All Your Base Web Game Pentest
Zealynx ran a one-week blackbox penetration test of the All Your Base betting game (allyourbase.virtual.tech), a NestJS-backed web2 application that interfaces with smart contracts for token price prediction bets. Four issues were identified: one High (decimals not handled by the application frontend, producing exponential session-balance values), two Medium (content spoofing via url/w/q parameters in both unauthenticated and authenticated states; improper error handling in those same parameters), and one Informational (Strict-Transport-Security not enforced). All four were acknowledged at the time of report publication.
Scope
1 fileFindings
click any row for the full write-upKey Findings
- Decimals not handled by the application frontend (High, acknowledged). Users could manually enter long decimal values into the deposit amount, after which the frontend rendered an exponential amount (for example
1e-14) for both the virtual and session balances. Because the backend ties into blockchain settlement, these rounding errors could cause calculation issues or gas griefing if amount handling diverged between the UI and on-chain code. - Content spoofing via parameters
url,w, andq(Medium, acknowledged). Both authenticated (wallet-connected) and unauthenticated states allowed attacker-controlled values in theurl,w, andqquery parameters to render into the page content, enabling content spoofing variants of reflected XSS without script execution. - Improper error handling in parameters
url,w, andq(Medium, acknowledged). The same three parameters surfaced internal error messages when malformed values were submitted, leaking implementation details that aid an attacker mapping the application surface. - Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return an HSTS header, leaving the browser without protection against protocol downgrade attempts.
All four findings were acknowledged by the All Your Base team at report publication.
Team & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.