iConomy Dupe #18

  • New
  • Defect
Assigned to silentnight1990
  • _ForgeUser10361949 created this issue Jan 22, 2013

    What steps will reproduce the problem?
    1. Create a user-owned slot machine
    2. Deposit full user balance minus one spin cost into machine
    3. User spins their own machine
    3A) If machine loses, user withdraws enough to spin again
    3B) If machine wins, it pays out the full prize to the user, creating money from nothing

    For example, a user with $10,000 could deposit $9,000 into a slot machine sign that charges $1000/spin. If the user spun his own machine and lost, it would have a balance of $10,000. The user could withdraw $1,000 and repeat the process until a win happens. If, for example, the JJJ (jackpot) win payout is set to 100.0, the machine would pay $1,000,000 to the player that only had $10,000 to begin with (thus, creating money).

    What is the expected output? What do you see instead?
    The expected output would be that the machine does not pay out more money than the user has from their own machines.

    What version of the product are you using?
    SignCasino v1.5.1

    Do you have an error log of what happened?
    This does not produce an error log, as it seems to be functioning as intended. It simply allows for an abusable game-play exploit. Perhaps disallow users spinning their own slots?

  • _ForgeUser10361949 added the tags New Defect Jan 22, 2013
  • _ForgeUser10361949 posted a comment Feb 19, 2013

    Really no comments on this one, eh? I could go on any server running this plugin and make infinite iconomy money (provided it is an iconomy server), and would likely work with any economy plugin out there... seems strange this isn't seen as a bigger problem. Essentially makes the plugin useless on any economy based server, which is pretty much the only place this type of plugin would be useful.

    Has nobody found a way to prevent this? The plugin dev seems to be no longer active, and the plugin isn't open source...

To post a comment, please login or register a new account.