Dedprz Web Game Pentest
Zealynx ran a one-week blackbox penetration test of Dedprz, a Next.js Web2 coin-flip game that accepts $SUSA token bets against an on-chain backend. Seven issues were identified: one High (decimals not handled by the application frontend, producing $0 win/loss display while the session balance still updated by the decimal amount), three Medium (content spoofing through `url`/`w`/`q` parameters; denial of service via business logic flaw in authenticated state; improper error handling in the same parameters), two Low (no minimum session balance enforced; 'Recent flips' table can be used to deface the application), and one Informational (Strict-Transport-Security not enforced). All seven findings were acknowledged at the time of report publication.
Scope
1 fileFindings
click any row for the full write-upKey Findings
- Decimals not handled by the application frontend (High, acknowledged). Users could enter decimal wager amounts. The win/loss display rounded to
$0, but the session balance and Recent Flips table still updated according to the decimal value. Combined with on-chain settlement, this created an unexpected balance-mishandling class. - Content spoofing via parameters
url,w, andq(Medium, acknowledged). Image-related query parameters in/_next/imagewere modifiable on the fly, allowing content spoofing variants (defacement-style) while components loaded. - Business logic flaw causing denial of service in authenticated state (Medium, acknowledged). Specific authenticated request flows could be triggered to put the application into an unrecoverable state for the affected user.
- Improper error handling in parameters
url,w, andq(Medium, acknowledged). Malformed values returned internal error strings (q parameter (quality) must be a number between 1 and 100,requested resource isn't a valid image, etc.) that leaked implementation details. - No minimum session balance enforced (Low, acknowledged). Game flows allowed sessions with effectively zero balance, surfacing UI edge cases and creating opportunities for unexpected state.
- Recent flips table can deface the application (Low, acknowledged). Content rendered into the Recent Flips table could be manipulated to deface the public game view.
- Strict-Transport-Security not enforced (Informational, acknowledged).
All seven findings were acknowledged by the Dedprz team at report publication.
Team & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.