Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: low
Invalid

DoS attack via player registration

Summary

It isn't really a DoS but an attacker could prevent legitimate players from registering by filling up the player slots with multiple addresses.

Vulnerability Details

The approvePlayer function in ThePredicter.sol has a limit of 30 players, 14 that Ivan and his friends do not know. Someone could fill these 14 slots and prevent other players from joining.

Tools Used

Manual code review

Recommendations

Implement KYC for these 14 slots.

Updates

Lead Judging Commences

NightHawK Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.