create account

Some SPS-Validator Frontend Tests ... proactively Testing things... by louis88

View this thread on: hive.blogpeakd.comecency.com
· @louis88 ·
$11.83
Some SPS-Validator Frontend Tests ... proactively Testing things...
Over the past few days, I have been working a little more with the SPS Validator software and doing various tasks. As some of you already know, I like to work as a pentester, security researcher or ethical hacker in my spare time. At first, we only had the frontend at https://thespsdao.github.io/SPS-Validator/ to cast our votes for SPS validators and initially focused on the input fields that are available there. Technically, I simply write something in an input field, which in turn is written to the blockchain and output again a little later at a specific location. My approach here was to test stored XSS, which I have already done very often with other hive services. I must have tried around 50 different ways of writing code to the chain in order to break through the HTML displayed on the website and execute code. I made many attempts - nothing worked. This is great and actually exactly what I had in mind. 

Then I tried the same inputs again to test the frontend of Monstermarket. In this case, the inputs you enter are also rendered in special places. Again, everything was great and, as expected, I was unable to break through the rendered HTML and execute code. Perfect!

Then last but not least, Peakmonsters released their validator page and focused my work in that direction. Here, too, I have tried many different forms of payloads to inject code that doesn't belong there. I know the team behind Peakmonsters well and know that they produce very good and secure code. I haven't found any errors at Peakmonsters either and I have to say that I'm satisfied with how all the frontends have been implemented at this point. Three thumbs up!  👍👍👍

However, during all my work and research I noticed something that might be a problem? I don't know if you can break out of Docker logs - I'm not experienced enough at this point to make a statement - but as some validators may have observed, I was able to successfully use the Docker logs for advertising ;) Nothing earth-shattering but still a pretty funny thing in my opinion.

![image.png](https://files.peakd.com/file/peakd-hive/louis88/23swc1ry4s6GVxhYSRaPpbiaJCyyZRVBsmvLdrdHgTZKe368YoTN2fcBCTniCEz8gvoDm.png)

![image.png](https://files.peakd.com/file/peakd-hive/louis88/23tS2bqoZqYnnjkv16HWMzC2FTNZcBzXhMsu3QNWptZM4tJMAHbp8S1UxdJ3mpdzkNkAC.png)

Why am I doing this? Quite simply! I just want us to be safe here on Hive / Splinterlands and in our entire ecosystem and therefore I proactively invest my time and knowledge to test things. 


Thank you!
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 200 others
properties (23)
authorlouis88
permlinksome-sps-validator-frontend-tests--proactively-testing-things
categoryhive-13323
json_metadata{"app":"peakd/2025.2.3","format":"markdown","author":"louis88","tags":["sps","validator","splinterlands","community","hive","blog","security","testing","hacking","pentest"],"users":[],"image":["https://files.peakd.com/file/peakd-hive/louis88/23swc1ry4s6GVxhYSRaPpbiaJCyyZRVBsmvLdrdHgTZKe368YoTN2fcBCTniCEz8gvoDm.png","https://files.peakd.com/file/peakd-hive/louis88/23tS2bqoZqYnnjkv16HWMzC2FTNZcBzXhMsu3QNWptZM4tJMAHbp8S1UxdJ3mpdzkNkAC.png"]}
created2025-03-12 21:02:21
last_update2025-03-12 21:02:21
depth0
children8
last_payout2025-03-19 21:02:21
cashout_time1969-12-31 23:59:59
total_payout_value5.928 HBD
curator_payout_value5.898 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,524
author_reputation1,193,743,500,467,966
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,391,751
net_rshares34,905,393,034,901
author_curate_reward""
vote details (264)
@bozz ·
I'm glad to know that monster market and the others are good to go. I have my license delegated to them specifically.
properties (22)
authorbozz
permlinkre-louis88-2025312t194756338z
categoryhive-13323
json_metadata{"type":"comment","tags":["hive-13323","sps","validator","splinterlands","community","hive","blog","security","testing","hacking","pentest"],"app":"ecency/3.2.1-mobile","format":"markdown+html"}
created2025-03-12 23:47:57
last_update2025-03-12 23:47:57
depth1
children0
last_payout2025-03-19 23:47:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length117
author_reputation2,283,108,562,612,933
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,395,075
net_rshares0
@jackjackson2nd ·
your effort trying to make Hive/Splinterlands/the entire eco- a safer place- is very much appreciated- great work & have a great day
properties (22)
authorjackjackson2nd
permlinkre-louis88-st1as3
categoryhive-13323
json_metadata{"tags":["hive-13323"],"app":"peakd/2025.2.3","image":[],"users":[]}
created2025-03-12 23:33:42
last_update2025-03-12 23:33:42
depth1
children0
last_payout2025-03-19 23:33:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length132
author_reputation1,222,580,059,298
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,394,763
net_rshares0
@sc000 ·
You're doing a great job and often try things I don't even have on my radar :D
properties (22)
authorsc000
permlinkre-louis88-st1803
categoryhive-13323
json_metadata{"tags":["hive-13323"],"app":"peakd/2025.2.3","image":[],"users":[]}
created2025-03-12 22:33:39
last_update2025-03-12 22:33:39
depth1
children2
last_payout2025-03-19 22:33:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length78
author_reputation1,490,851,416,253
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,393,555
net_rshares0
@isnochys ·
Thank you for your [witness vote](https://hivesigner.com/sign/account-witness-vote?witness=isnochys&approve=1)!
 Have a !BEER on me!
To Opt-Out of my witness beer program just comment STOP below
properties (22)
authorisnochys
permlinkre-re-louis88-st1803-20250316t222700z
categoryhive-13323
json_metadata"{"app": "beem/0.24.26"}"
created2025-03-16 22:27:03
last_update2025-03-16 22:27:03
depth2
children0
last_payout2025-03-23 22:27:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length194
author_reputation47,862,727,229,949
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,477,610
net_rshares0
@isnochys ·
Thank you for your [witness vote](https://hivesigner.com/sign/account-witness-vote?witness=isnochys&approve=1)!
 Have a !BEER on me!
To Opt-Out of my witness beer program just comment STOP below
👎  
properties (23)
authorisnochys
permlinkre-re-louis88-st1803-20250323t220951z
categoryhive-13323
json_metadata"{"app": "beem/0.24.26"}"
created2025-03-23 22:09:54
last_update2025-03-23 22:09:54
depth2
children0
last_payout2025-03-30 22:09:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length194
author_reputation47,862,727,229,949
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,635,085
net_rshares-4,279,437,116
author_curate_reward""
vote details (1)
@splinterboost ·
 <center> This post has been supported by @Splinterboost with a 12% upvote! Delagate HP to Splinterboost to Earn Daily HIVE rewards for supporting the @Splinterlands community!</center> 

 <center> [ Delegate HP ](https://peakd.com/@splinterboost)  | [Join Discord](https://discord.gg/RK4ZHKmgcX) </center>
properties (22)
authorsplinterboost
permlinksome-sps-validator-frontend-tests--proactively-testing-things
categoryhive-13323
json_metadata{"app":"splinterboost/0.1"}
created2025-03-12 21:02:42
last_update2025-03-12 21:02:42
depth1
children0
last_payout2025-03-19 21:02:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length306
author_reputation13,837,298,077,758
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,391,756
net_rshares0
@vixmemon ·
Did you also scan the logs for PII or SPI data?
properties (22)
authorvixmemon
permlinkre-louis88-st3ff3
categoryhive-13323
json_metadata{"tags":["hive-13323"],"app":"peakd/2025.2.3","image":[],"users":[]}
created2025-03-14 03:09:06
last_update2025-03-14 03:09:06
depth1
children1
last_payout2025-03-21 03:09:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length47
author_reputation8,012,562,744,923
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,419,664
net_rshares0
@louis88 ·
Nope.
👍  
properties (23)
authorlouis88
permlinkre-vixmemon-st3wc6
categoryhive-13323
json_metadata{"tags":["hive-13323"],"app":"peakd/2025.2.3","image":[],"users":[]}
created2025-03-14 09:14:30
last_update2025-03-14 09:14:30
depth2
children0
last_payout2025-03-21 09:14:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length5
author_reputation1,193,743,500,467,966
root_title"Some SPS-Validator Frontend Tests ... proactively Testing things..."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id141,423,564
net_rshares0
author_curate_reward""
vote details (1)