Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
All Your Base · Smart Contract Security AssessmentAll Your Base Client Hub

All Your Base Web Game Pentest

Zealynx ran a one-week blackbox penetration test of the All Your Base betting game (allyourbase.virtual.tech), a NestJS-backed web2 application that interfaces with smart contracts for token price prediction bets. Four issues were identified: one High (decimals not handled by the application frontend, producing exponential session-balance values), two Medium (content spoofing via url/w/q parameters in both unauthenticated and authenticated states; improper error handling in those same parameters), and one Informational (Strict-Transport-Security not enforced). All four were acknowledged at the time of report publication.

TypescriptSmart Contract Code Review2024-07-12Zealynx methodology
Total findings
4
0 fixed · 4 acknowledged
Critical
00
High
01
Medium
02
Low + Info
01
02

Scope

1 file
Platform
- · Typescript
Methodology
File
allyourbase.virtual.tech (NestJS web app)
03

Findings

click any row for the full write-up
04

Key Findings

  • Decimals not handled by the application frontend (High, acknowledged). Users could manually enter long decimal values into the deposit amount, after which the frontend rendered an exponential amount (for example 1e-14) for both the virtual and session balances. Because the backend ties into blockchain settlement, these rounding errors could cause calculation issues or gas griefing if amount handling diverged between the UI and on-chain code.
  • Content spoofing via parameters url, w, and q (Medium, acknowledged). Both authenticated (wallet-connected) and unauthenticated states allowed attacker-controlled values in the url, w, and q query parameters to render into the page content, enabling content spoofing variants of reflected XSS without script execution.
  • Improper error handling in parameters url, w, and q (Medium, acknowledged). The same three parameters surfaced internal error messages when malformed values were submitted, leaking implementation details that aid an attacker mapping the application surface.
  • Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return an HSTS header, leaving the browser without protection against protocol downgrade attempts.

All four findings were acknowledged by the All Your Base team at report publication.

05

Team & approval

Lead Auditor
Jose Fernando
@0xMrjory
06

Disclaimer

This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.

Download PDF (22p)
ZEALYNX SECURITY · published 2024-07-12
4 findings · Typescript