Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
Dedprz · Smart Contract Security AssessmentDedprz Client Hub

Dedprz Web Game Pentest

Zealynx ran a one-week blackbox penetration test of Dedprz, a Next.js Web2 coin-flip game that accepts $SUSA token bets against an on-chain backend. Seven issues were identified: one High (decimals not handled by the application frontend, producing $0 win/loss display while the session balance still updated by the decimal amount), three Medium (content spoofing through `url`/`w`/`q` parameters; denial of service via business logic flaw in authenticated state; improper error handling in the same parameters), two Low (no minimum session balance enforced; 'Recent flips' table can be used to deface the application), and one Informational (Strict-Transport-Security not enforced). All seven findings were acknowledged at the time of report publication.

TypescriptSmart Contract Code Review2024-07-12Zealynx methodology
Total findings
7
0 fixed · 7 acknowledged
Critical
00
High
01
Medium
03
Low + Info
03
02

Scope

1 file
Platform
- · Typescript
Methodology
File
dedprz.virtual.tech (Next.js Web2 coin-flip app)
03

Findings

click any row for the full write-up
04

Key Findings

  • Decimals not handled by the application frontend (High, acknowledged). Users could enter decimal wager amounts. The win/loss display rounded to $0, but the session balance and Recent Flips table still updated according to the decimal value. Combined with on-chain settlement, this created an unexpected balance-mishandling class.
  • Content spoofing via parameters url, w, and q (Medium, acknowledged). Image-related query parameters in /_next/image were modifiable on the fly, allowing content spoofing variants (defacement-style) while components loaded.
  • Business logic flaw causing denial of service in authenticated state (Medium, acknowledged). Specific authenticated request flows could be triggered to put the application into an unrecoverable state for the affected user.
  • Improper error handling in parameters url, w, and q (Medium, acknowledged). Malformed values returned internal error strings (q parameter (quality) must be a number between 1 and 100, requested resource isn't a valid image, etc.) that leaked implementation details.
  • No minimum session balance enforced (Low, acknowledged). Game flows allowed sessions with effectively zero balance, surfacing UI edge cases and creating opportunities for unexpected state.
  • Recent flips table can deface the application (Low, acknowledged). Content rendered into the Recent Flips table could be manipulated to deface the public game view.
  • Strict-Transport-Security not enforced (Informational, acknowledged).

All seven findings were acknowledged by the Dedprz team at report publication.

05

Team & approval

Lead Auditor
Jose Fernando
@0xMrjory
06

Disclaimer

This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.

Download PDF (25p)
ZEALYNX SECURITY · published 2024-07-12
7 findings · Typescript