Here we come

Here we come
From our previous trip to San Diego in 2008 .- celebrating 40 years of matrimony

fredag 28 augusti 2020

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.

Related word


  1. Tools Used For Hacking
  2. Hacking Tools For Kali Linux
  3. Hack Tools Github
  4. Pentest Tools Apk
  5. Nsa Hacker Tools
  6. Hacker
  7. Hack Website Online Tool
  8. Hack Tools Download
  9. Hacker
  10. Hack Apps
  11. What Are Hacking Tools
  12. Pentest Tools Kali Linux
  13. Hack Tools Pc
  14. Hack Tools
  15. Pentest Tools Bluekeep
  16. Hack Tools Mac
  17. Pentest Tools For Android
  18. Hacking Tools Software
  19. Best Pentesting Tools 2018
  20. Hacker Tools Apk
  21. Hack Tools Github
  22. Hacking Tools For Windows
  23. Hacker Tools
  24. Beginner Hacker Tools
  25. Hacking Tools Windows 10
  26. Hacking Tools Usb
  27. Nsa Hack Tools
  28. Nsa Hack Tools Download
  29. Pentest Tools Android
  30. How To Install Pentest Tools In Ubuntu
  31. How To Hack
  32. Pentest Tools Free
  33. Hacker Tools Free
  34. Android Hack Tools Github
  35. Bluetooth Hacking Tools Kali
  36. Nsa Hack Tools Download
  37. Nsa Hack Tools Download
  38. Hacker Hardware Tools
  39. Hacker Tools Free Download
  40. Hacking Tools For Windows 7
  41. Best Hacking Tools 2020
  42. Hacker Tools Github
  43. Pentest Box Tools Download
  44. Hack Website Online Tool
  45. Nsa Hack Tools Download
  46. Hacker Tools List
  47. Best Pentesting Tools 2018
  48. Hacker Tools Github
  49. Hacking Tools Hardware
  50. Hacking Tools And Software
  51. Hacker Tools Apk
  52. Hacker Tools Linux
  53. Pentest Tools For Windows
  54. Pentest Tools
  55. Hack Tools
  56. Pentest Tools For Windows
  57. Hacker Search Tools
  58. Hacking Tools Software
  59. Hacking Tools Hardware
  60. Hacking Tools And Software
  61. Pentest Automation Tools
  62. Hacking Tools Usb
  63. Pentest Tools Website
  64. What Is Hacking Tools
  65. Pentest Tools Linux
  66. Pentest Tools Linux
  67. Hack And Tools
  68. Hacker Tools Online
  69. What Are Hacking Tools
  70. Hack Tool Apk
  71. Growth Hacker Tools
  72. Pentest Tools List
  73. Hacker Tools 2019
  74. Hack Tools Mac
  75. Pentest Tools For Ubuntu
  76. Hack Tools Github
  77. What Are Hacking Tools
  78. Hacker Tools For Ios
  79. Hacking Tools 2019
  80. Hacking Tools For Windows Free Download
  81. Tools 4 Hack
  82. Pentest Tools List
  83. Pentest Reporting Tools
  84. Pentest Tools
  85. Pentest Tools For Ubuntu
  86. Hacking Tools For Windows 7
  87. Hack Tools Pc
  88. Hacker Tools
  89. Nsa Hacker Tools
  90. Hack Tool Apk
  91. Pentest Tools Bluekeep
  92. Hack Tools For Ubuntu
  93. Hacker Tools For Mac
  94. World No 1 Hacker Software
  95. Hacking Tools For Kali Linux
  96. Hacker Techniques Tools And Incident Handling
  97. Hacker Tools Apk Download
  98. Hacking Tools For Mac
  99. Hack Tools
  100. Hacker Tools Mac
  101. Hack Tools
  102. Pentest Automation Tools
  103. Pentest Tools Review
  104. Pentest Tools Tcp Port Scanner
  105. Nsa Hacker Tools
  106. Pentest Tools Framework
  107. Hack Tools Mac
  108. Hack And Tools
  109. Pentest Tools Nmap
  110. Ethical Hacker Tools
  111. How To Make Hacking Tools
  112. Hack And Tools
  113. Hak5 Tools
  114. Hacking Tools 2019
  115. Hacking Tools For Windows Free Download
  116. Pentest Box Tools Download
  117. Tools Used For Hacking
  118. Hackers Toolbox
  119. Best Pentesting Tools 2018
  120. Physical Pentest Tools
  121. How To Install Pentest Tools In Ubuntu
  122. Hack Tools For Pc
  123. Pentest Tools Alternative
  124. Pentest Tools Online
  125. Hack Tools Online
  126. Pentest Tools Kali Linux
  127. Pentest Tools For Android
  128. World No 1 Hacker Software
  129. Hacker Tools Online
  130. Pentest Tools For Android
  131. Hack Tools Pc
  132. Hack Tools 2019
  133. Hack Rom Tools
  134. Hack Tools Mac
  135. Pentest Tools Free
  136. Tools For Hacker
  137. Hack Rom Tools
  138. Hacker Tools Hardware
  139. Hacker Tools Github
  140. Hacker Security Tools
  141. Pentest Tools Open Source

Inga kommentarer:

Skicka en kommentar