׉?ׁB!בCט  {u׉׉	 7cassandra://PPcWwF1f_xQHLrJTOrnATRwCpF3OoyIAN_Ik8kIaD5c ^7`
׉	 7cassandra://bDpo68u0jTAz0M6ngqqImyBbF-ZbScAR_qevEidCv_k8`T׉	 7cassandra://a6YMv4zgmvEP9p6A1eJu9Tz6MzQWIZTjGx4Uo9jb8ng`̵ jt\^D^ȏנjt\^D^ȋ ̝ 9׉Hhttps://vgy.me/u/tX01hAGׁׁrנjt\^D^Ȍ Y-H9׉H *https://smcloud.cc/dashboard/check_key.phpGׁׁrנjt\^D^ȍ xq9׉Hhttps://www.hcaptcha.com/Gׁׁrנjt\^D^Ȏ Y79׉H 'https://www.google.com/recaptcha/about/Gׁׁrנjt\^D^ș Y79ׁH 'https://www.google.com/recaptcha/about/ׁׁЈנjt\^D^Ș xy9ׁHhttps://www.hcaptcha.com/ׁׁЈנjt\^D^ȗ Y4H9ׁH *https://smcloud.cc/dashboard/check_key.phpׁׁЈנjt\^D^Ȗ W9ׁHhttp://smcloud.ccׁׁЈנjt\^D^ȕ Ys9ׁHhttp://smcloud.ccׁׁЈנjt\^D^Ȕ ̥9ׁHhttps://vgy.me/u/tX01hAׁׁЈ׈Ejt\^D^ȅ׉ESOME OF OUR VOUCHES CAN BE FOUND IN: https://vgy.me/u/tX01hA
smcloud.cc – Security Analysis Report
Domain: smcloud.cc
Active CDN: Cloudflare
Example = Recommendation
Report
Part 1: Website entry
At first entry to the website, there is a captcha which is a great practice to stop many DDoS
attacks, excluding those that are exclusively made for Captcha Bypass.
The good side of this is that rarely there are any legit booters that have Captcha Bypass, and
those that do, have a hefty cost, inaccessible for most people.
Part 2: Index
For the most part, the index is secured. The only problem found is that there is no captcha added to
https://smcloud.cc/dashboard/check_key.php and there is no rate limiting.
In order to add rate limiting you can simply use Cloudflare “protect my login”.
In order to add captcha, you should use https://www.hcaptcha.com/ or
https://www.google.com/recaptcha/about/ .
I would also recommend “WAF” to be on, also called “Web Application Firewall”. This can be found in
Cloudflare.
Part 3: Client Area
The client area is nearly perfect: the only recommendation I could give would be hosting the combos on
your own website and not an external service.
׉	 7cassandra://a6YMv4zgmvEP9p6A1eJu9Tz6MzQWIZTjGx4Uo9jb8ng`̵ jt\^D^Ȇjt\^D^ȅ{בCט   {u׉׉	 7cassandra://lf83fqWExrPCQ_QeGrUo1EEeQWxlCZkFtZFiKgYDgEE l`
׉	 7cassandra://SSZtk4cIr5fb9NBuMluK5Q5F8PDfNkWRGtSJoV76-4I"`T׉	 7cassandra://tcBpknmfZLWAJ2O4Lad3NuXPXspwsxoNQ33wAV4J-hs`̵ jt\^D^Țנjt\^D^Ȓ %̈9׉Hhttps://smcloud.ccGׁׁrנjt\^D^ȓ ̴I9׉H *https://smcloud.cc/dashboard/check_key.phpGׁׁrנjt\^D^ȝ ̴I9ׁH *https://smcloud.cc/dashboard/check_key.phpׁׁЈנjt\^D^Ȝ -̈9ׁHhttps://smcloud.ccׁׁЈ׉ENext Page
Part 4: Ending Note
In general, the https://smcloud.cc website is very nicely made, with a very straight forward UI,
easy-to-use interface. It is lacking protection, but all this can be easily fixed with a bit of effort.
Vulnerabilities found:
● https://smcloud.cc/dashboard/check_key.php is vulnerable to POST attacks, we recommend
adding rate limiting and a captcha challenge.
● Backend is exposed: (54.39.51.94) although this IP is protected by OVH ddos protection,
bypasses are coming out more & more, and are getting cheaper & more publicly used, so you
should still research into load balancing and protecting your backend through IPTables
configuration.
Debug Labs Corporation est.2022
׉	 7cassandra://tcBpknmfZLWAJ2O4Lad3NuXPXspwsxoNQ33wAV4J-hs`̵ jt\^D^ȉ׈Ejt\^D^Ȋjt\^D^ȉ{,SMCloud report-1jtSդ