae0", "surface": "POST /revolve/api/account/updateEmail and /updateMobileNumber", "risk_area": "Account takeover via email/mobile change", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "updateEmail returned code 193 \"Email has already been updated.\" for fresh, already-registered and unrelated addresses, and the profile email never changed. updateMobileNumber validates format. No unverified identifier-change path observed.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "af7389", "surface": "Session management (SessionCorrelationId / userCorrelationId cookies)", "risk_area": "Session fixation / predictable tokens", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Every login issues a fresh random UUID session; a second login invalidates the first (single active session); logout invalidates immediately. Session cookie is Secure/HttpOnly. No fixation or reuse observed.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "90d629", "surface": "POST /revolve/api/register/lite (account creation)", "risk_area": "Business logic / tenant confusion", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registration requires a full validated profile and rejects duplicate email/mobile; account is created under the PLAY-UK-CASINO tenant; accountSystemTag/platformTag supplied in later requests are ignored (session tenant enforced). Anti-fraud...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "b51b71", "surface": "betmaze.co.uk / betsuna.com — custom child-theme fetch-sports.php, fetch-promotions.php, fetch-sports-promotions.php, fetch-games.php", "risk_area": "SSRF / path traversal / injection / unauth data exposure in custom theme code", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "Only fetch-games.php consumes input: gameType (string compare) and category (case-insensitive substring match over the game catalogue). Traversal payloads (../../etc/passwd, %2f variants, php://filter) return count 0 (no file read); quote/O...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "da00ee", "surface": "betmaze.co.uk, betsuna.com, jeffbet.net — /wp-json/wp/v2/users (WordPress REST user enumeration)", "risk_area": "Unauthenticated information disclosure (username enumeration)", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "Unauth GET returns login usernames: betmaze.co.uk -> id1 slug 'betmaze_login'; betsuna.com -> id2 slug 'betsunaadmin'; jeffbet.net -> ids 1/2/5 slugs 'admin','simon-young','ross-young'. Also enumerable via ?author=N (betmaze.com -> /author/...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "9dc081", "surface": "betmaze.co.uk — wp-login.php", "risk_area": "Missing rate limiting / account lockout on authentication", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "15 consecutive failed logins (plus ~20 in a separate run) each returned HTTP 302 with no 429/lockout/CAPTCHA; a subsequent attempt still processed normally. No WC_* / Limit-Login style throttling observed. Contrast: jeffbet.net returns 403...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "4b8b96", "surface": "betmaze.co.uk & betsuna.com — xmlrpc.php (system.multicall / wp.getUsersBlogs)", "risk_area": "Missing restriction on excessive authentication attempts (XML-RPC brute-force amplification)", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "POST system.listMethods shows system.multicall, wp.getUsersBlogs and pingback.ping enabled. A single system.multicall request carrying 30 wp.getUsersBlogs attempts was fully processed (HTTP 200, 30 faultCode entries) — no throttling, so one...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "2a4682", "surface": "jeffbet.net — wp-login.php and xmlrpc.php", "risk_area": "Brute force / missing authentication throttling", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "15+ rapid failed POSTs to /wp-login.php returned HTTP 403 for the first 5 then HTTP 429 (rate limited), and xmlrpc.php returns 403 at the edge (nginx/WP Engine). A control is present, so this is not a brute-force vector here.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "c3cdb3", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — WordPress REST write endpoints", "risk_area": "Unauthenticated content/user modification (REST write endpoints)", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "POST /wp-json/wp/v2/users with username+email+password on betmaze/betsuna returns 401 rest_cannot_create_user; POST /wp/v2/posts, /pages, /media return 401 rest_cannot_create. No unauthenticated write/modify path via REST.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "ee7046", "surface": "jeffbet.net — WordPress plugins (CF7, Responsive Accordion &amp; Collapse, Redirection, Akismet)", "risk_area": "Known plugin CVEs / unauthenticated plugin functionality", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "Plugins/versions read from unauthenticated readme.txt: contact-form-7 6.1.7, responsive-accordion-and-collapse 2.5.3, redirection 5.9.0, akismet 5.7.2. REST namespaces for each require auth (redirection/v1/redirect 401, contact-form-7/v1/co...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "d39faf", "surface": "jeffbet.net — /wp-json/wpe_sign_on_plugin/v1/* (WP Engine Sign-On)", "risk_area": "Authentication bypass via SSO/sign-on endpoints", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "GET /wp-json/wpe_sign_on_plugin/v1/login and /is_user_logged_in both return 307 with Location: /wp-login.php (auth required); POST /has_logged returns \\\"false\\\". No credential or session can be obtained without a valid login.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "487571", "surface": "betmaze.co.uk / betsuna.com — wp-admin/admin-ajax.php custom actions", "risk_area": "Unauthenticated custom AJAX actions", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "POST admin-ajax.php with actions fetch_games/fetch_sports/get_promotions/getTenantData etc. all returned HTTP 400 body '0' (no such handler) on betmaze and betsuna — the custom theme registers no admin-ajax actions. The fetch-*.php files ar...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "974c5a", "surface": "betsuna.com — wp-login.php / xmlrpc.php", "risk_area": "Authentication throttling behaviour", "outcome": "reported", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Resolved (was needs_follow_up due to an earlier transient edge 400/timeouts). Re-tested from this environment: xmlrpc.php on betsuna.com works and is completely unthrottled - a single system.multicall request carrying 500 wp.getUsersBlogs a...", "agent_name": "WP Takeover Chain Validator", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "fe7cb9", "surface": "betmaze.co.uk / betsuna.com — xmlrpc.php pingback.ping", "risk_area": "XML-RPC pingback SSRF", "outcome": "reported", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Resolved: the prior note assumed pingback was inert because no post exists, but the WordPress origin still fetches the attacker-supplied sourceUri. With an OAST listener, unique hostnames placed only in the pingback.ping sourceUri were reso...", "agent_name": "WordPress Fleet Hunter A", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "6959f9", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — web root &amp; wp-content", "risk_area": "Exposed sensitive files / backups / directory listing", "outcome": "no_issue_found", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Probed wp-config.php(.bak/~/.save/.old/.orig), .env, .git/config, debug.log, .user.ini, .htaccess, phpinfo.php, dir listings (wp-content/uploads|plugins|themes), composer.json, theme .DS_Store/backups on all three hosts: all 403/404 or empt...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "015433", "surface": "Imperva-fronted in-scope hosts (www.highstakes.co.uk, www.supabet.co.uk, www.hotwinscasino.com, play.betzi.co, www.luckcity.com, www.mrrex.com, www.mamzinobet.com, lobby.moneyplay.com, www.ne-bet.com, www.betblink.com, www.21luckybet.com, www.lekkerbets.co.za)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: an Imperva/Incapsula IP-level block at the edge of every host (apex 301->www, then a ~770-883 byte Incapsula block page with no Server header). Ran ~150 request variations (methods GET/HEAD/POST/OPTIONS/TRACE; UA none/curl/Mozilla/...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "2b9d33", "surface": "promo.hotwinscasino.com", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: the openresty origin behind Cloudflare returns 403 for every request (body '403 Forbidden / openresty/1.31.1.1'). Tested direct, encoded paths, Host-header variants, spoofed XFF/X-Real-IP/CF-Connecting-IP, Referer/Origin, and a rea...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "16dd65", "surface": "games.playuk.com", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: AWS ALB returns a blanket fixed 403 (Server: awselb/2.0, 118-byte body) for EVERY path including the apex '/', so there is no restricted path prefix to encode around. Tested 17 paths/encodings (/%2f, //, /%2e/, /./, static assets,...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "c92ddc", "surface": "SiteGround sgcaptcha WordPress fleet (headless.mrslot.com, headless.mrmobi.com, staging6.mrsuperplay.com, staging3.mrjackvegas.com, headless.slotlux.com, headless.queensbingo.com, headless.jazzyspins.com, comingsoon.pandabingo.com)", "risk_area": "Edge WAF bypass / bot-challenge bypass", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: SiteGround sgcaptcha JS proof-of-work challenge (202 + /.well-known/sgcaptcha). The challenge IS solvable — a real headless Chrome completed it and obtained the `_I_` cookie — but the origin then returns '403 Forbidden / Access to...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "7aeaf2", "surface": "whm.betmorph.com, cpanel.betmorph.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "Published (non-wildcard) records proxied to a Duda origin returning \"SITE NOT FOUND / This site is not published or does not have a domain assigned to it\" with Duda dm404* classes and irp.cdn-website.com assets. Filed vuln-0015.", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "1bba35", "surface": "casino.playuk.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "A -> Cloudflare -> WP Engine origin; HTTP 404 \"Site Not Configured ... domain is successfully pointed at WP Engine, but is not configured for an account on our platform\" for all paths; HTTPS 301-redirects to www.playuk.com (partial mitigati...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "a3f464", "surface": "qa.uk-bingo.net, qa.pandabingo.com, qa.chitchatbingo.com, qa.playuk.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> d1ama3lmihrvrd.cloudfront.net (distribution exists). qa.uk-bingo.net returns CloudFront 403 \"this request could not be satisfied\" (hostname not configured on the distribution); no signature on the others. Same open question as the...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "df5d6f", "surface": "support.uk-bingo.net", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> ukbingo.zendesk.com, which 301-redirects to www.zendesk.com/app/help-center-closed/ (closed/unclaimed help centre = dangling target). Exploitation is currently blocked by a named control: the proxy path returns Cloudflare error 103...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "44dfa4", "surface": "api.pandabingo.com, api.playuk.com, api.uk-bingo.net", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> d31tqz5bd5ida4.cloudfront.net, which does NOT resolve (distribution deleted); names currently fail to resolve. Gap: a CloudFront alternate-domain claim requires a TLS certificate covering the name, which I could not verify is or is...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "51ea3b", "surface": "wiki.jackpot.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> cname.vercel-dns.com; Vercel edge returns 404 x-vercel-error: DEPLOYMENT_NOT_FOUND, byte-identical to an arbitrary unconfigured host; no _vercel TXT -> domain unassigned/claimable. Filed vuln-0011.", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "884c7b", "surface": "www.jackpot.com restricted-path classes (/wp-admin, /wp-login.php, /xmlrpc.php, *.php, /.git/config, /content-admin, /api/admin)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Control: the AWS ALB's substring/regex rule classes. Unlike the prefix rules (/admin*, /Areas/Admin*), these matched every encoded variant tested (/%2f, /%2F, /%2f%2f, /%252f, //, /./, /%2e/, /.%2f, /%5c, trailing %2f/%20/%09/%23/%2e/., ;/,...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "182cc9", "surface": "app.tangobet.co.uk /wp-login.php (Cloudflare path rule)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Cloudflare returns 403 'Access Denied' (1148 B) for /wp-login.php, but the rule is case/postfix-sensitive: /WP-LOGIN.PHP, /wp-login.php%23 and /wp-login.php/ pass the edge and hit the origin (404, 24 B) because the host serves a static Apps...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "976fd8", "surface": "Next.js / Nuxt marketing hosts (betmorph.com, 777tigers.com, slotlux.com, acedbet.com, uat.*, playuk.com SPAs)", "risk_area": "Query-string router bypass of edge path rules", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Tested `?_route=/admin`, `/admin?_route=/`, `/%2fadmin`, `/admin/../admin` against /admin on each host: no query-string trick changed routing or defeated an edge rule (777tigers `/%2fadmin` -> 400, betmorph -> 307, slotlux -> SPA index 200...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "7354e6", "surface": "uat.uk-bingo.net /api/cms/[...path] proxy — \"Malicious Path\" guard", "risk_area": "Edge/proxy guard bypass (SSRF / path-normalization)", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Tested guard-bypass encodings against the proxy's path check: %2f%2f, %2F%2F, %252f%252f, %5c%5c, ..%5c..%5c, %2e%2e%2f, tab/space-prefixed, @-prefixed, http:%2f%2f, x%00 forms — none produced a fetch of an external host; all returned a sam...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "4aa54e", "surface": "promotions.pandabingo.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "A -> 77.68.12.66 (Fasthosts; PTR linux.prod.activewin.co.uk) returns a Plesk \"Web Server's Default Page\" for ANY Host header. Control: the vhost is unconfigured on a shared Plesk server and can only be populated with server-side account acc...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "5b48a5", "surface": "games.luckcity.com, games.savibet.com, promo.luckcity.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "A -> 45.63.98.231 (Vultr) serves the Cloudways \"maintenance-domain-mapping\" page (403) — the server exists but no application is mapped to the hostname. Gap: claiming would require access to the Cloudways account/server, and I could not con...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "7156dd", "surface": "test.jackpot.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "CNAME -> chlfv.x.incapdns.net (Imperva/Incapsula). Control: the target is a vendor-managed hostname under Imperva's domain that a third party cannot register or bind; the site name resolves only within Imperva's platform, so there is no cla...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "6ecf02", "surface": "47 in-scope apexes + their subdomains (fleet DNS/takeover sweep)", "risk_area": "Subdomain takeover / dangling DNS (fleet-wide DNS sweep)", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "A/AAAA/CNAME/NS/MX/TXT resolved for all 47 apexes and ~265 associated subdomains (recon inventory + certspotter/crt.sh CT + 105-name DNS brute force per apex with wildcard detection); every resolving host was HTTP/HTTPS-probed against known...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "ae3e91", "surface": "lobby.mrslot.com, lobby.mrmobi.com, lobby.mrjackvegas.com, lobby.mrsuperplay.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Bare A records to 185.27.56.100 (Computer Solutions Ltd, MT); no service on TCP/80 or 443 (timeout), no PTR. Gap: cannot rule out that the IP is a shared host that auto-provisions a vhost for a pointing domain without proving it; there is n...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "33799b", "surface": "ftp.betmorph.com, mail.betmorph.com, smtp.betmorph.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Published Cloudflare-proxied records for ftp/mail/smtp.betmorph.com return Cloudflare 522 (origin unreachable). Gap: same Duda-origin question as vuln-0015 (whm/cpanel) but no provider page was returned to confirm the origin, so claimabilit...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "539572", "surface": "app.luckcity.com, app.savibet.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:40 UTC", "evidence": "CNAME -> <project>.web.app (Firebase Hosting). Both resolve to 199.36.158.100 and return 301 to the owning apex domain (luckcity.com / savibet.com), i.e. the Firebase Hosting project is claimed and serving content, so the resource is owned...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "6ef926", "surface": "ProgressPlay marketing hosts /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Hardcoded third-party credentials in client bundle", "outcome": "reported", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Secret scan (gitleaks + manual review) of the marketing build's chunks found only the provider credential set (Evolution apiUsername/apiPassword, Skywind username/password/secretKey, Tomhorn sign_key) in chunk 5218-5c354764053c3ff3.js, whic...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "b8fcf7", "surface": "acelucky.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW) as africasports.com; all non-root paths and any query string return the Imperva 403 block page from this egress. Dynamic client-side testing not possible; identical build means the a...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "203140", "surface": "dynobet.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); Imperva 403 on all paths/query strings from this egress. Dynamic client-side testing not possible. Gap: WAF IP restriction.", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "7d1d15", "surface": "ProgressPlay marketing fleet __NEXT_DATA__ (africasports.com, acelucky.com, 777bet.casino, betstorm.com, dynobet.com)", "risk_area": "Client-side configuration / secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "The server-rendered __NEXT_DATA__ runtimeConfig is identical on all five hosts. Every embedded value is public-by-design or informational: paypalSandboxKey (PayPal sandbox/public client id), SMARTICO BRAND_KEY/LABEL_KEY (client widget ident...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "2bb682", "surface": "africasports.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Imperva/Incapsula blocks every path except `/` from the tester egress (all of /games, /promotions, /?a=1, /api/getTenantData return the 883-byte 403 block page to curl_cffi, in-page fetch, and a real headless browser), so reflected/DOM XSS...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "ad6e74", "surface": "777bet.casino marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); all non-root paths/query strings return the Imperva 403 block page from this egress. Dynamic client-side testing not possible; static build analysis applies. Gap: WAF IP restriction...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "fe6bb3", "surface": "betstorm.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); Imperva 403 on all paths/query strings from this egress. Dynamic client-side testing not possible. Gap: WAF IP restriction.", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "4864e9", "surface": "www.neonrush.com (Cogni) — geo-restriction gate on all pages", "risk_area": "Access control / geo-restriction bypass (IP spoofing)", "outcome": "reported", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "GET / returns 302 -> /geo-block with no header or with a non-US X-Forwarded-For; returns 200 (full app, title \"Neon Rush\") with X-Forwarded-For: 8.8.8.8 or 127.0.0.1. Only XFF is honored (X-Real-IP/X-Client-IP/True-Client-IP/Forwarded ignor...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "0e3762", "surface": "www.neonrush.com ABP application services (/api/services/app/*)", "risk_area": "Broken function-level authorization on unauth endpoints", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "Enumerated 191 routes via /AbpServiceProxies/GetAll and /AbpScripts/GetScripts. All sensitive services (transactions, wallet, profile, notification, document, playerAccount) return 401 \"Current user did not login\" unauthenticated. Only low-...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "9636ea", "surface": "play.neonrush.com /api/* (ProgressPlay tenant 284)", "risk_area": "IDOR / unauth data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Re-enumerated the full client bundle route set (Game/*, player/*, deposit, withdrawal, aml, playResponsibly, registration). Anonymous calls return only the empty/anon player (getPlayer PlayerId:0, getPlayerDetails empty, getPlayerBalance 41...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "d8c126", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "Prototype pollution / reflected data", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Endpoint echoes a fixed {FreeSpinsOffer,Deposit,undefined,TimeStamp} object. Attempts to send __proto__/constructor.prototype and nested-object bodies were rejected at the edge (Incapsula 403), so server-side prototype pollution could not b...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "e4a75e", "surface": "affiliates.neonrush.com admin/affiliate login", "risk_area": "Weak/default credentials & brute force", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "POST /admin/login and POST /account/login (Laravel Sanctum, CSRF via /sanctum/csrf-cookie) return 422 \"Credentials not found\" and then 429 \"Too many login attempts\" after ~5-6 attempts for the same account. Lockout enforced.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "b50eb0", "surface": "trk.neonrush.com tracker", "risk_area": "Open redirect / SSRF", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "All probed paths (/click, /track, /redirect, /c/1, /r/1, /pixel, etc.) return 404 with a static error page; no redirect/tracking endpoint is reachable.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "930c98", "surface": "affiliates.neonrush.com /api/v1/*", "risk_area": "IDOR / broken authorization on affiliate API", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "/api/v1/users/me, /api/v1/session/check, /api/v1/users/* return 401 \"Unauthenticated.\"; other guessed object paths return 404 \"Record not found.\" No unauth object read found.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "f5bd58", "surface": "https://www.queensbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative (no DOM reflection/execution); /promotions 301 is a static route-rule redirect to play.queensbingo.com, not attacker-controlled; no redirect param honored; no URL prototype poll...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "c5b336", "surface": "https://www.pandabingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Same shared Nuxt template build as wombatbingo/slotlux; same param/hash/path DOM-XSS sweep (0 reflections/executions, 171 combos on the shared template), no redirect param honored, no client prototype pollution. Unknown paths redirect to /...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "8876ce", "surface": "https://www.wombatbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Broad param sweep (~57 params incl. clickkey/tracker/btag/affid/lang/title/query/s/keyword/redirect/return/next/url/callbackUrl) with HTML+attr-break XSS payloads: no payload reached the DOM (checked outerHTML reflection AND window.__x exec...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "40582b", "surface": "https://www.uk-bingo.net (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative; no redirect param honored; no client prototype pollution. Unknown paths fall back to / (SPA catch-all).", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "236be8", "surface": "https://jazzyspins.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). /lp/* and /promotion/* only 308-normalize to a trailing slash; /promotions is a static route-rule 301 to play.jazzyspins.com. No redirect param honored; no cli...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "028307", "surface": "https://www.vampirebingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative; no redirect param honored; no client prototype pollution. Only third-party script is cloud.umami.is/script.js (standard, no URL-driven DOM sink).", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "97f0ec", "surface": "https://betarno.com (Nuxt + Prismic SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Distinct Nuxt+i18n build. Query/path/hash XSS sweep negative; the only URL param reaching the DOM is clickkey -> href attribute binding (Vue escapes, prefix is https://www.betarno.com so no javascript:/scheme injection). /preview?token=&doc...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "2125cd", "surface": "https://www.chitchatbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). Unknown paths fall back to / (SPA catch-all). No redirect param honored; no client prototype pollution. Content/config fetched from out-of-scope *.tech1960.wor...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "b78e2f", "surface": "https://slotlux.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). Unknown paths fall back to / (SPA catch-all). No redirect param honored; no client prototype pollution. No embedded secrets/API keys found in the shipped bundl...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "58946d", "surface": "Nuxt marketing SPA CMS/config-content innerHTML sinks (shared across the 9 hosts)", "risk_area": "Stored/DOM XSS via CMS content rendered with innerHTML", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "The apps render CMS/config strings via innerHTML (e.g. sig_terms/sigTerms, heading/subheading/body/intro, footerHtml, compliance HTML, WordPress content.rendered). The data is fetched from OUT-OF-SCOPE sources (access-content-pp.tech1960.wo...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "75cd8f", "surface": "www.neonrush.com /account/login and /api/services/app/playeraccount/register", "risk_area": "Captcha/anti-automation control on standard auth flows", "outcome": "ruled_out", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "Login and registration endpoints enforce a Cloudflare Turnstile challenge (\"You must prove that you are not a robot.\"); the interactive challenge could not be solved in the headless browser, so end-to-end login/session testing was not possi...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "f3ea57", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Missing authentication / anti-automation bypass on account creation", "outcome": "reported", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "POST /api/services/app/playeraccount/registerexternalfromapi creates an active/login-capable account (successful:true, active:true, canLogin:true, userId increments) with no auth, no API key and no captcha; isusernameavailable confirms the...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "86e5a0", "surface": "betmaze.co.uk & betsuna.com — /wp-json/oembed/1.0/proxy", "risk_area": "SSRF via oEmbed proxy", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "GET /wp-json/oembed/1.0/proxy?url=<any> returns HTTP 401 {\"code\":\"rest_forbidden\",\"message\":\"Sorry, you are not allowed to make proxied oEmbed requests.\"} for external (OAST) and internal (127.0.0.1, localhost, [::1], 169.254.169.254) targe...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "1d7cf9", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — /wp-json/* CORS response headers", "risk_area": "CORS misconfiguration (reflected Origin + credentials)", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "With Origin: https://evil.example the REST API reflects Access-Control-Allow-Origin and sends Access-Control-Allow-Credentials: true. This is WordPress core default behaviour (rest_send_cors_headers), not a site misconfiguration, and it is...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "f3a540", "surface": "jeffbet.net — plugin REST surface (contact-form-7, redirection, akismet, ACF, wpe)", "risk_area": "Unauthenticated plugin endpoints / plugin CVEs", "outcome": "no_issue_found", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "Fingerprinted installed plugins/versions: CF7 6.1.7, Redirection 5.9.0, Akismet 5.7.2, Yoast 28.3, ACF 6.8.8, Accordion FAQ 2.5.3 (all current). Plugin REST routes are access-controlled: /contact-form-7/v1/contact-forms -> 403 wpcf7_forbidd...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "ea0d54", "surface": "jeffbet.net — /xmlrpc.php", "risk_area": "XML-RPC pingback SSRF / credential brute force", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "Control: POST /xmlrpc.php returns HTTP 403 (nginx \"403 Forbidden\", Cloudflare-fronted) for system.listMethods, pingback.ping and wp.getUsersBlogs alike — the endpoint is denied at the edge before reaching WordPress, so neither SSRF nor mult...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "c2255b", "surface": "ProgressPlay marketing/player fleet — client-side injection (africasports.com, acelucky.com, 777bet.casino, betstorm.com, dynobet.com)", "risk_area": "Reflected/DOM XSS and open redirect on the Imperva-fronted Next.js app", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Reached the sites only via the browser JS-challenge (page loads after open+reload), but every subresource `fetch()` and every direct navigation to a non-root path (`/game/<payload>`, `/games?search=`, `/promotions?id=`, `/nonexistent-<paylo...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "cd3f33", "surface": "ProgressPlay Next.js marketing/player fleet — __NEXT_DATA__ runtime config (www.africasports.com, www.acelucky.com, www.777bet.casino, www.betstorm.com, www.dynobet.com)", "risk_area": "Information disclosure of embedded secrets (config exposure)", "outcome": "ruled_out", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Extracted the full __NEXT_DATA__/runtimeConfig from the live page (buildId WpePWuKOnX3rgMNqj5LeW) on all five hosts. Every flagged value was classified: `paypalSandboxKey: sandbox_7bh7m9qm_hkgcyxcmtk4c9yq7` is a PayPal **sandbox publishable...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "161f63", "surface": "Marketing SPAs — client-side XSS / open redirect (www.mrslot.com, www.mrsuperplay.com, www.mrjackvegas.com)", "risk_area": "Reflected/DOM XSS and open redirect", "outcome": "no_issue_found", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Nuxt/Vue SSG apps, directly reachable (HTTP 200, no WAF). Drove a real browser across 15 attacker-controlled query parameters (q,s,search,query,redirect,returnUrl,return,next,url,u,lang,locale,email,btag,err,error,msg) with `\"><img src=x on...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "e9cde7", "surface": "app.luckcity.com (Firebase Hosting / Dynamic Links project luck-city-i2zy6e)", "risk_area": "Open redirect / deep-link abuse", "outcome": "ruled_out", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "`app.luckcity.com` is Firebase Hosting (CNAME luck-city-i2zy6e.web.app, 199.36.158.100) and answers with a fixed `301 Location: https://luckcity.com/`. Supplying `?link=https://example.com/pwn` (and the encoded/`apn` variant) does NOT redir...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "9be3d2", "surface": "POST/PUT /api/admin/users[/{id}]", "risk_area": "mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Create and update accept only username (and password on create); injected fields role, isAdmin, permissions, and id were ignored in the response and in the persisted record. The user model exposes only id/username/created/updated and has no...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "b2311f", "surface": "DELETE /api/admin/users/{id}", "risk_area": "sensitive data exposure (password hash)", "outcome": "reported", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "The delete response returns the full user row including the bcrypt password hash, while GET/POST/PUT do not. Reproduced with a synthetic user (created then deleted). Filed as vuln-0019.", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "8e0646", "surface": "POST /api/auth/login", "risk_area": "user enumeration (timing side channel)", "outcome": "reported", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Valid usernames respond consistently slower (~0.31s admin, ~0.28s betty_admin) than non-existent usernames (~0.21s) because a bcrypt comparison runs only for existing accounts; identical 401 body in all cases. Filed as vuln-0020.", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "1afe36", "surface": "POST /api/auth/login", "risk_area": "SQL/NoSQL injection and authentication bypass", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Login is parameterized and type-checked. Payloads tried: single quote, ' OR '1'='1, admin'--, \"admin \" (trailing space), NoSQL operator objects for username and/or password ({$ne:null}), and an extra $where field; every wrong-credential att...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "909fa4", "surface": "/api/admin/* authorization enforcement", "risk_area": "broken access control (unauthenticated admin access)", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "Unauthenticated, malformed-token, and empty-bearer requests to GET/POST/PUT/DELETE on /api/admin/users, /players, /users/count all return 401 {\"message\":\"Unauthorized\"}; the 401 is emitted before any route logic. Auth is enforced server-sid...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "f3576e", "surface": "GET /api/admin/players", "risk_area": "undocumented route / additional data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "Undocumented GET /api/admin/players returns the same paginated/sortable/searchable player list as the documented POST /api/admin/players/search (params limit/page/search/sortField honored); it exposes no fields beyond the player dataset alr...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "f09883", "surface": "HS256 bearer JWT issued by /api/auth/login", "risk_area": "JWT forgery / weak signing secret", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "alg:none token rejected (401). An HS256 forgery requires the signing secret; the secret is not present in rockyou.txt (14.34M candidates) nor in the 10k common list previously attempted, and the token header carries no kid/jku/jwk to abuse....", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "0c93fc", "surface": "POST /api/admin/players/search (incl. /count, advancedFilter, sortField, search, page/limit)", "risk_area": "SQL/NoSQL injection via filter, sort, search and pagination", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "search and advancedFilter `value` inputs are bound, not interpolated: quote/% payloads are matched literally ('%' acts as a LIKE wildcard but '1 OR 1=1', stacked SLEEP(5), and filter-value SLEEP(5) produced no delay/error; a 100k-char searc...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "9806ad", "surface": "POST /api/admin/notifications/send", "risk_area": "unauthorized/mass notification action", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Deliberately not executed per the non-destructive rule: targetType accepts 'all' and 'selected', and a send would push to the full pushable audience (~1,046 players). Request-schema validation, authorization, and rate-limiting of this route...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "bd3364", "surface": "Betty Admin SPA rendered fields (username, players table)", "risk_area": "stored/reflected XSS in admin UI", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "All dangerouslySetInnerHTML occurrences in the shipped bundle belong to React/PrimeReact internals (DOM property handling, hydration bootstrap script, a label &amp;nbsp;); application data such as the username column is rendered through Rea...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "33e647", "surface": "API error handling (invalid inputs)", "risk_area": "information disclosure via error handling", "outcome": "no_issue_found", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Malformed or unexpected inputs (duplicate username, empty body, page=-1, non-numeric limit, wrong advancedFilter shape, PUT/DELETE on a non-existent id) all return a generic {\"statusCode\":500,\"message\":\"Internal server error\"} with no stack...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "e6f3d7", "surface": "Betty Admin SPA (index HTML + API responses)", "risk_area": "missing anti-framing headers / clickjacking", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Responses carry no X-Frame-Options, no CSP frame-ancestors, no HSTS, no X-Content-Type-Options and no Referrer-Policy, and the SPA bundle contains no frame-busting logic, so the admin UI is embeddable in an iframe. Impact is not confirmed:...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "117573", "surface": "appmanager.tangobet.co.uk API CORS &amp; session model", "risk_area": "CORS misconfiguration / CSRF", "outcome": "not_applicable", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "The API returns no Access-Control-Allow-Origin or Access-Control-Allow-Credentials headers for any origin, and OPTIONS preflight to /api/admin/users returns 404 (no CORS middleware). Authentication is via an Authorization bearer header, not...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "487f20", "surface": "Betty Admin SPA bundle (index-BuNztArT.js) — Send Notification page (component Zg)", "risk_area": "bundle analysis: fields, HTML sinks, hidden endpoints, client-only restrictions", "outcome": "no_issue_found", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "Single bundle, no dynamic imports/lazy chunks. Notification page submits {title,content,targetType:'all'|'selected',advancedFilter?} to POST /api/admin/notifications/send; counts come from POST /api/admin/players/count; the response count/f...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "4e97a0", "surface": "POST /api/admin/notifications/send — advancedFilter handling / fail-open", "risk_area": "fail-open mass targeting", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "A valid zero-match filter (Status eq '__zz_no_such_status__', proven total:0 via players/count) produced count 0 on the send route, so the filter IS honoured for well-formed input (no observed fail-open). The behaviour for a MISSING or INVA...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "2b5480", "surface": "POST /api/admin/notifications/send — authorization &amp; method surface", "risk_area": "broken access control / unauthenticated access", "outcome": "ruled_out", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "No token or bad token -> 401 {\"message\":\"Unauthorized\"}; valid token -> 201. Route is POST-only: GET/HEAD/OPTIONS/PUT/PATCH/DELETE all -> 404 \"Cannot <METHOD> /api/admin/notifications/send\". Path variants (/trailing slash, //, /., mixed cas...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "5906ac", "surface": "POST /api/admin/notifications/send — input validation", "risk_area": "validation bypass / injection", "outcome": "no_issue_found", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "Missing or empty title/content -> 400 {\"message\":\"Title and content are required\"} (checked before dispatch, so {} never delivers). Non-string title/content (number/object) are accepted (201) but no impact was demonstrable and the recipient...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "69fa9d", "surface": "Notification title/content rendered in player client", "risk_area": "stored content injection into player-facing push payload", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "Notification title/content are fully caller-controlled and stored/forwarded verbatim (no sanitization observed server-side; the admin UI renders nothing server-returned via an HTML sink). Whether the player-facing mobile/webview client rend...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "13cbeb", "surface": "Notification recipient-safety gates (pushable&gt;0, selected-requires-filter)", "risk_area": "client-side-only enforcement (CWE-602)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "The UI enforces recipient-safety gates (cannot send when matched-audience pushable===0; 'selected' requires a filter), but the API accepted a send request the UI would block, returning 201 {\"success\":true,\"count\":0}. Impact is unproven beca...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "2dc782", "surface": "POST /api/admin/notifications/send — request frequency", "risk_area": "abuse controls / rate limiting", "outcome": "reported", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "25 consecutive POSTs in 5.6s all returned 201; no 429, no Retry-After, no rate-limit headers. Filed as vuln-0021. Tests were pinned to a proven zero-recipient filter so no notification was delivered.", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "ba974f", "surface": "affiliates/promos.dynobet.com and affiliates/promos.tangobet.co.uk (AWS Elastic Beanstalk, nginx)", "risk_area": "RCE via application origin (Spring/Actuator/app RCE)", "outcome": "ruled_out", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "nginx returns 403 only for `/` (and equivalent /%2f, //, /%2e/) and 404 for every other path (/index.html, /health, /actuator/env, /api, /.env, /..;/). No application content is served at all, so there is no reachable app surface; edge-bypa...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "1e0765", "surface": "uat.uk-bingo.net / uat.pandabingo.com — /api/cms/[...path] Strapi proxy", "risk_area": "SQL injection / DB access / RCE via CMS proxy", "outcome": "ruled_out", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "Proxy is GET/HEAD/OPTIONS only (OPTIONS -> `allow: GET, HEAD, OPTIONS`; POST/JSON + X-HTTP-Method-Override + ?_method=POST all -> 405). Strapi content-API filters are parameterized: `filters[username][$eq]=x'` and `$startsWith`/`$ne` return...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "8a46e7", "surface": "All 47 in-scope apex hosts — exposed RCE-capable tooling sweep (actuator, jenkins, solr, h2-console, .git/.env, trace.axd, swagger, graphql, docker, k8s, etc.)", "risk_area": "Exposed debug/admin RCE panels and config files", "outcome": "no_issue_found", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "Bounded sweep of ~37 high-risk paths x 46 hosts. All 200 responses were catch-all SPA fallbacks (betmorph.com returned the identical 5616-byte Hercules index for every path; slotlux.com returned its 56884-byte Nuxt index for every path), i....", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "f71c90", "surface": "affiliates/promos.tangobet.co.uk (AWS Elastic Beanstalk)", "risk_area": "exposed backend / DB / endpoints", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "nginx front returns 403 for / and 404 for every probed path (/api, /api/v1, /api/login, /login, /register, /admin, /health, /status, /robots.txt, /.env, /actuator/env, /assets/, /portal). Only TCP 80/443 open on the ELB IPs (35.176.252.169,...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "aa576f", "surface": "tangobet.co.uk subdomain enumeration (db/mail/ops)", "risk_area": "exposed DB/mail subdomain", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "subfinder (-all) + crt.sh returned 38 names. Resolving: appmanager + deletemyaccount (Railway), affiliates/promos (AWS Elastic Beanstalk), app (AppsFlyer), www (Imperva). db/database/mysql/postgres/pg/mongo/redis/adminer/phpmyadmin/sql/mail...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "2825bc", "surface": "appmanager.tangobet.co.uk config/secret disclosure", "risk_area": "exposed config/secrets (.env, .git, source maps, backups)", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "Every non-asset path returns the 451-byte SPA index (Express catch-all); only /assets/index-BuNztArT.js, /assets/index-CSAF6Qde.css and /favicon.svg are genuinely served. No .env/.git/config/.map/backup file exists; traversal variants and V...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "f01230", "surface": "deletemyaccount.tangobet.co.uk (Railway)", "risk_area": "hidden API / email-sending primitive", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "Serves a static account-closure page (2664 bytes + styles.css + assets/logo.png) via nginx/1.27.5; POST to any path returns 405 and GET returns the static page; no API, no form, and the only contact is a mailto: link to a third-party suppor...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "c89fbb", "surface": "appmanager.tangobet.co.uk database reachability", "risk_area": "exposed database service / DB credential disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "nmap shows every DB port filtered on the app host (3306/5432/27017/6379/1433/1521/9042/5984/9200/11211/5672/2375/9229); only TCP 80/443 are open (Railway edge 'railway-hikari'). The Postgres addon sits on Railway's private network with no p...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "214d27", "surface": "appmanager.tangobet.co.uk JSON body handling", "risk_area": "prototype pollution (Node) pivot", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "Sent __proto__ / constructor.prototype objects in the JSON body of /api/admin/players/search and nested inside advancedFilter: all returned normal 201 responses with unchanged data, no server error, and no observable side effect on a subseq...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "3ed848", "surface": "tangobet.co.uk DNS email-auth records (SPF/DKIM/DMARC)", "risk_area": "email spoofing / sender authenticity (missing DMARC)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "dig shows SPF 'v=spf1 include:mailgun.org ~all' (softfail) and NO DMARC record (_dmarc.tangobet.co.uk is empty); DKIM exists only for selector s1 (Mailgun RSA key). With no published DMARC policy, receivers get no reject/quarantine instruct...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "7a81b8", "surface": "tangobet.co.uk email infrastructure (SMTP/IMAP/Mailgun)", "risk_area": "email service reach / transactional-email credential exposure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "No self-hosted mail service exists: MX = mxa/mxb.eu.mailgun.org (Mailgun SaaS). No genuine SMTP/IMAP/POP service on any in-scope host — the 'open' 143/993 seen on the Imperva apex IPs are edge artifacts (arbitrary ports 1234/12345 also 'acc...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "8a28c8", "surface": "appmanager.tangobet.co.uk API error surfaces", "risk_area": "error-based DB/ORM information disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "Type-confusion/malformed inputs to /api/admin/players/search (page as object, page/limit as strings, operator/value as objects, invalid/absent field names) all return normal data or a generic {\"statusCode\":500,\"message\":\"Internal server err...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "d15dbb", "surface": "45.132.74.81 (origin IP of *.potsofluck.com) — ports 22/80/443/4000 (NoMachine NX 10.0.59)", "risk_area": "Host-level RCE via exposed remote-desktop/SSH service", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:39:38 UTC", "evidence": "nmap -sV: 45.132.74.81 (origin of dev/qa/lp/promo/promotions/games.potsofluck.com) exposes 22/tcp OpenSSH 9.6p1 Ubuntu, 80/443 nginx 1.24.0, and 4000/tcp NoMachine NX Server 10.0.59. CVE-2026-18264 (NoMachine command injection in the port-4...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "518e02", "surface": "In-scope reachable hosts — DB admin consoles (phpMyAdmin/Adminer/etc.)", "risk_area": "Exposed database management interface", "outcome": "no_issue_found", "created_at": "2026-09-27 17:41:42 UTC", "evidence": "Probed 25 DB-admin paths (phpmyadmin, phpMyAdmin, pma, adminer.php, sqladmin, dbadmin, mysqladmin, _phpmyadmin, phpMyAdmin-4.9.7, dbmanager...) across 20 reachable hosts (betmaze, betsuna, jeffbet, mogobet, playuk, theonlinecasino, appmanag...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "fcabc7", "surface": "betmaze.co.uk (/betmaze-portal/) & betsuna.com (/wp-login.php) — login forms", "risk_area": "Username enumeration via authentication error messages", "outcome": "reported", "created_at": "2026-09-27 17:43:45 UTC", "evidence": "Login-form error messages distinguish a valid account (\"password incorrect\") from an unknown one (\"unknown username\") without cookies or a nonce. This second oracle reveals account `admin` on betsuna.com, which the REST users collection doe...", "agent_name": "WP Takeover Chain Validator"}, {"entry_id": "28cc97", "surface": "betmaze.co.uk & betsuna.com — enumerated admin accounts (betmaze_login, betsunaadmin, admin)", "risk_area": "Account takeover via credential brute-force / password guessing (validation of the username-enumeration + missing-throttle chain)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:43:45 UTC", "evidence": "Chain capability validated end-to-end: identifiers are valid logins (confirmed via login error differential), the XML-RPC endpoint evaluates credentials genuinely (demo.sayHello succeeds in the same multicall), a single request carries 500...", "agent_name": "WP Takeover Chain Validator"}, {"entry_id": "a888c0", "surface": "appmanager.tangobet.co.uk — admin API features taking URLs/hosts (notifications, players, users, mobile-app)", "risk_area": "SSRF into internal services (Railway internal / cloud metadata / localhost)", "outcome": "not_applicable", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Enumerated the complete API surface from the SPA bundle and by fuzzing ~70 route names under /api/admin/* — no import/webhook/export/feed/url/host-consuming feature exists. `POST /api/admin/notifications/send` dispatches push notifications...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "3bab3a", "surface": "appmanager.tangobet.co.uk — /api/admin/players/search advancedFilter + sortField + search (JSON body, qs query, form-urlencoded)", "risk_area": "Prototype pollution (server-side, Node/Express) → RCE gadget", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Sent `{\"__proto__\":{...}}`, `{\"constructor\":{\"prototype\":{...}}}`, nested `advancedFilter.__proto__`, condition `field:\"__proto__\"`, plus qs forms `?__proto__[x]=`, `?constructor[prototype][x]=` and form-urlencoded equivalents (11 JSON + 5...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "26affb", "surface": "appmanager.tangobet.co.uk — host root and /api/* hidden routes (exec/import/upload/settings/config/export)", "risk_area": "Hidden dangerous functionality (file write / command exec / deserialization)", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "GET sweep of ~65 candidate admin route names (exec/run/upload/import/export/backup/db/query/sql/files/...) all return NestJS 404. Root and all non-API paths return the SPA index (451-byte index.html); /.env, /.git/config, /package.json, /pr...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "c6fc95", "surface": "appmanager.tangobet.co.uk — players search/filter/sort/pagination values (search, sortField, operator, field)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Time-based and boolean probes on `search` (`' OR SLEEP(5)-- -`, `1;SELECT pg_sleep(5)--`, UNION, quote breakers) all returned in ~0.18-0.20s with `total:0` — no delay, no error. NoSQL operator injection in `advancedFilter.operator` (`$ne/$g...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "56f3d4", "surface": "www.neonrush.com — ABP application services (/api/services/app/*) enumeration for RCE-capable operations", "risk_area": "Unauthenticated file upload / import / template / command execution", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Enumerated all 191 ABP application-service actions from the unauthenticated `/AbpServiceProxies/GetAll` map and probed each (declared method, empty body). All file/import/export/exec/template-capable services (`documentuser/create`, `accoun...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "68d5bf", "surface": "www.neonrush.com — /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "Missing authentication for critical function — SSO token minting", "outcome": "reported", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "`POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=` returns a signed RS256 token with attacker-controlled sub/email/email_verified/balance claims, unauthenticated. Filed as vuln-0022 (medium)...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "72e9c8", "surface": "www.neonrush.com — authenticated document/KYC upload + pushCashPayment.authorizePayment(tenantBaseSiteUrl)", "risk_area": "File upload path traversal → arbitrary file write; SSRF via tenantBaseSiteUrl", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Resolved by the Neonrush Auth RCE Hunter with a live authenticated tenant-1 session. Document/KYC upload (`/api/accountverification/proof-documents`) requires a server-only `X-Server-Authorization` key (401 without it; no client copy of the...", "agent_name": "Neonrush Auth RCE Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "fc04bc", "surface": "api-uat.playuk.com &amp; api-qa.playuk.com — Markor revolve API (/revolve/api/*) for file/document upload", "risk_area": "File upload / path traversal / filename injection → code execution", "outcome": "not_applicable", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Extracted the full 76-route `/revolve/api/*` inventory from the `uat.playuk.com` bundle: KYC is delegated to SumSub (`getSumSubAccessToken`, disabled on this tenant, code 213) and `kycDocumentUploaded` is a status flag only; there is no mul...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "8745c6", "surface": "play.neonrush.com — /api/record/saveLastAction (key echo)", "risk_area": "Prototype pollution → RCE gadget", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "All `__proto__`/`constructor`/`prototype` token variants (plain, unicode-escaped `\\u005f`, `\\u0074o`, mixed case, nested, array form, 4 content-types) are blocked by the Incapsula/Imperva WAF with a 403 `_Incapsula_Resource` page; the only...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "cb1678", "surface": "UAT Next.js route handlers — /api/cms/[...path], /api/env/vars", "risk_area": "Write / deserialization → code execution via the in-scope Next.js API routes", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "POST and PUT to `/api/cms/users` and `/api/env/vars` return HTTP 405; the catch-all proxy forwards only GET/HEAD/OPTIONS (prior agent confirmed POST→405 for the whole route). /api/env/vars only returns NEXT_PUBLIC_* vars. No write, upload o...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "dfb79d", "surface": "In-scope Next.js hosts (47 apexes + uat.* / neonrush / appmanager subdomains)", "risk_area": "React Server Components deserialization RCE (CVE-2025-55182) — fleet sweep", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "Swept the verified CVE-2025-55182 template across all 47 apex hosts plus uat.* and neonrush/appmanager subdomains (51 targets). No match anywhere. Reachable Next.js hosts (uat.*, play.neonrush.com, acedbet.com) are confirmed not vulnerable;...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "031690", "surface": "uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com (Next.js App Router UAT)", "risk_area": "React Server Components deserialization RCE (CVE-2025-55182)", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "Ran the official verified nuclei template for CVE-2025-55182 (React Server Components unsafe deserialization → unauth RCE, React 19.0.0-19.2.0) and a manual multipart/Next-Action payload with three `child_process` accessor variants against...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "9ff418", "surface": "Nuxt 3 marketing fleet (wombatbingo/pandabingo/queensbingo/uk-bingo.net/jazzyspins/vampirebingo/betarno/chitchatbingo/slotlux) — /__nuxt_island/", "risk_area": "Nuxt island template injection → Nitro RCE (CVE-2026-71318 / CVE-2026-71320)", "outcome": "ruled_out", "created_at": "2026-09-27 17:47:30 UTC", "evidence": "CVE-2026-71318/71320 require the Nuxt island endpoint (/__nuxt_island/<Name>.json) with componentIslands enabled. On all 9 Nuxt marketing hosts the endpoint is absent: jazzyspins returns the Nuxt 404 error page (text/html, no JSON) and the...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "5f32cb", "surface": "uat.uk-bingo.net / uat.pandabingo.com — /api/cms/<collection> Strapi proxy (where[] oracle)", "risk_area": "Strapi unauth query-sanitizer bypass → admin secret exfiltration/account takeover (CVE-2026-27886)", "outcome": "ruled_out", "created_at": "2026-09-27 17:47:30 UTC", "evidence": "CVE-2026-27886 technique: compare meta.pagination.total for baseline vs `?where[id][$lt]=-1` (cannot match a row, so a vulnerable DB-layer WHERE collapses the count to 0). Tested via the unauth /api/cms proxy on uat.uk-bingo.net and uat.pan...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "b0f377", "surface": "www.neonrush.com /api/services/app/playeraccount/register + /login (Turnstile)", "risk_area": "anti-automation control bypass (captcha) via client-controlled tenant header", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Abp.TenantId:1 skips Turnstile on playeraccount/register and playeraccount/login (200 successful:true); without the header the same calls are rejected with 'You must prove that you are not a robot.' Filed vuln-0025.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "75b3cf", "surface": "www.neonrush.com /api/authentication/login", "risk_area": "auth bypass on server-to-server login (apiKey)", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "POST api/authentication/login returns 401 {errorcode:'InvalidAPIKey'} for arbitrary X-Server-Authorization values; the apiKey is genuinely validated (an empty header produces a model-validation 'apiKey required' error).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "c18355", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser|byusername", "risk_area": "IDOR on profile pictures (PII)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "profile/getprofilepicturebyuser and byusername are reachable by a low-priv session but returned empty for all probed ids; updateprofilepicture returned HTTP 500 for several body shapes, so a picture could not be set and cross-user read of a...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "abe254", "surface": "www.neonrush.com /api/services/app/documentuser/getall + referafrienduser/getall", "risk_area": "IDOR via client-supplied userId", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Both endpoints returned only the caller's (empty) data and ignored a supplied ?userId= for a different user id — object scoping holds (contrast with the login-attempts IDOR).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5caf28", "surface": "www.neonrush.com /api/services/app/userlogin/getuserloginattempts + getuserloginattemptcount", "risk_area": "IDOR / broken object-level authorization (arbitrary userId)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Confirmed IDOR: session A (user 1853801) read user 1853802's login records incl. clientIpAddress 1.2.3.4 (A's own was 9.9.9.9); getUserLoginAttemptCount returns count for arbitrary userIds. Filed vuln-0023.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "e00cbc", "surface": "www.neonrush.com /api/services/app/turnstilepolicy/getvalidationpolicy", "risk_area": "sensitive information / credential disclosure (server-side secret)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Unauthenticated GET /api/services/app/turnstilepolicy/getvalidationpolicy?turnstileFlow=PlayerLogin&tenantId=17 returns the server-side Cloudflare Turnstile secretKey (0x4AAAAAAChdt6yjJop7KSPCX6pJnYqk6I0). Filed vuln-0024.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5c0687", "surface": "www.neonrush.com /api/services/app/* (pushcashpayment, kyc, trackingevent, stickeralbum, freeentrycode, sportsbook)", "risk_area": "BFLA on privileged ABP application services", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "With a valid low-priv tenant-1 session, every listed service returned 401 'Current user did not login' (permission-gated); a few returned 500 only on missing DTO. No unauth or low-priv access to these privileged services.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "319855", "surface": "www.neonrush.com /api/services/app/playeraccountuser/selfexclude + suspend", "risk_area": "IDOR / DoS via account self-exclude or suspend", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "playerAccountUser.selfExclude/suspend returned 200 on one session and 401 'Current user did not login' on another; it could not be determined whether a target userId/account can be supplied (self vs other). No confirmed impact.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "1f4b0f", "surface": "appmanager.tangobet.co.uk POST /api/auth/login (HS256 JWT)", "risk_area": "JWT HS256 signing-secret recovery / token forgery", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:49:37 UTC", "evidence": "Captured a valid HS256 token via the default credential and attempted an offline brute-force: the prior reviewer had already exhausted rockyou (14.34M) + a 10k list; this pass added ~200,500 mutated/targeted candidates (betty/tangobet/railw...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "2da235", "surface": "playuk.com (4 hosts) — leftover backup directories /wp-content/updraft and /wp-content/ai1wm-backups", "risk_area": "Downloadable backup archive -> DB/wp-config -> RCE", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:03 UTC", "evidence": "Directory listing disabled (index files only: UpdraftPlus placeholder HTML, AIO 'Kangaroos cannot jump here'). The backup plugins are NOT installed (main plugin file all-in-one-wp-migration.php and updraftplus.php -> 404), so no export/down...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "23ec98", "surface": "playuk.com — PHP runtime command-execution capability", "risk_area": "OS command execution if any code-execution foothold is obtained", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:03 UTC", "evidence": "phpinfo (vuln-0026) shows disable_functions includes exec, shell_exec, system, passthru, popen, pclose, proc_open, proc_close, pcntl_exec, dl, symlink -> no OS command execution primitive available to PHP even with a webshell. open_basedir...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "d507b0", "surface": "mogobet.com, jeffbet.net — Redirection 5.9.0 REST API", "risk_area": "Capability-check bypass fixed in 5.10.0", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "All redirection/v1 routes (redirect, plugin, setting) return 401 rest_forbidden unauthenticated on mogobet (404 where the plugin is not installed). The 5.10.0 fix is an authorization hardening for authenticated users and only enables redire...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "f57f0e", "surface": "all WP hosts — unauthenticated REST surface (wp-abilities, batch, yoast, block-editor, redirection, wp/v2/users)", "risk_area": "Broken function-level authorization / unauth code execution via REST", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "wp-abilities/v1/abilities and /abilities/{name}/run -> 401; yoast/v1/file_size -> 401; wp-block-editor/v1/url-details -> 401 for external URLs and 400 for internal ones (no SSRF); wp/v2/users POST -> 401 rest_cannot_create_user; redirection...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "f50fdd", "surface": "betsuna.com — LiteSpeed Cache plugin", "risk_area": "CVE-2024-28000 / CVE-2024-50550 (LSCWP unauth privilege escalation)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "readme.txt Stable tag = 7.8.1; both CVEs affect versions < 6.5.1 (CVE-2024-28000 < 6.4, CVE-2024-50550 < 6.5.1). Patched. litespeed/v1 REST endpoints return 404 (features off). Plugin absent on theonlinecasino/mogobet.", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "ae2f6e", "surface": "playuk.com — /info.php", "risk_area": "Information disclosure (debug script exposed)", "outcome": "reported", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Unauthenticated GET /info.php returns full phpinfo() (120KB): PHP 7.4.33.15 (EOL), DOCUMENT_ROOT /nas/content/live/playuk, USER fpm200035, full disable_functions, loaded modules, env. Filed as vuln-0026.", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "6913d3", "surface": "theonlinecasino.co.uk, mogobet.com, betmaze.co.uk, betsuna.com, jeffbet.net, playuk.com — WordPress admin-credential path to theme-editor RCE", "risk_area": "RCE via admin credential compromise -> theme/plugin editor", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "No unauthenticated file-write/upload primitive and registration is disabled, so RCE requires valid admin credentials. xmlrpc.php system.multicall + wp-login.php have no rate limiting/lockout (vuln-0014), making credential brute force the re...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "6aef6a", "surface": "theonlinecasino.co.uk — WordPress custom theme (Theonlinecasino)", "risk_area": "RCE via theme PHP (file write / LFI / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Theme exposes only static JSON proxies (fetch-games/sports/promotions/sports-promotions.php) plus style.css/sports-cache.json. fetch-sports.php params are inert; POST returns identical body. No upload/backup PHP files (404). No user input r...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "d6b10b", "surface": "betmaze.co.uk / betsuna.com — WordPress custom child theme (twentytwentyfive-child)", "risk_area": "RCE via theme PHP (file write / LFI / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Theme ships only read-only JSON proxies (fetch-games/sports/promotions/sports-promotions.php). Every tested parameter (file,url,path,include,template,view,page,gameType,category,src,type,lang,cache,debug) and POST bodies return byte-identic...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "a62488", "surface": "mogobet.com, jeffbet.net, theonlinecasino.co.uk, playuk.com, betmaze.co.uk — Advanced Custom Fields 6.8.8", "risk_area": "ACF file upload / frontend-form validation bypass / REST reference exposure -> RCE", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Source-diffed 6.8.8 vs 6.8.10: fixes are PDF-upload prefilter, REST reference read-permission enforcement, _acf_form token TTL/render binding, frontend field validation, and user-field nonce check — information-disclosure/validation, not co...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "22adc5", "surface": "FTP (tcp/21) on 35.214.94.72, 35.214.89.161, 77.68.12.66 (Pure-FTPd / ProFTPD)", "risk_area": "Anonymous FTP / file disclosure yielding DB credentials", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Re-tested ProFTPD on 77.68.12.66: anonymous login rejected (530 Login incorrect); `SITE CPFR`/`SITE CPTO` both rejected (500 \"'SITE CPFR' not understood\" / 503 Bad sequence), i.e. mod_copy CVE-2015-3306 is NOT loaded; banner is version-mask...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["ruled_out"]}, {"entry_id": "aff7a9", "surface": "35.214.94.72 (headless.mrslot/mrmobi/mrsuperplay, staging3.mrjackvegas) — MySQL 3306 / PostgreSQL 5432", "risk_area": "Exposed database service / default-credential DB access", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "MySQL/PG listen on the public IP but access is blocked by two named server-side controls: MySQL returns ERROR 1130 \"Host '64.111.92.186' is not allowed to connect to this MySQL server\" (host-based ACL) for every user; PostgreSQL returns FAT...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "30cbc7", "surface": "In-scope apexes + ~200 subdomains — full TCP DB/exposure port sweep (128 IPs)", "risk_area": "Exposed database services across the fleet", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "naabu + nmap -sV over 128 resolved IPs for 3306/5432/1433/1521/27017/6379/9200/11211/5984/7474/7687/9042/8086/2181/5672/2375/2379/5985/5986/21/22/25. Only real DB services are the MySQL/PG on the two GCP origins and MariaDB on 77.68.12.66 (...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "af41fd", "surface": "35.214.94.72 / 35.214.89.161 — direct origin access to headless/staging WordPress (SiteGround challenge bypass)", "risk_area": "Edge bypass to reach origin files (wp-config/DB creds)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Requesting the origin IP directly with Host: headless.mrslot.com / headless.jazzyspins.com still returns HTTP 202 with an sgcaptcha JS/meta-refresh challenge for every path (.env, wp-config.php.bak, .git, etc.). No path reached application...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "e398d4", "surface": "In-scope fleet — config/backup artifact sweep (.env, wp-config.php.*, .git, .svn, *.sql, backups, actuator)", "risk_area": "Leaked configuration / DB credentials via exposed files", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "6061 path probes over 209 resolving in-scope hosts (https). Every 200 was an SPA catch-all fallback (identical body size for all paths); genuine hits were only the already-known mogobet.com debug.log and an Apple .DS_Store on affiliates.dyn...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "6e15f5", "surface": "77.68.12.66 (promotions.pandabingo.com) — MariaDB 10.5.29 on tcp/3306", "risk_area": "Internet-exposed database service / weak-credential DB access", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Additional targeted testing by this agent: 1,254 more attempts (usernames root/admin/psa/mysql/promotions/pandabingo/panda/bingo/promo/web/www/db/database/user/test/wordpress/wp/plesk/backup/sql/debian-sys-maint x brand-/server-/Plesk-deriv...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "8434c8", "surface": "77.68.12.66:8443 — Plesk panel + default vhost (promotions.pandabingo.com)", "risk_area": "Exposed hosting control panel / DB credential disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Traversal gap CLOSED by this agent on Plesk Obsidian 18.0.80. Tested the sw-cp-server static-file/path-traversal class exhaustively via raw HTTPS (no proxy normalization) plus curl --path-as-is: every payload containing `../` — plain, singl...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["no_issue_found", "needs_follow_up"]}, {"entry_id": "2253f5", "surface": "35.214.89.161 (headless.jazzyspins, ftp.jazzyspins) — MySQL 3306 / PostgreSQL 5432", "risk_area": "Exposed database service / default-credential DB access", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Same controls as the sibling GCP origin: MySQL ERROR 1130 host-not-allowed; PostgreSQL FATAL no pg_hba.conf entry for 64.111.92.186. Both reject before any credential check.", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "32962c", "surface": "mogobet.com /wp-content/debug.log — DB credential/query content", "risk_area": "DB credentials or queries leaked in debug log", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Full 2660-byte log retrieved: contains only four PHP Fatal \"array_filter(): Argument #1 must be of type array, null given\" TypeErrors in the twentytwentyfour theme; no DB connection strings, credentials, queries or table names. (Info-disclo...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "55b0c9", "surface": "In-scope fleet — client JS bundles scanned for DB connection strings/credentials", "risk_area": "Embedded DB credentials in client-side code", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Downloaded ~50 JS bundles from 15 reachable hosts (Cogni ABP, PlayUK/Betty, WordPress, Nuxt, ProgressPlay) and ran gitleaks + regex for mysql/postgres/mssql/mongodb/redis URIs, DATABASE_URL, connectionString, DB_PASSWORD. Only findings are...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "4d948e", "surface": "www.jackpot.com Content Admin Area authentication (POST /%2fadmin via ALB %2f bypass)", "risk_area": "Authentication bypass / privilege escalation to admin", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:04 UTC", "evidence": "Reached the \"Login to the Content Admin Area\" form via /%2fadmin (non-browser UA). Controls confirmed on the attacker path: (1) MVC [Authorize] — all admin controllers (User, Promotion, Tickets, Config, Pages, News, Dashboard, Widget, Conte...", "agent_name": "Jackpot Admin Access Hunter"}, {"entry_id": "0cc87f", "surface": "www.jackpot.com admin login credentials (default/weak set)", "risk_area": "Weak / default credentials", "outcome": "no_issue_found", "created_at": "2026-09-27 17:54:04 UTC", "evidence": "Bounded set of 18 default/weak pairs (admin:admin, admin:admin123, admin:password, administrator:admin, test:test, admin:Admin@123, admin:letmein, admin:P@ssw0rd, admin:Password1, admin:123456, admin:jackpot, admin:jackpot123, jackpot:jackp...", "agent_name": "Jackpot Admin Access Hunter"}, {"entry_id": "0bec0f", "surface": "api-uat/api-qa.playuk.com /revolve/api/* authenticated routes (account/payments/loyalty/limits)", "risk_area": "SQL / NoSQL injection (post-auth)", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Closed by PlayUK Authenticated Injection Hunter. Obtained an authenticated QA session (register/lite) and tested the authenticated /revolve/api/* routes for SQL/NoSQL injection (error/boolean/time-based incl. SLEEP(3), and type-juggling). N...", "agent_name": "PlayUK Authenticated Injection Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "e9e7cf", "surface": "playuk.com /info.php (phpinfo environment)", "risk_area": "DB credentials disclosure via phpinfo environment", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "phpinfo() is live (200, 120KB) but the Environment/$_SERVER/$_ENV sections contain only USER=fpm200035 and WPENGINE_* flags (WPENGINE_ACCOUNT=playuk, PHPSESSIONS on, DB_SESSIONS off) - no DB_NAME/DB_USER/DB_PASSWORD/MYSQL_*/DATABASE_URL. WP...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "7d92d3", "surface": "mogobet.com /wp-content/debug.log content", "risk_area": "DB credentials / SQL queries disclosed in debug log", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Fetched in full (2660B): contains only 4 PHP `array_filter(): Argument #1 must be of type array, null given` TypeErrors from the child theme (index.php:173/232) with stack traces. No SQL statements, no wpdb/SQL errors, no DB credentials or...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "d271cb", "surface": "jackpot.com string-parameter widget endpoints (UsWebIdentity/CheckUser, UsaServices/ComplianceCheck, UsWebIdentity/Error?id=, Menu/Timezones|Results, Promotion/Tac, UsGames/*)", "risk_area": "SQL injection via application parameters", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Extended testing: /%2ftrace.axd reaches the ASP.NET Trace handler but returns a 3425B \"Trace Error\" page (remote tracing disabled, localOnly); /elmah.axd + /%2felmah.axd -> 404 (not deployed). /shoppingcart?promoCode|search|sort|orderby ->...", "agent_name": "App-Layer SQLi Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "3861ef", "surface": "www.neonrush.com ABP /api/services/app/* parameters (isusernameavailable, getprofilepicturebyuser/byusername, isgeoblocked...)", "risk_area": "SQL injection (EF Core / ABP)", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Control: ABP + EF Core parameterization on every reachable app-service. isusernameavailable?input= returns {\"result\":true} for quote/OR payloads (literal, no error); getprofilepicturebyuser?userId=1' returns ABP model-validation 400 (type-b...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "285576", "surface": "www.neonrush.com /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "unauthenticated identity forgery / SSO token minting (missing authentication + claim injection)", "outcome": "reported", "created_at": "2026-09-27 17:57:14 UTC", "evidence": "Independently reproduced the unauthenticated SSO token minting (POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=) and added cryptographic proof: the RS256 signature on the minted token verif...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "e38d11", "surface": "games.betsuna.com/Media.aspx POST handling", "risk_area": "File upload to webshell", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: page ignores POST body. Multipart uploads with field names file/upload/media/image/FileUpload1/fu/attachment/document and form-encoded action=upload/cmd=save all return the identical 200/590B page; nothing stored.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "286b43", "surface": "games.betsuna.com URL handling", "risk_area": "Path traversal / LFI to code exec", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: IIS requestFiltering. .%2e/%2e%2e/…, \\..\\..\\…, %2e%2e//google.com all => 403.3 'Forbidden URL'. web.config 404; trace.axd 403 localOnly.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "6ae0b1", "surface": "games.betsuna.com/Media.aspx (__VIEWSTATE)", "risk_area": "ViewState deserialization RCE", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: .NET machineKey MAC validation. Page emits __VIEWSTATE (80B, randomised/encrypted) + __VIEWSTATEGENERATOR=F93C166E, no __EVENTVALIDATION. POST with original VS=200; flipped byte / minimal ff0100 / 'AAAA' => HTTP 500 'Validation of...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "f85758", "surface": "www.jackpot.com file-serving routes (/themes, /Media, /Content)", "risk_area": "Path traversal / LFI to code exec", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: IIS URL normalization + static handler. ../../web.config, %2e%2e%2f, ..%5c.., %2e%2e%2f in path => 404 or 400 Bad Request. Encoded traversal is rejected before any file open.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "3e31dd", "surface": "www.jackpot.com application pages (ViewState)", "risk_area": "ViewState deserialization RCE", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: framework choice. jackpot.com is ASP.NET MVC 5.2 (Razor) pages served without WebForms ViewState; admin login form uses __RequestVerificationToken anti-forgery and no __VIEWSTATE. No ViewState exists to attack on this host.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "d99daf", "surface": "www.jackpot.com admin upload/import endpoints", "risk_area": "Unauthenticated file upload to webshell", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: MVC [Authorize] + no public upload feature. Content/Upload,UploadImage,UploadFile,FileManager,Media,EditorUpload,Home/Upload,User/UploadAvatar,UserPhoto,Themes/Templates => MVC 404 or 302->/Admin?ReturnUrl (login). /Admin/User/MyPr...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "a674d0", "surface": "www.jackpot.com + games.betsuna.com client components", "risk_area": "Known-CVE RCE in vendor UI components", "outcome": "not_applicable", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: no vulnerable third-party component is present. Full HTML/JS review across jackpot.com and games.betsuna.com found no Telerik/Kendo/DevExpress/Syncfusion/Infragistics/CKFinder/CKEditor/Uploadify/elFinder and no WebResource.axd/Scri...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "b4c75a", "surface": "www.jackpot.com Areas/Widgets API endpoints", "risk_area": "XXE / deserialization / SSRF on widget APIs", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: endpoints ignore attacker input. XXE (SYSTEM file:///C:/Windows/win.ini DTD, application/xml) and JSON __type ObjectDataProvider POSTs to /Widgets/Menu/LocState,/UsaServices/ComplianceCheck,/Widget/Phrases => 200 empty, no resoluti...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "b55803", "surface": "*.hotwinscasino.com Microsoft-HTTPAPI hosts", "risk_area": "RCE surface (HTTP.sys listeners)", "outcome": "no_issue_found", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "admin/m/brand/partners.hotwinscasino.com are Microsoft-HTTPAPI/2.0 listeners returning a stock 404 (315B) for every path probed (/, /api, /api/health, /swagger, /health, /stats) — no application content or handler is served. No code path re...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "7f13db", "surface": "games.playuk.com", "risk_area": "RCE surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "games.playuk.com returns a blanket 403 awselb/2.0 for every path, User-Agent, method and normalization variant (incl. /%2f) — the ALB exposes no content and no origin hostname, so no code path is reachable to assess. Access-limited, not cle...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "8a9a18", "surface": "Fleet games./media./cms.* subdomain sweep", "risk_area": "Discovery of additional .NET hosts", "outcome": "no_issue_found", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Probed games./media./cms.<apex> for all 47 apexes. Only games.betsuna.com is a real .NET site; the rest are NXDOMAIN (Caido 502), Cloudflare, S3, nginx or AWS ALB 403. No additional in-scope IIS/ASP.NET origin found.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "92a848", "surface": "www.jackpot.com + games.betsuna.com diagnostics & config files", "risk_area": "Diagnostics / config / machineKey exposure", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: ASP.NET trace localOnly + IIS requestFiltering. /trace.axd => 403 'current trace settings prevent trace.axd from being viewed remotely'. /elmah.axd,/glimpse.axd,/appsettings.json,/web.config(.bak/.old/.txt),/bin/,/App_Data/,/packag...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "f7df5f", "surface": "www.jeffbet.net — custom twentytwentyfive theme admin-ajax actions (search_games, search_games_by_category, load_default_games, load_more_games)", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "Unauthenticated admin-ajax actions query a 'game' CPT. Manual tests: ' AND 1=1-- - == ' AND 1=2-- - (identical length), no SLEEP(5) delay, no SQL error; quote stripped. sqlmap (BEUT L2-3 R1-2, space2comment) on search/category/tax/term/page...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "7a8e37", "surface": "www.betmaze.co.uk — WordPress 7.1.2 core search/REST + twentytwentyfive-child theme PHP", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/{posts,users,pages,search}?search|author|orderby|cat|p|page_id plus child-theme fetch-*.php: no SQL error, no boolean differential (true==false length), no SLEEP delay, no 500; sqlmap on ?s= 'not injectable'. fetch-*...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "dcedc5", "surface": "www.jeffbet.net — WordPress core search/REST + unauthenticated game enumeration", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/*?search= show no boolean/timing/error differential; parameterized WP_Query. Game data returned by admin-ajax is intended-public catalogue content.", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "001a49", "surface": "www.mogobet.com — WordPress 7.1 core search/REST + twentytwentyfour theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/posts?search=: no boolean/timing differential, no SQL error, no 500 → WP_Query parameterization. Accordion FAQ 2.5.3 / Yoast 28.3 / Redirection 5.9.0 / ACF 6.8.8 all current (no applicable SQLi CVE).", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "683d94", "surface": "www.betsuna.com — WordPress 7.x core search/REST + game CPT + twentytwentyfive-child theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/wp-json/wp/v2/game?search= and /wp/v2/posts?search=: 'blackjack' and 'blackjack' return identical rows (quote stripped), sleep/boolean payloads return empty with no delay and no differential → parameterized (WP_Query). fetch-*.php params b...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "2a2cca", "surface": "www.mogobet.com — /wp-content/debug.log credential mining (vuln-0006)", "risk_area": "Leaked DB credentials / SQL error disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "Full 2660-byte log contains only 5 PHP Fatals (theme twentytwentyfour/index.php array_filter TypeError) + path /home/mogobet.com/public_html/. No SQL query, no SQL error, no table prefix, no DB host/user/password. No rotated copies exposed....", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "81fb0f", "surface": "www.theonlinecasino.co.uk — WordPress 7.1 core search/REST + Theonlinecasino theme fetch-*.php + sports-cache.json", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/posts?search=: no boolean/timing/error differential. fetch-sports/promotions/games.php + sports-cache.json return ProgressPlay catalogue data; all 10+ tested params (id/code/name/promotionId/wl/...) byte-identical →...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "b77c5a", "surface": "WordPress fleet (betmaze, betsuna, jeffbet, mogobet, playuk, theonlinecasino) — sensitive files / DB dumps / config backups", "risk_area": "Exposed DB credentials / database backups", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "~90-path sweep + ffuf: wp-config.* (.bak/.old/.save/.swp/.txt/.gz/.zip/~), .env*, *.sql/*.sql.gz dumps (root, uploads, ai1wm/updraft/backups), .git, adminer/phpMyAdmin, mu-plugins → no 200 with data. wp-config* blocked by a robust WAF rule...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "0ad1d0", "surface": "www.playuk.com — WordPress 7.x core search/REST + PlayUk theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/*?search= and fetch-*.php (theme PlayUk): no boolean/timing/error differential; fetch params byte-identical (ProgressPlay proxy). Yoast 28.3 / ACF 6.8.8 current. wp-login POST 400 at WPEngine edge (untestable from eg...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "f637f4", "surface": "www.betsuna.com — front-end /?s= search parameter", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Front-end requests to betsuna.com return 0-byte / connection-reset responses (InvalidChunkLength gzip errors; all payload variants time out at ~5.2s) so the theme-level search handler could not be differentially tested. The /wp-json/ REST s...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "8b549d", "surface": "promo.hotwinscasino.com — WordPress SQL injection surface", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Host live but its origin (openresty) returns 403 Forbidden for EVERY request incl. a real browser and the /?rest_route= bypass (wp/v2/users, redirection/v1, llar) — Cloudflare fronting + origin IP block. WordPress REST/plugin SQLi surface c...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "68c706", "surface": "api-uat.playuk.com /revolve/api/account/login (JSON login.principle param)", "risk_area": "SQL injection (sqlmap BEUT)", "outcome": "ruled_out", "created_at": "2026-09-27 18:10:02 UTC", "evidence": "sqlmap --technique=BEUT on POST /revolve/api/account/login (JSON login.principle, --ignore-code=401,400) reported \"all tested parameters do not appear to be injectable\" (327x 401, no boolean/time/error signal); manual quote/OR/SLEEP probes...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "d4e2cd", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser?userId", "risk_area": "SQL injection (sqlmap BEUT)", "outcome": "ruled_out", "created_at": "2026-09-27 18:10:02 UTC", "evidence": "sqlmap --technique=BEUT on GET /api/services/app/profile/getprofilepicturebyuser?userId=1 (XFF 8.8.8.8, --ignore-code=400,401) reported \"all tested parameters do not appear to be injectable\" (384x 400 = ABP model-validation on non-int userI...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "9493f0", "surface": "www.jackpot.com (IIS10/ASP.NET MVC5.2) + games.betsuna.com (IIS10/ASP.NET WebForms) + games.playuk.com", "risk_area": "RCE on IIS/.NET hosts (ViewState deserialization, file upload, path traversal, vendor-component CVEs, XXE/SSRF)", "outcome": "ruled_out", "created_at": "2026-09-27 18:12:12 UTC", "evidence": "Full vector sweep with named controls: games.betsuna.com Media.aspx __VIEWSTATE is encrypted and MAC-validated (tamper → 500 \"Validation of viewstate MAC failed\") and no machineKey/web.config is exposed → ViewState ObjectStateFormatter RCE...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "d53824", "surface": "GET /api/services/app/userlogin/getuserloginattempts (sorting parameter) — www.neonrush.com", "risk_area": "SQL injection / EF Core Dynamic LINQ expression injection", "outcome": "reported", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Client-supplied `sorting` is passed to System.Linq.Dynamic.Core and translated by EF Core to SQL. Data-dependent SQL boolean oracle: `sorting=IIF(it.ClientIpAddress==\"8.8.8.8\", it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 (true) vs the same with...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "863359", "surface": "ABP dynamic-API params on www.neonrush.com (filter, userId, OData $filter/$orderby)", "risk_area": "SQL injection (classic value-parameter injection)", "outcome": "ruled_out", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "`userId` is bound as an integer — non-numeric input (`1'`, `1 OR 1=1`, `abc`, overflow) returns HTTP 400 model-validation, so no string reaches SQL. `filter` is a literal substring/LIKE predicate: `8.8.8.8` matches the stored value while `'...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "88d218", "surface": "POST /api/services/app/publicenabledgames/search — www.neonrush.com", "risk_area": "SQL injection / data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Anonymous endpoint returning the public game catalogue. Injection-shaped and unknown fields (keyword/filter/searchText/provider/category, quoted payloads) are ignored — byte-identical catalogue, no error or timing differential. No auth bypa...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "a19c3a", "surface": "www.jackpot.com — Widgets/UsaServices + UsWebIdentity string params", "risk_area": "SQL injection (string parameters)", "outcome": "ruled_out", "created_at": "2026-09-27 18:31:40 UTC", "evidence": "Direct probe: UsaServices/ComplianceCheck?state_id=1 → constant \"NonCompliant\" for benign and `1'`/`1 AND 1=1`/`1 AND 1=2` (no differential); UsWebIdentity/CheckUser?email=a@b.com vs a'@b.com → identical empty 200; UsWebIdentity/Error?id=1...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "48c0b7", "surface": "www.neonrush.com — ABP `sorting` parameter (EF Core Dynamic LINQ)", "risk_area": "SQL injection / database access", "outcome": "reported", "created_at": "2026-09-27 18:31:40 UTC", "evidence": "CONFIRMED DB ACCESS, filed vuln-0027 (High 7.1, CWE-89). ABP `sorting` param → System.Linq.Dynamic.Core `OrderBy(string)` → SQL. Blind oracle `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 true / HTTP 500 (SQL divide-by-zero)...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "b99455", "surface": "www.neonrush.com — cross-tenant query via client-controlled Abp.TenantId header (post-auth)", "risk_area": "Tenant isolation bypass", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "With a tenant-1 (CogniSweeps) session, setting `Abp.TenantId: 17` (the populated real NeonRush tenant) returns HTTP 401 \"Current user did not login to the application\" on service endpoints; the header only influences pre-auth flows (registr...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "f98a8c", "surface": "www.neonrush.com — other sortable service list endpoints (documentuser/getall etc.)", "risk_area": "SQL injection via sorting parameter", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "documentuser/getall ignores the sorting parameter entirely: `it.Id`, `it.Bogus` and `it.Player.EmailAddress` all return HTTP 200 with byte-identical rows, so it is not an injection sink. Across the full AbpServiceProxies route map only user...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "4612d3", "surface": "www.neonrush.com — freeentrycodeuser/getall (FreeEntryCode -> Player navigation reachable via sorting injection)", "risk_area": "Cross-table data read via navigation property in injected dynamic-LINQ OrderBy", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "Injected sorting expression resolves a RELATED table: `it.Player.EmailAddress`, `it.Player.UserName`, `it.Player.PhoneNumber`, `it.Player.DateOfBirth`, `it.Player.Gender` all return HTTP 200 (entity translates to a SQL JOIN) while root-only...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "6d948f", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: database metadata (engine/version, schema, table list)", "risk_area": "Database metadata disclosure / DBMS identification", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "The injected expression is bound to the queryable entity, so only that entity's mapped columns are evaluable; there is no resolvable SQL-metadata function (EF.Functions.Like -> 500; typeof/reflection -> 500) and unhandled query failures ret...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "b7452d", "surface": "www.neonrush.com — minted SSO token consumption (in-scope consumers)", "risk_area": "Account impersonation via forged SSO token", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Proof gap on the consumer only. Minted token for a foreign playerId verifies RS256 against the published JWKS (kid e63ad091-...), but no in-scope endpoint accepts it: the ABP API rejects it as a bearer credential (session/getcurrentlogininf...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "0f6f31", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: arbitrary .NET type resolution / reflection escape", "risk_area": "Remote code execution (expression-injection escape to file read / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Named control: System.Linq.Dynamic.Core's restricted predefined-type provider. Positive controls prove client-side funcevaluation works (System.Math.Abs(-5)==5 -> HTTP 200; System.Convert.ToBase64String(new byte[]{65,66})==\"QUI=\" -> 200) wh...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "beac0b", "surface": "api-qa.playuk.com POST /revolve/api/account/getHistorical{Account,Game,Sports}History (from/to)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named control: server-side date parse + 3-month range validation runs BEFORE the query — every quote/boolean/time payload to `from`/`to` returns `code 119/217` (Dates are not in three months range / From and To dates range should not exceed...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "7a5d25", "surface": "api-qa.playuk.com POST /revolve/api/account/isBonusCodeValid (bonusCode)", "risk_area": "SQL injection / database access", "outcome": "reported", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "CONFIRMED time-based blind SQLi: payload `TESTCODE' AND (SELECT 8983 FROM (SELECT(SLEEP(5)))Dynt) AND 'koru'='koru` yields a deterministic +5s delay (5.2-5.6s vs 0.2-0.5s baseline); SLEEP(0) control inert; `-- -` comment form inert. Corrobo...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "dd38e2", "surface": "api-qa.playuk.com /revolve/api/account/{getTransaction,getGame,getSports,getRummy,getWheel}History (pageIndex/pageSize/pageNumber)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named control: integer type validation before use — non-integer values return `code 223 Invalid pageIndex or pageSize` (or a 500 int-parse error); no boolean/time differential across probes.", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "fe4825", "surface": "api-qa.playuk.com POST /revolve/api/account/validateDob (dateOfBirth)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Param name resolved to `dateOfBirth`. Named control: strict date-format validation before any query — all quote/time payloads return `code 153 Invalid Date Format`; valid date returns 200 with no delay.", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "b282ac", "surface": "api-qa.playuk.com POST /revolve/api/account/updateProfile (firstName, lastName, city, state, addressLine1, postCode, nationalId, title, email)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named controls: firstName/lastName enforce an alphabetic allowlist (`code 219/220 can only contain alphabets [A-Z,a-z]`); the remaining string fields accept a quote-bearing payload (`X' AND SLEEP(3)-- -`) and return 200 with no error and no...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "40c422", "surface": "api-qa.playuk.com POST /revolve/api/account/optInToPromotion (identifier) and /revolve/api/payments/paymentMethods (operationType)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named controls: enum/type validation before use — `optInToPromotion.identifier` rejects non-integers with `code 124 Invalid Promotion identifier`; `paymentMethods.operationType` rejects non-enum values with `code 242 Invalid Cashier request...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "42a6b8", "surface": "api-uat.playuk.com — session acquisition / authenticated API", "risk_area": "SQL injection / database access", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Re-confirmed api-uat session acquisition is blocked: POST /revolve/api/register/lite returns anti-fraud 400 code 3 (\"potential breach of terms\") for every payload/email-domain variant, with and without spoofed UK X-Forwarded-For. The block...", "agent_name": "PlayUK Authenticated Injection Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "00d18e", "surface": "appmanager.tangobet.co.uk /api/admin/players/search (advancedFilter/sortField)", "risk_area": "SQL injection in the query-builder tokens", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Time-based and breakout payloads in field/operator/sortField (pg_sleep, WAITFOR, OR 1=1, CASE, stacked) all returned identical 201 bodies and identical ~0.22-0.26s timings; unknown fields are silently dropped (fail-open), values parameteriz...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "3bf536", "surface": "appmanager.tangobet.co.uk JWT (HS256)", "risk_area": "Token forgery via weak/crackable signing secret", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Captured valid HS256 token; offline crack of rockyou.txt (14.3M) + mutation rules over 8 cores (~60s) found no match; alg:none rejected (401, sibling). Signing secret is not a dictionary/weak value, so token forgery is not achievable.", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "33b7f7", "surface": "www.jackpot.com /%2fadmin Content Admin login", "risk_area": "Default credentials and SQL injection on the admin login", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Reached the login via the ALB encoded-slash bypass (direct /admin = 403, /%2fadmin = 200). 5 default/weak cred pairs all rejected with a uniform JSON error; 9 SQLi payloads (incl. WAITFOR DELAY time-based) produced byte-identical responses...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "e5b377", "surface": "appmanager.tangobet.co.uk /api/* (admin API surface)", "risk_area": "Undocumented endpoints enabling SSRF / export / webhook pivots", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Full API recovered from SPA bundle + ffuf (112 names under /api/ and sub-path fuzzing): only auth/login, admin/users[/count], admin/users/{id}, admin/players[/search|/count], admin/notifications/send, mobile-app/stats. No URL-fetching/expor...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "d06832", "surface": "www.neonrush.com /api/authentication/{login,register,social-login,social-signup}", "risk_area": "Authentication bypass via the X-Server-Authorization API key", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "All four endpoints are non-Turnstile but reject requests without the static X-Server-Authorization key (401 InvalidAPIKey). The key was not found in any shipped client asset (SPA bundles, abpscripts, LoginCore/RegisterCore, Median/Smartico/...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "407c4f", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Privilege escalation via role mass-assignment", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Unauth captcha-free account creation confirmed (vuln-0017); roleNames/isAdmin/roles fields were accepted without error, but the effect could not be verified because player login is Turnstile-gated and no session could be obtained (session/g...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "e753de", "surface": "www.neonrush.com playeraccount sendpasswordresetcode / sendemailactivationlink", "risk_area": "Unauthenticated resource abuse (outbound security-email flooding)", "outcome": "reported", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Both endpoints return 200 with no authentication and no captcha; identical responses for known/unknown addresses (no enumeration); 15/15 rapid requests accepted (no rate limiting). resetpassword (the completing step) is Turnstile-gated, so...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "12b9be", "surface": "www.neonrush.com /signalr-banking/negotiate", "risk_area": "cross-user data exposure via SignalR hub", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "The negotiate returns an Azure SignalR access token whose JWT is bound to the caller (nameid/unique_name/tenantId = my user, role Player), so the bankinghub connection is scoped to the requesting user; no cross-user balance/recent-game broa...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "b31250", "surface": "www.neonrush.com authenticated ABP application services (RCE sinks: file-write, eval, deserialization, command)", "risk_area": "Remote code execution", "outcome": "no_issue_found", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "Enumerated all 46 ABP controllers / 191 actions from AbpServiceProxies/GetAll and drove every file/URL/export/log sink with an authenticated session. No code-eval, template, deserialization or command sink is reachable; the only server-side...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "5c4778", "surface": "www.neonrush.com /api/services/app/pushcashpayment/* (tenantBaseSiteUrl / URL params)", "risk_area": "SSRF", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "On tenant 1 (CogniSweeps) an authenticated `authorizePayment`/`authorizeRedemptionPayment` with a unique interactsh host in `tenantBaseSiteUrl` returned 200 no-op with NO server-side fetch (no OOB hit, repeated); `createWidgetUrl` returns s...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "541c5a", "surface": "www.neonrush.com /file/downloadtempfile + /file/downloadbinaryfile", "risk_area": "path traversal / arbitrary file read", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "downloadbinaryfile validates the `id` as a GUID (400 for any traversal/absolute/path value). downloadtempfile treats `fileToken` as an opaque store key (traversal tokens → 404) and sanitises `fileName` in Content-Disposition (raw CRLF/newli...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "4a24eb", "surface": "www.neonrush.com — freeentrycodeuser/getall navigation traversal (FreeEntryCode.Player)", "risk_area": "Cross-table PII read via dynamic-LINQ navigation traversal (sorting injection)", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Navigation resolves (`Sorting=it.Player.EmailAddress` -> HTTP 200 in tenants 1/5/11) but the queryset is always empty and the injected ORDER BY is never evaluated. The only row-creating path, `freeentrycodeuser/getnewcode`, is refused serve...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "a6cea6", "surface": "www.neonrush.com — userlogin/getuserloginattempts (the only non-empty injectable entity)", "risk_area": "Cross-user / cross-table PII extraction via injection navigation", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Only this endpoint is observably injectable (scan of all 188 routes: baseline 200 -> injected 500). Its entity (UserLoginAttempt) has NO navigation property: ~40 candidate names (`it.Player.*`, `it.User.*`, `it.PlayerAccountUser.*`, `it.Cre...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "c08447", "surface": "www.neonrush.com — tenant 17 (NeonRush) session acquisition", "risk_area": "Reach the populated tenant to test the cross-table PII escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:29:44 UTC", "evidence": "Tenant 17 (the populated \"NeonRush\" tenant) cannot be reached: register and login fail CLOSED on Turnstile (policy for PlayerRegistration/PlayerLogin reports isConfigurationValid:false), and no request-level bypass worked (Abp.TenantId swit...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "8b9a7b", "surface": "api-qa.playuk.com /revolve/api/payments/* + limits/deposit + loyalty/redemption + psp/epg + paynplay", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "Amounts/limits are numerically typed (strings → generic 500, no delay); paynplay countryCode/currencyCode/accountSystemTag are allow-list validated (codes 4/5/26); betable/initiatePayment and chapaCashier require typed fields (code 1); with...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "3e7e32", "surface": "api-qa.playuk.com /revolve/api/account/updateProfile + updateMobileNumber + updateEmail + changeLanguagePreference", "risk_area": "SQL / NoSQL injection (write path)", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "updateProfile (which performs a real DB update, 200) validates firstName/lastName to alphabets (codes 219/220) and dateOfBirth (code 152); remaining text fields accept markers but return identical 200 with no timing delay (parameterized ent...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "47ccae", "surface": "api-qa.playuk.com /revolve/api/account/*History endpoints (from/to/pageIndex/pageSize/pageNumber)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "Tested getGame/Transaction/Bonus/CashRewards/FreeRounds/Wheel/Rummy/Sports/Historical*History with date/page params. from/to are strictly format-validated (code 153 \"Invalid Date Format\" for any marker); pageIndex/pageSize are validated (co...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "805d7f", "surface": "api-qa.playuk.com /revolve/api/* lookup endpoints (redeemPromocode, isBonusCodeValid, claimReward, optInToPromotion, loginWithToken, transactionStatus, cancelPendingWithdrawal)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "String-keyed DB lookups return byte-identical parameterized responses for benign vs injection markers and show no SLEEP delay (promoCode verified across 6 fresh accounts; bonusCode identical {\"isBonusCodeValid\":false}; paymentRecord identic...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "d21d4d", "surface": "In-scope API/app hosts (www.neonrush.com, appmanager.tangobet.co.uk, api-qa/uat.playuk.com, www.jackpot.com, play.neonrush.com, uat.uk-bingo.net, promo.hotwinscasino.com, www.betmaze.co.uk, www.playuk.com)", "risk_area": "CORS misconfiguration + Host-header reflection / password-reset poisoning", "outcome": "no_issue_found", "created_at": "2026-09-27 20:46:22 UTC", "evidence": "Independent probe: GET with Origin: https://irt-probe-9f3a.example.com returned no reflected ACAO and no Access-Control-Allow-Credentials on any host; api-qa/uat.playuk.com return ACAO:* only (wildcard, no Allow-Credentials => no credential...", "agent_name": "Independent Red Team Lead 4"}, {"entry_id": "73b264", "surface": "77.68.12.66:3306 MariaDB 10.5.29 + Plesk 8443 (promotions.pandabingo.com)", "risk_area": "Internet-exposed database service / weak credentials / data exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:31 UTC", "evidence": "Independently verified: nmap -sV reports 3306/tcp open MariaDB 5.5.5-10.5.29 and 8443/tcp Plesk sw-cp-server login on 77.68.12.66 = A record of in-scope promotions.pandabingo.com. Gap: authentication not yet tested; ownership/scope nuance (...", "agent_name": "Independent Red Team Lead 2"}, {"entry_id": "1dc941", "surface": "45.132.74.81:4000 NoMachine NX Server 10.0.59 (origin of dev/qa/lp/promo/promotions/games.potsofluck.com)", "risk_area": "Exposed remote-desktop / command injection (CVE-2026-18264, CVSS 8.8)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:31 UTC", "evidence": "Independently verified: nmap -sV reports 4000/tcp open nomachine-nx 10.0.59; local vulnx confirms CVE-2026-18264 NoMachine Command Injection (High, CVSS 8.8, no public PoC/nuclei template/KEV) and CVE-2026-53694. Host also 22/80/443. Owners...", "agent_name": "Independent Red Team Lead 2"}, {"entry_id": "c6f7f2", "surface": "Cross-subdomain cookie scoping on live in-scope apps (www.jackpot.com, play.neonrush.com, appmanager.tangobet.co.uk, uat.uk-bingo.net, partners.jackpot.com) vs dormant-subdomain takeover candidates", "risk_area": "Subdomain takeover escalating to parent-domain cookie tossing / session fixation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:50 UTC", "evidence": "Observed: play.neonrush.com sets incap_ses/visid_incap with Domain=.neonrush.com (incap_ses NOT HttpOnly); www.jackpot.com session cookies (ASP.NET_SessionId, jp_geolocation) are host-only, so a claimed sibling (wiki.jackpot.com, vuln-0011)...", "agent_name": "Independent Red Team Lead 1"}], "filtered_count": 353, "total_count": 353, "outcome_counts": {"reported": 41, "no_issue_found": 90, "ruled_out": 138, "not_applicable": 10, "needs_follow_up": 74}}