{"success": true, "entries": [{"entry_id": "65365f", "surface": "luckcity.com (+ www, play, app.luckcity.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "luckcity.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"LuckCity\", 31KB). Mapped ProgressPlay app: whiteLabelName=luckcity; standard routes; no secrets. app.luckcity.com -> Fireb...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "f308ca", "surface": "mrjackvegas.com (+ www, play, staging3)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site fully crawled/mapped: static routes (/all-games,/casino-games,/compliance/*), JS bundles recovered, whitelabel ID 107 and play.mrjackvegas.com identified. staging3.mrjackvegas.com = headless WordPr...", "agent_name": "Recon Charlie"}, {"entry_id": "d1add8", "surface": "mrrex.com (+ www)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "mrrex.com/www: REACHABLE — Incapsula challenge browser-solvable, not an IP block. agent-browser load+reload => 200 real app (title \"MrRex\", 41KB). Mapped ProgressPlay app: whiteLabelName=mrrex; standard routes; no secrets in __NEXT_DATA__/p...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "720511", "surface": "mamzinobet.com (+ www)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "mamzinobet.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"MamzinoBet\", 42KB). Mapped ProgressPlay app: whiteLabelName=mamzinobet; standard routes; no secrets. Supersedes prior \"b...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "a38a21", "surface": "mrslot.com (+ www, play, headless, lobby)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 77, play.mrslot.com). headless.mrslot.com WP REST behind SiteGround sgcaptcha (blocked even via real browser). lobby.mrslot.com→185.27.56.100 (stale). No app issue on reachable s...", "agent_name": "Recon Charlie"}, {"entry_id": "3fa973", "surface": "moneyplay.com (+ lobby.moneyplay.com, mta-sts)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "moneyplay.com: www/apex are direct Cloudflare (302 -> lobby.moneyplay.com); lobby is Imperva-fronted but REACHABLE via browser (challenge browser-solvable). agent-browser load+reload returns 200 real app (title \"MoneyPlay\", 25KB). Mapped Pr...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "a18dcd", "surface": "mogobet.com (+ www, play.mogobet.com)", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "Tested to closure. CONFIRMED: GET https://mogobet.com/wp-content/debug.log returns 200 with a live PHP debug log (absolute path /home/mogobet.com/public_html/, stack traces) — filed as a finding. Also unauth user enum via /wp-json/wp/v2/use...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "47acd5", "surface": "mrsuperplay.com (+ www, play, staging6)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 102, play.mrsuperplay.com). staging6.mrsuperplay.com headless WP (35.214.94.72) behind SiteGround challenge. No issue on reachable static surface.", "agent_name": "Recon Charlie"}, {"entry_id": "a3a9bc", "surface": "mrmobi.com (+ www, play, headless, lobby)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "LIVE 200 Cloudflare+Nuxt.js marketing site mapped (whitelabel 76, play.mrmobi.com). headless.mrmobi.com WP REST behind SiteGround sgcaptcha (blocked). lobby.mrmobi.com→185.27.56.100 no HTTPS service (likely stale DNS). No app-level issue on...", "agent_name": "Recon Charlie"}, {"entry_id": "b3cbe3", "surface": "content.progressplay.net/api23/api/* (ProgressPlay backend API)", "risk_area": "broken access control / unauthenticated API", "outcome": "not_applicable", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "content.progressplay.net is a third-party platform-vendor backend and is NOT among the 47 system-verified in-scope targets. Observe-only; no active testing authorized there. Recorded as out-of-scope rather than an open item.", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "6641ec", "surface": "ne-bet.com (+ www)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "ne-bet.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"Ne-Bet\", 42KB). Mapped ProgressPlay app: whiteLabelName=ne-bet; standard routes; no secrets. Supersedes prior \"blocked\" (see...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "0d215a", "surface": "*.tech1960.workers.dev (Cloudflare Workers micro-APIs)", "risk_area": "attack surface mapping / unauthenticated API", "outcome": "not_applicable", "created_at": "2026-09-27 16:12:07 UTC", "evidence": "*.tech1960.workers.dev is a third-party Cloudflare Workers domain, not an in-scope target. Observe-only; no active testing authorized. Out-of-scope, not an open item.", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "7599c5", "surface": "potsofluck.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant, og:url https://games.potsofluck.com. Related live subs: dev/qa/lp/promo/promotions.potsofluck.com. api/uat/api-qa/api-uat.potsofluck.com have NO DNS.", "agent_name": "Recon Delta"}, {"entry_id": "1ac831", "surface": "playuk.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: WordPress on WP Engine (nginx/PHP/MySQL, Yoast 28.3); 301→www.playuk.com. Casino backend playuk.casino-pp.net (ProgressPlay). REST exposed: /wp-json/ (261KB), /wp-json/wp/v2/users (admin,playuk), pages 1367/3916; /xmlrpc.php 405;...", "agent_name": "Recon Delta"}, {"entry_id": "ba9455", "surface": "play.neonrush.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: Next.js/React behind Cloudflare+AWS S3+Imperva. ProgressPlay tenant whiteLabelId=284. Enumerated unauth APIs: /api/getTenantData?wl=, /api/getWhiteLabelConfig, /api/player/getDefault, /api/player/getPlayer (PlayerId:0 anon), /api/...", "agent_name": "Recon Delta"}, {"entry_id": "f0d0f9", "surface": "play.betzi.co", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "play.betzi.co: REACHABLE — Incapsula challenge browser-solvable, not an IP block. agent-browser load+reload => 200 real player app (title \"Betzi Online Casino, Slots, Sportsbook and more\", 26KB). Mapped ProgressPlay app: whiteLabelName=betz...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["no_issue_found", "needs_follow_up"]}, {"entry_id": "6fa904", "surface": "q88bets.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www.q88bets.com, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=200 (\"q88bets\"). Same /api/* pattern reachable in-browser. promo.q88bets.com = Apache 2.4.52 WP-ish offers page.", "agent_name": "Recon Delta"}, {"entry_id": "02ed25", "surface": "rainbetsplash.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403 on 45.60.243.194/45.60.249.194). Browser render confirms ProgressPlay tenant whiteLabelId=8 (\"rainbetsplash\").", "agent_name": "Recon Delta"}, {"entry_id": "71038d", "surface": "slotlux.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE 200: Nuxt.js/Vue on Cloudflare; headless WordPress backend (headless.slotlux.com/wp-json behind SiteGround captcha); play.slotlux.com 403 Imperva. Enumerated /api/pp/games (unauth full catalog), /compliance/* routes. Confirmed .env/.gi...", "agent_name": "Recon Delta"}, {"entry_id": "33398e", "surface": "stakespin.casino", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=166 (\"stakespin\").", "agent_name": "Recon Delta"}, {"entry_id": "77c01d", "surface": "ProgressPlay /api/getTenantData?wl= + whiteLabelId", "risk_area": "IDOR / cross-tenant access via wl parameter", "outcome": "ruled_out", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Resolved by the ProgressPlay IDOR Hunter on the reachable play.* hosts: the `wl`/`whiteLabelId` parameter is IGNORED — tenant is fixed per deployment server-side (getDefault/getTenantData return the host's own tenant); player endpoints retu...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "0da114", "surface": "playuk.com /wp-json + xmlrpc.php", "risk_area": "WordPress REST exposure / user enumeration / plugin CVEs", "outcome": "reported", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Tested to closure. Confirmed unauthenticated user enumeration: GET https://playuk.com/wp-json/wp/v2/users (and /?rest_route=/wp/v2/users) returns admin(id1)+playuk(id2) without auth. xmlrpc.php POST is blocked (403 nginx for our egress; sys...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "190915", "surface": "dev/qa/lp/promo/promotions.potsofluck.com Apache Guacamole", "risk_area": "exposed remote-desktop gateway", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "Resolved by the Guacamole Gateway Hunter: the gateway (all six potsofluck.com hosts = one Apache Guacamole 1.6.0 instance) rejects default/weak credentials, enforces an unbypassable brute-force throttle (429 after ~5 attempts; spoofed IP he...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "60f56c", "surface": "savibet.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:16:21 UTC", "evidence": "LIVE: Imperva-gated (301→www, Incapsula 403). Browser render confirms ProgressPlay tenant whiteLabelId=268 (\"savibet\").", "agent_name": "Recon Delta"}, {"entry_id": "0c45c1", "surface": "supabet.co.uk", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:05 UTC", "evidence": "supabet.co.uk/www: REACHABLE — Incapsula challenge is browser-solvable, not an IP block. agent-browser load+reload => 200 real app (title \"SupaBet.co.uk\", 25KB). Mapped ProgressPlay app: whiteLabelName=supabet; routes /, /games, /favourites...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "293759", "surface": "vampirebingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Live www branded Nuxt.js/Vue3 marketing site (Cloudflare); platform at play.vampirebingo.com returns Imperva 403 (blocked). Marketing routes enumerated; no API surface exposed on marketing site.", "agent_name": "Recon Echo"}, {"entry_id": "c84fe9", "surface": "betblink.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "betblink.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"BetBlink\", 25KB). Mapped ProgressPlay app: whiteLabelName=betblink; standard routes; no secrets. Supersedes prior \"blocked...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "3ae16c", "surface": "theonlinecasino.co.uk", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Tested to closure. CONFIRMED unauth user enumeration via /wp-json/wp/v2/users (admin id1) and ?rest_route= bypass. wp-login.php/wp-admin are rewritten to a custom /404 (login is served by the custom theme page /theonlinecasino-portal/, whic...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "201e32", "surface": "21luckybet.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "21luckybet.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"21LuckyBet\", 42KB). Mapped ProgressPlay app: whiteLabelName=21luckybet; standard routes; no secrets. pro/promo.21luckybe...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "1b12f2", "surface": "betarno.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Apex (Heroku) serves Nuxt.js/Vue3 betting site + Prismic CMS; enumerated routes incl /test/home and i18n prefixes; /linkResolver.js returns JSON 404. www.* is Imperva 403. No exposed API surface on marketing site.", "agent_name": "Recon Echo"}, {"entry_id": "6833c5", "surface": "tangobet.co.uk (+subdomains)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "apex/www Imperva 403 (blocked for sandbox IP). Reachable subdomains mapped: appmanager (Betty Admin SPA + /api/admin/* Bearer-JWT, 401 gated, unauth /api/mobile-app/stats), app (AppsFlyer OneLink), deletemyaccount, affiliates/promos (403 ng...", "agent_name": "Recon Echo"}, {"entry_id": "ece8bd", "surface": "acedbet.com", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:10 UTC", "evidence": "Reachable via headless browser (Vercel Security Checkpoint returns 429 to curl). Next.js + Auth.js credentials provider; /api/auth/providers, /api/auth/csrf, /api/auth/signin/credentials, /api/auth/callback/credentials, /api/auth/session al...", "agent_name": "Recon Echo"}, {"entry_id": "576b2b", "surface": "promo.hotwinscasino.com (WordPress)", "risk_area": "attack surface mapping", "outcome": "reported", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Tested to closure. Cloudflare managed challenge intermittently gates the host; wp-login.php / xmlrpc.php / wp/v2/users return 403 to our egress. CONFIRMED: the WAF rule blocking /wp-json/wp/v2/users is bypassed via /?rest_route=/wp/v2/users...", "agent_name": "WordPress Fleet Hunter B", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "802305", "surface": "jeffbet.net", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "WordPress 7.1.2 + CF7 6.1.7 + Yoast 28.3 on WP Engine/Cloudflare mapped. Observed unauthenticated user enumeration via /wp-json/wp/v2/users (200, 18KB → admin, simon-young, ross-young) — handed to downstream note. xmlrpc.php 403, wp-login.p...", "agent_name": "Recon Bravo"}, {"entry_id": "314c14", "surface": "pandabingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare, 188.114.x) mapped; SPA fallback returns index 200 for unknown paths. Public game catalogue /api/pp/games + /api/worker/games (identical ~6.9MB JSON). Subs: bingo.→www, uat.pandabingo.com Next.js on AWS EKS (see...", "agent_name": "Recon Bravo"}, {"entry_id": "dfe0aa", "surface": "uk-bingo.net", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped. Subs: play. Imperva 403; support.→ukbingo.zendesk.com; uat.uk-bingo.net = Next.js app on AWS EKS (see UAT coverage). No exploitable surface at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "018859", "surface": "uat.uk-bingo.net / uat.pandabingo.com (shared EKS UAT app)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Both resolve to one AWS ELB k8s-devkrake-sitesing-...eu-west-2.elb.amazonaws.com; Next.js/React/Webpack. /api/health → 200; /api/v1 → 308→/api/v1 (404); other /api/* 404. App bundles reference platform API api.dev.kraken.ptops.net/api/v1, W...", "agent_name": "Recon Bravo"}, {"entry_id": "ce38a9", "surface": "wombatbingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare, 188.114.x) mapped; public /api/pp/games + /api/worker/games. Subs: play.wombatbingo.com Imperva 403 (app tier). SPA fallback returns 200 index for arbitrary paths (not a file hit). No exploitable surface at mapp...", "agent_name": "Recon Bravo"}, {"entry_id": "bd4c94", "surface": "jazzyspins.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped; returns 404 (no SPA fallback); /lp/ campaign landing (robots disallow). Public /api/pp/games. Subs: play. Imperva 403; headless. Imperva 202. No exploitable surface at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "6e6bad", "surface": "jackpot.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "IIS 10.0 / ASP.NET MVC 5.2 behind AWS ALB mapped. /admin and /trace.axd → 403 (exist-but-blocked); /api,/login,/account,/register → 404 (custom 2916B); sitemap.xml 1336 game routes; robots disallow /admin. Verbose X-AspNetMvc-Version header...", "agent_name": "Recon Bravo"}, {"entry_id": "a97694", "surface": "lekkerbets.co.za", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "lekkerbets.co.za/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"LekkerBets: Sports Betting, Online Casino & Live Casino\", 26KB). Mapped ProgressPlay app: whiteLabelName=lekkerbets; s...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "e578e7", "surface": "hotwinscasino.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "hotwinscasino.com/www: REACHABLE — Incapsula challenge browser-solvable. agent-browser load+reload => 200 real app (title \"HotWinsCasino\", 42KB). Mapped ProgressPlay app: whiteLabelName=hotwinscasino; standard routes; no secrets in __NEXT_D...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "d1b86f", "surface": "queensbingo.com", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "Nuxt.js/Vue SPA (Cloudflare) mapped. Subs: play. Imperva 403; headless. Imperva 202 challenge; anna./staging3. DNS NXDOMAIN (stale CT records → unreachable). No exploitable surface found at mapping depth.", "agent_name": "Recon Bravo"}, {"entry_id": "d996ce", "surface": "highstakes.co.uk", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:17:33 UTC", "evidence": "highstakes.co.uk/www: REACHABLE — the Incapsula \"block\" is a browser-solvable JS/fingerprint challenge, not an IP deny. agent-browser (load + one reload) returns HTTP 200 real app (title \"HighStakes\", 53KB). Mapped ProgressPlay player app:...", "agent_name": "Imperva Blocked-Tenant Reach", "previous_outcomes": ["needs_follow_up", "needs_follow_up", "no_issue_found"]}, {"entry_id": "013a04", "surface": "betmorph.com (+ www, play.betmorph.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "REACHED (Cloudflare, no Imperva). betmorph.com = Hercules React/Vite SPA; /admin,/admin/users,/admin/cms/* client-routed, return SPA index (200) with no data — admin guard is client-side/OIDC (already tracked as c45341). Marketing/home tier...", "agent_name": "Imperva Host Reachability Mapper", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "f5f194", "surface": "betstorm.com (+ www, play.betstorm.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 2939242); browser+cookie bypass → 200. ProgressPlay white-label Next.js (whiteLabelName \"betstorm\"), title \"BetStorm - Lightning can strike twice\". offers.betstorm.com → 157.53.227.1 (404).", "agent_name": "Recon Alpha"}, {"entry_id": "411914", "surface": "betmaze.co.uk (+ www.betmaze.co.uk, play.betmaze.co.uk)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE WordPress 7.1.2 (LiteSpeed/PHP/MySQL, twentytwentyfive-child theme) behind Cloudflare. /wp-json/wp/v2/users enumerates user `betmaze_login`; xmlrpc.php present; custom theme PHP fetch-sports.php/fetch-promotions.php/fetch-games.php AJA...", "agent_name": "Recon Alpha"}, {"entry_id": "24efa9", "surface": "chitchatbingo.com (+ www, play, uat, api, support)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE. Marketing = Nuxt3/Vue on Cloudflare with API /api/pp/games, /api/worker/games and Cloudflare Workers *.tech1960.workers.dev. play.chitchatbingo.com = Betable app behind Imperva. uat.chitchatbingo.com = AWS EKS Next.js staging (1.3MB)...", "agent_name": "Recon Alpha"}, {"entry_id": "da1916", "surface": "acelucky.com (+ www, play.acelucky.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3181109); browser+cookie bypass → 200. ProgressPlay white-label Next.js (whiteLabelName \"acelucky\"), title \"AceLucky: Online Casino – Online Slots, Live Casino & Sports\".", "agent_name": "Recon Alpha"}, {"entry_id": "eb311b", "surface": "dynobet.com (+ www, play, affiliates, promos, *.uat/*.qa)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "LIVE ProgressPlay white-label (Imperva acct 3119998), title \"Dynobet: Sports betting and Online Casino\". affiliates.dynobet.com + promos.dynobet.com → AWS Elastic Beanstalk webapp-env.eba-4x3ezugm.eu-west-2.elasticbeanstalk.com (403 nginx)....", "agent_name": "Recon Alpha"}, {"entry_id": "a91887", "surface": "betsuna.com (+ www.betsuna.com, games.betsuna.com)", "risk_area": "attack surface mapping", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "WordPress behind Cloudflare+LiteSpeed; root `/` has a 301↔302 redirect loop returning no body, but /robots.txt, /wp-json/ (224KB exposed), /wp-json/wp/v2/users (user `betsunaadmin`), /wp-login.php all respond. games.betsuna.com → Microsoft-...", "agent_name": "Recon Alpha"}, {"entry_id": "37f5af", "surface": "africasports.com (+ www, play.africasports.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3271531); browser+cookie bypass → 200. ProgressPlay white-label Next.js; __NEXT_DATA__ leaks platform config (whiteLabelName \"africasports\", playMode IDs, testWhiteLabelName \"betsteve\", paypal sandbox key, Smartico key...", "agent_name": "Recon Alpha"}, {"entry_id": "e3c035", "surface": "777bet.casino (+ www.777bet.casino, play.777bet.casino)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "Mapped. Imperva (acct 3213198) in front; plain HTTP blocked, bypassed via browser-reload + curl_cffi cookies → 200. ProgressPlay white-label Next.js (whiteLabelName \"777bet\"), title \"777Bet | Online Casino and Sports Betting\". No subdomains...", "agent_name": "Recon Alpha"}, {"entry_id": "c49f39", "surface": "777tigers.com (+ www, play.777tigers.com)", "risk_area": "attack surface mapping", "outcome": "no_issue_found", "created_at": "2026-09-27 16:20:23 UTC", "evidence": "REACHED (Cloudflare). 777tigers.com = Hercules React/Vite SPA (/assets/index-B_Xeu_nP.js, /_hercules/i.*.js). /admin,/admin/users client-routed SPA index (200), no data (admin guard client-side, tracked as e360e7). NOTE: one browser load re...", "agent_name": "Imperva Host Reachability Mapper", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "9b0b28", "surface": "https://appmanager.tangobet.co.uk /api/mobile-app/stats", "risk_area": "Missing authentication / information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Unauthenticated GET returns only aggregate counts {\"count\":8722,\"pnAllowed\":3533}; no PII or identifiers. Low sensitivity and plausibly intended for the public mobile app.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "69329b", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "Brute-force / missing rate limiting", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "15 consecutive failed logins each returned 401 with no rate-limit headers, no Retry-After, no lockout; a valid login immediately after still succeeded. Filed as report.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "89cf7a", "surface": "https://appmanager.tangobet.co.uk /api/admin/*", "risk_area": "Missing authentication / BFLA", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Server-side gate: every /api/admin/users[/count], /api/admin/players/search, /api/admin/players/count, /api/admin/notifications/send returns {\"message\":\"Unauthorized\",\"statusCode\":401} without a valid Bearer token (GET/POST/PUT/DELETE teste...", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "c1a0ec", "surface": "https://appmanager.tangobet.co.uk /api/admin/players/search", "risk_area": "Sensitive player data exposure (PII / financial)", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "With the token obtained from default credentials, POST /api/admin/players/search returns 4,460 player records incl. Alias/real names, age, gender, country, deposit, cashout, revenue, currency. Reported as impact of the credential finding.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "4310a5", "surface": "https://appmanager.tangobet.co.uk /api/admin/users (POST/PUT)", "risk_area": "Mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "POST /api/admin/users with role/isAdmin/isSuperuser/permissions returned only {id,username,created,updated}; extra fields not stored. GET /api/admin/users shows the model has no role field (flat admin concept), so no privilege field to esca...", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "402e4b", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "JWT forgery (alg:none / weak secret)", "outcome": "ruled_out", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "Self-signed alg:none token rejected 401. HS256 secret not recovered from 10k common-password list plus targeted candidates (betty/tangobet/railway/etc); token is short-lived (1h exp). No kid/jku/jwk headers present to abuse.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "46c30e", "surface": "https://appmanager.tangobet.co.uk /api/auth/login", "risk_area": "Weak/default administrative credentials", "outcome": "reported", "created_at": "2026-09-27 16:23:27 UTC", "evidence": "POST /api/auth/login with {\"username\":\"admin\",\"password\":\"admin123\"} returns HTTP 201 + HS256 access_token (payload {\"username\":\"admin\",\"sub\":1}). Token grants the full /api/admin/* API. Filed as report.", "agent_name": "Betty Admin Panel Hunter"}, {"entry_id": "d0fc2e", "surface": "uat.pandabingo.com /api/cms/[...path]", "risk_area": "Broken access control / sensitive data exposure", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Independently re-verified by the Shared-Platform Cross-Tenant Amplifier with unauthenticated requests on this host: /api/cms/users -> 200 (1,770 B, 6 accounts), /users/count -> 6, /users-permissions/roles -> 200, /users-permissions/permissi...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["reported"]}, {"entry_id": "92a2e7", "surface": "UAT apps /api/env/vars", "risk_area": "Secret / environment variable disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Endpoint enforces prefix startswith NEXT_PUBLIC_ (NEXT_PUBLIC 11 chars rejected, NEXT_PUBLIC_ works; SECRETS/DATABASE_URL rejected). Only public NEXT_PUBLIC_* vars returned (feature flags, Sentry DSN, API base URL) — all client-embedded by...", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "3a0e56", "surface": "UAT apps /api/cms privilege escalation (BFLA)", "risk_area": "Broken function-level authorization", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Proxy forwards only GET/HEAD/OPTIONS (POST/PUT/DELETE -> 405). Traversal to admin endpoints (/admin/users, /admin/permissions, /admin/api-tokens) returns 401 Missing or invalid credentials — no write or privileged action achievable.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "e4b24f", "surface": "uat.uk-bingo.net /api/cms/[...path] (Strapi CMS proxy)", "risk_area": "Broken access control / sensitive data exposure (unauthenticated CMS API) + path traversal", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Unauth GETs return 200: /api/cms/users (6 staff emails), /users-permissions/roles, /sites (51 brands, 31MB), /upload/files (10MB), /content-type-builder/content-types (33 schemas). Traversal /api/cms/..%2fadmin%2finit -> admin config; POST...", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "55a468", "surface": "uat.chitchatbingo.com /api/cms/[...path]", "risk_area": "Broken access control / sensitive data exposure", "outcome": "reported", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Same build; /api/cms/users + /users/count return 200 unauth (identical 6 CMS accounts).", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "739cba", "surface": "UAT apps account/wallet/player routes", "risk_area": "IDOR / BOLA", "outcome": "not_applicable", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "The UAT Next.js app exposes no account/wallet/player route handlers; client calls the out-of-scope backend api.dev.kraken.ptops.net/api/v1 directly. No in-scope object-scoped endpoints to test.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "192be7", "surface": "UAT apps /api/cms proxy SSRF", "risk_area": "Server-Side Request Forgery", "outcome": "ruled_out", "created_at": "2026-09-27 16:25:28 UTC", "evidence": "Host-injection attempts (//example.com, %2f%2f, ..%2f%2f%2f, 169.254.169.254) return {\"status\":400,\"message\":\"Malicious Path\"}; traversal only reaches same-host CMS sibling paths. No arbitrary-host fetch.", "agent_name": "UAT Next.js API Hunter"}, {"entry_id": "c45341", "surface": "betmorph.com SPA admin routes (/admin, /admin/users, /admin/cms/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Admin guard is client-side only (OIDC isAuthenticated + Convex users.isAdmin; false -> redirect /). Unauth requests to /admin, /admin/users, /admin/cms/home render only the sign-in prompt (no data). All privileged data/actions resolve to Co...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "1d70c6", "surface": "betmorph.com / 777tigers.com OIDC login flow (/auth/callback, hercules.app issuer)", "risk_area": "Authentication / token handling", "outcome": "no_issue_found", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "oidc-client-ts flow uses authorization code + PKCE S256 and state validation; redirect_uri is fixed to window.location.origin + /auth/callback; the callback component navigates to a hardcoded \"/\" (no attacker-controllable returnUrl); no tok...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "e360e7", "surface": "777tigers.com SPA admin routes (/admin, /admin/users, /admin/games, /admin/pages/*)", "risk_area": "Broken Function Level Authorization / admin authorization", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Same client-side-only guard as betmorph. Unauth /admin/users and /admin/games show \"Admin Access Required / Please sign in\". Privileged functions (users.getAllUsers, users.updateUserRole role-escalation, games.create/update/remove, cms.upse...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "83852c", "surface": "betmorph.com / 777tigers.com static assets and config exposure", "risk_area": "Information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "betmorph.com /.env and /.git/config return 403 (Cloudflare); all other unknown paths return the SPA index HTML (no source maps, no config). No API keys/secrets in either JS bundle. 777tigers.com /.env and /.git/config return 403.", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "324ff7", "surface": "777tigers.com apex DNS (A record 100.24.208.97)", "risk_area": "Dangling DNS / domain takeover", "outcome": "reported", "created_at": "2026-09-27 16:29:04 UTC", "evidence": "Apex has two A records: 104.18.220.38 (Cloudflare -> real Hercules site) and 100.24.208.97 (rDNS staticip2.multiscreensite.com = Duda). Direct HTTPS/HTTP to 100.24.208.97 with SNI/Host 777tigers.com returns Duda's \"SITE NOT FOUND / not publ...", "agent_name": "Hercules Admin AuthZ Hunter"}, {"entry_id": "d20baa", "surface": "https://www.jackpot.com/admin (AWS ALB path rule)", "risk_area": "Access control / path-normalization bypass", "outcome": "reported", "created_at": "2026-09-27 16:37:23 UTC", "evidence": "Re-verified live with a non-browser client (curl/8.5.0). Rule shape is EXACT-SEGMENT, not an /admin* glob: /admin, /Admin, /ADMIN, /admin-panel, /Areas/Admin -> 403 (awselb/2.0, 118B), but /administrator, /adminx, /adminlogin, /Areas/Admini...", "agent_name": "Jackpot Admin Surface", "previous_outcomes": ["reported", "reported"]}, {"entry_id": "44a707", "surface": "https://www.jackpot.com admin area controllers/actions", "risk_area": "Broken function-level authorization (admin area)", "outcome": "ruled_out", "created_at": "2026-09-27 16:37:31 UTC", "evidence": "Deep re-enumeration via the /%2f ALB bypass found NO unauthenticated admin action. Home controller exposes only Index (login, AllowAnonymous; /%2fadmin/Home/Index -> 200 login view), Error (302 -> /Admin/Home/LogOff) and LogOff (302 -> http...", "agent_name": "Jackpot Admin Surface", "previous_outcomes": ["ruled_out", "ruled_out"]}, {"entry_id": "9bbfcb", "surface": "https://www.jackpot.com public/widget parameters", "risk_area": "SQL injection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:12 UTC", "evidence": "Tested admin login (14 SQLi/auth-bypass payloads: admin'--, ' OR '1'='1'--, WAITFOR DELAY, UNION, comment/quote variants — all identical 133-byte 'Wrong USERNAME and/or PASSWORD!' JSON, no timing/content differential) and public widget para...", "agent_name": "Jackpot ASP.NET Hunter"}, {"entry_id": "e04858", "surface": "*.potsofluck.com gateway — exposed network services (45.132.74.81)", "risk_area": "Exposed backend services (guacd/database/RDP)", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Only 22/80/443 open. guacd 4822, MySQL 3306, PostgreSQL 5432, Tomcat 8080/8081, RDP 3389, VNC 5900, Redis 6379 all filtered from the internet — the gateway reaches guacd over loopback only.", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "ba8b12", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST)", "risk_area": "Authentication bypass / token forgery", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "No alternate auth extension: POST with 'data=' (JSON-auth) returns the standard expected:[username,password] response, ruling out guacamole-auth-json forgeable-token path. Guacamole 1.6.0 — CVE-2021-43999 (auth bypass) is SAML-only/<=1.3.0...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "4ddf8b", "surface": "*.potsofluck.com gateway — TLS transport (all six vhosts)", "risk_area": "Transport security / certificate validity", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Protocol/cipher posture is sound: TLS 1.0/1.1 refused, TLS 1.2/1.3 with ECDHE-ECDSA-AES256-GCM / AES256-GCM. OBSERVATION (not an exploitable finding): every host serves a Let's Encrypt cert with CN/SAN=cl.exalt-digital.ru, an unrelated thir...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "870781", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Injection markers in username/password (\"guacadmin'-- -\", \"' OR '1'='1\" in username, \"' OR '1'='1\" in password) all returned byte-identical 403 INVALID_CREDENTIALS with no error/ambiguity. Guacamole JDBC auth uses parameterized queries. NOT...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "9b76c4", "surface": "*.potsofluck.com Guacamole gateway — /api/session/* , /api/session/ext/quickconnect", "risk_area": "Unauthenticated access to session/connection data", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "All /api/session, /api/session/data, /api/session/data/{mysql,jdbc,postgresql}/* and quickconnect paths return 403 {\"message\":\"Permission Denied.\"} for every method/token shape tried. Standard Guacamole permission check runs before dataSour...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "f1e58c", "surface": "*.potsofluck.com Guacamole gateway — /api/tokens (POST) [dev/qa/lp/promo/promotions/games]", "risk_area": "Weak / default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "Default guacadmin/guacadmin, guacadmin/password, admin/admin, root/root, potsofluck/potsofluck all rejected with 403 INVALID_CREDENTIALS. Auth provider is JDBC username/password (guacamole-auth-jdbc). Built-in rate limiter blocks after ~4-5...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "cfd5e6", "surface": "*.potsofluck.com gateway web root — static/management paths, .git/.env/backups, Tomcat apps", "risk_area": "Exposed management artifacts / information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:16 UTC", "evidence": "~140-path fuzz returned only expected Guacamole resources. Tomcat /manager, /host-manager, /docs, /examples all 404; no .git, .env, config, dump, or backup files. Port 80 serves the stock nginx welcome page (no API over cleartext). Only dis...", "agent_name": "Guacamole Gateway Hunter"}, {"entry_id": "d030fc", "surface": "https://www.jackpot.com widget endpoints (malformed params)", "risk_area": "Verbose error / stack-trace information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:20 UTC", "evidence": "Resolved the open verbose-error surface by exhaustive secret mining. Re-confirmed www.jackpot.com runs customErrors mode=\"Off\" (yellow-screen stack traces and a //<!-- comment stating so). Triggered ~480 unhandled exceptions across /Widgets...", "agent_name": "Jackpot Trace Secret Miner", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "e5a53b", "surface": "https://www.jackpot.com Widget API endpoints", "risk_area": "IDOR / object-level authorization", "outcome": "no_issue_found", "created_at": "2026-09-27 16:38:20 UTC", "evidence": "No unauthenticated data-bearing object endpoints found. Widget endpoints that take identifiers are bound to Int32 (Menu/Timezones state, Promotion/Tac id, UsWebIdentity/ModalSeen customerID) and return non-sensitive content (promotion T&C t...", "agent_name": "Jackpot ASP.NET Hunter"}, {"entry_id": "67adc0", "surface": "api-uat/api-qa.playuk.com IP whitelist", "risk_area": "IP allowlist bypass via forwarding headers", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:20 UTC", "evidence": "Probed the full route list against api-uat: baseline /api/{prod,qa}/frontend returns 401 for our egress, and header-spoofing attempts (X-Forwarded-For, X-Real-IP, X-Originating-IP, Client-IP, True-Client-IP, X-Client-IP, Forwarded, CF-Conne...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "b856a7", "surface": "api-uat.playuk.com /revolve/api/* (UAT casino account API)", "risk_area": "broken access control / IDOR on casino account + wallet API", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:20 UTC", "evidence": "Resolved by the PlayUK UAT API Hunter on api-uat/api-qa.playuk.com: after authenticating against all /revolve/api/* object-scoped routes, identity is derived solely from SessionCorrelationId; the userCorrelationId cookie is ignored (swappin...", "agent_name": "Root Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "515f16", "surface": "xmlrpc.php pingback (theonlinecasino.co.uk, mogobet.com)", "risk_area": "SSRF via xmlrpc pingback", "outcome": "ruled_out", "created_at": "2026-09-27 16:40:24 UTC", "evidence": "xmlrpc.php is enabled on theonlinecasino.co.uk and mogobet.com (system.listMethods lists pingback.ping + system.multicall). Issued pingback.ping(sourceURI=http://<oast>/tag, targetURI=<real post URL>) with a live interactsh listener: the on...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "690d4d", "surface": "uat.playuk.com &amp; qa.playuk.com SPA bundles", "risk_area": "exposed JS secrets / source maps", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:24 UTC", "evidence": "Mapped the in-scope subdomain SPAs uat.playuk.com and qa.playuk.com (S3+CloudFront, Vue). Extracted the app bundles and inline runtime config (window.settings/siteconfig/config). Only secret-shaped value is a RavenTrack affiliate-pixel JWT...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "bc0166", "surface": "theonlinecasino.co.uk /wp-content/themes/Theonlinecasino/fetch-*.php", "risk_area": "LFI / SQLi / parameter injection in custom theme PHP", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:29 UTC", "evidence": "Directly executable theme PHP endpoints (fetch-games.php=5537 games, fetch-sports.php=158, fetch-promotions.php=6, fetch-sports-promotions.php=21) return cached JSON. Parameter fuzzing (file/cache/name/type/src/url/path/template/debug/refre...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "d7357f", "surface": "WordPress login (playuk/theonlinecasino/mogobet portal forms)", "risk_area": "weak/default credentials on WordPress admin", "outcome": "no_issue_found", "created_at": "2026-09-27 16:40:29 UTC", "evidence": "Bounded credential test (no massive brute force) against the reachable WordPress login surfaces for the enumerated admins: 31 passwords × {admin,playuk} on www.playuk.com/wp-login.php, and 31 × admin on the /theonlinecasino-portal/ and /mog...", "agent_name": "WordPress Fleet Hunter B"}, {"entry_id": "defa95", "surface": "play.neonrush.com /api/player/getPlayer|getPlayerDetails|getPlayerBalance|refreshToken (unauthenticated)", "risk_area": "IDOR / broken object-level authorization (player boundary)", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Player is derived server-side from the session cookie, not from client input. Supplying PlayerId/playerId/PlayerID/id/UserHash/Email query params or X-Player-Id/X-User-Id/Authorization headers always returned the anonymous player (PlayerId:...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "d5d77f", "surface": "play.neonrush.com /api/getTenantData,getWhiteLabelConfig,getDefault (tenant selection via wl/whiteLabelId)", "risk_area": "cross-tenant IDOR / tenant boundary", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Tenant is fixed per deployment. getDefault?wl=200 and getTenantData?wl=284/200/166/8 returned the host's own tenant (whiteLabelId=284, whitelabelName \"neonrush\") or an empty object; the wl/whiteLabelId param is not honoured. Confirmed on pl...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "222fae", "surface": "play.neonrush.com authenticated player IDOR (balance/account/wallet, /api/deposit/*, /api/withdrawal/*)", "risk_area": "IDOR / horizontal privilege escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Could not obtain a player session to test authenticated object access: registration via /api/registration/registrationStepFirst is blocked server-side with em_feature_not_allowed_in_region_text (egress IP geolocated NL, isActiveCountry:fals...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "23a037", "surface": "play.neonrush.com + play.mrslot.com client JS bundle (/_next/static/chunks/5218-*.js)", "risk_area": "credential / secret exposure in client code", "outcome": "reported", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Reported as vuln-0008 and now broadened by the Shared-Platform Cross-Tenant Amplifier: the same byte-identical chunk (sha256 47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7e683992fcac, 73033 B, identical buildId WpePWuKOn3XrgMNqj5LeW)...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["reported"]}, {"entry_id": "0e3dbe", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "prototype pollution / injection", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Endpoint is reachable unauthenticated and echoes caller-supplied keys (returned {\"FreeSpinsOffer\":{},\"Deposit\":{},\"undefined\":{...}}). Requests carrying __proto__/constructor.prototype bodies were blocked by the edge WAF (Incapsula 403), so...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "5f771b", "surface": "play.neonrush.com /api/player/loginOneTime and /api/player/getErrorFromCache", "risk_area": "authentication bypass / session minting", "outcome": "ruled_out", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "loginOneTime with guessed messageid values (1, 100, all-zero UUID) returned success:false with a trustly_login_failed popup and no player/Token; getErrorFromCache?messageid= returned empty. No session is minted without a valid provider call...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "828857", "surface": "jazzyspins.com /api/pp/games + /api/worker/games", "risk_area": "query-param injection / mass-data handling", "outcome": "no_issue_found", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "Public catalogue endpoints return 200. Injecting provider=1', whitelabelId=284', lang=en', country=1', \"1 OR 1=1\", id=1' and other params produced byte-identical responses (7,167,811 bytes), so parameters are not processed by the backend; n...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "4caecb", "surface": "play.africasports.com, play.acelucky.com, play.777bet.casino, play.betstorm.com, play.dynobet.com, play.luckcity.com, play.mamzinobet.com, play.mrrex.com, play.moneyplay.com, play.ne-bet.com, play.q88bets.com, play.stakespin.casino, play.savibet.com, play.rainbetsplash.com", "risk_area": "attack surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:44:47 UTC", "evidence": "No DNS for these play.* hosts (dig returns nothing; proxy 502 = unresolved, not a target response); play.betstorm.com resolves to Cloudflare but the origin returns 522. play.mogobet.com and play.mrslot.com resolve but sit behind Imperva (40...", "agent_name": "ProgressPlay IDOR Hunter"}, {"entry_id": "fa834f", "surface": "play.* player apps (play.chitchatbingo.com, play.uk-bingo.net, play.pandabingo.com, play.wombatbingo.com, play.queensbingo.com, play.jazzyspins.com)", "risk_area": "Unauthenticated CMS proxy / broken access control (blast-radius check for vuln-0003)", "outcome": "ruled_out", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Imperva challenge passed with agent-browser (reload loop); in-page fetch from each host returns HTTP 404 (Next.js player-app 404 page) for /api/cms/users, /api/cms/users/count, /api/health and /api/pp/games. The Betable/ProgressPlay player...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "538573", "surface": "promotions.pandabingo.com", "risk_area": "Subdomain takeover / unconfigured vhost", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Serves the Plesk default \"Web Server's Default Page\" from 77.68.12.66 with no CNAME to any claimable third-party service; DNS record is under the organisation's own control. Unconfigured vhost only — not a takeover candidate.", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "cc9cad", "surface": "uat.* subdomain discovery across all 47 in-scope apexes", "risk_area": "Additional tenants carrying the same Next.js/CMS-proxy build", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "DNS A/CNAME resolution for uat.<apex> on all 47 apexes: only uat.chitchatbingo.com, uat.pandabingo.com and uat.uk-bingo.net resolve to the shared EKS ELB (the three hosts already reported in vuln-0003); uat.playuk.com resolves to CloudFront...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "cbf9b6", "surface": "Marketing Nuxt fleet /api/cms proxy blast radius (chitchatbingo, pandabingo, queensbingo, wombatbingo, uk-bingo.net, jazzyspins, vampirebingo, slotlux, betarno)", "risk_area": "Unauthenticated CMS proxy / broken access control (blast-radius check for vuln-0003)", "outcome": "ruled_out", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Control: the marketing apps are Nuxt 3/Nitro, whose entire server route table is /api/pp/games and /api/worker/games (only /api/* literals extracted from the shipped _nuxt bundles). Direct probes of /api/cms/users, /users/count, /users-perm...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "598161", "surface": "Public game catalogue /api/pp/games + /api/worker/games (marketing fleet)", "risk_area": "Query-parameter injection / unauth data exposure / reflection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:45:22 UTC", "evidence": "Intended public catalogue (5,518 records, Access-Control-Allow-Origin: *, cached 300s, no PII/secrets). 15 param/payload variants (wl, whiteLabelId, tenant, siteId, gameId, id, callback, filter=1', <script>, pagination[...], url=, path trav...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "e0aa35", "surface": "acedbet.com", "risk_area": "Unauthenticated CMS proxy (blast-radius check for vuln-0003) / general surface", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:45:57 UTC", "evidence": "Every request (including the root `/`) returns HTTP 429 from Vercel, repeatedly, even when spaced ~8s apart — egress is rate-limited/blocked, so /api/cms and the app surface could not be observed. The 429 body (data-astro-cid marker) indica...", "agent_name": "CMS Proxy Fleet Hunter"}, {"entry_id": "b6ade2", "surface": "Cross-tenant operator-panel credential reuse (Betty Admin product, 47-apex fleet)", "risk_area": "Weak/default credentials — reuse across tenants", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Enumerated ~110 operator/admin hostname labels (appmanager, app, admin, manage, manager, backoffice, bo, ops, panel, dashboard, console, operator, staff, crm, risk, bi, affiliate, rabbit, betty, etc.) across all 47 apexes (DNS brute) plus s...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "568f9d", "surface": "bonus.supabet.co.uk (HTTP Basic operator panel)", "risk_area": "Weak/default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Endpoint is protected by HTTP Basic (WWW-Authenticate: Basic realm=\"Login\"). A bounded set (admin/admin123, admin/admin, admin/password, supabet/supabet, bonus/bonus, etc.) all returned 401, and the server then rate-limited (429), so brute...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "6f82b3", "surface": "partners.jackpot.com Cellxpert partner/admin login (/authenticate, /authenticate/admin-auth)", "risk_area": "Weak/default credentials", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Exposed partner portal and a separate admin login (/v2/login/admin-login/). Login POST /authenticate/admin-auth returns {\"error\":true,\"isCaptchaRequired\":true,\"reason\":\"Bad Captcha\"} for every credential — the server rejects on captcha BEFO...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "245ced", "surface": "affiliates.neonrush.com (RavenTrack affiliate portal) POST /account/login", "risk_area": "Weak/default credentials", "outcome": "ruled_out", "created_at": "2026-09-27 16:48:26 UTC", "evidence": "Recovered the real login endpoint (POST /account/login, Laravel Sanctum; CSRF via /sanctum/csrf-cookie) and replayed a bounded set with a valid X-XSRF-TOKEN. Every attempt returned 422 {\"errors\":{\"email\":[\"Credentials not found.\"]}} and the...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "216f06", "surface": "WordPress wp-admin logins (jeffbet.net, playuk.com, theonlinecasino.co.uk, mogobet.com, betmaze.co.uk, betsuna.com)", "risk_area": "Weak/default administrative credentials", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "Greatly expanded credential test on the enumerated accounts: 106,684 candidates were evaluated per account for betmaze_login (betmaze.co.uk), betsunaadmin (betsuna.com) and admin (betsuna.com) - ~320,000 attempts in total, comprising the to...", "agent_name": "WP Takeover Chain Validator", "previous_outcomes": ["no_issue_found"]}, {"entry_id": "84017c", "surface": "Hidden operator/admin consoles across the 47-apex fleet (hostname discovery)", "risk_area": "Exposed operator/admin panel discovery", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "Subfinder (16 apexes) + crt.sh + ~110-label DNS brute over all 47 apexes surfaced only known/previously-mapped hosts; the only new admin-ish finds were marketing/affiliate surfaces (partners.jackpot.com, affiliates.neonrush.com, bonus.supab...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "81ab56", "surface": "tangobet.co.uk sibling apps (deletemyaccount.tangobet.co.uk, app.tangobet.co.uk)", "risk_area": "Exposed operator panel / weak credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "deletemyaccount.tangobet.co.uk is a 2.6KB static SPA with no JS bundle and no API endpoints (no login). app.tangobet.co.uk is an AppsFlyer OneLink deep-link page (noindex). Neither exposes a management panel or credential login, so the Bett...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "e28959", "surface": "acedbet.com Auth.js credentials login (/api/auth/callback/credentials)", "risk_area": "Weak/default credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "acedbet.com is a player-facing casino site (Sign in / Create account), not an operator console; no /admin surface exists (client-routed /admin renders the public SPA). The Auth.js credentials endpoint returned 403 {\"error\":\"Access denied\"}...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "46c22d", "surface": "uat.playuk.com (Markor lobby) + api-uat.playuk.com", "risk_area": "Exposed operator panel / weak credentials", "outcome": "not_applicable", "created_at": "2026-09-27 16:48:32 UTC", "evidence": "uat.playuk.com is the PlayUK player lobby SPA (Vue/Nuxt, server: MarkorLobby); it has no login form in-page and no operator/admin routes. Its backing API api-uat.playuk.com returns 401 (JSON) for all paths. No operator console with default...", "agent_name": "Default Cred Reuse Hunter"}, {"entry_id": "6d32ad", "surface": "acedbet.com POST /api/auth/callback/credentials", "risk_area": "Authentication — credential validation, CSRF enforcement, enumeration, brute-force, callbackUrl redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Endpoint returns HTTP 403 {\"error\":\"Access denied\"} for every input: valid CSRF + wrong creds, missing/garbage CSRF, empty creds, JSON/text-plain bodies, method override, X-Auth-Return-Redirect:1, full browser headers, and a fresh page-gene...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "b2d561", "surface": "acedbet.com /api/auth/error and /api/auth/signin pages", "risk_area": "Reflected XSS / open redirect", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "error param is not reflected (tested <script> and \"><img onerror> payloads and a benign marker; none appeared in the HTML). Vercel WAF blocks <script> in query with 403 {\"error\":{\"code\":\"403\",\"message\":\"Forbidden\"}}. signin?callbackUrl=http...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "5b8575", "surface": "acedbet.com POST /api/auth/signout", "risk_area": "CSRF on state-changing endpoint", "outcome": "no_issue_found", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Signout without a valid CSRF token returns 302 to /api/auth/signin?error=MissingCSRF; token required and rejected when invalid.", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "5c0c15", "surface": "acedbet.com password-reset Server Action (POST /?modal=forgot-password)", "risk_area": "User enumeration / reset-flow abuse", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Action reached (body [\"email\",\"en\"]) but returns 1:{\"success\":false,\"error\":\"ACCESS_DENIED\"} for the probed address, so existing-vs-nonexistent response differences could not be compared. Client-side validator rejected mailinator.com addres...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "fd2dc6", "surface": "acedbet.com registration Server Action (POST /?modal=create-account)", "risk_area": "Account creation abuse / anti-bot control enforcement", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Action executes its business logic regardless of x-is-human (absent, empty, 5KB junk, \"hello\", \"[]\") but always returns 1:{\"success\":false,\"error\":\"ACCESS_DENIED\"} for every email/country/btag tested, including from the real UI with a real...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "3d8a79", "surface": "acedbet.com x-is-human anti-bot header (all POST routes)", "risk_area": "Security-control enforcement / bot-protection bypass", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Auth Server Actions process requests with the header absent or forged (junk/empty/non-JSON), proving the client-side token is not enforced there; the token's signing key material is hardcoded in the client SDK so it is forgeable. No route w...", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "096efe", "surface": "acedbet.com /api/auth/session and /api/auth/csrf", "risk_area": "Session / JWT handling and cookie flags", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:48:56 UTC", "evidence": "Anonymous session returns null; CSRF cookie confirmed HttpOnly+Secure+SameSite=Lax. No session/JWT could be obtained (login denied), so signing strength, alg confusion, fixation and session-cookie flags could not be assessed.", "agent_name": "Acedbet Auth.js Hunter"}, {"entry_id": "2440ef", "surface": "/revolve/api/account/* and /payments/* object-scoped routes (balance, history, updateProfile, transactionStatus, cancelPendingWithdrawal)", "risk_area": "IDOR / BOLA", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "All routes resolve the player from the SessionCorrelationId cookie; no player/object identifier is accepted. Swapping the userCorrelationId cookie returns the session owner's data (cookie ignored); random/removed session -> 401. transaction...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "3d80df", "surface": "POST /revolve/api/account/updateProfile", "risk_area": "Mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Server whitelists fields: securityLevel, vip, playerGroupIds, kycStatus, depositCount, bonusAbuser, optoutOfAllRewards, registrationLevel were accepted in the request (HTTP 200) but none changed in the returned profile. Only whitelisted pro...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "a2631d", "surface": "POST /revolve/api/account/mobileCheck (api-uat/api-qa.playuk.com)", "risk_area": "Unauthenticated account enumeration", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registered mobile -> HTTP 400 {\"code\":30,\"message\":\"Mobile Number already exists.\"}; unregistered -> HTTP 200. No session required; 20/20 requests accepted (no rate limit).", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "fb3ef4", "surface": "CORS policy on api-uat.playuk.com (/revolve/api/*)", "risk_area": "Cross-origin data exposure with SameSite=None cookies", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Access-Control-Allow-Credentials: true is returned universally, but Access-Control-Allow-Origin is only emitted for the allow-listed origin https://uat.playuk.com. Attacker origins (evil.example, null, other playuk hosts) receive no ACAO, s...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "73d521", "surface": "POST /revolve/api/account/login (api-uat/api-qa.playuk.com)", "risk_area": "Account lockout denial of service", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "3 failed passwords -> HTTP 400 code 246 \"Player cannot login as too many failed login attempts\"; the correct password is then rejected (locked >=17 min, still locked at time of testing). Unauthenticated, per-account.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "fbd691", "surface": "POST /revolve/api/account/validateSMS and /resendSMS", "risk_area": "Unauthenticated OTP validation / brute force", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "With the correct parameter (smsPin) both endpoints return HTTP 401 \"Invalid session or session has expired\" before any code comparison; resendSMS also 401. OTP validation is session-bound.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "f58c0d", "surface": "POST /revolve/api/account/checkEmail (api-uat/api-qa.playuk.com)", "risk_area": "Unauthenticated account enumeration", "outcome": "reported", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registered email -> HTTP 200 (empty); unregistered -> HTTP 404. No session required; 30/30 requests accepted (no rate limit). Reproduced on both api-uat and api-qa with separate per-environment databases.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "268eb7", "surface": "GET/POST injection sweep on /revolve/api/account/checkEmail, mobileCheck", "risk_area": "SQL injection / NoSQL injection", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "SQLi markers (quote, boolean, UNION, SLEEP/WAITFOR/pg_sleep) produced no error or timing differential (all ~0.09s). NoSQL/type-confusion objects gave 404 (checked at format) or a generic 500 on mobileCheck with no data leak.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "8b718e", "surface": "POST /revolve/api/account/changePassword", "risk_area": "Account takeover via password change", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Client contract requires oldPassword + newPassword; the endpoint is session-gated. No password-only or token-only change path was found.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "aeaae0", "surface": "POST /revolve/api/account/updateEmail and /updateMobileNumber", "risk_area": "Account takeover via email/mobile change", "outcome": "ruled_out", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "updateEmail returned code 193 \"Email has already been updated.\" for fresh, already-registered and unrelated addresses, and the profile email never changed. updateMobileNumber validates format. No unverified identifier-change path observed.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "af7389", "surface": "Session management (SessionCorrelationId / userCorrelationId cookies)", "risk_area": "Session fixation / predictable tokens", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Every login issues a fresh random UUID session; a second login invalidates the first (single active session); logout invalidates immediately. Session cookie is Secure/HttpOnly. No fixation or reuse observed.", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "90d629", "surface": "POST /revolve/api/register/lite (account creation)", "risk_area": "Business logic / tenant confusion", "outcome": "no_issue_found", "created_at": "2026-09-27 16:53:29 UTC", "evidence": "Registration requires a full validated profile and rejects duplicate email/mobile; account is created under the PLAY-UK-CASINO tenant; accountSystemTag/platformTag supplied in later requests are ignored (session tenant enforced). Anti-fraud...", "agent_name": "PlayUK UAT API Hunter"}, {"entry_id": "b51b71", "surface": "betmaze.co.uk / betsuna.com — custom child-theme fetch-sports.php, fetch-promotions.php, fetch-sports-promotions.php, fetch-games.php", "risk_area": "SSRF / path traversal / injection / unauth data exposure in custom theme code", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "Only fetch-games.php consumes input: gameType (string compare) and category (case-insensitive substring match over the game catalogue). Traversal payloads (../../etc/passwd, %2f variants, php://filter) return count 0 (no file read); quote/O...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "da00ee", "surface": "betmaze.co.uk, betsuna.com, jeffbet.net — /wp-json/wp/v2/users (WordPress REST user enumeration)", "risk_area": "Unauthenticated information disclosure (username enumeration)", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "Unauth GET returns login usernames: betmaze.co.uk -> id1 slug 'betmaze_login'; betsuna.com -> id2 slug 'betsunaadmin'; jeffbet.net -> ids 1/2/5 slugs 'admin','simon-young','ross-young'. Also enumerable via ?author=N (betmaze.com -> /author/...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "9dc081", "surface": "betmaze.co.uk — wp-login.php", "risk_area": "Missing rate limiting / account lockout on authentication", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "15 consecutive failed logins (plus ~20 in a separate run) each returned HTTP 302 with no 429/lockout/CAPTCHA; a subsequent attempt still processed normally. No WC_* / Limit-Login style throttling observed. Contrast: jeffbet.net returns 403...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "4b8b96", "surface": "betmaze.co.uk & betsuna.com — xmlrpc.php (system.multicall / wp.getUsersBlogs)", "risk_area": "Missing restriction on excessive authentication attempts (XML-RPC brute-force amplification)", "outcome": "reported", "created_at": "2026-09-27 16:56:01 UTC", "evidence": "POST system.listMethods shows system.multicall, wp.getUsersBlogs and pingback.ping enabled. A single system.multicall request carrying 30 wp.getUsersBlogs attempts was fully processed (HTTP 200, 30 faultCode entries) — no throttling, so one...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "2a4682", "surface": "jeffbet.net — wp-login.php and xmlrpc.php", "risk_area": "Brute force / missing authentication throttling", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "15+ rapid failed POSTs to /wp-login.php returned HTTP 403 for the first 5 then HTTP 429 (rate limited), and xmlrpc.php returns 403 at the edge (nginx/WP Engine). A control is present, so this is not a brute-force vector here.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "c3cdb3", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — WordPress REST write endpoints", "risk_area": "Unauthenticated content/user modification (REST write endpoints)", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "POST /wp-json/wp/v2/users with username+email+password on betmaze/betsuna returns 401 rest_cannot_create_user; POST /wp/v2/posts, /pages, /media return 401 rest_cannot_create. No unauthenticated write/modify path via REST.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "ee7046", "surface": "jeffbet.net — WordPress plugins (CF7, Responsive Accordion &amp; Collapse, Redirection, Akismet)", "risk_area": "Known plugin CVEs / unauthenticated plugin functionality", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "Plugins/versions read from unauthenticated readme.txt: contact-form-7 6.1.7, responsive-accordion-and-collapse 2.5.3, redirection 5.9.0, akismet 5.7.2. REST namespaces for each require auth (redirection/v1/redirect 401, contact-form-7/v1/co...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "d39faf", "surface": "jeffbet.net — /wp-json/wpe_sign_on_plugin/v1/* (WP Engine Sign-On)", "risk_area": "Authentication bypass via SSO/sign-on endpoints", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:06 UTC", "evidence": "GET /wp-json/wpe_sign_on_plugin/v1/login and /is_user_logged_in both return 307 with Location: /wp-login.php (auth required); POST /has_logged returns \\\"false\\\". No credential or session can be obtained without a valid login.", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "487571", "surface": "betmaze.co.uk / betsuna.com — wp-admin/admin-ajax.php custom actions", "risk_area": "Unauthenticated custom AJAX actions", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "POST admin-ajax.php with actions fetch_games/fetch_sports/get_promotions/getTenantData etc. all returned HTTP 400 body '0' (no such handler) on betmaze and betsuna — the custom theme registers no admin-ajax actions. The fetch-*.php files ar...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "974c5a", "surface": "betsuna.com — wp-login.php / xmlrpc.php", "risk_area": "Authentication throttling behaviour", "outcome": "reported", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Resolved (was needs_follow_up due to an earlier transient edge 400/timeouts). Re-tested from this environment: xmlrpc.php on betsuna.com works and is completely unthrottled - a single system.multicall request carrying 500 wp.getUsersBlogs a...", "agent_name": "WP Takeover Chain Validator", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "fe7cb9", "surface": "betmaze.co.uk / betsuna.com — xmlrpc.php pingback.ping", "risk_area": "XML-RPC pingback SSRF", "outcome": "ruled_out", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Re-validated by an independent agent. Control: the origin returns a byte-identical canned IXR fault (faultCode 0, empty faultString, 372B) for pingback.ping on every input, including inputs stock WordPress answers with distinct codes/messag...", "agent_name": "SSRF & Error-Leak Pivot Hunter", "previous_outcomes": ["needs_follow_up", "reported"]}, {"entry_id": "6959f9", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — web root &amp; wp-content", "risk_area": "Exposed sensitive files / backups / directory listing", "outcome": "no_issue_found", "created_at": "2026-09-27 16:56:11 UTC", "evidence": "Probed wp-config.php(.bak/~/.save/.old/.orig), .env, .git/config, debug.log, .user.ini, .htaccess, phpinfo.php, dir listings (wp-content/uploads|plugins|themes), composer.json, theme .DS_Store/backups on all three hosts: all 403/404 or empt...", "agent_name": "WordPress Fleet Hunter A2"}, {"entry_id": "015433", "surface": "Imperva-fronted in-scope hosts (www.highstakes.co.uk, www.supabet.co.uk, www.hotwinscasino.com, play.betzi.co, www.luckcity.com, www.mrrex.com, www.mamzinobet.com, lobby.moneyplay.com, www.ne-bet.com, www.betblink.com, www.21luckybet.com, www.lekkerbets.co.za)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "reported", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "RESOLVED (Shared-Platform Cross-Tenant Amplifier) — this row was wrong, not the hosts. The edge block is a browser-solvable Incapsula challenge, not an IP-level deny, and it does not protect static assets. Every listed host that could be re...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["ruled_out", "needs_follow_up"]}, {"entry_id": "2b9d33", "surface": "promo.hotwinscasino.com", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: the openresty origin behind Cloudflare returns 403 for every request (body '403 Forbidden / openresty/1.31.1.1'). Tested direct, encoded paths, Host-header variants, spoofed XFF/X-Real-IP/CF-Connecting-IP, Referer/Origin, and a rea...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "16dd65", "surface": "games.playuk.com", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: AWS ALB returns a blanket fixed 403 (Server: awselb/2.0, 118-byte body) for EVERY path including the apex '/', so there is no restricted path prefix to encode around. Tested 17 paths/encodings (/%2f, //, /%2e/, /./, static assets,...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "c92ddc", "surface": "SiteGround sgcaptcha WordPress fleet (headless.mrslot.com, headless.mrmobi.com, staging6.mrsuperplay.com, staging3.mrjackvegas.com, headless.slotlux.com, headless.queensbingo.com, headless.jazzyspins.com, comingsoon.pandabingo.com)", "risk_area": "Edge WAF bypass / bot-challenge bypass", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:22 UTC", "evidence": "Control: SiteGround sgcaptcha JS proof-of-work challenge (202 + /.well-known/sgcaptcha). The challenge IS solvable — a real headless Chrome completed it and obtained the `_I_` cookie — but the origin then returns '403 Forbidden / Access to...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "7aeaf2", "surface": "whm.betmorph.com, cpanel.betmorph.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "whm.betmorph.com (intermittent) and cpanel.betmorph.com (consistent) return Duda 'SITE NOT FOUND' (dm404* classes, irp.cdn-website.com assets). Filed vuln-0015 (medium). Provider-specific CLAIMABILITY evidence added by this review: Duda hel...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["reported"]}, {"entry_id": "1bba35", "surface": "casino.playuk.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "A -> Cloudflare -> WP Engine origin; HTTP 404 \"Site Not Configured ... domain is successfully pointed at WP Engine, but is not configured for an account on our platform\" for all paths; HTTPS 301-redirects to www.playuk.com (partial mitigati...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "a3f464", "surface": "qa.uk-bingo.net, qa.pandabingo.com, qa.chitchatbingo.com, qa.playuk.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "Re-tested 2026-09. All four CNAME -> d1ama3lmihrvrd.cloudfront.net (live). qa.pandabingo.com and qa.playuk.com serve HTTP 200 live AmazonS3-via-CloudFront content -> CONFIGURED, not dangling. qa.uk-bingo.net (TLS handshake failure) and qa.c...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "df5d6f", "surface": "support.uk-bingo.net", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> ukbingo.zendesk.com -> 301 /app/help-center-closed/. KEY CONTROL TEST: a random unregistered subdomain zzznotreal99x8y7.zendesk.com returns BYTE-IDENTICAL responses (301 to help-center-closed with utm_content=<host>; 404 9-byte on...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "44dfa4", "surface": "api.pandabingo.com, api.playuk.com, api.uk-bingo.net", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "Re-tested 2026-09. Named control = AWS-assigned distribution identifier + ACM requirement: CNAME -> d31tqz5bd5ida4.cloudfront.net which has NO A record (distribution deleted; names do not resolve). The dXXXX.cloudfront.net hostname is rando...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "51ea3b", "surface": "wiki.jackpot.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "reported", "created_at": "2026-09-27 16:58:24 UTC", "evidence": "CNAME -> cname.vercel-dns.com; Vercel edge returns 404 x-vercel-error: DEPLOYMENT_NOT_FOUND, byte-identical to an arbitrary unconfigured host; no _vercel TXT -> domain unassigned/claimable. Filed vuln-0011.", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "884c7b", "surface": "www.jackpot.com restricted-path classes (/wp-admin, /wp-login.php, /xmlrpc.php, *.php, /.git/config, /content-admin, /api/admin)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Control: the AWS ALB's substring/regex rule classes. Unlike the prefix rules (/admin*, /Areas/Admin*), these matched every encoded variant tested (/%2f, /%2F, /%2f%2f, /%252f, //, /./, /%2e/, /.%2f, /%5c, trailing %2f/%20/%09/%23/%2e/., ;/,...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "182cc9", "surface": "app.tangobet.co.uk /wp-login.php (Cloudflare path rule)", "risk_area": "Edge WAF bypass / path-normalization", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Cloudflare returns 403 'Access Denied' (1148 B) for /wp-login.php, but the rule is case/postfix-sensitive: /WP-LOGIN.PHP, /wp-login.php%23 and /wp-login.php/ pass the edge and hit the origin (404, 24 B) because the host serves a static Apps...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "976fd8", "surface": "Next.js / Nuxt marketing hosts (betmorph.com, 777tigers.com, slotlux.com, acedbet.com, uat.*, playuk.com SPAs)", "risk_area": "Query-string router bypass of edge path rules", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Tested `?_route=/admin`, `/admin?_route=/`, `/%2fadmin`, `/admin/../admin` against /admin on each host: no query-string trick changed routing or defeated an edge rule (777tigers `/%2fadmin` -> 400, betmorph -> 307, slotlux -> SPA index 200...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "7354e6", "surface": "uat.uk-bingo.net /api/cms/[...path] proxy — \"Malicious Path\" guard", "risk_area": "Edge/proxy guard bypass (SSRF / path-normalization)", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:28 UTC", "evidence": "Tested guard-bypass encodings against the proxy's path check: %2f%2f, %2F%2F, %252f%252f, %5c%5c, ..%5c..%5c, %2e%2e%2f, tab/space-prefixed, @-prefixed, http:%2f%2f, x%00 forms — none produced a fetch of an external host; all returned a sam...", "agent_name": "Edge WAF Bypass Hunter"}, {"entry_id": "4aa54e", "surface": "promotions.pandabingo.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "A -> 77.68.12.66 (Fasthosts; PTR linux.prod.activewin.co.uk) returns a Plesk \"Web Server's Default Page\" for ANY Host header. Control: the vhost is unconfigured on a shared Plesk server and can only be populated with server-side account acc...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "5b48a5", "surface": "games.luckcity.com, games.savibet.com, promo.luckcity.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Re-tested 2026-09. Named control = server/account ownership. A -> 45.63.98.231 (whois: Vultr / The Constant Company, PTR 45.63.98.231.vultrusercontent.com) returning the Cloudways SERVER-SIDE 'maintenance-domain-mapping' 403 (body iframes c...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "7156dd", "surface": "test.jackpot.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "CNAME -> chlfv.x.incapdns.net (Imperva/Incapsula). Control: the target is a vendor-managed hostname under Imperva's domain that a third party cannot register or bind; the site name resolves only within Imperva's platform, so there is no cla...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "6ecf02", "surface": "47 in-scope apexes + their subdomains (fleet DNS/takeover sweep)", "risk_area": "Subdomain takeover / dangling DNS (fleet-wide DNS sweep)", "outcome": "no_issue_found", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "A/AAAA/CNAME/NS/MX/TXT resolved for all 47 apexes and ~265 associated subdomains (recon inventory + certspotter/crt.sh CT + 105-name DNS brute force per apex with wildcard detection); every resolving host was HTTP/HTTPS-probed against known...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "ae3e91", "surface": "lobby.mrslot.com, lobby.mrmobi.com, lobby.mrjackvegas.com, lobby.mrsuperplay.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Re-tested 2026-09. Named control = no service + no provider claim flow. A -> 185.27.56.100 (whois: Computer Solutions Ltd, MT, AS51840); no listening service on TCP 80/443/21/8080/2082/2083 (all closed/filtered; no PTR). Bare-IP target with...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "33799b", "surface": "ftp.betmorph.com, mail.betmorph.com, smtp.betmorph.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "needs_follow_up", "created_at": "2026-09-27 16:58:32 UTC", "evidence": "Re-tested 2026-09 (30s timeouts). Cloudflare-proxied A (104.21.56.95 / 172.67.183.188); every HTTPS and HTTP request returns Cloudflare HTTP 522 (origin unreachable), consistently across attempts (while the same-zone whm/cpanel resolve to a...", "agent_name": "Subdomain Takeover Claimability Verifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "539572", "surface": "app.luckcity.com, app.savibet.com", "risk_area": "Subdomain takeover / dangling DNS", "outcome": "ruled_out", "created_at": "2026-09-27 16:58:40 UTC", "evidence": "CNAME -> <project>.web.app (Firebase Hosting). Both resolve to 199.36.158.100 and return 301 to the owning apex domain (luckcity.com / savibet.com), i.e. the Firebase Hosting project is claimed and serving content, so the resource is owned...", "agent_name": "Subdomain Takeover Sweeper"}, {"entry_id": "6ef926", "surface": "ProgressPlay marketing hosts /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Hardcoded third-party credentials in client bundle", "outcome": "reported", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Secret scan (gitleaks + manual review) of the marketing build's chunks found only the provider credential set (Evolution apiUsername/apiPassword, Skywind username/password/secretKey, Tomhorn sign_key) in chunk 5218-5c354764053c3ff3.js, whic...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "b8fcf7", "surface": "acelucky.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW) as africasports.com; all non-root paths and any query string return the Imperva 403 block page from this egress. Dynamic client-side testing not possible; identical build means the a...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "203140", "surface": "dynobet.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); Imperva 403 on all paths/query strings from this egress. Dynamic client-side testing not possible. Gap: WAF IP restriction.", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "7d1d15", "surface": "ProgressPlay marketing fleet __NEXT_DATA__ (africasports.com, acelucky.com, 777bet.casino, betstorm.com, dynobet.com)", "risk_area": "Client-side configuration / secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "The server-rendered __NEXT_DATA__ runtimeConfig is identical on all five hosts. Every embedded value is public-by-design or informational: paypalSandboxKey (PayPal sandbox/public client id), SMARTICO BRAND_KEY/LABEL_KEY (client widget ident...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "2bb682", "surface": "africasports.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Imperva/Incapsula blocks every path except `/` from the tester egress (all of /games, /promotions, /?a=1, /api/getTenantData return the 883-byte 403 block page to curl_cffi, in-page fetch, and a real headless browser), so reflected/DOM XSS...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "ad6e74", "surface": "777bet.casino marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); all non-root paths/query strings return the Imperva 403 block page from this egress. Dynamic client-side testing not possible; static build analysis applies. Gap: WAF IP restriction...", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "fe6bb3", "surface": "betstorm.com marketing SPA", "risk_area": "Client-side XSS / DOM XSS / open redirect", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:05:49 UTC", "evidence": "Same shared Next.js build (buildId WpePWuKOnX3rgMNqj5LeW); Imperva 403 on all paths/query strings from this egress. Dynamic client-side testing not possible. Gap: WAF IP restriction.", "agent_name": "ProgressPlay Marketing Hunter 2"}, {"entry_id": "4864e9", "surface": "www.neonrush.com (Cogni) — geo-restriction gate on all pages", "risk_area": "Access control / geo-restriction bypass (IP spoofing)", "outcome": "reported", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "GET / returns 302 -> /geo-block with no header or with a non-US X-Forwarded-For; returns 200 (full app, title \"Neon Rush\") with X-Forwarded-For: 8.8.8.8 or 127.0.0.1. Only XFF is honored (X-Real-IP/X-Client-IP/True-Client-IP/Forwarded ignor...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "0e3762", "surface": "www.neonrush.com ABP application services (/api/services/app/*)", "risk_area": "Broken function-level authorization on unauth endpoints", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:35 UTC", "evidence": "Enumerated 191 routes via /AbpServiceProxies/GetAll and /AbpScripts/GetScripts. All sensitive services (transactions, wallet, profile, notification, document, playerAccount) return 401 \"Current user did not login\" unauthenticated. Only low-...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "9636ea", "surface": "play.neonrush.com /api/* (ProgressPlay tenant 284)", "risk_area": "IDOR / unauth data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Re-enumerated the full client bundle route set (Game/*, player/*, deposit, withdrawal, aml, playResponsibly, registration). Anonymous calls return only the empty/anon player (getPlayer PlayerId:0, getPlayerDetails empty, getPlayerBalance 41...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "d8c126", "surface": "play.neonrush.com /api/record/saveLastAction", "risk_area": "Prototype pollution / reflected data", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "Endpoint echoes a fixed {FreeSpinsOffer,Deposit,undefined,TimeStamp} object. Attempts to send __proto__/constructor.prototype and nested-object bodies were rejected at the edge (Incapsula 403), so server-side prototype pollution could not b...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "e4a75e", "surface": "affiliates.neonrush.com admin/affiliate login", "risk_area": "Weak/default credentials & brute force", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "POST /admin/login and POST /account/login (Laravel Sanctum, CSRF via /sanctum/csrf-cookie) return 422 \"Credentials not found\" and then 429 \"Too many login attempts\" after ~5-6 attempts for the same account. Lockout enforced.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "b50eb0", "surface": "trk.neonrush.com tracker", "risk_area": "Open redirect / SSRF", "outcome": "no_issue_found", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "All probed paths (/click, /track, /redirect, /c/1, /r/1, /pixel, etc.) return 404 with a static error page; no redirect/tracking endpoint is reachable.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "930c98", "surface": "affiliates.neonrush.com /api/v1/*", "risk_area": "IDOR / broken authorization on affiliate API", "outcome": "ruled_out", "created_at": "2026-09-27 17:11:40 UTC", "evidence": "/api/v1/users/me, /api/v1/session/check, /api/v1/users/* return 401 \"Unauthenticated.\"; other guessed object paths return 404 \"Record not found.\" No unauth object read found.", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "f5bd58", "surface": "https://www.queensbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative (no DOM reflection/execution); /promotions 301 is a static route-rule redirect to play.queensbingo.com, not attacker-controlled; no redirect param honored; no URL prototype poll...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "c5b336", "surface": "https://www.pandabingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Same shared Nuxt template build as wombatbingo/slotlux; same param/hash/path DOM-XSS sweep (0 reflections/executions, 171 combos on the shared template), no redirect param honored, no client prototype pollution. Unknown paths redirect to /...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "8876ce", "surface": "https://www.wombatbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Broad param sweep (~57 params incl. clickkey/tracker/btag/affid/lang/title/query/s/keyword/redirect/return/next/url/callbackUrl) with HTML+attr-break XSS payloads: no payload reached the DOM (checked outerHTML reflection AND window.__x exec...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "40582b", "surface": "https://www.uk-bingo.net (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative; no redirect param honored; no client prototype pollution. Unknown paths fall back to / (SPA catch-all).", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "236be8", "surface": "https://jazzyspins.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). /lp/* and /promotion/* only 308-normalize to a trailing slash; /promotions is a static route-rule 301 to play.jazzyspins.com. No redirect param honored; no cli...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "028307", "surface": "https://www.vampirebingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Shared Nuxt template build. Param/path/hash XSS sweep negative; no redirect param honored; no client prototype pollution. Only third-party script is cloud.umami.is/script.js (standard, no URL-driven DOM sink).", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "97f0ec", "surface": "https://betarno.com (Nuxt + Prismic SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "Distinct Nuxt+i18n build. Query/path/hash XSS sweep negative; the only URL param reaching the DOM is clickkey -> href attribute binding (Vue escapes, prefix is https://www.betarno.com so no javascript:/scheme injection). /preview?token=&doc...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "2125cd", "surface": "https://www.chitchatbingo.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). Unknown paths fall back to / (SPA catch-all). No redirect param honored; no client prototype pollution. Content/config fetched from out-of-scope *.tech1960.wor...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "b78e2f", "surface": "https://slotlux.com (Nuxt SPA)", "risk_area": "Client-side DOM XSS / open redirect / prototype pollution / postMessage", "outcome": "no_issue_found", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "57-param DOM-XSS sweep plus path/hash tests negative (0 reflections/executions). Unknown paths fall back to / (SPA catch-all). No redirect param honored; no client prototype pollution. No embedded secrets/API keys found in the shipped bundl...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "58946d", "surface": "Nuxt marketing SPA CMS/config-content innerHTML sinks (shared across the 9 hosts)", "risk_area": "Stored/DOM XSS via CMS content rendered with innerHTML", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:13:40 UTC", "evidence": "The apps render CMS/config strings via innerHTML (e.g. sig_terms/sigTerms, heading/subheading/body/intro, footerHtml, compliance HTML, WordPress content.rendered). The data is fetched from OUT-OF-SCOPE sources (access-content-pp.tech1960.wo...", "agent_name": "Nuxt Marketing SPA Hunter"}, {"entry_id": "75cd8f", "surface": "www.neonrush.com /account/login and /api/services/app/playeraccount/register", "risk_area": "Captcha/anti-automation control on standard auth flows", "outcome": "ruled_out", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "Login and registration endpoints enforce a Cloudflare Turnstile challenge (\"You must prove that you are not a robot.\"); the interactive challenge could not be solved in the headless browser, so end-to-end login/session testing was not possi...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "f3ea57", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Missing authentication / anti-automation bypass on account creation", "outcome": "reported", "created_at": "2026-09-27 17:15:52 UTC", "evidence": "POST /api/services/app/playeraccount/registerexternalfromapi creates an active/login-capable account (successful:true, active:true, canLogin:true, userId increments) with no auth, no API key and no captcha; isusernameavailable confirms the...", "agent_name": "Neonrush Platform Hunter"}, {"entry_id": "86e5a0", "surface": "betmaze.co.uk & betsuna.com — /wp-json/oembed/1.0/proxy", "risk_area": "SSRF via oEmbed proxy", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "GET /wp-json/oembed/1.0/proxy?url=<any> returns HTTP 401 {\"code\":\"rest_forbidden\",\"message\":\"Sorry, you are not allowed to make proxied oEmbed requests.\"} for external (OAST) and internal (127.0.0.1, localhost, [::1], 169.254.169.254) targe...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "1d7cf9", "surface": "betmaze.co.uk / betsuna.com / jeffbet.net — /wp-json/* CORS response headers", "risk_area": "CORS misconfiguration (reflected Origin + credentials)", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "With Origin: https://evil.example the REST API reflects Access-Control-Allow-Origin and sends Access-Control-Allow-Credentials: true. This is WordPress core default behaviour (rest_send_cors_headers), not a site misconfiguration, and it is...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "f3a540", "surface": "jeffbet.net — plugin REST surface (contact-form-7, redirection, akismet, ACF, wpe)", "risk_area": "Unauthenticated plugin endpoints / plugin CVEs", "outcome": "no_issue_found", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "Fingerprinted installed plugins/versions: CF7 6.1.7, Redirection 5.9.0, Akismet 5.7.2, Yoast 28.3, ACF 6.8.8, Accordion FAQ 2.5.3 (all current). Plugin REST routes are access-controlled: /contact-form-7/v1/contact-forms -> 403 wpcf7_forbidd...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "ea0d54", "surface": "jeffbet.net — /xmlrpc.php", "risk_area": "XML-RPC pingback SSRF / credential brute force", "outcome": "ruled_out", "created_at": "2026-09-27 17:20:24 UTC", "evidence": "Control: POST /xmlrpc.php returns HTTP 403 (nginx \"403 Forbidden\", Cloudflare-fronted) for system.listMethods, pingback.ping and wp.getUsersBlogs alike — the endpoint is denied at the edge before reaching WordPress, so neither SSRF nor mult...", "agent_name": "WordPress Fleet Hunter A"}, {"entry_id": "c2255b", "surface": "ProgressPlay marketing/player fleet — client-side injection (africasports.com, acelucky.com, 777bet.casino, betstorm.com, dynobet.com)", "risk_area": "Reflected/DOM XSS and open redirect on the Imperva-fronted Next.js app", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Reached the sites only via the browser JS-challenge (page loads after open+reload), but every subresource `fetch()` and every direct navigation to a non-root path (`/game/<payload>`, `/games?search=`, `/promotions?id=`, `/nonexistent-<paylo...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "cd3f33", "surface": "ProgressPlay Next.js marketing/player fleet — __NEXT_DATA__ runtime config (www.africasports.com, www.acelucky.com, www.777bet.casino, www.betstorm.com, www.dynobet.com)", "risk_area": "Information disclosure of embedded secrets (config exposure)", "outcome": "ruled_out", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Extracted the full __NEXT_DATA__/runtimeConfig from the live page (buildId WpePWuKOnX3rgMNqj5LeW) on all five hosts. Every flagged value was classified: `paypalSandboxKey: sandbox_7bh7m9qm_hkgcyxcmtk4c9yq7` is a PayPal **sandbox publishable...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "161f63", "surface": "Marketing SPAs — client-side XSS / open redirect (www.mrslot.com, www.mrsuperplay.com, www.mrjackvegas.com)", "risk_area": "Reflected/DOM XSS and open redirect", "outcome": "no_issue_found", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "Nuxt/Vue SSG apps, directly reachable (HTTP 200, no WAF). Drove a real browser across 15 attacker-controlled query parameters (q,s,search,query,redirect,returnUrl,return,next,url,u,lang,locale,email,btag,err,error,msg) with `\"><img src=x on...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "e9cde7", "surface": "app.luckcity.com (Firebase Hosting / Dynamic Links project luck-city-i2zy6e)", "risk_area": "Open redirect / deep-link abuse", "outcome": "ruled_out", "created_at": "2026-09-27 17:21:07 UTC", "evidence": "`app.luckcity.com` is Firebase Hosting (CNAME luck-city-i2zy6e.web.app, 199.36.158.100) and answers with a fixed `301 Location: https://luckcity.com/`. Supplying `?link=https://example.com/pwn` (and the encoded/`apn` variant) does NOT redir...", "agent_name": "ProgressPlay Marketing Hunter"}, {"entry_id": "9be3d2", "surface": "POST/PUT /api/admin/users[/{id}]", "risk_area": "mass assignment / privilege escalation", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Create and update accept only username (and password on create); injected fields role, isAdmin, permissions, and id were ignored in the response and in the persisted record. The user model exposes only id/username/created/updated and has no...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "b2311f", "surface": "DELETE /api/admin/users/{id}", "risk_area": "sensitive data exposure (password hash)", "outcome": "reported", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "The delete response returns the full user row including the bcrypt password hash, while GET/POST/PUT do not. Reproduced with a synthetic user (created then deleted). Filed as vuln-0019.", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "8e0646", "surface": "POST /api/auth/login", "risk_area": "user enumeration (timing side channel)", "outcome": "reported", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Valid usernames respond consistently slower (~0.31s admin, ~0.28s betty_admin) than non-existent usernames (~0.21s) because a bcrypt comparison runs only for existing accounts; identical 401 body in all cases. Filed as vuln-0020.", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "1afe36", "surface": "POST /api/auth/login", "risk_area": "SQL/NoSQL injection and authentication bypass", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:20 UTC", "evidence": "Login is parameterized and type-checked. Payloads tried: single quote, ' OR '1'='1, admin'--, \"admin \" (trailing space), NoSQL operator objects for username and/or password ({$ne:null}), and an extra $where field; every wrong-credential att...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "909fa4", "surface": "/api/admin/* authorization enforcement", "risk_area": "broken access control (unauthenticated admin access)", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "Unauthenticated, malformed-token, and empty-bearer requests to GET/POST/PUT/DELETE on /api/admin/users, /players, /users/count all return 401 {\"message\":\"Unauthorized\"}; the 401 is emitted before any route logic. Auth is enforced server-sid...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "f3576e", "surface": "GET /api/admin/players", "risk_area": "undocumented route / additional data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "Undocumented GET /api/admin/players returns the same paginated/sortable/searchable player list as the documented POST /api/admin/players/search (params limit/page/search/sortField honored); it exposes no fields beyond the player dataset alr...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "f09883", "surface": "HS256 bearer JWT issued by /api/auth/login", "risk_area": "JWT forgery / weak signing secret", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "alg:none token rejected (401). An HS256 forgery requires the signing secret; the secret is not present in rockyou.txt (14.34M candidates) nor in the 10k common list previously attempted, and the token header carries no kid/jku/jwk to abuse....", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "0c93fc", "surface": "POST /api/admin/players/search (incl. /count, advancedFilter, sortField, search, page/limit)", "risk_area": "SQL/NoSQL injection via filter, sort, search and pagination", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:24 UTC", "evidence": "search and advancedFilter `value` inputs are bound, not interpolated: quote/% payloads are matched literally ('%' acts as a LIKE wildcard but '1 OR 1=1', stacked SLEEP(5), and filter-value SLEEP(5) produced no delay/error; a 100k-char searc...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "9806ad", "surface": "POST /api/admin/notifications/send", "risk_area": "unauthorized/mass notification action", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Deliberately not executed per the non-destructive rule: targetType accepts 'all' and 'selected', and a send would push to the full pushable audience (~1,046 players). Request-schema validation, authorization, and rate-limiting of this route...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "bd3364", "surface": "Betty Admin SPA rendered fields (username, players table)", "risk_area": "stored/reflected XSS in admin UI", "outcome": "ruled_out", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "All dangerouslySetInnerHTML occurrences in the shipped bundle belong to React/PrimeReact internals (DOM property handling, hydration bootstrap script, a label &amp;nbsp;); application data such as the username column is rendered through Rea...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "33e647", "surface": "API error handling (invalid inputs)", "risk_area": "information disclosure via error handling", "outcome": "no_issue_found", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Malformed or unexpected inputs (duplicate username, empty body, page=-1, non-numeric limit, wrong advancedFilter shape, PUT/DELETE on a non-existent id) all return a generic {\"statusCode\":500,\"message\":\"Internal server error\"} with no stack...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "e6f3d7", "surface": "Betty Admin SPA (index HTML + API responses)", "risk_area": "missing anti-framing headers / clickjacking", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "Responses carry no X-Frame-Options, no CSP frame-ancestors, no HSTS, no X-Content-Type-Options and no Referrer-Policy, and the SPA bundle contains no frame-busting logic, so the admin UI is embeddable in an iframe. Impact is not confirmed:...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "117573", "surface": "appmanager.tangobet.co.uk API CORS &amp; session model", "risk_area": "CORS misconfiguration / CSRF", "outcome": "not_applicable", "created_at": "2026-09-27 17:23:30 UTC", "evidence": "The API returns no Access-Control-Allow-Origin or Access-Control-Allow-Credentials headers for any origin, and OPTIONS preflight to /api/admin/users returns 404 (no CORS middleware). Authentication is via an Authorization bearer header, not...", "agent_name": "Betty Admin Backend Reviewer"}, {"entry_id": "487f20", "surface": "Betty Admin SPA bundle (index-BuNztArT.js) — Send Notification page (component Zg)", "risk_area": "bundle analysis: fields, HTML sinks, hidden endpoints, client-only restrictions", "outcome": "no_issue_found", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "Single bundle, no dynamic imports/lazy chunks. Notification page submits {title,content,targetType:'all'|'selected',advancedFilter?} to POST /api/admin/notifications/send; counts come from POST /api/admin/players/count; the response count/f...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "4e97a0", "surface": "POST /api/admin/notifications/send — advancedFilter handling / fail-open", "risk_area": "fail-open mass targeting", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "A valid zero-match filter (Status eq '__zz_no_such_status__', proven total:0 via players/count) produced count 0 on the send route, so the filter IS honoured for well-formed input (no observed fail-open). The behaviour for a MISSING or INVA...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "2b5480", "surface": "POST /api/admin/notifications/send — authorization &amp; method surface", "risk_area": "broken access control / unauthenticated access", "outcome": "ruled_out", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "No token or bad token -> 401 {\"message\":\"Unauthorized\"}; valid token -> 201. Route is POST-only: GET/HEAD/OPTIONS/PUT/PATCH/DELETE all -> 404 \"Cannot <METHOD> /api/admin/notifications/send\". Path variants (/trailing slash, //, /., mixed cas...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "5906ac", "surface": "POST /api/admin/notifications/send — input validation", "risk_area": "validation bypass / injection", "outcome": "no_issue_found", "created_at": "2026-09-27 17:32:21 UTC", "evidence": "Missing or empty title/content -> 400 {\"message\":\"Title and content are required\"} (checked before dispatch, so {} never delivers). Non-string title/content (number/object) are accepted (201) but no impact was demonstrable and the recipient...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "69fa9d", "surface": "Notification title/content rendered in player client", "risk_area": "stored content injection into player-facing push payload", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "Notification title/content are fully caller-controlled and stored/forwarded verbatim (no sanitization observed server-side; the admin UI renders nothing server-returned via an HTML sink). Whether the player-facing mobile/webview client rend...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "13cbeb", "surface": "Notification recipient-safety gates (pushable&gt;0, selected-requires-filter)", "risk_area": "client-side-only enforcement (CWE-602)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "The UI enforces recipient-safety gates (cannot send when matched-audience pushable===0; 'selected' requires a filter), but the API accepted a send request the UI would block, returning 201 {\"success\":true,\"count\":0}. Impact is unproven beca...", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "2dc782", "surface": "POST /api/admin/notifications/send — request frequency", "risk_area": "abuse controls / rate limiting", "outcome": "reported", "created_at": "2026-09-27 17:32:27 UTC", "evidence": "25 consecutive POSTs in 5.6s all returned 201; no 429, no Retry-After, no rate-limit headers. Filed as vuln-0021. Tests were pinned to a proven zero-recipient filter so no notification was delivered.", "agent_name": "Betty Notification Page Reviewer"}, {"entry_id": "ba974f", "surface": "affiliates/promos.dynobet.com and affiliates/promos.tangobet.co.uk (AWS Elastic Beanstalk, nginx)", "risk_area": "RCE via application origin (Spring/Actuator/app RCE)", "outcome": "ruled_out", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "nginx returns 403 only for `/` (and equivalent /%2f, //, /%2e/) and 404 for every other path (/index.html, /health, /actuator/env, /api, /.env, /..;/). No application content is served at all, so there is no reachable app surface; edge-bypa...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "1e0765", "surface": "uat.uk-bingo.net / uat.pandabingo.com — /api/cms/[...path] Strapi proxy", "risk_area": "SQL injection / DB access / RCE via CMS proxy", "outcome": "ruled_out", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "Proxy is GET/HEAD/OPTIONS only (OPTIONS -> `allow: GET, HEAD, OPTIONS`; POST/JSON + X-HTTP-Method-Override + ?_method=POST all -> 405). Strapi content-API filters are parameterized: `filters[username][$eq]=x'` and `$startsWith`/`$ne` return...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "8a46e7", "surface": "All 47 in-scope apex hosts — exposed RCE-capable tooling sweep (actuator, jenkins, solr, h2-console, .git/.env, trace.axd, swagger, graphql, docker, k8s, etc.)", "risk_area": "Exposed debug/admin RCE panels and config files", "outcome": "no_issue_found", "created_at": "2026-09-27 17:37:57 UTC", "evidence": "Bounded sweep of ~37 high-risk paths x 46 hosts. All 200 responses were catch-all SPA fallbacks (betmorph.com returned the identical 5616-byte Hercules index for every path; slotlux.com returned its 56884-byte Nuxt index for every path), i....", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "f71c90", "surface": "affiliates/promos.tangobet.co.uk (AWS Elastic Beanstalk)", "risk_area": "exposed backend / DB / endpoints", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "nginx front returns 403 for / and 404 for every probed path (/api, /api/v1, /api/login, /login, /register, /admin, /health, /status, /robots.txt, /.env, /actuator/env, /assets/, /portal). Only TCP 80/443 open on the ELB IPs (35.176.252.169,...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "aa576f", "surface": "tangobet.co.uk subdomain enumeration (db/mail/ops)", "risk_area": "exposed DB/mail subdomain", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "subfinder (-all) + crt.sh returned 38 names. Resolving: appmanager + deletemyaccount (Railway), affiliates/promos (AWS Elastic Beanstalk), app (AppsFlyer), www (Imperva). db/database/mysql/postgres/pg/mongo/redis/adminer/phpmyadmin/sql/mail...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "2825bc", "surface": "appmanager.tangobet.co.uk config/secret disclosure", "risk_area": "exposed config/secrets (.env, .git, source maps, backups)", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "Every non-asset path returns the 451-byte SPA index (Express catch-all); only /assets/index-BuNztArT.js, /assets/index-CSAF6Qde.css and /favicon.svg are genuinely served. No .env/.git/config/.map/backup file exists; traversal variants and V...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "f01230", "surface": "deletemyaccount.tangobet.co.uk (Railway)", "risk_area": "hidden API / email-sending primitive", "outcome": "no_issue_found", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "Serves a static account-closure page (2664 bytes + styles.css + assets/logo.png) via nginx/1.27.5; POST to any path returns 405 and GET returns the static page; no API, no form, and the only contact is a mailto: link to a third-party suppor...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "c89fbb", "surface": "appmanager.tangobet.co.uk database reachability", "risk_area": "exposed database service / DB credential disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:26 UTC", "evidence": "nmap shows every DB port filtered on the app host (3306/5432/27017/6379/1433/1521/9042/5984/9200/11211/5672/2375/9229); only TCP 80/443 are open (Railway edge 'railway-hikari'). The Postgres addon sits on Railway's private network with no p...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "214d27", "surface": "appmanager.tangobet.co.uk JSON body handling", "risk_area": "prototype pollution (Node) pivot", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "Sent __proto__ / constructor.prototype objects in the JSON body of /api/admin/players/search and nested inside advancedFilter: all returned normal 201 responses with unchanged data, no server error, and no observable side effect on a subseq...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "3ed848", "surface": "tangobet.co.uk DNS email-auth records (SPF/DKIM/DMARC)", "risk_area": "email spoofing / sender authenticity (missing DMARC)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "dig shows SPF 'v=spf1 include:mailgun.org ~all' (softfail) and NO DMARC record (_dmarc.tangobet.co.uk is empty); DKIM exists only for selector s1 (Mailgun RSA key). With no published DMARC policy, receivers get no reject/quarantine instruct...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "7a81b8", "surface": "tangobet.co.uk email infrastructure (SMTP/IMAP/Mailgun)", "risk_area": "email service reach / transactional-email credential exposure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "No self-hosted mail service exists: MX = mxa/mxb.eu.mailgun.org (Mailgun SaaS). No genuine SMTP/IMAP/POP service on any in-scope host — the 'open' 143/993 seen on the Imperva apex IPs are edge artifacts (arbitrary ports 1234/12345 also 'acc...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "8a28c8", "surface": "appmanager.tangobet.co.uk API error surfaces", "risk_area": "error-based DB/ORM information disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:38:32 UTC", "evidence": "Type-confusion/malformed inputs to /api/admin/players/search (page as object, page/limit as strings, operator/value as objects, invalid/absent field names) all return normal data or a generic {\"statusCode\":500,\"message\":\"Internal server err...", "agent_name": "Betty DB and Email Reach Hunter"}, {"entry_id": "d15dbb", "surface": "45.132.74.81 (origin IP of *.potsofluck.com) — ports 22/80/443/4000 (NoMachine NX 10.0.59)", "risk_area": "Host-level RCE via exposed remote-desktop/SSH service", "outcome": "ruled_out", "created_at": "2026-09-27 17:39:38 UTC", "evidence": "Discrepancy RESOLVED by independent re-scan (2x nmap -sV -Pn + --top-ports 1000): 45.132.74.81 exposes 22/tcp OpenSSH 9.6p1, 80/443 nginx 1.24.0, and 4000/tcp NoMachine NX Server 10.0.59 — port 4000 IS open now, so Red Team A's port claim w...", "agent_name": "Potsofluck Origin Services", "previous_outcomes": ["needs_follow_up", "ruled_out"]}, {"entry_id": "518e02", "surface": "In-scope reachable hosts — DB admin consoles (phpMyAdmin/Adminer/etc.)", "risk_area": "Exposed database management interface", "outcome": "no_issue_found", "created_at": "2026-09-27 17:41:42 UTC", "evidence": "Probed 25 DB-admin paths (phpmyadmin, phpMyAdmin, pma, adminer.php, sqladmin, dbadmin, mysqladmin, _phpmyadmin, phpMyAdmin-4.9.7, dbmanager...) across 20 reachable hosts (betmaze, betsuna, jeffbet, mogobet, playuk, theonlinecasino, appmanag...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "fcabc7", "surface": "betmaze.co.uk (/betmaze-portal/) & betsuna.com (/wp-login.php) — login forms", "risk_area": "Username enumeration via authentication error messages", "outcome": "reported", "created_at": "2026-09-27 17:43:45 UTC", "evidence": "Login-form error messages distinguish a valid account (\"password incorrect\") from an unknown one (\"unknown username\") without cookies or a nonce. This second oracle reveals account `admin` on betsuna.com, which the REST users collection doe...", "agent_name": "WP Takeover Chain Validator"}, {"entry_id": "28cc97", "surface": "betmaze.co.uk & betsuna.com — enumerated admin accounts (betmaze_login, betsunaadmin, admin)", "risk_area": "Account takeover via credential brute-force / password guessing (validation of the username-enumeration + missing-throttle chain)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:43:45 UTC", "evidence": "Chain capability validated end-to-end: identifiers are valid logins (confirmed via login error differential), the XML-RPC endpoint evaluates credentials genuinely (demo.sayHello succeeds in the same multicall), a single request carries 500...", "agent_name": "WP Takeover Chain Validator"}, {"entry_id": "a888c0", "surface": "appmanager.tangobet.co.uk — admin API features taking URLs/hosts (notifications, players, users, mobile-app)", "risk_area": "SSRF into internal services (Railway internal / cloud metadata / localhost)", "outcome": "not_applicable", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Enumerated the complete API surface from the SPA bundle and by fuzzing ~70 route names under /api/admin/* — no import/webhook/export/feed/url/host-consuming feature exists. `POST /api/admin/notifications/send` dispatches push notifications...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "3bab3a", "surface": "appmanager.tangobet.co.uk — /api/admin/players/search advancedFilter + sortField + search (JSON body, qs query, form-urlencoded)", "risk_area": "Prototype pollution (server-side, Node/Express) → RCE gadget", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Sent `{\"__proto__\":{...}}`, `{\"constructor\":{\"prototype\":{...}}}`, nested `advancedFilter.__proto__`, condition `field:\"__proto__\"`, plus qs forms `?__proto__[x]=`, `?constructor[prototype][x]=` and form-urlencoded equivalents (11 JSON + 5...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "26affb", "surface": "appmanager.tangobet.co.uk — host root and /api/* hidden routes (exec/import/upload/settings/config/export)", "risk_area": "Hidden dangerous functionality (file write / command exec / deserialization)", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "GET sweep of ~65 candidate admin route names (exec/run/upload/import/export/backup/db/query/sql/files/...) all return NestJS 404. Root and all non-API paths return the SPA index (451-byte index.html); /.env, /.git/config, /package.json, /pr...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "c6fc95", "surface": "appmanager.tangobet.co.uk — players search/filter/sort/pagination values (search, sortField, operator, field)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:07 UTC", "evidence": "Time-based and boolean probes on `search` (`' OR SLEEP(5)-- -`, `1;SELECT pg_sleep(5)--`, UNION, quote breakers) all returned in ~0.18-0.20s with `total:0` — no delay, no error. NoSQL operator injection in `advancedFilter.operator` (`$ne/$g...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "56f3d4", "surface": "www.neonrush.com — ABP application services (/api/services/app/*) enumeration for RCE-capable operations", "risk_area": "Unauthenticated file upload / import / template / command execution", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Enumerated all 191 ABP application-service actions from the unauthenticated `/AbpServiceProxies/GetAll` map and probed each (declared method, empty body). All file/import/export/exec/template-capable services (`documentuser/create`, `accoun...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "68d5bf", "surface": "www.neonrush.com — /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "Missing authentication for critical function — SSO token minting", "outcome": "reported", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "`POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=` returns a signed RS256 token with attacker-controlled sub/email/email_verified/balance claims, unauthenticated. Filed as vuln-0022 (medium)...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "72e9c8", "surface": "www.neonrush.com — authenticated document/KYC upload + pushCashPayment.authorizePayment(tenantBaseSiteUrl)", "risk_area": "File upload path traversal → arbitrary file write; SSRF via tenantBaseSiteUrl", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Resolved by the Neonrush Auth RCE Hunter with a live authenticated tenant-1 session. Document/KYC upload (`/api/accountverification/proof-documents`) requires a server-only `X-Server-Authorization` key (401 without it; no client copy of the...", "agent_name": "Neonrush Auth RCE Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "fc04bc", "surface": "api-uat.playuk.com &amp; api-qa.playuk.com — Markor revolve API (/revolve/api/*) for file/document upload", "risk_area": "File upload / path traversal / filename injection → code execution", "outcome": "not_applicable", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "Extracted the full 76-route `/revolve/api/*` inventory from the `uat.playuk.com` bundle: KYC is delegated to SumSub (`getSumSubAccessToken`, disabled on this tenant, code 213) and `kycDocumentUploaded` is a status flag only; there is no mul...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "8745c6", "surface": "play.neonrush.com — /api/record/saveLastAction (key echo)", "risk_area": "Prototype pollution → RCE gadget", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:14 UTC", "evidence": "All `__proto__`/`constructor`/`prototype` token variants (plain, unicode-escaped `\\u005f`, `\\u0074o`, mixed case, nested, array form, 4 content-types) are blocked by the Incapsula/Imperva WAF with a 403 `_Incapsula_Resource` page; the only...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "cb1678", "surface": "UAT Next.js route handlers — /api/cms/[...path], /api/env/vars", "risk_area": "Write / deserialization → code execution via the in-scope Next.js API routes", "outcome": "ruled_out", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "POST and PUT to `/api/cms/users` and `/api/env/vars` return HTTP 405; the catch-all proxy forwards only GET/HEAD/OPTIONS (prior agent confirmed POST→405 for the whole route). /api/env/vars only returns NEXT_PUBLIC_* vars. No write, upload o...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "dfb79d", "surface": "In-scope Next.js hosts (47 apexes + uat.* / neonrush / appmanager subdomains)", "risk_area": "React Server Components deserialization RCE (CVE-2025-55182) — fleet sweep", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "Swept the verified CVE-2025-55182 template across all 47 apex hosts plus uat.* and neonrush/appmanager subdomains (51 targets). No match anywhere. Reachable Next.js hosts (uat.*, play.neonrush.com, acedbet.com) are confirmed not vulnerable;...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "031690", "surface": "uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com (Next.js App Router UAT)", "risk_area": "React Server Components deserialization RCE (CVE-2025-55182)", "outcome": "no_issue_found", "created_at": "2026-09-27 17:45:20 UTC", "evidence": "Ran the official verified nuclei template for CVE-2025-55182 (React Server Components unsafe deserialization → unauth RCE, React 19.0.0-19.2.0) and a manual multipart/Next-Action payload with three `child_process` accessor variants against...", "agent_name": "Node API RCE Hunter"}, {"entry_id": "9ff418", "surface": "Nuxt 3 marketing fleet (wombatbingo/pandabingo/queensbingo/uk-bingo.net/jazzyspins/vampirebingo/betarno/chitchatbingo/slotlux) — /__nuxt_island/", "risk_area": "Nuxt island template injection → Nitro RCE (CVE-2026-71318 / CVE-2026-71320)", "outcome": "ruled_out", "created_at": "2026-09-27 17:47:30 UTC", "evidence": "CVE-2026-71318/71320 require the Nuxt island endpoint (/__nuxt_island/<Name>.json) with componentIslands enabled. On all 9 Nuxt marketing hosts the endpoint is absent: jazzyspins returns the Nuxt 404 error page (text/html, no JSON) and the...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "5f32cb", "surface": "uat.uk-bingo.net / uat.pandabingo.com — /api/cms/<collection> Strapi proxy (where[] oracle)", "risk_area": "Strapi unauth query-sanitizer bypass → admin secret exfiltration/account takeover (CVE-2026-27886)", "outcome": "ruled_out", "created_at": "2026-09-27 17:47:30 UTC", "evidence": "CVE-2026-27886 technique: compare meta.pagination.total for baseline vs `?where[id][$lt]=-1` (cannot match a row, so a vulnerable DB-layer WHERE collapses the count to 0). Tested via the unauth /api/cms proxy on uat.uk-bingo.net and uat.pan...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "b0f377", "surface": "www.neonrush.com /api/services/app/playeraccount/register + /login (Turnstile)", "risk_area": "anti-automation control bypass (captcha) via client-controlled tenant header", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Abp.TenantId:1 skips Turnstile on playeraccount/register and playeraccount/login (200 successful:true); without the header the same calls are rejected with 'You must prove that you are not a robot.' Filed vuln-0025.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "75b3cf", "surface": "www.neonrush.com /api/authentication/login", "risk_area": "auth bypass on server-to-server login (apiKey)", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "POST api/authentication/login returns 401 {errorcode:'InvalidAPIKey'} for arbitrary X-Server-Authorization values; the apiKey is genuinely validated (an empty header produces a model-validation 'apiKey required' error).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "c18355", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser|byusername", "risk_area": "IDOR on profile pictures (PII)", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "profile/getprofilepicturebyuser and byusername are reachable by a low-priv session but returned empty for all probed ids; updateprofilepicture returned HTTP 500 for several body shapes, so a picture could not be set and cross-user read of a...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "abe254", "surface": "www.neonrush.com /api/services/app/documentuser/getall + referafrienduser/getall", "risk_area": "IDOR via client-supplied userId", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Both endpoints returned only the caller's (empty) data and ignored a supplied ?userId= for a different user id — object scoping holds (contrast with the login-attempts IDOR).", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5caf28", "surface": "www.neonrush.com /api/services/app/userlogin/getuserloginattempts + getuserloginattemptcount", "risk_area": "IDOR / broken object-level authorization (arbitrary userId)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Confirmed IDOR: session A (user 1853801) read user 1853802's login records incl. clientIpAddress 1.2.3.4 (A's own was 9.9.9.9); getUserLoginAttemptCount returns count for arbitrary userIds. Filed vuln-0023.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "e00cbc", "surface": "www.neonrush.com /api/services/app/turnstilepolicy/getvalidationpolicy", "risk_area": "sensitive information / credential disclosure (server-side secret)", "outcome": "reported", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "Unauthenticated GET /api/services/app/turnstilepolicy/getvalidationpolicy?turnstileFlow=PlayerLogin&tenantId=17 returns the server-side Cloudflare Turnstile secretKey (0x4AAAAAAChdt6yjJop7KSPCX6pJnYqk6I0). Filed vuln-0024.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "5c0687", "surface": "www.neonrush.com /api/services/app/* (pushcashpayment, kyc, trackingevent, stickeralbum, freeentrycode, sportsbook)", "risk_area": "BFLA on privileged ABP application services", "outcome": "ruled_out", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "With a valid low-priv tenant-1 session, every listed service returned 401 'Current user did not login' (permission-gated); a few returned 500 only on missing DTO. No unauth or low-priv access to these privileged services.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "319855", "surface": "www.neonrush.com /api/services/app/playeraccountuser/selfexclude + suspend", "risk_area": "IDOR / DoS via account self-exclude or suspend", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:48:49 UTC", "evidence": "playerAccountUser.selfExclude/suspend returned 200 on one session and 401 'Current user did not login' on another; it could not be determined whether a target userId/account can be supplied (self vs other). No confirmed impact.", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "1f4b0f", "surface": "appmanager.tangobet.co.uk POST /api/auth/login (HS256 JWT)", "risk_area": "JWT HS256 signing-secret recovery / token forgery", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:49:37 UTC", "evidence": "Captured a valid HS256 token via the default credential and attempted an offline brute-force: the prior reviewer had already exhausted rockyou (14.34M) + a 10k list; this pass added ~200,500 mutated/targeted candidates (betty/tangobet/railw...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "2da235", "surface": "playuk.com (4 hosts) — leftover backup directories /wp-content/updraft and /wp-content/ai1wm-backups", "risk_area": "Downloadable backup archive -> DB/wp-config -> RCE", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:03 UTC", "evidence": "Directory listing disabled (index files only: UpdraftPlus placeholder HTML, AIO 'Kangaroos cannot jump here'). The backup plugins are NOT installed (main plugin file all-in-one-wp-migration.php and updraftplus.php -> 404), so no export/down...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "23ec98", "surface": "playuk.com — PHP runtime command-execution capability", "risk_area": "OS command execution if any code-execution foothold is obtained", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:03 UTC", "evidence": "phpinfo (vuln-0026) shows disable_functions includes exec, shell_exec, system, passthru, popen, pclose, proc_open, proc_close, pcntl_exec, dl, symlink -> no OS command execution primitive available to PHP even with a webshell. open_basedir...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "d507b0", "surface": "mogobet.com, jeffbet.net — Redirection 5.9.0 REST API", "risk_area": "Capability-check bypass fixed in 5.10.0", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "All redirection/v1 routes (redirect, plugin, setting) return 401 rest_forbidden unauthenticated on mogobet (404 where the plugin is not installed). The 5.10.0 fix is an authorization hardening for authenticated users and only enables redire...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "f57f0e", "surface": "all WP hosts — unauthenticated REST surface (wp-abilities, batch, yoast, block-editor, redirection, wp/v2/users)", "risk_area": "Broken function-level authorization / unauth code execution via REST", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "wp-abilities/v1/abilities and /abilities/{name}/run -> 401; yoast/v1/file_size -> 401; wp-block-editor/v1/url-details -> 401 for external URLs and 400 for internal ones (no SSRF); wp/v2/users POST -> 401 rest_cannot_create_user; redirection...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "f50fdd", "surface": "betsuna.com — LiteSpeed Cache plugin", "risk_area": "CVE-2024-28000 / CVE-2024-50550 (LSCWP unauth privilege escalation)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "readme.txt Stable tag = 7.8.1; both CVEs affect versions < 6.5.1 (CVE-2024-28000 < 6.4, CVE-2024-50550 < 6.5.1). Patched. litespeed/v1 REST endpoints return 404 (features off). Plugin absent on theonlinecasino/mogobet.", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "ae2f6e", "surface": "playuk.com — /info.php", "risk_area": "Information disclosure (debug script exposed)", "outcome": "reported", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Unauthenticated GET /info.php returns full phpinfo() (120KB): PHP 7.4.33.15 (EOL), DOCUMENT_ROOT /nas/content/live/playuk, USER fpm200035, full disable_functions, loaded modules, env. Filed as vuln-0026.", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "6913d3", "surface": "theonlinecasino.co.uk, mogobet.com, betmaze.co.uk, betsuna.com, jeffbet.net, playuk.com — WordPress admin-credential path to theme-editor RCE", "risk_area": "RCE via admin credential compromise -> theme/plugin editor", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "No unauthenticated file-write/upload primitive and registration is disabled, so RCE requires valid admin credentials. xmlrpc.php system.multicall + wp-login.php have no rate limiting/lockout (vuln-0014), making credential brute force the re...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "6aef6a", "surface": "theonlinecasino.co.uk — WordPress custom theme (Theonlinecasino)", "risk_area": "RCE via theme PHP (file write / LFI / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Theme exposes only static JSON proxies (fetch-games/sports/promotions/sports-promotions.php) plus style.css/sports-cache.json. fetch-sports.php params are inert; POST returns identical body. No upload/backup PHP files (404). No user input r...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "d6b10b", "surface": "betmaze.co.uk / betsuna.com — WordPress custom child theme (twentytwentyfive-child)", "risk_area": "RCE via theme PHP (file write / LFI / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Theme ships only read-only JSON proxies (fetch-games/sports/promotions/sports-promotions.php). Every tested parameter (file,url,path,include,template,view,page,gameType,category,src,type,lang,cache,debug) and POST bodies return byte-identic...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "a62488", "surface": "mogobet.com, jeffbet.net, theonlinecasino.co.uk, playuk.com, betmaze.co.uk — Advanced Custom Fields 6.8.8", "risk_area": "ACF file upload / frontend-form validation bypass / REST reference exposure -> RCE", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:04 UTC", "evidence": "Source-diffed 6.8.8 vs 6.8.10: fixes are PDF-upload prefilter, REST reference read-permission enforcement, _acf_form token TTL/render binding, frontend field validation, and user-field nonce check — information-disclosure/validation, not co...", "agent_name": "WP RCE CVE Hunter"}, {"entry_id": "22adc5", "surface": "FTP (tcp/21) on 35.214.94.72, 35.214.89.161, 77.68.12.66 (Pure-FTPd / ProFTPD)", "risk_area": "Anonymous FTP / file disclosure yielding DB credentials", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Re-tested ProFTPD on 77.68.12.66: anonymous login rejected (530 Login incorrect); `SITE CPFR`/`SITE CPTO` both rejected (500 \"'SITE CPFR' not understood\" / 503 Bad sequence), i.e. mod_copy CVE-2015-3306 is NOT loaded; banner is version-mask...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["ruled_out"]}, {"entry_id": "aff7a9", "surface": "35.214.94.72 (headless.mrslot/mrmobi/mrsuperplay, staging3.mrjackvegas) — MySQL 3306 / PostgreSQL 5432", "risk_area": "Exposed database service / default-credential DB access", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "MySQL/PG listen on the public IP but access is blocked by two named server-side controls: MySQL returns ERROR 1130 \"Host '64.111.92.186' is not allowed to connect to this MySQL server\" (host-based ACL) for every user; PostgreSQL returns FAT...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "30cbc7", "surface": "In-scope apexes + ~200 subdomains — full TCP DB/exposure port sweep (128 IPs)", "risk_area": "Exposed database services across the fleet", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "naabu + nmap -sV over 128 resolved IPs for 3306/5432/1433/1521/27017/6379/9200/11211/5984/7474/7687/9042/8086/2181/5672/2375/2379/5985/5986/21/22/25. Only real DB services are the MySQL/PG on the two GCP origins and MariaDB on 77.68.12.66 (...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "af41fd", "surface": "35.214.94.72 / 35.214.89.161 — direct origin access to headless/staging WordPress (SiteGround challenge bypass)", "risk_area": "Edge bypass to reach origin files (wp-config/DB creds)", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Requesting the origin IP directly with Host: headless.mrslot.com / headless.jazzyspins.com still returns HTTP 202 with an sgcaptcha JS/meta-refresh challenge for every path (.env, wp-config.php.bak, .git, etc.). No path reached application...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "e398d4", "surface": "In-scope fleet — config/backup artifact sweep (.env, wp-config.php.*, .git, .svn, *.sql, backups, actuator)", "risk_area": "Leaked configuration / DB credentials via exposed files", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "6061 path probes over 209 resolving in-scope hosts (https). Every 200 was an SPA catch-all fallback (identical body size for all paths); genuine hits were only the already-known mogobet.com debug.log and an Apple .DS_Store on affiliates.dyn...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "6e15f5", "surface": "77.68.12.66 (promotions.pandabingo.com) — MariaDB 10.5.29 on tcp/3306", "risk_area": "Internet-exposed database service / weak-credential DB access", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Additional targeted testing by this agent: 1,254 more attempts (usernames root/admin/psa/mysql/promotions/pandabingo/panda/bingo/promo/web/www/db/database/user/test/wordpress/wp/plesk/backup/sql/debian-sys-maint x brand-/server-/Plesk-deriv...", "agent_name": "Plesk to MySQL Credential Hunter", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "8434c8", "surface": "77.68.12.66:8443 — Plesk panel + default vhost (promotions.pandabingo.com)", "risk_area": "Exposed hosting control panel / DB credential disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Independently corroborated by a second agent on Plesk Obsidian 18.0.80 (build 18.0.80.8): bounded sw-cp-server static-file traversal probe (144 payload variants across 8 prefixes x 6 encodings x {etc/passwd, etc/psa/.psa.shadow, etc/psa/pri...", "agent_name": "Exposed MariaDB/Plesk Validator", "previous_outcomes": ["no_issue_found", "needs_follow_up", "ruled_out"]}, {"entry_id": "2253f5", "surface": "35.214.89.161 (headless.jazzyspins, ftp.jazzyspins) — MySQL 3306 / PostgreSQL 5432", "risk_area": "Exposed database service / default-credential DB access", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Same controls as the sibling GCP origin: MySQL ERROR 1130 host-not-allowed; PostgreSQL FATAL no pg_hba.conf entry for 64.111.92.186. Both reject before any credential check.", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "32962c", "surface": "mogobet.com /wp-content/debug.log — DB credential/query content", "risk_area": "DB credentials or queries leaked in debug log", "outcome": "ruled_out", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Full 2660-byte log retrieved: contains only four PHP Fatal \"array_filter(): Argument #1 must be of type array, null given\" TypeErrors in the twentytwentyfour theme; no DB connection strings, credentials, queries or table names. (Info-disclo...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "55b0c9", "surface": "In-scope fleet — client JS bundles scanned for DB connection strings/credentials", "risk_area": "Embedded DB credentials in client-side code", "outcome": "no_issue_found", "created_at": "2026-09-27 17:51:42 UTC", "evidence": "Downloaded ~50 JS bundles from 15 reachable hosts (Cogni ABP, PlayUK/Betty, WordPress, Nuxt, ProgressPlay) and ran gitleaks + regex for mysql/postgres/mssql/mongodb/redis URIs, DATABASE_URL, connectionString, DB_PASSWORD. Only findings are...", "agent_name": "DB Service & Cred Leak Sweeper"}, {"entry_id": "4d948e", "surface": "www.jackpot.com Content Admin Area authentication (POST /%2fadmin via ALB %2f bypass)", "risk_area": "Authentication bypass / privilege escalation to admin", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:04 UTC", "evidence": "Reached the \"Login to the Content Admin Area\" form via /%2fadmin (non-browser UA). Controls confirmed on the attacker path: (1) MVC [Authorize] — all admin controllers (User, Promotion, Tickets, Config, Pages, News, Dashboard, Widget, Conte...", "agent_name": "Jackpot Admin Access Hunter"}, {"entry_id": "0cc87f", "surface": "www.jackpot.com admin login credentials (default/weak set)", "risk_area": "Weak / default credentials", "outcome": "no_issue_found", "created_at": "2026-09-27 17:54:04 UTC", "evidence": "Bounded set of 18 default/weak pairs (admin:admin, admin:admin123, admin:password, administrator:admin, test:test, admin:Admin@123, admin:letmein, admin:P@ssw0rd, admin:Password1, admin:123456, admin:jackpot, admin:jackpot123, jackpot:jackp...", "agent_name": "Jackpot Admin Access Hunter"}, {"entry_id": "0bec0f", "surface": "api-uat/api-qa.playuk.com /revolve/api/* authenticated routes (account/payments/loyalty/limits)", "risk_area": "SQL / NoSQL injection (post-auth)", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Closed by PlayUK Authenticated Injection Hunter. Obtained an authenticated QA session (register/lite) and tested the authenticated /revolve/api/* routes for SQL/NoSQL injection (error/boolean/time-based incl. SLEEP(3), and type-juggling). N...", "agent_name": "PlayUK Authenticated Injection Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "e9e7cf", "surface": "playuk.com /info.php (phpinfo environment)", "risk_area": "DB credentials disclosure via phpinfo environment", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "phpinfo() is live (200, 120KB) but the Environment/$_SERVER/$_ENV sections contain only USER=fpm200035 and WPENGINE_* flags (WPENGINE_ACCOUNT=playuk, PHPSESSIONS on, DB_SESSIONS off) - no DB_NAME/DB_USER/DB_PASSWORD/MYSQL_*/DATABASE_URL. WP...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "7d92d3", "surface": "mogobet.com /wp-content/debug.log content", "risk_area": "DB credentials / SQL queries disclosed in debug log", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Fetched in full (2660B): contains only 4 PHP `array_filter(): Argument #1 must be of type array, null given` TypeErrors from the child theme (index.php:173/232) with stack traces. No SQL statements, no wpdb/SQL errors, no DB credentials or...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "d271cb", "surface": "jackpot.com string-parameter widget endpoints (UsWebIdentity/CheckUser, UsaServices/ComplianceCheck, UsWebIdentity/Error?id=, Menu/Timezones|Results, Promotion/Tac, UsGames/*)", "risk_area": "SQL injection via application parameters", "outcome": "needs_follow_up", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Extended testing: /%2ftrace.axd reaches the ASP.NET Trace handler but returns a 3425B \"Trace Error\" page (remote tracing disabled, localOnly); /elmah.axd + /%2felmah.axd -> 404 (not deployed). /shoppingcart?promoCode|search|sort|orderby ->...", "agent_name": "App-Layer SQLi Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "3861ef", "surface": "www.neonrush.com ABP /api/services/app/* parameters (isusernameavailable, getprofilepicturebyuser/byusername, isgeoblocked...)", "risk_area": "SQL injection (EF Core / ABP)", "outcome": "ruled_out", "created_at": "2026-09-27 17:54:39 UTC", "evidence": "Control: ABP + EF Core parameterization on every reachable app-service. isusernameavailable?input= returns {\"result\":true} for quote/OR payloads (literal, no error); getprofilepicturebyuser?userId=1' returns ABP model-validation 400 (type-b...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "285576", "surface": "www.neonrush.com /api/services/app/shopifyssotokenservice/generatejwt", "risk_area": "unauthenticated identity forgery / SSO token minting (missing authentication + claim injection)", "outcome": "reported", "created_at": "2026-09-27 17:57:14 UTC", "evidence": "Independently reproduced the unauthenticated SSO token minting (POST /api/services/app/shopifyssotokenservice/generatejwt?playerId=&email=&balance=&emailVerified=) and added cryptographic proof: the RS256 signature on the minted token verif...", "agent_name": "Red Team C2 — Priv-Esc & Pivots"}, {"entry_id": "e38d11", "surface": "games.betsuna.com/Media.aspx POST handling", "risk_area": "File upload to webshell", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: page ignores POST body. Multipart uploads with field names file/upload/media/image/FileUpload1/fu/attachment/document and form-encoded action=upload/cmd=save all return the identical 200/590B page; nothing stored.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "286b43", "surface": "games.betsuna.com URL handling", "risk_area": "Path traversal / LFI to code exec", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: IIS requestFiltering. .%2e/%2e%2e/…, \\..\\..\\…, %2e%2e//google.com all => 403.3 'Forbidden URL'. web.config 404; trace.axd 403 localOnly.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "6ae0b1", "surface": "games.betsuna.com/Media.aspx (__VIEWSTATE)", "risk_area": "ViewState deserialization RCE", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: .NET machineKey MAC validation. Page emits __VIEWSTATE (80B, randomised/encrypted) + __VIEWSTATEGENERATOR=F93C166E, no __EVENTVALIDATION. POST with original VS=200; flipped byte / minimal ff0100 / 'AAAA' => HTTP 500 'Validation of...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "f85758", "surface": "www.jackpot.com file-serving routes (/themes, /Media, /Content)", "risk_area": "Path traversal / LFI to code exec", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: IIS URL normalization + static handler. ../../web.config, %2e%2e%2f, ..%5c.., %2e%2e%2f in path => 404 or 400 Bad Request. Encoded traversal is rejected before any file open.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "3e31dd", "surface": "www.jackpot.com application pages (ViewState)", "risk_area": "ViewState deserialization RCE", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: framework choice. jackpot.com is ASP.NET MVC 5.2 (Razor) pages served without WebForms ViewState; admin login form uses __RequestVerificationToken anti-forgery and no __VIEWSTATE. No ViewState exists to attack on this host.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "d99daf", "surface": "www.jackpot.com admin upload/import endpoints", "risk_area": "Unauthenticated file upload to webshell", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:26 UTC", "evidence": "Control: MVC [Authorize] + no public upload feature. Content/Upload,UploadImage,UploadFile,FileManager,Media,EditorUpload,Home/Upload,User/UploadAvatar,UserPhoto,Themes/Templates => MVC 404 or 302->/Admin?ReturnUrl (login). /Admin/User/MyPr...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "a674d0", "surface": "www.jackpot.com + games.betsuna.com client components", "risk_area": "Known-CVE RCE in vendor UI components", "outcome": "not_applicable", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: no vulnerable third-party component is present. Full HTML/JS review across jackpot.com and games.betsuna.com found no Telerik/Kendo/DevExpress/Syncfusion/Infragistics/CKFinder/CKEditor/Uploadify/elFinder and no WebResource.axd/Scri...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "b4c75a", "surface": "www.jackpot.com Areas/Widgets API endpoints", "risk_area": "XXE / deserialization / SSRF on widget APIs", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: endpoints ignore attacker input. XXE (SYSTEM file:///C:/Windows/win.ini DTD, application/xml) and JSON __type ObjectDataProvider POSTs to /Widgets/Menu/LocState,/UsaServices/ComplianceCheck,/Widget/Phrases => 200 empty, no resoluti...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "b55803", "surface": "*.hotwinscasino.com Microsoft-HTTPAPI hosts", "risk_area": "RCE surface (HTTP.sys listeners)", "outcome": "no_issue_found", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "admin/m/brand/partners.hotwinscasino.com are Microsoft-HTTPAPI/2.0 listeners returning a stock 404 (315B) for every path probed (/, /api, /api/health, /swagger, /health, /stats) — no application content or handler is served. No code path re...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "7f13db", "surface": "games.playuk.com", "risk_area": "RCE surface reachability", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "games.playuk.com returns a blanket 403 awselb/2.0 for every path, User-Agent, method and normalization variant (incl. /%2f) — the ALB exposes no content and no origin hostname, so no code path is reachable to assess. Access-limited, not cle...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "8a9a18", "surface": "Fleet games./media./cms.* subdomain sweep", "risk_area": "Discovery of additional .NET hosts", "outcome": "no_issue_found", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Probed games./media./cms.<apex> for all 47 apexes. Only games.betsuna.com is a real .NET site; the rest are NXDOMAIN (Caido 502), Cloudflare, S3, nginx or AWS ALB 403. No additional in-scope IIS/ASP.NET origin found.", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "92a848", "surface": "www.jackpot.com + games.betsuna.com diagnostics & config files", "risk_area": "Diagnostics / config / machineKey exposure", "outcome": "ruled_out", "created_at": "2026-09-27 18:04:33 UTC", "evidence": "Control: ASP.NET trace localOnly + IIS requestFiltering. /trace.axd => 403 'current trace settings prevent trace.axd from being viewed remotely'. /elmah.axd,/glimpse.axd,/appsettings.json,/web.config(.bak/.old/.txt),/bin/,/App_Data/,/packag...", "agent_name": "IIS ASP.NET RCE Hunter"}, {"entry_id": "f7df5f", "surface": "www.jeffbet.net — custom twentytwentyfive theme admin-ajax actions (search_games, search_games_by_category, load_default_games, load_more_games)", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "Unauthenticated admin-ajax actions query a 'game' CPT. Manual tests: ' AND 1=1-- - == ' AND 1=2-- - (identical length), no SLEEP(5) delay, no SQL error; quote stripped. sqlmap (BEUT L2-3 R1-2, space2comment) on search/category/tax/term/page...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "7a8e37", "surface": "www.betmaze.co.uk — WordPress 7.1.2 core search/REST + twentytwentyfive-child theme PHP", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/{posts,users,pages,search}?search|author|orderby|cat|p|page_id plus child-theme fetch-*.php: no SQL error, no boolean differential (true==false length), no SLEEP delay, no 500; sqlmap on ?s= 'not injectable'. fetch-*...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "dcedc5", "surface": "www.jeffbet.net — WordPress core search/REST + unauthenticated game enumeration", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/*?search= show no boolean/timing/error differential; parameterized WP_Query. Game data returned by admin-ajax is intended-public catalogue content.", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "001a49", "surface": "www.mogobet.com — WordPress 7.1 core search/REST + twentytwentyfour theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/posts?search=: no boolean/timing differential, no SQL error, no 500 → WP_Query parameterization. Accordion FAQ 2.5.3 / Yoast 28.3 / Redirection 5.9.0 / ACF 6.8.8 all current (no applicable SQLi CVE).", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "683d94", "surface": "www.betsuna.com — WordPress 7.x core search/REST + game CPT + twentytwentyfive-child theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/wp-json/wp/v2/game?search= and /wp/v2/posts?search=: 'blackjack' and 'blackjack' return identical rows (quote stripped), sleep/boolean payloads return empty with no delay and no differential → parameterized (WP_Query). fetch-*.php params b...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "2a2cca", "surface": "www.mogobet.com — /wp-content/debug.log credential mining (vuln-0006)", "risk_area": "Leaked DB credentials / SQL error disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "Full 2660-byte log contains only 5 PHP Fatals (theme twentytwentyfour/index.php array_filter TypeError) + path /home/mogobet.com/public_html/. No SQL query, no SQL error, no table prefix, no DB host/user/password. No rotated copies exposed....", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "81fb0f", "surface": "www.theonlinecasino.co.uk — WordPress 7.1 core search/REST + Theonlinecasino theme fetch-*.php + sports-cache.json", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/posts?search=: no boolean/timing/error differential. fetch-sports/promotions/games.php + sports-cache.json return ProgressPlay catalogue data; all 10+ tested params (id/code/name/promotionId/wl/...) byte-identical →...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "b77c5a", "surface": "WordPress fleet (betmaze, betsuna, jeffbet, mogobet, playuk, theonlinecasino) — sensitive files / DB dumps / config backups", "risk_area": "Exposed DB credentials / database backups", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "~90-path sweep + ffuf: wp-config.* (.bak/.old/.save/.swp/.txt/.gz/.zip/~), .env*, *.sql/*.sql.gz dumps (root, uploads, ai1wm/updraft/backups), .git, adminer/phpMyAdmin, mu-plugins → no 200 with data. wp-config* blocked by a robust WAF rule...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "0ad1d0", "surface": "www.playuk.com — WordPress 7.x core search/REST + PlayUk theme", "risk_area": "SQL injection (DB access)", "outcome": "ruled_out", "created_at": "2026-09-27 18:07:05 UTC", "evidence": "/?s= and /wp-json/wp/v2/*?search= and fetch-*.php (theme PlayUk): no boolean/timing/error differential; fetch params byte-identical (ProgressPlay proxy). Yoast 28.3 / ACF 6.8.8 current. wp-login POST 400 at WPEngine edge (untestable from eg...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "f637f4", "surface": "www.betsuna.com — front-end /?s= search parameter", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Front-end requests to betsuna.com return 0-byte / connection-reset responses (InvalidChunkLength gzip errors; all payload variants time out at ~5.2s) so the theme-level search handler could not be differentially tested. The /wp-json/ REST s...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "8b549d", "surface": "promo.hotwinscasino.com — WordPress SQL injection surface", "risk_area": "SQL injection (DB access)", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:07:09 UTC", "evidence": "Host live but its origin (openresty) returns 403 Forbidden for EVERY request incl. a real browser and the /?rest_route= bypass (wp/v2/users, redirection/v1, llar) — Cloudflare fronting + origin IP block. WordPress REST/plugin SQLi surface c...", "agent_name": "WordPress DB Injection Hunter"}, {"entry_id": "68c706", "surface": "api-uat.playuk.com /revolve/api/account/login (JSON login.principle param)", "risk_area": "SQL injection (sqlmap BEUT)", "outcome": "ruled_out", "created_at": "2026-09-27 18:10:02 UTC", "evidence": "sqlmap --technique=BEUT on POST /revolve/api/account/login (JSON login.principle, --ignore-code=401,400) reported \"all tested parameters do not appear to be injectable\" (327x 401, no boolean/time/error signal); manual quote/OR/SLEEP probes...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "d4e2cd", "surface": "www.neonrush.com /api/services/app/profile/getprofilepicturebyuser?userId", "risk_area": "SQL injection (sqlmap BEUT)", "outcome": "ruled_out", "created_at": "2026-09-27 18:10:02 UTC", "evidence": "sqlmap --technique=BEUT on GET /api/services/app/profile/getprofilepicturebyuser?userId=1 (XFF 8.8.8.8, --ignore-code=400,401) reported \"all tested parameters do not appear to be injectable\" (384x 400 = ABP model-validation on non-int userI...", "agent_name": "App-Layer SQLi Hunter"}, {"entry_id": "9493f0", "surface": "www.jackpot.com (IIS10/ASP.NET MVC5.2) + games.betsuna.com (IIS10/ASP.NET WebForms) + games.playuk.com", "risk_area": "RCE on IIS/.NET hosts (ViewState deserialization, file upload, path traversal, vendor-component CVEs, XXE/SSRF)", "outcome": "ruled_out", "created_at": "2026-09-27 18:12:12 UTC", "evidence": "Full vector sweep with named controls: games.betsuna.com Media.aspx __VIEWSTATE is encrypted and MAC-validated (tamper → 500 \"Validation of viewstate MAC failed\") and no machineKey/web.config is exposed → ViewState ObjectStateFormatter RCE...", "agent_name": "Red Team A — RCE Paths"}, {"entry_id": "d53824", "surface": "GET /api/services/app/userlogin/getuserloginattempts (sorting parameter) — www.neonrush.com", "risk_area": "SQL injection / EF Core Dynamic LINQ expression injection", "outcome": "reported", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Client-supplied `sorting` is passed to System.Linq.Dynamic.Core and translated by EF Core to SQL. Data-dependent SQL boolean oracle: `sorting=IIF(it.ClientIpAddress==\"8.8.8.8\", it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 (true) vs the same with...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "863359", "surface": "ABP dynamic-API params on www.neonrush.com (filter, userId, OData $filter/$orderby)", "risk_area": "SQL injection (classic value-parameter injection)", "outcome": "ruled_out", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "`userId` is bound as an integer — non-numeric input (`1'`, `1 OR 1=1`, `abc`, overflow) returns HTTP 400 model-validation, so no string reaches SQL. `filter` is a literal substring/LIKE predicate: `8.8.8.8` matches the stored value while `'...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "88d218", "surface": "POST /api/services/app/publicenabledgames/search — www.neonrush.com", "risk_area": "SQL injection / data exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 18:14:51 UTC", "evidence": "Anonymous endpoint returning the public game catalogue. Injection-shaped and unknown fields (keyword/filter/searchText/provider/category, quoted payloads) are ignored — byte-identical catalogue, no error or timing differential. No auth bypa...", "agent_name": "Cogni ABP Authz DB Injection"}, {"entry_id": "a19c3a", "surface": "www.jackpot.com — Widgets/UsaServices + UsWebIdentity string params", "risk_area": "SQL injection (string parameters)", "outcome": "ruled_out", "created_at": "2026-09-27 18:31:40 UTC", "evidence": "Direct probe: UsaServices/ComplianceCheck?state_id=1 → constant \"NonCompliant\" for benign and `1'`/`1 AND 1=1`/`1 AND 1=2` (no differential); UsWebIdentity/CheckUser?email=a@b.com vs a'@b.com → identical empty 200; UsWebIdentity/Error?id=1...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "48c0b7", "surface": "www.neonrush.com — ABP `sorting` parameter (EF Core Dynamic LINQ)", "risk_area": "SQL injection / database access", "outcome": "reported", "created_at": "2026-09-27 18:31:40 UTC", "evidence": "CONFIRMED DB ACCESS, filed vuln-0027 (High 7.1, CWE-89). ABP `sorting` param → System.Linq.Dynamic.Core `OrderBy(string)` → SQL. Blind oracle `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 true / HTTP 500 (SQL divide-by-zero)...", "agent_name": "Red Team B — DB Access Paths"}, {"entry_id": "b99455", "surface": "www.neonrush.com — cross-tenant query via client-controlled Abp.TenantId header (post-auth)", "risk_area": "Tenant isolation bypass", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "With a tenant-1 (CogniSweeps) session, setting `Abp.TenantId: 17` (the populated real NeonRush tenant) returns HTTP 401 \"Current user did not login to the application\" on service endpoints; the header only influences pre-auth flows (registr...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "f98a8c", "surface": "www.neonrush.com — other sortable service list endpoints (documentuser/getall etc.)", "risk_area": "SQL injection via sorting parameter", "outcome": "ruled_out", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "documentuser/getall ignores the sorting parameter entirely: `it.Id`, `it.Bogus` and `it.Player.EmailAddress` all return HTTP 200 with byte-identical rows, so it is not an injection sink. Across the full AbpServiceProxies route map only user...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "4612d3", "surface": "www.neonrush.com — freeentrycodeuser/getall (FreeEntryCode -> Player navigation reachable via sorting injection)", "risk_area": "Cross-table data read via navigation property in injected dynamic-LINQ OrderBy", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:33:58 UTC", "evidence": "Injected sorting expression resolves a RELATED table: `it.Player.EmailAddress`, `it.Player.UserName`, `it.Player.PhoneNumber`, `it.Player.DateOfBirth`, `it.Player.Gender` all return HTTP 200 (entity translates to a SQL JOIN) while root-only...", "agent_name": "Cogni Injection Impact Extension"}, {"entry_id": "6d948f", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: database metadata (engine/version, schema, table list)", "risk_area": "Database metadata disclosure / DBMS identification", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "The injected expression is bound to the queryable entity, so only that entity's mapped columns are evaluable; there is no resolvable SQL-metadata function (EF.Functions.Like -> 500; typeof/reflection -> 500) and unhandled query failures ret...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "b7452d", "surface": "www.neonrush.com — minted SSO token consumption (in-scope consumers)", "risk_area": "Account impersonation via forged SSO token", "outcome": "needs_follow_up", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Re-checked for an in-scope token consumer this pass: the minted RS256 JWT is not accepted as a bearer credential (ABP session stays user:null); `/api/sso`, `/api/ssolaunch`, `/api/sso/token`, `/account/single-sign-in` all 404; `/account/log...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "0f6f31", "surface": "www.neonrush.com — dynamic-LINQ `sorting` injection: arbitrary .NET type resolution / reflection escape", "risk_area": "Remote code execution (expression-injection escape to file read / command execution)", "outcome": "ruled_out", "created_at": "2026-09-27 18:45:42 UTC", "evidence": "Named control: System.Linq.Dynamic.Core's restricted predefined-type provider. Positive controls prove client-side funcevaluation works (System.Math.Abs(-5)==5 -> HTTP 200; System.Convert.ToBase64String(new byte[]{65,66})==\"QUI=\" -> 200) wh...", "agent_name": "Neonrush DB/ATO Chain Agent"}, {"entry_id": "beac0b", "surface": "api-qa.playuk.com POST /revolve/api/account/getHistorical{Account,Game,Sports}History (from/to)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named control: server-side date parse + 3-month range validation runs BEFORE the query — every quote/boolean/time payload to `from`/`to` returns `code 119/217` (Dates are not in three months range / From and To dates range should not exceed...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "7a5d25", "surface": "api-qa.playuk.com POST /revolve/api/account/isBonusCodeValid (bonusCode)", "risk_area": "SQL injection / database access", "outcome": "reported", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "CONFIRMED time-based blind SQLi: payload `TESTCODE' AND (SELECT 8983 FROM (SELECT(SLEEP(5)))Dynt) AND 'koru'='koru` yields a deterministic +5s delay (5.2-5.6s vs 0.2-0.5s baseline); SLEEP(0) control inert; `-- -` comment form inert. Corrobo...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "dd38e2", "surface": "api-qa.playuk.com /revolve/api/account/{getTransaction,getGame,getSports,getRummy,getWheel}History (pageIndex/pageSize/pageNumber)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named control: integer type validation before use — non-integer values return `code 223 Invalid pageIndex or pageSize` (or a 500 int-parse error); no boolean/time differential across probes.", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "fe4825", "surface": "api-qa.playuk.com POST /revolve/api/account/validateDob (dateOfBirth)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Param name resolved to `dateOfBirth`. Named control: strict date-format validation before any query — all quote/time payloads return `code 153 Invalid Date Format`; valid date returns 200 with no delay.", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "b282ac", "surface": "api-qa.playuk.com POST /revolve/api/account/updateProfile (firstName, lastName, city, state, addressLine1, postCode, nationalId, title, email)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named controls: firstName/lastName enforce an alphabetic allowlist (`code 219/220 can only contain alphabets [A-Z,a-z]`); the remaining string fields accept a quote-bearing payload (`X' AND SLEEP(3)-- -`) and return 200 with no error and no...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "40c422", "surface": "api-qa.playuk.com POST /revolve/api/account/optInToPromotion (identifier) and /revolve/api/payments/paymentMethods (operationType)", "risk_area": "SQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Named controls: enum/type validation before use — `optInToPromotion.identifier` rejects non-integers with `code 124 Invalid Promotion identifier`; `paymentMethods.operationType` rejects non-enum values with `code 242 Invalid Cashier request...", "agent_name": "PlayUK Auth API Injection"}, {"entry_id": "42a6b8", "surface": "api-uat.playuk.com — session acquisition / authenticated API", "risk_area": "SQL injection / database access", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:14:52 UTC", "evidence": "Re-confirmed api-uat session acquisition is blocked: POST /revolve/api/register/lite returns anti-fraud 400 code 3 (\"potential breach of terms\") for every payload/email-domain variant, with and without spoofed UK X-Forwarded-For. The block...", "agent_name": "PlayUK Authenticated Injection Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "00d18e", "surface": "appmanager.tangobet.co.uk /api/admin/players/search (advancedFilter/sortField)", "risk_area": "SQL injection in the query-builder tokens", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Time-based and breakout payloads in field/operator/sortField (pg_sleep, WAITFOR, OR 1=1, CASE, stacked) all returned identical 201 bodies and identical ~0.22-0.26s timings; unknown fields are silently dropped (fail-open), values parameteriz...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "3bf536", "surface": "appmanager.tangobet.co.uk JWT (HS256)", "risk_area": "Token forgery via weak/crackable signing secret", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Captured valid HS256 token; offline crack of rockyou.txt (14.3M) + mutation rules over 8 cores (~60s) found no match; alg:none rejected (401, sibling). Signing secret is not a dictionary/weak value, so token forgery is not achievable.", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "33b7f7", "surface": "www.jackpot.com /%2fadmin Content Admin login", "risk_area": "Default credentials and SQL injection on the admin login", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Reached the login via the ALB encoded-slash bypass (direct /admin = 403, /%2fadmin = 200). 5 default/weak cred pairs all rejected with a uniform JSON error; 9 SQLi payloads (incl. WAITFOR DELAY time-based) produced byte-identical responses...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "e5b377", "surface": "appmanager.tangobet.co.uk /api/* (admin API surface)", "risk_area": "Undocumented endpoints enabling SSRF / export / webhook pivots", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Full API recovered from SPA bundle + ffuf (112 names under /api/ and sub-path fuzzing): only auth/login, admin/users[/count], admin/users/{id}, admin/players[/search|/count], admin/notifications/send, mobile-app/stats. No URL-fetching/expor...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "d06832", "surface": "www.neonrush.com /api/authentication/{login,register,social-login,social-signup}", "risk_area": "Authentication bypass via the X-Server-Authorization API key", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Additional hunt this pass, still not obtained. Confirmed: the `apiKey` DTO property is bound strictly to the `X-Server-Authorization` header (alternate header names `ApiKey`/`X-API-Key`/`Server-Authorization` and query `?apiKey=` all yield...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "needs_follow_up"]}, {"entry_id": "407c4f", "surface": "www.neonrush.com /api/services/app/playeraccount/registerexternalfromapi", "risk_area": "Privilege escalation via role mass-assignment", "outcome": "ruled_out", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Obtained a real session for the registerExternalFromApi-created account (created with roleNames:[\"Admin\"], roles:[\"Admin\"], isAdmin:true; HTTP 200) by using the password-reset disclosure to set its password, then logging in (HTTP 200 sessio...", "agent_name": "NeonRush Auth-Gap Closer", "previous_outcomes": ["needs_follow_up", "ruled_out"]}, {"entry_id": "e753de", "surface": "www.neonrush.com playeraccount sendpasswordresetcode / sendemailactivationlink", "risk_area": "Unauthenticated resource abuse (outbound security-email flooding)", "outcome": "reported", "created_at": "2026-09-27 20:19:22 UTC", "evidence": "Both endpoints return 200 with no authentication and no captcha; identical responses for known/unknown addresses (no enumeration); 15/15 rapid requests accepted (no rate limiting). resetpassword (the completing step) is Turnstile-gated, so...", "agent_name": "Red Team C — Priv-Esc & Pivots"}, {"entry_id": "12b9be", "surface": "www.neonrush.com /signalr-banking/negotiate", "risk_area": "cross-user data exposure via SignalR hub", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "The negotiate returns an Azure SignalR access token whose JWT is bound to the caller (nameid/unique_name/tenantId = my user, role Player), so the bankinghub connection is scoped to the requesting user; no cross-user balance/recent-game broa...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "b31250", "surface": "www.neonrush.com authenticated ABP application services (RCE sinks: file-write, eval, deserialization, command)", "risk_area": "Remote code execution", "outcome": "no_issue_found", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "Enumerated all 46 ABP controllers / 191 actions from AbpServiceProxies/GetAll and drove every file/URL/export/log sink with an authenticated session. No code-eval, template, deserialization or command sink is reachable; the only server-side...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "5c4778", "surface": "www.neonrush.com /api/services/app/pushcashpayment/* (tenantBaseSiteUrl / URL params)", "risk_area": "SSRF", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "On tenant 1 (CogniSweeps) an authenticated `authorizePayment`/`authorizeRedemptionPayment` with a unique interactsh host in `tenantBaseSiteUrl` returned 200 no-op with NO server-side fetch (no OOB hit, repeated); `createWidgetUrl` returns s...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "541c5a", "surface": "www.neonrush.com /file/downloadtempfile + /file/downloadbinaryfile", "risk_area": "path traversal / arbitrary file read", "outcome": "ruled_out", "created_at": "2026-09-27 20:25:16 UTC", "evidence": "downloadbinaryfile validates the `id` as a GUID (400 for any traversal/absolute/path value). downloadtempfile treats `fileToken` as an opaque store key (traversal tokens → 404) and sanitises `fileName` in Content-Disposition (raw CRLF/newli...", "agent_name": "Neonrush Auth RCE Hunter"}, {"entry_id": "4a24eb", "surface": "www.neonrush.com — freeentrycodeuser/getall navigation traversal (FreeEntryCode.Player)", "risk_area": "Cross-table PII read via dynamic-LINQ navigation traversal (sorting injection)", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Navigation resolves (`Sorting=it.Player.EmailAddress` -> HTTP 200 in tenants 1/5/11) but the queryset is always empty and the injected ORDER BY is never evaluated. The only row-creating path, `freeentrycodeuser/getnewcode`, is refused serve...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "a6cea6", "surface": "www.neonrush.com — userlogin/getuserloginattempts (the only non-empty injectable entity)", "risk_area": "Cross-user / cross-table PII extraction via injection navigation", "outcome": "ruled_out", "created_at": "2026-09-27 20:29:40 UTC", "evidence": "Only this endpoint is observably injectable (scan of all 188 routes: baseline 200 -> injected 500). Its entity (UserLoginAttempt) has NO navigation property: ~40 candidate names (`it.Player.*`, `it.User.*`, `it.PlayerAccountUser.*`, `it.Cre...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "c08447", "surface": "www.neonrush.com — tenant 17 (NeonRush) session acquisition", "risk_area": "Reach the populated tenant to test the cross-table PII escalation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:29:44 UTC", "evidence": "Tenant 17 (the populated \"NeonRush\" tenant) cannot be reached: register and login fail CLOSED on Turnstile (policy for PlayerRegistration/PlayerLogin reports isConfigurationValid:false), and no request-level bypass worked (Abp.TenantId swit...", "agent_name": "Neonrush Cross-Table DB Extractor"}, {"entry_id": "8b9a7b", "surface": "api-qa.playuk.com /revolve/api/payments/* + limits/deposit + loyalty/redemption + psp/epg + paynplay", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "Amounts/limits are numerically typed (strings → generic 500, no delay); paynplay countryCode/currencyCode/accountSystemTag are allow-list validated (codes 4/5/26); betable/initiatePayment and chapaCashier require typed fields (code 1); with...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "3e7e32", "surface": "api-qa.playuk.com /revolve/api/account/updateProfile + updateMobileNumber + updateEmail + changeLanguagePreference", "risk_area": "SQL / NoSQL injection (write path)", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "updateProfile (which performs a real DB update, 200) validates firstName/lastName to alphabets (codes 219/220) and dateOfBirth (code 152); remaining text fields accept markers but return identical 200 with no timing delay (parameterized ent...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "47ccae", "surface": "api-qa.playuk.com /revolve/api/account/*History endpoints (from/to/pageIndex/pageSize/pageNumber)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "Tested getGame/Transaction/Bonus/CashRewards/FreeRounds/Wheel/Rummy/Sports/Historical*History with date/page params. from/to are strictly format-validated (code 153 \"Invalid Date Format\" for any marker); pageIndex/pageSize are validated (co...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "805d7f", "surface": "api-qa.playuk.com /revolve/api/* lookup endpoints (redeemPromocode, isBonusCodeValid, claimReward, optInToPromotion, loginWithToken, transactionStatus, cancelPendingWithdrawal)", "risk_area": "SQL / NoSQL injection", "outcome": "ruled_out", "created_at": "2026-09-27 20:31:39 UTC", "evidence": "String-keyed DB lookups return byte-identical parameterized responses for benign vs injection markers and show no SLEEP delay (promoCode verified across 6 fresh accounts; bonusCode identical {\"isBonusCodeValid\":false}; paymentRecord identic...", "agent_name": "PlayUK Authenticated Injection Hunter"}, {"entry_id": "d21d4d", "surface": "In-scope API/app hosts (www.neonrush.com, appmanager.tangobet.co.uk, api-qa/uat.playuk.com, www.jackpot.com, play.neonrush.com, uat.uk-bingo.net, promo.hotwinscasino.com, www.betmaze.co.uk, www.playuk.com)", "risk_area": "CORS misconfiguration + Host-header reflection / password-reset poisoning", "outcome": "reported", "created_at": "2026-09-27 20:46:22 UTC", "evidence": "Correction: my initial probe tested only the host root, where api-uat.playuk.com returned ACAO:* (wildcard, no credentials) and no host-header reflection — but that did NOT cover the /revolve/api/* route groups. A separate agent's deeper sw...", "agent_name": "Independent Red Team Lead 4", "previous_outcomes": ["no_issue_found"]}, {"entry_id": "73b264", "surface": "77.68.12.66:3306 MariaDB 10.5.29 + Plesk 8443 (promotions.pandabingo.com)", "risk_area": "Internet-exposed database service / weak credentials / data exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:31 UTC", "evidence": "Independently re-verified 2026-09-27 (egress 64.111.92.186). nmap -sV: 21/ProFTPD, 22/OpenSSH 8.0, 80/nginx, 443/nginx, 3306/MariaDB 5.5.5-10.5.29, 8443/Plesk sw-cp-server. MariaDB completes handshake (no host ACL — ERROR 1045, not 1130). C...", "agent_name": "Exposed MariaDB/Plesk Validator", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "1dc941", "surface": "45.132.74.81:4000 NoMachine NX Server 10.0.59 (origin of dev/qa/lp/promo/promotions/games.potsofluck.com)", "risk_area": "Exposed remote-desktop / command injection (CVE-2026-18264, CVSS 8.8)", "outcome": "ruled_out", "created_at": "2026-09-27 20:47:31 UTC", "evidence": "RESOLVED (NoMachine RCE Validator). Target runs NoMachine 10.0.59 — confirmed by nmap -sV AND by the NX handshake itself (send `NXSH-6.0.0\\n` -> server replies `NXD-10.0.59\\n`). Both candidate CVEs are non-applicable, each against a NAMED c...", "agent_name": "NoMachine NX RCE Validator", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "c6f7f2", "surface": "Cross-subdomain cookie scoping on live in-scope apps (www.jackpot.com, play.neonrush.com, appmanager.tangobet.co.uk, uat.uk-bingo.net, partners.jackpot.com) vs dormant-subdomain takeover candidates", "risk_area": "Subdomain takeover escalating to parent-domain cookie tossing / session fixation", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:47:50 UTC", "evidence": "Observed: play.neonrush.com sets incap_ses/visid_incap with Domain=.neonrush.com (incap_ses NOT HttpOnly); www.jackpot.com session cookies (ASP.NET_SessionId, jp_geolocation) are host-only, so a claimed sibling (wiki.jackpot.com, vuln-0011)...", "agent_name": "Independent Red Team Lead 1"}, {"entry_id": "80afa8", "surface": "45.132.74.81 origin: nginx 1.24.0, Apache Tomcat 9.0.121 + Guacamole 1.6.0, OpenSSH 9.6p1, NoMachine NX 10.0.59 (dev/qa/lp/promo/promotions/games.potsofluck.com)", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "nmap confirms 22/OpenSSH 9.6p1 Ubuntu 3ubuntu13.19 (CVE-2024-6387 range 8.5p1-9.7p1 -> in range upstream but distro rev far past patched 3ubuntu13.4, likely backported) and 4000/NoMachine 10.0.59 (CVE-2026-18264 authenticated cmd-injection,...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "596bb1", "surface": "77.68.12.66 (promotions.pandabingo.com): Plesk Obsidian 18.0.80.8, MariaDB 10.5.29:3306, ProFTPD:21, OpenSSH 8.0, nginx, Dovecot", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "Version-matched Plesk CVEs giving RCE/root are all authenticated (CVE-2026-58046 9.9 XML-RPC SQLi, CVE-2026-65646 9.9 BAC, CVE-2026-64636 7.7 SQLi); unauth RCE/traversal CVEs (2026-67397/68492/67394) are fixed at 18.0.80.8. NEW (from compon...", "agent_name": "Independent RCE-Candidate Inventory Agent", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "ced5c7", "surface": "WordPress fleet: betmaze.co.uk, betsuna.com, mogobet.com, theonlinecasino.co.uk, jeffbet.net, playuk.com, promo.hotwinscasino.com", "risk_area": "RCE candidate inventory (component to CVE to RCE mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "No unauthenticated RCE path: plugins current (LSCWP 7.8.1 vs CVE range <6.5.1; CF7 6.1.7; ACF 6.8.8), no upload/file-write primitive, custom themes expose only inert static JSON proxies, wp-abilities/v1 run -> 401. Only RCE path is authenti...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "81e139", "surface": "www.jackpot.com + games.betsuna.com (IIS 10.0 / ASP.NET MVC 5.2 / WebForms Media.aspx ViewState)", "risk_area": "RCE via ViewState deserialization / .NET gadget", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "No RCE reached; the path is held shut only by .NET machineKey MAC+encryption (ViewState tamper -> 500 \"Validation of viewstate MAC failed\"; no __EVENTVALIDATION). No machineKey/web.config leak found; no vendor RCE components (no Telerik/Ken...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "f1c871", "surface": "Next.js / React Server Components fleet: uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com, ProgressPlay marketing (africasports/acelucky/777bet/betstorm/dynobet buildId WpePWuKOnX3rgMNqj5LeW), acedbet.com, play.slotlux", "risk_area": "Unauthenticated RCE (CVE-2025-55182 / Next.js RCE family)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "Tested UAT EKS App-Router hosts are patched (nuclei template + manual RSC payload, no oracle). CVE-2026-75604 is Windows-only -> N/A (hosts Linux). Gap: Next.js patch level on the Imperva-blocked hosts was never verifiable (edge 403 to egre...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "188d1a", "surface": "UAT EKS Strapi CMS via /api/cms/[...path] (uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com)", "risk_area": "RCE via Strapi admin account-takeover", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:53:56 UTC", "evidence": "CVE-2026-27886 (Strapi BAC, confirmed in vulnx) is a query-sanitizer bypass on the content API -> admin ATO -> potential RCE. Proxy is GET/HEAD/OPTIONS-only (405) and its filters are parameterized (Knex), so the sanitizer bypass was ruled o...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "023b2e", "surface": "Nuxt.js/Nitro marketing fleet (wombatbingo, pandabingo, queensbingo, uk-bingo.net, jazzyspins, vampirebingo, betarno, chitchatbingo, slotlux, mrjackvegas, mrmobi, mrslot, mrsuperplay)", "risk_area": "RCE via Nuxt/Nitro server-side template injection", "outcome": "no_issue_found", "created_at": "2026-09-27 20:54:08 UTC", "evidence": "CVE-2026-71318 (Nuxt 3.1.0-3.21.10 / 4.x<4.5.1, /__nuxt_island/ template injection -> Nitro RCE; vulnx status rejected) checked against all 9 reachable Nuxt hosts: the island endpoint returns 404 / SPA catch-all, never JSON, so the injectio...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "8d5125", "surface": "appmanager.tangobet.co.uk (Betty Admin, Node/NestJS/Express on Railway)", "risk_area": "RCE candidate inventory (prototype pollution / dependency RCE)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:54:08 UTC", "evidence": "Operator admin access is confirmed (admin/admin123, vuln-0001) but no RCE sink exists on the recovered API: typed JSON DTOs (19 prototype-pollution vectors inert), no recursive merge/eval, no URL-consuming feature (no SSRF), no upload/impor...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "7658e7", "surface": "api-qa.playuk.com /revolve/api/* (Markor Revolve player API + MySQL 8.0.42-33)", "risk_area": "SQL injection to RCE escalation (INTO OUTFILE webshell)", "outcome": "needs_follow_up", "created_at": "2026-09-27 20:54:08 UTC", "evidence": "Confirmed time-based blind SQLi (vuln-0028) on POST /revolve/api/account/isBonusCodeValid; MySQL 8.0.42-33 is the backend. Read access proven (version()/database()). Escalation to RCE requires INTO OUTFILE/stacked-query write to a web-serve...", "agent_name": "Independent RCE-Candidate Inventory Agent"}, {"entry_id": "6ec605", "surface": "api-qa.playuk.com /revolve/api/account/isBonusCodeValid (bonusCode SQLi) — escalation to file read/write/RCE", "risk_area": "SQL injection escalation to file read/write and RCE (LOAD_FILE / INTO OUTFILE)", "outcome": "ruled_out", "created_at": "2026-09-27 20:55:02 UTC", "evidence": "Injection re-confirmed live from a fresh self-registered QA session: exact payload bonusCode=\"TESTCODE' AND (SELECT 8983 FROM (SELECT(SLEEP(5)))Dynt) AND 'koru'='koru\" → deterministic 5.2s vs 0.2s baseline; clean boolean oracle = \"ZZ' AND (...", "agent_name": "Independent Red Team Lead 5"}, {"entry_id": "83c738", "surface": "www.playuk.com /xmlrpc.php pingback.ping", "risk_area": "SSRF to cloud metadata / internal-only services", "outcome": "ruled_out", "created_at": "2026-09-27 20:59:33 UTC", "evidence": "Control: pingback.ping returns the same byte-identical canned IXR fault (faultCode 0, empty faultString, ~371B) regardless of source/target, identical to betmaze/betsuna/theonlinecasino/mogobet, and no HTTP interaction reached the external...", "agent_name": "SSRF & Error-Leak Pivot Hunter"}, {"entry_id": "281af3", "surface": "WordPress /xmlrpc.php (www.betmaze.co.uk, www.betsuna.com, www.theonlinecasino.co.uk, www.mogobet.com, www.playuk.com)", "risk_area": "XXE / server-side external entity resolution", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:05 UTC", "evidence": "Named control (verified empirically on all 5 hosts): the WordPress XML-RPC parser never resolves external entities. A DOCTYPE internal subset containing an ENTITY (or ELEMENT) declaration is rejected outright with faultCode -32700 \"parse er...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "4a5f26", "surface": "*.potsofluck.com TLS hostname mismatch (cert CN/SAN=cl.exalt-digital.ru)", "risk_area": "Certificate impersonation / MITM / cross-tenant", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:21 UTC", "evidence": "All seven hostnames queried against origin 45.132.74.81:443 with SNI return the same Let's Encrypt cert (CN=cl.exalt-digital.ru, SAN=DNS:cl.exalt-digital.ru, notAfter Nov 28 2026). The control: a TLS cert is only trusted for the names in it...", "agent_name": "Potsofluck Origin Services"}, {"entry_id": "b243fd", "surface": "*.potsofluck.com 443 vhosts (dev/qa/lp/promo/promotions/games) + default vhost", "risk_area": "Alternate apps / default vhost / admin paths / HSTS", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:21 UTC", "evidence": "All six subdomains + the nginx default vhost (Host: notarealhost.potsofluck.com) return the byte-identical Guacamole login index (md5 73e7dca9268fd41aaaba0089fd0da5b7, 2811 bytes, build 20260830005846); no distinct app, no differences per h...", "agent_name": "Potsofluck Origin Services"}, {"entry_id": "68f4c7", "surface": "www.neonrush.com (Cogni/ABP) REST API services", "risk_area": "XXE / XML request-body formatter", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: ASP.NET Core app registers no XML input formatter. POST application/xml to /api/services/app/publicenabledgames/search and /api/services/app/playeraccount/register returns HTTP 415 Unsupported Media Type (json=200/400 on the...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "d1b43f", "surface": "UAT Next.js app (uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com)", "risk_area": "XXE / XML route handlers / feed or sitemap ingestion", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: the only XML-emitting route (GET /sitemap.xml -> application/xml) is output-only (server-generated urlset); /rss.xml, /feed.xml, /api/sitemap, /api/v1 all return the SPA 404 HTML. POST /api/v1 with an application/xml DOCTYPE-...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "df185d", "surface": "appmanager.tangobet.co.uk (Betty Admin NestJS API)", "risk_area": "XXE / XML request-body parsing", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: Node/NestJS JSON-only body parser with Bearer-JWT authorization. POST application/xml + DOCTYPE-entity body to /api/auth/login and /api/admin/users returns 401 {\"message\":\"Unauthorized\"} — the request is rejected at the auth...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "c525e3", "surface": "www.jackpot.com (IIS/ASP.NET MVC + WebForms) SOAP/WSDL/MVC actions", "risk_area": "XXE / SOAP-XML request parsing", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: no XML-consuming endpoint exists. /?wsdl returns the HTML homepage; Service.asmx / UsWebIdentity.asmx / UsaServices.asmx / api?wsdl / services?wsdl all 404. POST with application/xml/text/xml + DOCTYPE entity to /UsWebIdentit...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "ca2d75", "surface": "api-qa.playuk.com + api-uat.playuk.com (Markor \"revolve\" JSON API)", "risk_area": "XXE / XML request-body deserialization", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: request bodies are deserialized as JSON regardless of Content-Type. Cross-content-type test on /revolve/api/account/login: a JSON body sent with Content-Type: application/xml is accepted (401 \"Player not found\"); an XML body...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "fa5470", "surface": "www.neonrush.com /account/profile/upload-profile-picture (multipart upload)", "risk_area": "XXE via SVG/Office/XML upload", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Named control: upload handler enforces an extension allowlist (.gif, .jpeg, .jpg, .png, .webp) AND image content sniffing. Authenticated attempts: SVG (with external entity, parameter entity, XInclude, file:// entity) named .svg -> \"File ty...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "6342b5", "surface": "api-uat.playuk.com /revolve/api/{payments,loyalty,register,v1}/ (POST)", "risk_area": "CORS misconfiguration (credentialed cross-origin read)", "outcome": "reported", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Server reflects arbitrary Origin (incl. literal null) into Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true on payments/loyalty/register route groups; reflection unchanged with a session cookie present; session cookie...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "ab2f88", "surface": "www.betmaze.co.uk + www.jeffbet.net /wp-json/ (WordPress REST)", "risk_area": "CORS misconfiguration", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "WP core rest_send_cors_headers reflects arbitrary Origin + ACAC true, but the named control that rules it out is the REST nonce check: /wp-json/wp/v2/users/me returns 401 rest_not_logged_in and /wp-json/wp/v2/settings returns 401 rest_forbi...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "fe87e4", "surface": "www.pandabingo.com, www.uk-bingo.net, jazzyspins.com, www.vampirebingo.com, www.chitchatbingo.com, slotlux.com, www.queensbingo.com (Cloudflare/Nuxt marketing) plus /api/pp/games", "risk_area": "CORS misconfiguration", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:22 UTC", "evidence": "Responses return Access-Control-Allow-Origin: * with no Access-Control-Allow-Credentials, and the paths serve public marketing content only; a wildcard without credentials cannot be used to read credentialed responses. Tested Origin reflect...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "9b8558", "surface": "potsofluck.com estate fronting (Imperva apex vs direct-to-origin subdomains)", "risk_area": "WAF edge bypass / direct origin exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "DNS: apex potsofluck.com -> 45.60.249.194 / 45.60.243.194 and www -> z5nq7mr.impervadns.net (45.60.243.194) = Imperva/Incapsula edge; but dev/qa/lp/promo/promotions/games.potsofluck.com resolve DIRECTLY to the origin 45.132.74.81, so the Gu...", "agent_name": "Potsofluck Origin Services"}, {"entry_id": "cb44c1", "surface": "*.potsofluck.com Guacamole 1.6.0 /api/tokens (dev/qa/lp/promo/promotions/games)", "risk_area": "Authentication enforcement / brute-force throttling (re-verified)", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Re-verified independently. Version confirmed 1.6.0 (guacamole-common-js `VERSION=\"1.6.0\"`). Auth enforced: POST /api/tokens with guacadmin/guacadmin -> 403 INVALID_CREDENTIALS; unauthenticated GET /api/session/data/postgres/connections -> 4...", "agent_name": "Potsofluck Origin Services"}, {"entry_id": "f36a54", "surface": "IIS .NET game hosts (games.betsuna.com, games.playuk.com)", "risk_area": "XXE / SOAP or WebForms XML parsing", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Named control: no SOAP/WSDL endpoint exists (Service.asmx?WSDL 404 on betsuna; 403 nginx on playuk; ?wsdl 403). Media.aspx is an ASP.NET WebForms page that consumes form/viewstate input, not raw XML/entities. No attacker-supplied XML docume...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "e0583f", "surface": "www.jeffbet.net /xmlrpc.php + promo.hotwinscasino.com /xmlrpc.php", "risk_area": "XXE / server-side external entity resolution", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Proof gap: both XML-RPC endpoints are blocked at the edge for the test egress (www.jeffbet.net 403 Cloudflare; promo.hotwinscasino.com 403 openresty), so the parser could not be exercised. Sibling WordPress hosts of the same fleet (5 tested...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "9835b9", "surface": "headless/staging WordPress subdomains (headless.slotlux.com, headless.mrslot.com, staging3.mrjackvegas.com, staging6.mrsuperplay.com, headless.mrmobi.com)", "risk_area": "XXE / XML-RPC or REST XML parsing", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Proof gap: SiteGround sgcaptcha returns HTTP 202 with a JS challenge for every request (including /xmlrpc.php); the origin parser is unreachable for automated probing, so XML-RPC/XXE behaviour could not be verified.", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "bb47d1", "surface": "betmaze.co.uk WordPress theme AJAX handlers (fetch-sports.php, fetch-games.php, fetch-promotions.php)", "risk_area": "XXE / XML feed parsing on server-side fetch", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Named control: these handlers act as JSON content proxies to the ProgressPlay backend and ignore the request body entirely. POSTing an XML DOCTYPE-entity body returns the same JSON catalogue (fetch-sports.php 200/178KB JSON; fetch-games.php...", "agent_name": "XXE XML-Consumer Hunter"}, {"entry_id": "bcef76", "surface": "Representative Cloudflare/Nuxt/WP/ALB/Next.js hosts (root path)", "risk_area": "Host-header injection / routing confusion / open redirect", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Across 14 representative hosts (www.jackpot.com, www.betmaze.co.uk, www.mogobet.com, www.jeffbet.net, www.theonlinecasino.co.uk, www.playuk.com, uat.uk-bingo.net, uat.pandabingo.com, api-uat.playuk.com, www.pandabingo.com, jazzyspins.com, b...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "857bfd", "surface": "26 representative hosts (Cloudflare, ALB/IIS, Next.js/ELB, CloudFront)", "risk_area": "Cache poisoning via unkeyed headers", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Injected X-Forwarded-Host, X-Forwarded-Server, X-Forwarded-Scheme, X-Forwarded-Proto, X-Forwarded-Prefix, X-Host, X-Original-URL, X-Rewrite-URL, X-Forwarded-Port and Forwarded:host= against 26 hosts; none of the canary values appeared in th...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "86476a", "surface": "www.jeffbet.net (Cloudflare + WP Engine cache) and www.playuk.com (WP Engine x-cache)", "risk_area": "Web cache deception / cache-key poisoning", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:34 UTC", "evidence": "Named controls: (1) Cloudflare's cache key includes the full URL/query so the unique cache-buster cannot be shared, and no attacker-controlled unkeyed header is reflected into the response; (2) cache rules return cf-cache-status BYPASS with...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "b0fbc2", "surface": "uat.chitchatbingo.com /api/cms/[...path]", "risk_area": "Broken access control / unauthenticated sensitive-data exposure (vuln-0003 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:00:35 UTC", "evidence": "Independently reproduced: unauth GET /api/cms/users -> 200 (6 staff accounts, 1770 B), /users-permissions/roles -> 200, /users-permissions/permissions -> 200 (5049 B grant matrix), /content-type-builder/content-types -> 200 (35933 B), /site...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "244ed1", "surface": "www.betmorph.com + www.777tigers.com (Hercules Vite/React SPA bundles)", "risk_area": "Client-side secret exposure (Convex deploy key / OIDC client secret / tokens)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:35 UTC", "evidence": "Downloaded both main bundles (/assets/index-Cxr_rJma.js 680,036 B; /assets/index-B_Xeu_nP.js 704,084 B) plus the shared /_hercules/i.5l7zxvo29.js (31,185 B). gitleaks: 0 findings. Manual greps for prod:/dev: deploy keys, apiKey/password/sec...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "d7dd6a", "surface": "Betable UAT shared Next.js build — hostname blast radius (47 apexes x 25 prefixes = 1175 names)", "risk_area": "Blast radius of a shared-build defect (vuln-0003) — is any other in-scope host exposed?", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:35 UTC", "evidence": "Control: DNS CNAME/A resolution against the shared ELB k8s-devkrake-sitesing-45b8dfc26e-1857226897.eu-west-2.elb.amazonaws.com and its three A records (13.135.45.19, 18.130.165.243, 51.24.75.183). Exactly 3 of 1175 names matched: uat.uk-bin...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "13a394", "surface": "play.neonrush.com shared ProgressPlay Next.js build — full chunk set (buildId WpePWuKOn3XrgMNqj5LeW)", "risk_area": "Client-side secret exposure (additional secrets beyond vuln-0008)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:35 UTC", "evidence": "Enumerated the webpack runtime chunk map and downloaded 150 chunks (2.32 MB) plus the initial chunk set; gitleaks (--no-git, json report) and manual high-signal greps found ONLY the already-reported vuln-0008 material in 5218-5c354764053c3f...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "99cc96", "surface": "www.jackpot.com, www.jeffbet.net, uat.uk-bingo.net, api-uat.playuk.com", "risk_area": "HTTP/2 desync (H2.CL / H2.TE downgrade smuggling)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:46 UTC", "evidence": "Crafted HTTP/2 frames via the h2 library. Named controls: H2.CL (a content-length regular header that mismatches the DATA frame) was rejected with 400 on www.jackpot.com, www.jeffbet.net, uat.uk-bingo.net and api-uat.playuk.com; H2.TE (spec...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "928967", "surface": "www.jackpot.com (ALB->IIS), www.jeffbet.net (CF->WP Engine), www.playuk.com, uat.uk-bingo.net (ELB->Next.js), www.betmaze.co.uk", "risk_area": "HTTP/1.1 request smuggling (CL.TE, TE.CL, TE.TE obfuscation)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:00:46 UTC", "evidence": "Timing probes returned fast responses (0.0-2.1s) with no 10-30s desync delay. Named controls: the edges reject ambiguous framing outright - CL.TE probe -> 400 Bad Request, TE.CL probe -> 400/403, TE.TE obfuscation (duplicate/xchunked TE) ->...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "2499af", "surface": "api-qa.playuk.com (/revolve/api/register/lite, /revolve/api/account/isBonusCodeValid, /)", "risk_area": "CORS misconfiguration", "outcome": "ruled_out", "created_at": "2026-09-27 21:00:46 UTC", "evidence": "api-qa.playuk.com POST reflects the Origin only when it equals its own front-end (https://qa.playuk.com) and emits no ACAO for arbitrary/null origins; GET emits Access-Control-Allow-Origin: * without Access-Control-Allow-Credentials. Named...", "agent_name": "Edge Cross-Cutting Sweep"}, {"entry_id": "f457a4", "surface": "WordPress fleet XML-RPC pingback.ping behaviour (www.betmaze.co.uk, www.betsuna.com, www.theonlinecasino.co.uk, www.mogobet.com, www.playuk.com)", "risk_area": "SSRF / blind DNS-resolution-only artifact vs real server-side HTTP fetch", "outcome": "ruled_out", "created_at": "2026-09-27 21:02:18 UTC", "evidence": "Named control: the pingback call is short-circuited by an application-side interception component before WordPress core's fetch stage. Evidence on all five hosts: (1) the attacker-supplied sourceUri hostname still resolves even when targetU...", "agent_name": "WP Pingback Fleet Reach"}, {"entry_id": "958793", "surface": "www.jeffbet.net /xmlrpc.php", "risk_area": "XML-RPC pingback SSRF / endpoint reachability", "outcome": "ruled_out", "created_at": "2026-09-27 21:02:18 UTC", "evidence": "Named control: POST /xmlrpc.php returns HTTP 403 (nginx 403 Forbidden, Cloudflare-fronted) for demo.sayHello, system.listMethods and pingback.ping alike; the endpoint is denied at the edge before reaching WordPress, so no pingback handler e...", "agent_name": "WP Pingback Fleet Reach"}, {"entry_id": "dc5fc6", "surface": "promo.hotwinscasino.com /xmlrpc.php", "risk_area": "XML-RPC pingback SSRF / endpoint reachability", "outcome": "ruled_out", "created_at": "2026-09-27 21:02:18 UTC", "evidence": "Named control: the endpoint is denied at the edge before PHP is reached. POST /xmlrpc.php returns HTTP 403 from openresty/1.31.1.1 for demo.sayHello, system.listMethods and pingback.ping alike, so no XML-RPC handler executes and no attacker...", "agent_name": "WP Pingback Fleet Reach"}, {"entry_id": "11f361", "surface": "www.neonrush.com /api/authentication/{login,social-login,social-signup,register,logout}", "risk_area": "X-Server-Authorization API-key bypass (would enable authz bypass + make social-login a token consumer)", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Named control: a static shared API key validated after DTO validation. With a complete DTO (email/password/latitude/longitude/accuracy) every request returns HTTP 401 {\"errorcode\":\"InvalidAPIKey\"}; the header is only field-level \"required\"...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "5f7804", "surface": "www.neonrush.com /api/ controller space (content discovery)", "risk_area": "undocumented token/SSO authentication routes", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "ffuf against /api/FUZZ (295-word API endpoint list) with 404+301 filtered, plus a curated sso/token/jwt/launch/lobby/oidc list at the root: no real endpoint beyond the known controllers. /api/TokenAuth and /api/ssoAuthenticate matched only...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "62d72a", "surface": "www.neonrush.com /api/services/app/session/updateusersignintoken", "risk_area": "IDOR — mint a sign-in token for a foreign user", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Named control: the returned token and `encodedUserId` are always derived from the authenticated session's user, ignoring all request input. Supplying userId/id/encodedUserId/tenantId in the JSON body or query string (targeting user 1853837)...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "dfc26c", "surface": "www.neonrush.com ABP service map (/abpserviceproxies/getall + /abpscripts/getscripts)", "risk_area": "SSO/token-consumer route discovery (sso/jwt/token/launch/lobby/cogniplay/shopify/redirect/callback/authenticate)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "Enumerated all 191 auto-exposed app-service methods and their URLs. The only token-minting/consuming routes are: shopifyssotokenservice/generatejwt (the already-reported vuln-0022), session/updateusersignintoken (PUT, no-arg, returns the ca...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "c77e66", "surface": "Fleet sweep of all 47 in-scope hosts for a sibling Cogni/ASP.NET Boilerplate deployment or JWKS issuer", "risk_area": "SSO token consumer (does any in-scope host run the same platform/trust id.neonrush.com)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:35 UTC", "evidence": "GET /AbpServiceProxies/GetAll + /.well-known/jwks.json across all 47 hosts: only www.neonrush.com returns the ABP JS map and a JWKS (kid e63ad091-...). The 200s elsewhere are SPA catch-all fallbacks (Nuxt/Next marketing), not ABP. No siblin...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "a721fd", "surface": "WordPress fleet /?s= search (betmaze.co.uk, mogobet.com, playuk.com, theonlinecasino.co.uk, www.*)", "risk_area": "Reflected XSS", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "Payload `\"><zqx7>` reflected only HTML-encoded (&quot; &lt; &gt;) in the search field value, page title, RSS title and JSON-LD name on all hosts — no raw `<`, `>`, `\"` reaches an executable context (WordPress esc_html/esc_attr). No breakout...", "agent_name": "XSS Client-Injection & Race Breadth Hunter"}, {"entry_id": "441f6b", "surface": "appmanager.tangobet.co.uk (Betty admin API)", "risk_area": "CSRF / cross-site request forgery", "outcome": "not_applicable", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "Authentication is a Bearer JWT supplied in the Authorization header (stored in localStorage); no cookie session exists, so there is no ambient authority for a cross-site request to abuse. Confirmed by prior reviewer and re-checked on /api/a...", "agent_name": "XSS Client-Injection & Race Breadth Hunter"}, {"entry_id": "a92b96", "surface": "appmanager.tangobet.co.uk notification title/content (stored)", "risk_area": "Stored XSS reaching a renderer", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "title/content are stored verbatim and the admin React UI renders them as text (no HTML sink). No in-scope player-facing web surface that renders these notifications was reachable (tangobet player app play.tangobet.co.uk is Imperva 403). Whe...", "agent_name": "XSS Client-Injection & Race Breadth Hunter"}, {"entry_id": "36a893", "surface": "www.neonrush.com /api/services/app/* (ABP dynamic API)", "risk_area": "CSRF / cross-site request forgery", "outcome": "reported", "created_at": "2026-09-27 21:03:38 UTC", "evidence": "anti-forgery not enforced (no token, bogus X-XSRF-TOKEN/RequestVerificationToken, X-Requested-With all -> 200 success); identity cookie SameSite=None; forged cross-origin POST executed a durable server-side change (theme darkMode false->tru...", "agent_name": "XSS Client-Injection & Race Breadth Hunter"}, {"entry_id": "b83a13", "surface": "www.neonrush.com session/updateusersignintoken signInToken redemption", "risk_area": "sign-in-token replay / consumer", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "A fresh (cookie-less) session could not redeem the sign-in token: GET/POST /account/login/?signInToken=, GET /?signInToken=, POST /api/services/app/playeraccount/login {signInToken} all return the normal page or a generic validation error a...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "a94c45", "surface": "www.neonrush.com API CORS behaviour", "risk_area": "CORS misconfiguration / credentialed cross-origin read", "outcome": "ruled_out", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "Origin: https://evil.example and Origin: null on the authenticated API produced no Access-Control-Allow-Origin / -Credentials headers; the OPTIONS preflight returned 400. No CORS reflection, so cookie-session responses cannot be read cross-...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "14168a", "surface": "Minted SSO token replay across in-scope host APIs (neonrush, api-uat/qa.playuk, appmanager.tangobet)", "risk_area": "bearer/cookie acceptance of the minted SSO token", "outcome": "no_issue_found", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "Minted RS256 token (iss https://id.neonrush.com, aud cogniplay-sso, sub=attacker-chosen) replayed as Authorization: Bearer, X-Server-Authorization, and Cookie .AspNetCore.Identity.Application= against api-uat.playuk.com, api-qa.playuk.com,...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "faef87", "surface": "qa.neonrush.com / stg.neonrush.com", "risk_area": "reachability / token consumer behind Basic auth", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "dev/qa/stg.neonrush.com all sit behind the same HTTP Basic auth (WWW-Authenticate: Basic realm=\"Secure Area\") on every path incl. /.well-known/jwks.json and /AbpServiceProxies/GetAll. ~24 default/predictable credential pairs (admin/*, brand...", "agent_name": "SSO Consumer & Session Auth Hunter", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "484905", "surface": "www.neonrush.com /api/games/launch-url (+ /api/loggedoutlobby/*)", "risk_area": "token-consuming game-launch route", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:03:48 UTC", "evidence": "GET and POST /api/games/launch-url return HTTP 401 with a fully authenticated tenant-1 session cookie (empty body). The sibling lobby/game endpoints (api/loggedoutlobby/*) also require a X-Server-Authorization key. Gap: the game-launch inpu...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "28041f", "surface": "neonrush.com subdomain enumeration (affiliates, lp, play, qa, stg, trk)", "risk_area": "attack surface mapping / hidden token-accepting hosts", "outcome": "no_issue_found", "created_at": "2026-09-27 21:04:01 UTC", "evidence": "subfinder + crt.sh for neonrush.com yielded only affiliates/lp/play/qa/stg/trk/www. play.* is ProgressPlay (different platform); affiliates./trk. CNAME to raventrack.com and lp. redirects to hub.mamba.im (out-of-scope vendor). qa/stg are Ba...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "7336ff", "surface": "lp.neonrush.com", "risk_area": "SSO token consumer", "outcome": "not_applicable", "created_at": "2026-09-27 21:04:01 UTC", "evidence": "https://lp.neonrush.com/ is a 4.6KB static PHP \"Mamba Hub\" landing page (x-powered-by PHP/8.5.10, StackCDN) whose only link (/admin) 301-redirects to http://hub.mamba.im/admin/ — an out-of-scope third-party host. No token/SSO query-param ha...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "51f94f", "surface": "play.mrjackvegas.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "dd733a", "surface": "play.mogobet.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "95610b", "surface": "www.hotwinscasino.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Parent re-verified independently (browser session passes the Incapsula first-request challenge): HTTP 200, 73029 chars, all 4 credential markers present, byte-identical chunk. Folded into vuln-0008's broadened 22-host blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "3b905b", "surface": "www.betarno.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Parent re-verified independently with a plain unauthenticated HTTP client (no challenge on this host for the static path): HTTP 200, 73033 bytes, all 4 credential markers present, sha256 47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "64bfca", "surface": "play.mrsuperplay.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "20f9d4", "surface": "play.mrslot.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "f842fa", "surface": "play.mrmobi.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:05:34 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "5eded9", "surface": "www.mrslot.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "not_applicable", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Not applicable to the target risk. www.mrslot.com (Cloudflare, 200) is a Nuxt.js/Vue server-rendered marketing site, not the ProgressPlay Next.js build: it loads /_nuxt/*.js entry bundles, contains no reference to 5218-5c354764053c3ff3.js,...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "0b7fd7", "surface": "www.mrsuperplay.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "not_applicable", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Not applicable to the target risk. www.mrsuperplay.com (Cloudflare, 200) is a Nuxt.js/Vue marketing site (/_nuxt/BWkL8DXz.js entry bundle), no reference to 5218-5c354764053c3ff3.js; the chunk path returns the SPA catch-all index HTML (200,...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "7b2f49", "surface": "www.mogobet.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "not_applicable", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Not applicable to the target risk. www.mogobet.com (Cloudflare, 200, 658902 B) is a non-Next.js site (WordPress-style CMS markup); no buildId and no reference to 5218-5c354764053c3ff3.js in the HTML. GET of the chunk path returns HTTP 404 (...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "b8ce39", "surface": "www.mrmobi.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "not_applicable", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Not applicable to the target risk. www.mrmobi.com (Cloudflare, 200) is a Nuxt.js/Vue marketing site; no reference to 5218-5c354764053c3ff3.js and the chunk path returns the SPA catch-all index HTML (200, same 62461 bytes as /). No marker st...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "33bb40", "surface": "www.mrjackvegas.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "not_applicable", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Not applicable to the target risk. www.mrjackvegas.com (Cloudflare, 200) is a Nuxt.js/Vue marketing site; no reference to 5218-5c354764053c3ff3.js and the chunk path returns the SPA catch-all index HTML (200, same 67747 bytes as /). No mark...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "441927", "surface": "play.hotwinscasino.com (host reachability)", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Unreachable - named blocker. play.hotwinscasino.com has NO DNS record (dig +short returns empty; hotwinscasino.com apex and www.hotwinscasino.com do resolve to Imperva 45.60.243.194). A browser navigation and the HTTP proxy both fail with D...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "d5a977", "surface": "www.betmorph.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "ruled_out", "created_at": "2026-09-27 21:05:49 UTC", "evidence": "Ruled out for this surface. Named control: an HTTP 308 Permanent Redirect at the edge (www.betmorph.com -> https://betmorph.com/) plus a different application at the destination. The apex betmorph.com returns the Hercules Vite/React SPA (82...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "c8e343", "surface": "play.betmorph.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "d87c98", "surface": "play.betstorm.com (host reachability)", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Unreachable - named blocker. play.betstorm.com resolves (Cloudflare) but every request (curl and real headless browser) returns Cloudflare error 522 \"Connection timed out\" (7252 B) - the origin is down/unreachable, so the chunk cannot be fe...", "agent_name": "PP Gated-Host Credential Chunk Verifier"}, {"entry_id": "5c3bed", "surface": "play.777tigers.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "026e9c", "surface": "www.betstorm.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Parent re-verified independently (browser session passes the Incapsula first-request challenge; same-origin fetch then returns the asset): HTTP 200, 73029 chars, all 4 credential markers present, chunk byte-identical to the platform referen...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "133bb1", "surface": "play.betmaze.co.uk /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) via a plain unauthenticated HTTP client (no WAF challenge on this host for the static path): HTTP 200, 73033 bytes, sha256 47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d...", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "e56f08", "surface": "play.vampirebingo.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "12ebbe", "surface": "play.theonlinecasino.co.uk /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "97691c", "surface": "play.jazzyspins.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "5821eb", "surface": "play.slotlux.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "dfd19d", "surface": "play.chitchatbingo.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:06:06 UTC", "evidence": "Confirmed by the parent (Shared-Platform Cross-Tenant Amplifier) with an independent in-page fetch: HTTP 200, credential chunk served, all 4 markers present. Folded into vuln-0008's broadened blast radius.", "agent_name": "Shared-Platform Cross-Tenant Amplifier", "previous_outcomes": ["needs_follow_up"]}, {"entry_id": "67470b", "surface": "appmanager.tangobet.co.uk (Betty Admin)", "risk_area": "CSRF", "outcome": "not_applicable", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Authentication is by an `Authorization: Bearer` JWT returned in the login JSON body; the login response sets no cookie (`Set-Cookie: None`) and the admin API is header-authenticated, so there is no ambient session credential for a cross-sit...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "425f89", "surface": "betmaze.co.uk, mogobet.com, playuk.com, uat.uk-bingo.net, partners.jackpot.com, jazzyspins.com, africasports.com, dynobet.com, betmorph.com — X-Forwarded-Host / Host reflection", "risk_area": "Host-header injection / web cache poisoning", "outcome": "no_issue_found", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "`X-Forwarded-Host: attacker.example` is not reflected in any response body or Location header on any host tested; Cloudflare-fronted responses are `CF-Cache-Status: DYNAMIC` (not cached). Foreign `Host:` values are rejected by the edges (40...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "1f9d6a", "surface": "www.neonrush.com — password-reset & email-activation link construction (/api/services/app/playeraccount/sendpasswordresetcode, sendemailactivationlink)", "risk_area": "Host-header injection / password-reset link poisoning", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Tested Host, X-Forwarded-Host, X-Forwarded-Proto, Forwarded, X-Host, X-Forwarded-Server variants against the unauth reset/activation endpoints: response is `{successful:true, redirectUrl:null, code:null, isGeoBlocked:false}` with NO reflect...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "9489e4", "surface": "www.jackpot.com — Host header handling / culture-link generation", "risk_area": "Host-header injection / cache poisoning / open redirect", "outcome": "ruled_out", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "The attacker-controlled `Host` header IS reflected into footer culture links (`<a href=\"https://attacker.example/es\">`), but the effect is self-only and non-exploitable: responses carry `Cache-Control: private` and `Vary: Accept-Encoding` (...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "5f985d", "surface": "www.neonrush.com — ABP service API state-changing endpoints (POST/PUT/DELETE; e.g. /api/services/app/uicustomizationsettings/changedarkmodeofcurrenttheme)", "risk_area": "CSRF / anti-forgery enforcement", "outcome": "reported", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Auth cookie issued `samesite=none; secure; httponly`. No anti-forgery token enforced and Origin/Referer not validated: a cross-site-shaped POST (Origin: https://attacker.example, form content-type, no X-XSRF-TOKEN) returned success:true and...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "fecca1", "surface": "WordPress hosts wp-admin / lost-password (playuk.com, mogebet.com, betmaze.co.uk, betsuna.com, jeffbet.net, theonlinecasino.co.uk)", "risk_area": "CSRF", "outcome": "not_applicable", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "WordPress protects authenticated state-changing admin actions with per-action nonces, and password-reset/activation links are built from the DB `siteurl`, not the request Host — `X-Forwarded-Host: attacker.example` produced no reflection on...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "d15eca", "surface": "api-qa.playuk.com / api-uat.playuk.com (Markor Revolve player API)", "risk_area": "CSRF / anti-forgery enforcement", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:06:21 UTC", "evidence": "Session is a `SessionCorrelationId` cookie; the observed state-changing endpoints (register/lite, isBonusCodeValid, login) take JSON request bodies and CORS is closed (no ACAO), so a preflight-free cross-site form cannot reach them. Gap: a...", "agent_name": "CSRF and Host-Header Poisoning Hunter"}, {"entry_id": "39dc32", "surface": "POST /revolve/api/limits/deposit (concurrency)", "risk_area": "Race condition / non-atomic state / lost update", "outcome": "no_issue_found", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Concurrent identical/submitted-different calls produce a large fraction of HTTP 500 (e.g. 14/20, 20/25) while sequential calls all return 200, and the final stored limit is non-deterministic (last writer among the 200s). However the effect...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "30db1b", "surface": "GET /revolve/api/limits/deposit", "risk_area": "Stale cache / cross-session information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Within one session the GET returns a stale cached copy of that session's own limits (kept showing 3/10/15 for >25s after the limits were changed to 111/222/333); a freshly authenticated session returns the correct current values. The stale...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "e01f3d", "surface": "POST /revolve/api/account/claimReward", "risk_area": "Race condition / reward double-claim + claimCode IDOR", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Body is {claimCode:<v>} (confirmed from the SPA bundles). All claimCode probes (\"1\",\"2\",\"0\",\"WHEEL\",\"ADVENTURE\",\"LEVEL1\") return a generic HTTP 500 System Error; 25 concurrent identical calls all 500. Valid claim codes are issued by CMS pro...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "4f8638", "surface": "POST /revolve/api/limits/deposit", "risk_area": "Responsible-gambling control bypass (missing cooling-off on increase)", "outcome": "reported", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Filed as vuln-0032. A genuine increase (active daily 5 -> 200) returned HTTP 200 with pendingDaily/pendingWeekly/pendingMonthly all null and the new value active immediately (confirmed from a fresh session), despite the API contract exposin...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "507475", "surface": "POST /revolve/api/promobonus/redeemPromocode", "risk_area": "Race condition / single-use promo-code double-claim", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:19 UTC", "evidence": "Could not reach the redemption success path: every code supplied (WELCOME, PLAYUK, GRACE, CASINO, FREESPINS, ...) returned code 37 \"Promo code is invalid\"; no valid code is obtainable within scope (promotions are served as CMS JSON from the...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "c0f790", "surface": "POST /account/rewardOptOut, /account/optInToPromotion, /loyalty/redemption/{id}/{blocks}, /account/cancelActiveBonus", "risk_area": "Race condition / non-idempotent promo &amp; preference state changes", "outcome": "no_issue_found", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "Concurrency tested on preference/promo state endpoints: POST /account/rewardOptOut (25x -> 21x200/4x500, final state correct), /account/setRealityCheckLimit (25x200, value correct), /account/optInToPromotion (25x400 code 124 — invalid ident...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "716964", "surface": "POST /revolve/api/account/updateProfile", "risk_area": "Mass assignment / privilege &amp; balance escalation", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "POST /revolve/api/account/updateProfile returns 200 \"Player profile has been updated successfully\" but silently drops all server-managed fields supplied in the body — playerAdventureRewardPoints, adventureRewardLevelID, nextAdventureRewardL...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "d29315", "surface": "POST /revolve/api/payments/withdraw + /payments/provider/cancelPendingWithdrawal + /payments/transactionStatus", "risk_area": "Race condition / double-pay &amp; withdrawal state-machine abuse", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "Withdrawals are disabled on QA: POST /revolve/api/payments/withdraw returns code 141 \"Payments are under maintenance\" for every body (empty, {amount:10}, {amount:10,currencyCode:\"GBP\"}). There are no pending withdrawal records to exercise:...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "ea1dcc", "surface": "paymentRecord / promoCode / identifier object references", "risk_area": "IDOR / object-level authorization on promo &amp; payment identifiers", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "Object ids in the promo/payment flows cannot be tested for cross-account access because no such objects exist to seed them: synthetic accounts have zero payment records, zero pending withdrawals, zero bonuses/rewards/transactions and a zero...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "9a6332", "surface": "SessionCorrelationId / userCorrelationId session cookies", "risk_area": "Session prediction / token reuse / concurrent-session abuse", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "SessionCorrelationId is a random UUIDv4 on every login (checked 6 logins: versions all 4, random first octets) — not time-based/predictable. Single-session enforcement is real: each new POST /revolve/api/account/login invalidates the accoun...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "9cc6a6", "surface": "POST /revolve/api/payments/deposit", "risk_area": "Business logic — negative/zero/fractional amount abuse &amp; deposit-limit bypass", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:31 UTC", "evidence": "POST /revolve/api/payments/deposit enforces both platform prescribed limits (code 107 \"not in the prescribed limits\" for negative/zero/0.01/1000000) and the per-player deposit limit (code 108 \"greater than the limits set\", e.g. amount 10 wh...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "1d3a3a", "surface": ".AspNetCore.Identity.Application session cookie (www.neonrush.com)", "risk_area": "Session cookie attributes (SameSite / HttpOnly / Secure / Domain) as a CSRF and theft defence", "outcome": "reported", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Raw Set-Cookie on register/login: `path=/; secure; samesite=none; httponly` with no Domain attribute (host-only). HttpOnly and Secure are correctly set and the host-only scope prevents sibling-subdomain theft, but SameSite=None means the br...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "4da926", "surface": "www.neonrush.com session fixation at the authentication transition", "risk_area": "Session fixation", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the server issues a newly generated `.AspNetCore.Identity.Application` value on each register/login and ignores a client-supplied value. Test: pre-setting the cookie to a fixed attacker-known value, then registering, produced...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "3e8f88", "surface": "GET /account/logout and server-side session revocation (www.neonrush.com)", "risk_area": "Logout / server-side session revocation", "outcome": "no_issue_found", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "On a dedicated synthetic account, GET /account/logout returned 302 with a clearing Set-Cookie; replaying the SAME pre-logout cookie against session/getcurrentlogininformations returned user:null, i.e. the session is revoked server-side. (Ob...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "b62ec0", "surface": "/api/services/app/session/updateusersignintoken (PUT) (www.neonrush.com)", "risk_area": "Sign-in token replay as an authentication credential", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Returns {\"signInToken\":\"<guid>\",\"encodedUserId\":\"<b64>\",\"encodedTenantId\":\"<b64>\"}. In a cookie-less session the token did NOT authenticate in any form tested (?signInToken= query, X-SignIn-Token header, as the identity-cookie value → user:...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "f534e7", "surface": "Session cookie Domain scope vs sibling subdomains (lp.qa.stg.neonrush.com)", "risk_area": "Cookie scope / sibling-subdomain cookie theft", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the Set-Cookie has no Domain attribute, so the cookie is host-only to www.neonrush.com and the browser will not send it to lp.neonrush.com / qa / stg. It is also HttpOnly (no JS read). Note lp.neonrush.com is a non-Cogni PHP...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "c9ee2b", "surface": "/api/services/app/profile/{changepassword,updatecurrentuseremailaddress,disablegoogleauthenticator,deleteaccount} (www.neonrush.com)", "risk_area": "CSRF reaching credential/account-takeover actions", "outcome": "ruled_out", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Named control: the ASP.NET Core JSON input formatter binds these complex `input` DTOs [FromBody] and rejects every browser-sendable content type — application/x-www-form-urlencoded, multipart/form-data and text/plain all return HTTP 415 (ve...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "f30bed", "surface": "ABP /api/services/app/* state-changing endpoints (www.neonrush.com)", "risk_area": "CSRF (cross-site request forgery)", "outcome": "reported", "created_at": "2026-09-27 21:07:48 UTC", "evidence": "Filed/covered by vuln-0031 (revised with additional evidence). Independently reproduced: with a cookie jar containing only the session cookie, a cross-origin form-encoded POST (Origin: https://evil.example, no anti-forgery token) returned 2...", "agent_name": "ABP Session Cookie Security"}, {"entry_id": "4c358f", "surface": "blog.lekkerbets.co.za (WordPress 7.1.2)", "risk_area": "Unauthenticated user enumeration / WP REST", "outcome": "reported", "created_at": "2026-09-27 21:08:39 UTC", "evidence": "NEW in-scope asset (subdomain of lekkerbets.co.za), Apache/WordPress 7.1.2, no WAF block. /wp-json/wp/v2/users and /?rest_route=/wp/v2/users both return 200 with users lekkerbets(admin,id1) and heidi(id2); /?author=1 also discloses the auth...", "agent_name": "Imperva Host Reachability Mapper"}, {"entry_id": "1ef706", "surface": "bonus.supabet.co.uk / media.hotwinscasino.com / sp-track.mrrex.com / sp-bounce.mrrex.com", "risk_area": "Unauthenticated exposure of subdomains", "outcome": "ruled_out", "created_at": "2026-09-27 21:08:39 UTC", "evidence": "bonus.supabet.co.uk: CloudFront returns 401 with WWW-Authenticate Basic realm=Login on every path (access-controlled by origin policy). media.hotwinscasino.com: S3 bucket returns AccessDenied for object, listing (?list-type=2) and ?acl (no...", "agent_name": "Imperva Host Reachability Mapper"}, {"entry_id": "84b42f", "surface": "offers.21luckybet.com / promo.21luckybet.com (21luckybet.com subdomains)", "risk_area": "attack surface mapping / client-side", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:39 UTC", "evidence": "Newly-discovered Cloudflare subdomains, reachable without the Imperva block. offers. = static Astro marketing (200, data-brand 21luckybet); promo. = static page doing a same-origin redirect to /${lang}/${page} (lang allowlisted en/fi/ie) —...", "agent_name": "Imperva Host Reachability Mapper"}, {"entry_id": "219a9e", "surface": "www.neonrush.com sendpasswordresetcode / sendemailactivationlink", "risk_area": "Host-header poisoning of password-reset / activation email links (ATO)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:08:41 UTC", "evidence": "Bounded check of POST /api/services/app/playeraccount/sendpasswordresetcode and /sendemailactivationlink with Host: evil.example (403 from Cloudflare), X-Forwarded-Host, X-Original-URL and Forwarded: host=evil.example — the generated link i...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "713fc5", "surface": "www.neonrush.com .AspNetCore.Identity.Application cookie scope + tenant binding", "risk_area": "cross-tenant session confusion / cookie scope", "outcome": "ruled_out", "created_at": "2026-09-27 21:08:41 UTC", "evidence": "Session cookie Set-Cookie attributes captured raw: `.AspNetCore.Identity.Application=...; expires=...; path=/; secure; samesite=none; httponly` — host-only (no Domain), so no sibling-subdomain (e.g. lp.neonrush.com) theft. Cross-tenant: a t...", "agent_name": "SSO Consumer & Session Auth Hunter"}, {"entry_id": "a846e0", "surface": "pandabingo.com /_nuxt bundle set (26 chunks, 416,193 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://www.pandabingo.com/ (entry DPY1EvNE.js), 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. runtimeConfig.public = {siteConfigImported:true}; /_payload.json 112 B JSON, no creden...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "2486ff", "surface": "betarno.com apex /_nuxt bundle set (39 chunks, 518,924 B) + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Nuxt app is on the APEX (https://betarno.com/, entry entry.1c1d78af.js); https://www.betarno.com is a separate Next.js app. Closed chunk set, 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean; runtimeConfig.p...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "13afb8", "surface": "vampirebingo.com /_nuxt bundle set (27 chunks, 388,572 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://www.vampirebingo.com/, 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. Only notable string was a public promo code in a marketing link (code=IGPVampireBingoWelcome). buildId 8...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "df2db6", "surface": "uk-bingo.net /_nuxt bundle set (26 chunks, 415,565 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://www.uk-bingo.net/, 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. runtimeConfig.public = {siteConfigImported:true}. buildId 5bc8fe28-16f1-4d60-b7b5-8da53c2ea334.", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "480df6", "surface": "chitchatbingo.com /_nuxt bundle set (26 chunks, 418,328 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://www.chitchatbingo.com/, 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. runtimeConfig.public = {siteConfigImported:true}, /_payload.json 112 B with no credential keys. buildId...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "b3db83", "surface": "jazzyspins.com /_nuxt bundle set (32 chunks, 460,394 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://jazzyspins.com/ (canonical apex), 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. runtimeConfig.public = {gtmId:\"GTM-NXQKF26Z\"} (public GTM container id, no secret). buildId 0...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "c17dc7", "surface": "queensbingo.com /_nuxt bundle set (23 chunks, 291,032 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://www.queensbingo.com/, 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean. runtimeConfig.public = {siteConfigImported:true}. Only high-entropy constants were base64 charset and an...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "ea837f", "surface": "slotlux.com /_nuxt bundle set (21 chunks, 273,479 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Closed chunk set from https://slotlux.com/ (canonical apex, entry BF8YulY3.js), 0 unresolved refs. gitleaks 0, trufflehog 0/0, manual regex + entropy sweep clean (zero >4.0-entropy non-library tokens). runtimeConfig.public = {} (empty). bui...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "0a11e4", "surface": "wombatbingo.com /_nuxt bundle set (27 chunks, 388,473 B) + apex/www + __NUXT__ payload", "risk_area": "client-side secret exposure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:08:56 UTC", "evidence": "Full closed chunk set enumerated from https://www.wombatbingo.com/ (entry CR3aIbcl.js) by following HTML refs + relative imports (0 unresolved refs). gitleaks --no-git: 0 findings; trufflehog filesystem: 0 verified / 0 unverified; manual hi...", "agent_name": "Nuxt Marketing Bundle Secret Scanner"}, {"entry_id": "1954a0", "surface": "www.jackpot.com POST /%2fadmin (Content Admin login) — auth abuse", "risk_area": "Authentication — user enumeration / lockout / credential stuffing", "outcome": "no_issue_found", "created_at": "2026-09-27 21:11:00 UTC", "evidence": "Every wrong-credential POST returns the byte-identical 133-byte JSON (message 'Wrong USERNAME and/or PASSWORD!') for admin, admin'-- -, admin' OR '1'='1 and a 300-char username, with constant ~0.63-0.84s timing -> no username enumeration vi...", "agent_name": "Jackpot Admin Surface"}, {"entry_id": "c4e77e", "surface": "www.jackpot.com admin endpoints (customErrors=Off verbose errors)", "risk_area": "Verbose error / stack-trace information disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:11:00 UTC", "evidence": "POST /%2fadmin with no anti-forgery token -> HTTP 500 verbose ASP.NET page (8365B) exposing only framework detail (.NET 4.8.9344.0 / System.Web.Mvc HttpAntiForgeryException); HTML in Username -> 500 request-validation page; no app source pa...", "agent_name": "Jackpot Admin Surface"}, {"entry_id": "64bcb7", "surface": "jackpot.com subdomains (results-dev/stage, lotto, uk, us, api-us, data, se, affs, rss, jplsbr, xp-sms, my, casino, thelotter, cdm.link.marketing)", "risk_area": "attack surface mapping / subdomain takeover", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:11:00 UTC", "evidence": "results-dev/results-stage -> AWS S3 403 (bucket exists, listing denied); se.jackpot.com -> DNSMadeEasy 'lostredirect' page (dangling CNAME, takeover candidate); affs.jackpot.com -> Cloudflare 'CNAME Cross-User Banned' (dangling CNAME); jpls...", "agent_name": "Jackpot Admin Surface"}, {"entry_id": "9dc69d", "surface": "state-changing /revolve/api/* routes (limits/deposit, rewardOptOut, account preferences, promobonus, payments)", "risk_area": "CSRF on state-changing routes", "outcome": "reported", "created_at": "2026-09-27 21:11:23 UTC", "evidence": "Filed as vuln-0034. Session cookie is `SameSite=None; Secure; HttpOnly`; state-changing JSON routes (limits/deposit, rewardOptOut, preference updates, promo, payments) accept a `text/plain` body (CORS-simple, no preflight) and apply changes...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "a6a38c", "surface": "GET on mutating /revolve/api/* routes", "risk_area": "State change via GET (GET-based CSRF)", "outcome": "ruled_out", "created_at": "2026-09-27 21:11:23 UTC", "evidence": "State change via GET was checked: GET /revolve/api/limits/deposit?daily=9 returns HTTP 200 but simply returns the CURRENT limits (daily 1000.00) and ignores the query parameter; GET /account/changeLanguagePreference?lang=es and GET /account...", "agent_name": "PlayUK Revolve Race &amp; Promo-Logic Hunter"}, {"entry_id": "69b793", "surface": "45.132.74.81 (nginx 1.24.0 -> Tomcat 9.0.121 / Apache Guacamole 1.6.0 / OpenSSH 9.6p1 / NoMachine NX 10.0.59)", "risk_area": "Component CVE → RCE (version-vs-advisory range mapping)", "outcome": "no_issue_found", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "vulnx id range check: Guacamole RCE CVEs (CVE-2024-35164 <=1.5.5, 2023-43826 <=1.5.3, 2023-30576 <=1.5.1, 2023-30575 <=1.5.1) all out of range for 1.6.0; Tomcat 9.0.121 > all affected ceilings (CVE-2025-24813 <=9.0.98, 2024-50379 <=9.0.97,...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "941eef", "surface": "WordPress fleet (betmaze/betsuna/jeffbet/playuk/theonlinecasino/mogobet/promo.hotwins) — plugins & core", "risk_area": "Component CVE → RCE (plugin/core version-vs-advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "Out of range: LiteSpeed Cache 7.8.1 (CVEs 2024-28000 <=6.3.0.1, 2024-50550 <=6.5.1, 2024-47637 <=6.4.1), ACF 6.8.8 (2023-1196 <6.1.0), Yoast (CVE-2026-10821 rejected/premium). WordPress core 7.1.2: CVE-2026-63030 (pre-auth REST batch SQLi→R...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "8d908f", "surface": "77.68.12.66 (Plesk Obsidian 18.0.80.8 / MariaDB 10.5.29 / ProFTPD / OpenSSH 8.0)", "risk_area": "Component CVE → RCE (version-vs-advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "OpenSSH 8.0: CVE-2023-38408 (<9.3p2) and CVE-2023-51385 (<9.6) are IN RANGE (pre-auth, PoC + nuclei available) but require agent-forwarding / untrusted-hostname preconditions — unconfirmed on this host. ProFTPD version UNKNOWN: CVE-2019-128...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "a3c8d6", "surface": "Next.js / React RSC fleet + Nuxt/Nitro + Strapi (UAT & marketing apps)", "risk_area": "Component CVE → RCE (framework/advisory range mapping)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:05 UTC", "evidence": "CVE-2025-55182 (React Server Components 19.0.0/19.1.0/19.1.1/19.2.0, unauth deserialization RCE, CVSS 10, PoC=100, KEV) — in range ONLY if an app pins those RSC versions; prior pack verified patched on UAT apps. CVE-2026-75604 (Next.js) sta...", "agent_name": "Component CVE-RCE Mapper"}, {"entry_id": "c3d84c", "surface": "https://www.jackpot.com Widgets/UsKroger/* (Kroger OAuth integration, Microsoft-HTTPAPI backend)", "risk_area": "Third-party OAuth/config secret disclosure via verbose error or handler output", "outcome": "no_issue_found", "created_at": "2026-09-27 21:12:15 UTC", "evidence": "Kroger handlers POST-only. KrogerConfirmation with a missing code/state throws an APPLICATION-level ArgumentNullException (\"Value cannot be null. Parameter name: stringToEscape\") at C:\\inetpub\\JackpotBuild\\Stage-East\\www.jackpot.com\\Lottery...", "agent_name": "Jackpot Trace Secret Miner"}, {"entry_id": "a20db8", "surface": "www.neonrush.com /api/services/app/playeraccount/{sendpasswordresetcode,resetpassword}", "risk_area": "Authentication bypass / account takeover via password-reset flow", "outcome": "reported", "created_at": "2026-09-27 21:12:16 UTC", "evidence": "Unauth `sendPasswordResetCode?sendEmail=false` returns the reset code in the body; `resetPassword` accepts it with a client-supplied future `expireDate`; login with attacker-set password yields a victim session. Full ATO proved end-to-end;...", "agent_name": "NeonRush Auth-Gap Closer"}, {"entry_id": "084b3e", "surface": "Abp.TenantId header on an authenticated session (tenant hopping)", "risk_area": "Cross-tenant isolation / session tenant override", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:22 UTC", "evidence": "With a valid tenant-1 (.AspNetCore.Identity.Application) cookie, session/getcurrentlogininformations returned the caller only for Abp.TenantId: 1. With the header absent, 0, 17, -1 or 99999 the same request resolved tenant 17 and returned u...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "7c812f", "surface": "userLogin.getUserLoginAttempts / getUserLoginAttemptCount (tenant scoping of the filed IDOR)", "risk_area": "Cross-tenant data access (IDOR scope)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:22 UTC", "evidence": "Cross-user read is confirmed (a tenant-1 session read another tenant-1 user's rows). The cross-TENANT scope could not be established: a tenant-17 user id (1854267, created via registerExternalFromApi without the tenant header) returned tota...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "c75e7e", "surface": "playerAccountUser.suspend and playerAccountUser.selfExclude", "risk_area": "IDOR / cross-user account suspension or self-exclusion", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:22 UTC", "evidence": "DTO oracle: both inputs declare only `reason`; userId, playerId, targetUserId, id, isPermanent, exclusionType, months, days are undeclared and silently ignored. Calling suspend with no user identifier suspended the caller's own account (sub...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "875545", "surface": "POST /api/services/app/playeraccount/registerexternalfromapi (mass-assignment fields)", "risk_area": "Mass assignment / privilege escalation to admin role", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:22 UTC", "evidence": "Type-mismatch DTO oracle (send a declared property with an impossible type and read the Newtonsoft error `Path '<key>'`, which is fail-safe because deserialization aborts before the service runs) proves the bound DTO declares only provider,...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "68b5f9", "surface": "https://www.jackpot.com/Media/widgets/widget-account/js/sign-up.js (client-side bundle)", "risk_area": "Hardcoded credentials / secret exposure in client-side JavaScript", "outcome": "reported", "created_at": "2026-09-27 21:12:24 UTC", "evidence": "Publicly served bundle (200, 44,927 B) contains a cleartext credential block at line 1090 inside the unused loadTestContent helper: 'Email':'vlada.jptest.001@jackpot.com','Password':'12345678', plus auth_CodeID 38010 and auth_ReferenceID '3...", "agent_name": "Jackpot Trace Secret Miner"}, {"entry_id": "e5ac0d", "surface": "www.jackpot.com method/Content-Type/body handling on widget actions (POST, empty body, 411, malformed types)", "risk_area": "Verbose error / server-framework disclosure", "outcome": "no_issue_found", "created_at": "2026-09-27 21:12:24 UTC", "evidence": "POST without a body returns Microsoft-HTTPAPI/2.0 411 (Length Required) for Kroger handlers and Microsoft-IIS/10.0 responses elsewhere; with an empty body the actions bind null and raise the same framework ArgumentException. No server versi...", "agent_name": "Jackpot Trace Secret Miner"}, {"entry_id": "fd73c1", "surface": "smartico.awardBonus / payPromotion / jackpotWin / gamesCatalog", "risk_area": "Operator-level function abuse (bonus/promotion credit to arbitrary user)", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:33 UTC", "evidence": "smartico.awardBonus/payPromotion/jackpotWin declare a client-supplied userId, but with a valid userId they fail closed: HTTP 500 generic error, no balance change (accountingUser.getBalanceForPlayer before/after), no transaction; their signa...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "26b4e2", "surface": "www.neonrush.com administrative surface (ABP Zero admin services + admin UI paths)", "risk_area": "Vertical privilege escalation to admin/operator", "outcome": "not_applicable", "created_at": "2026-09-27 21:12:33 UTC", "evidence": "No privilege-escalation target exists on this host. /admin, /admin/login, /hangfire, /elmah.axd, /swagger, /operator, /backoffice, /dashboard, /management, /cogniadmin, /adminpanel all 404 (the 301s are case-normalisation redirects that the...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "9e35f8", "surface": "transactionsUser.freeRefill", "risk_area": "BFLA / unauthorized funds grant to arbitrary user", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:33 UTC", "evidence": "freeRefillInput declares userId (Int64) and emailAddress. Supplying another account's email from either account's session is rejected with reason 'Invalid EmailAddress', while the caller's own email passes that check (then fails on 'Incompl...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "3de49a", "surface": "GET /api/services/app/accountinguser/getbalanceforplayer", "risk_area": "IDOR / cross-user balance disclosure", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:33 UTC", "evidence": "The action signature has no parameters (JS proxy stub: getBalanceForPlayer(ajaxParams); probing ?userId/?playerId/?id/?tenantId changes nothing and returns the identical zero-balance object for the caller, for another tenant-1 user, for a t...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "31232e", "surface": "Full ABP application-service surface (/api/services/app/*, 47 controllers)", "risk_area": "BFLA / missing function-level authorization", "outcome": "no_issue_found", "created_at": "2026-09-27 21:12:45 UTC", "evidence": "A full authenticated sweep of every application service published in AbpServiceProxies/GetAll (about 130 actions across 47 controllers) with a fresh tenant-1 player session produced zero 401/403 responses: 60x200, 35x500 (integration unconf...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "c4d90c", "surface": "POST /api/services/app/freeentrycodeuser/getnewcode (skipCaptcha / captchaResponse)", "risk_area": "Anti-automation bypass via client-controlled skipCaptcha", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:45 UTC", "evidence": "freeentrycodeuser/getnewcode requires a non-empty captchaResponse (validation error 'A non-empty request ... / Unexpected character' in every combination tried, including ?skipCaptcha=true and ?captchaResponse=x&skipCaptcha=true); skipCaptc...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "5fcbaf", "surface": "transactionsUser.reverse(batchId) and getProcessingStatus(batchId)", "risk_area": "Financial integrity / unauthorized transaction reversal", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:12:45 UTC", "evidence": "transactionsUser.reverse and getProcessingStatus take a batchId that rejects integers and non-GUID strings (HTTP 400 'Your request is not valid!'), so the target could not be selected without a real transaction batch identifier. No batch GU...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "ca47b5", "surface": "profile.* and documentUser.create input DTOs", "risk_area": "Mass assignment on authenticated profile/document DTOs", "outcome": "ruled_out", "created_at": "2026-09-27 21:12:45 UTC", "evidence": "DTO oracle for the writable profile services: completeAndActivateProfile declares name, surname, phoneNumber, dateOfBirth, addressLine1, addressLine2, city, state, country, zipCode; updateCurrentUserProfile declares name, surname, emailAddr...", "agent_name": "NeonRush ABP PrivEsc Chain Validator"}, {"entry_id": "278bca", "surface": "www.africasports.com + africasports.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:12:56 UTC", "evidence": "Independently re-verified by the Shared-Platform Cross-Tenant Amplifier with a plain unauthenticated HTTP client (no challenge on this host for the static path): HTTP 200, 73033 bytes, all 4 credential markers. Folded into vuln-0008's broad...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "d452d8", "surface": "www.acelucky.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:12:56 UTC", "evidence": "Independently re-verified (browser session passes the Incapsula first-request challenge; same-origin fetch then returns the asset): HTTP 200, 73029 chars, all 4 credential markers present. Folded into vuln-0008.", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "ee7714", "surface": "www.777bet.casino /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:12:56 UTC", "evidence": "Independently re-verified (browser session passes the Incapsula first-request challenge): HTTP 200, 73029 chars, all 4 credential markers present. Folded into vuln-0008.", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "6752b0", "surface": "www.dynobet.com /_next/static/chunks/5218-5c354764053c3ff3.js", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:12:56 UTC", "evidence": "Independently re-verified (browser session passes the Incapsula first-request challenge): HTTP 200, 73029 chars, all 4 credential markers present. Folded into vuln-0008.", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "547901", "surface": "www.jackpot.com web.config / App_Data / bin (machineKey & secret retrieval via ALB bypass)", "risk_area": "Configuration / secret exposure (machineKey, connection strings)", "outcome": "ruled_out", "created_at": "2026-09-27 21:14:12 UTC", "evidence": "Named control: IIS requestFiltering hiddenSegments + static file handler. With a clean control (/ = 200), every alternate encoding returned the IIS static 404 (1245B): /web.config::$DATA, /web.config%3a%3a%24DATA, /%2fweb.config::$DATA (NTF...", "agent_name": "Jackpot Admin Surface"}, {"entry_id": "39d9ef", "surface": "qa/stg/dev.neonrush.com (staging Cogni/ABP environments)", "risk_area": "Authentication bypass via shared X-Server-Authorization key / staging asset exposure", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:14:38 UTC", "evidence": "LIVE ABP instances. qa.neonrush.com serves the API without auth for /api/* (e.g. GET /api/services/app/session/getcurrentlogininformations → 200, tenant \"NeonRush\" id 20) but every non-/api path (/, /abpscripts, /abpserviceproxies, /dist/*,...", "agent_name": "Cogni X-Server-Authorization Key Hunter"}, {"entry_id": "450c4d", "surface": "www.neonrush.com unauthenticated GET surface (all 65 GET methods of the 46 ABP services)", "risk_area": "Configuration/secret disclosure in service responses", "outcome": "no_issue_found", "created_at": "2026-09-27 21:14:38 UTC", "evidence": "Enumerated every GET method from abpserviceproxies/getall and called each unauthenticated (X-Forwarded-For: 8.8.8.8, no session). Exactly 9 returned 200 and all are benign/public (geo decision, password-policy, locales, empty profile pictur...", "agent_name": "Cogni X-Server-Authorization Key Hunter"}, {"entry_id": "dfd207", "surface": "POST /revolve/api/account/login (api-qa.playuk.com) — per-account failed-login counter / lockout", "risk_area": "Race condition / TOCTOU defeating the account-lockout threshold", "outcome": "reported", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "Confirmed non-atomic counter. Sequential baseline (fresh QA account): 3 wrong passwords -> HTTP 401 code 11, 4th -> HTTP 400 code 246 locked. A concurrency-synchronised 20-request burst on a fresh account: 6 requests verified the wrong pass...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "ffc9fc", "surface": "POST /revolve/api/{account/claimReward,account/awardBonus,account/optInToPromotion,promobonus/redeemPromocode,loyalty/redemption,account/freeSpinDetails} (api-qa.playuk.com)", "risk_area": "Race condition on one-per-period bonus / reward / promotion claims (double-claim)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "All endpoints are reachable with an authenticated QA session but reject every test input at validation: claimReward -> code 1 \"Missing or invalid parameter(s)\"; awardBonus -> code 163 \"Invalid Bonus\"; redeemPromocode -> code 37 \"Promo code...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "577d23", "surface": "POST /revolve/api/register/lite and /revolve/api/register/superLite (api-qa.playuk.com)", "risk_area": "Race condition → duplicate account creation / uniqueness-check bypass", "outcome": "no_issue_found", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "Concurrent 4x register/lite with an identical email/mobile: exactly 1 HTTP 200 (account created) and 3 HTTP 500; uniqueness enforced. Cross-endpoint race (register/lite + register/superLite fired simultaneously with the same email): lite 20...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "cc864a", "surface": "POST /api/services/app/playeraccount/login (www.neonrush.com, ABP, tenant 1)", "risk_area": "Race condition / TOCTOU defeating the ABP account-lockout threshold", "outcome": "no_issue_found", "created_at": "2026-09-27 21:14:59 UTC", "evidence": "Sequential baseline: 4 wrong passwords -> \"Invalid user name or password\", 5th -> \"The user account has been locked out\" (threshold 4). A 10-request concurrent burst on a fresh account produced exactly 4 password verifications, 2 lockout re...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "bcd829", "surface": "www.neonrush.com /api/amoe/*, /api/freerefill, /api/redemption/*, /api/coins/*, /api/playerprofile/*, /api/services/app/transactionsuser/freerefill, /api/services/app/loyaltyuserservice/redeemloyaltypoints", "risk_area": "Race condition on privileged / one-per-user limit endpoints (refill, redemption, coins, loyalty points)", "outcome": "needs_follow_up", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Reachability gap: the dark API routes (amoe/code, amoe/info, amoe/history, freerefill, redemption/*, coins/packages*, playerprofile/*) all return HTTP 401 (coins/packages/query returns {\"errorcode\":\"InvalidAPIKey\"}) because they require the...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "b17853", "surface": "POST /api/services/app/playeraccount/register (www.neonrush.com, ABP, tenant 1)", "risk_area": "Race condition → duplicate account creation / username-uniqueness bypass", "outcome": "no_issue_found", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Concurrent 4x registration with an identical emailAddress/userName: exactly 1 HTTP 200 (account created, userId returned) and 3 HTTP 500 with \"Username '<email>' is already taken.\" A subsequent login with that email succeeded. Uniqueness en...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "eb53c8", "surface": "POST /api/services/app/freeentrycodeuser/getnewcode (www.neonrush.com, ABP, tenants 1/5/11)", "risk_area": "Race condition → single-use / one-per-period code over-issue", "outcome": "ruled_out", "created_at": "2026-09-27 21:15:07 UTC", "evidence": "Named control: the account-verification gate runs before any code is created. A synchronised 10-request concurrent burst with an authenticated tenant-1 session and skipCaptcha=true returned state 998 (\"Your Account Details Must Be Verified...", "agent_name": "Bounded Race Condition Hunter"}, {"entry_id": "b2a84c", "surface": "ProgressPlay white-label fleet — credential chunk 5218-5c354764053c3ff3.js across 41 in-scope hosts", "risk_area": "Client-side third-party game-provider credential exposure (vuln-0008 blast radius)", "outcome": "reported", "created_at": "2026-09-27 21:18:31 UTC", "evidence": "41 in-scope hostnames independently confirmed to serve the byte-identical credential chunk (sha256 47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7e683992fcac, 73033 B, buildId WpePWuKOn3XrgMNqj5LeW): 15 play.* player apps (neonrush, m...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "525e3d", "surface": "Nuxt marketing fleet — \"one shared build across 9 hosts\" assumption", "risk_area": "Shared-build assumption / cross-tenant blast radius", "outcome": "ruled_out", "created_at": "2026-09-27 21:19:07 UTC", "evidence": "Assumption DISPROVED. Prior recon (note d8bd89) held that the 9 Nuxt marketing hosts share one build. Full chunk-set harvest per host (247 chunks, 3,570,960 bytes) found 9 distinct Nuxt buildIds and zero chunk-filename overlap between any t...", "agent_name": "Shared-Platform Cross-Tenant Amplifier"}, {"entry_id": "4230d8", "surface": "POST /api/services/app/playeraccount/sendpasswordresetcode?sendEmail=false + /playeraccount/resetpassword (www.neonrush.com)", "risk_area": "Authentication / unauthenticated account takeover via password-reset code disclosure + client-controlled expiry", "outcome": "reported", "created_at": "2026-09-27 21:20:25 UTC", "evidence": "Independently reproduced end-to-end (IRT Lead 1, script /workspace/irt_verify_reset.py): unauth sendpasswordresetcode?sendEmail=false leaked code E17009DD35 for a fresh account (userId 1854419); resetpassword with client-supplied future exp...", "agent_name": "Independent Red Team Lead 1"}], "filtered_count": 516, "total_count": 516, "outcome_counts": {"reported": 76, "no_issue_found": 142, "ruled_out": 191, "not_applicable": 20, "needs_follow_up": 87}}