วันอาทิตย์ที่ 4 มิถุนายน พ.ศ. 2566

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.
Related word
  1. Install Pentest Tools Ubuntu
  2. Bluetooth Hacking Tools Kali
  3. Hacker Tools Linux
  4. Hack Tools 2019
  5. Hack Tools Github
  6. Hacking Tools
  7. Hacking Tools For Beginners
  8. Hacker Tools Linux
  9. Computer Hacker
  10. Hacks And Tools
  11. Hacker Techniques Tools And Incident Handling
  12. Hacker Tools 2020
  13. Pentest Tools For Android
  14. Easy Hack Tools
  15. Ethical Hacker Tools
  16. Pentest Tools For Mac
  17. Pentest Tools Find Subdomains
  18. Hacks And Tools
  19. Hacker Tool Kit
  20. Hacker Tools 2019
  21. Hackrf Tools
  22. Growth Hacker Tools
  23. How To Make Hacking Tools
  24. Hacking Tools Mac
  25. How To Hack
  26. Hacking Tools Kit
  27. New Hacker Tools
  28. Hack Tools
  29. Hacking Tools And Software
  30. Hacker Tools Hardware
  31. Nsa Hack Tools Download
  32. Hack Apps
  33. Hacking Tools Usb
  34. Hacking Tools For Beginners
  35. Hack Tools For Ubuntu
  36. Hack Tools Download
  37. Hacker Hardware Tools
  38. Hack And Tools
  39. Hacking Tools For Pc
  40. Game Hacking
  41. Hacker Tools Apk Download
  42. Pentest Tools For Ubuntu
  43. Pentest Tools List
  44. Hacker Security Tools
  45. Hack App
  46. Best Hacking Tools 2020
  47. Bluetooth Hacking Tools Kali
  48. Best Hacking Tools 2020
  49. Hacking Tools 2019
  50. Free Pentest Tools For Windows
  51. How To Install Pentest Tools In Ubuntu
  52. Kik Hack Tools
  53. Pentest Tools Website
  54. Hacking Tools 2020
  55. Hacking Tools Software
  56. Hack Tools Mac
  57. Pentest Tools Android
  58. Tools For Hacker
  59. Beginner Hacker Tools
  60. Pentest Tools Url Fuzzer
  61. Hackers Toolbox
  62. Hacker Tools Free
  63. Hack Tools Github
  64. Hack Apps
  65. Hack Tools For Ubuntu
  66. Hack Tools Github
  67. Hacking Tools Mac
  68. Hacker Tool Kit
  69. Hack Tools For Mac
  70. Pentest Tools Apk
  71. Blackhat Hacker Tools
  72. Growth Hacker Tools
  73. Pentest Tools Bluekeep
  74. Hacker Tool Kit
  75. Hacking Tools Online
  76. Hack Tools For Ubuntu
  77. Best Hacking Tools 2020
  78. Hack And Tools
  79. Computer Hacker
  80. Hack Tools For Games
  81. Pentest Tools For Android
  82. Tools Used For Hacking
  83. Android Hack Tools Github
  84. Hak5 Tools
  85. Pentest Tools For Android
  86. Hacker Tools For Mac
  87. Pentest Tools Website
  88. Hack Rom Tools
  89. Android Hack Tools Github
  90. Hack Apps
  91. New Hacker Tools
  92. Pentest Tools
  93. Pentest Tools For Mac
  94. Hacker Tools Apk
  95. Hack And Tools
  96. Hacking Tools 2020
  97. Hack Tools
  98. Hack Tools
  99. Hacker Tools Free
  100. Hack Website Online Tool
  101. Pentest Tools Linux
  102. Hacking Tools Software
  103. Hack App
  104. Pentest Tools Windows
  105. Hack Tools For Ubuntu
  106. Best Hacking Tools 2019
  107. Hacking Tools For Games
  108. Hacker Tools Mac
  109. Pentest Tools Online
  110. Blackhat Hacker Tools
  111. How To Hack
  112. Hacking Tools Online
  113. Hacker Tools For Pc
  114. Easy Hack Tools
  115. Pentest Tools
  116. Hacker Tools
  117. Hackers Toolbox
  118. Best Pentesting Tools 2018
  119. Hacker Techniques Tools And Incident Handling
  120. Hacker Tools 2019
  121. Hacker
  122. Hack Tools
  123. Tools For Hacker
  124. Hacking Tools Online
  125. New Hacker Tools
  126. New Hacker Tools
  127. Pentest Tools Online
  128. Pentest Tools Tcp Port Scanner
  129. Install Pentest Tools Ubuntu
  130. Hack Tools For Pc
  131. Hacking Tools For Beginners
  132. Github Hacking Tools
  133. Beginner Hacker Tools
  134. Hacking Tools Windows 10
  135. How To Install Pentest Tools In Ubuntu
  136. Hacker Tools Github
  137. Pentest Tools Url Fuzzer
  138. Hack Tools Pc
  139. Pentest Tools For Windows
  140. Pentest Box Tools Download
  141. How To Hack
  142. Pentest Reporting Tools
  143. Pentest Tools Alternative
  144. What Are Hacking Tools
  145. Pentest Tools Framework
  146. Pentest Tools Review
  147. Hacking Tools Software
  148. Hacking Tools For Windows Free Download
  149. Best Hacking Tools 2019
  150. Hacker Tools Free Download
  151. Pentest Tools Kali Linux
  152. Hacking Tools For Kali Linux
  153. Hacker Tools For Ios
  154. Pentest Tools Android
  155. How To Install Pentest Tools In Ubuntu
  156. Hacks And Tools

ไม่มีความคิดเห็น:

แสดงความคิดเห็น