A New Internet Library: Add Your Website/Blog or Suggest A Website/Blog to our Free Web Directory http://anil.myfunda.net.

Its very simple, free and SEO Friendly.
Submit Now....

Friday, August 28, 2020

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.

Continue reading


  1. Hacker Tools Hardware
  2. Hack App
  3. Hacker Tools Software
  4. Pentest Tools Kali Linux
  5. Hacking Tools
  6. Hacker Tools Free Download
  7. World No 1 Hacker Software
  8. Hacking Tools Download
  9. Best Hacking Tools 2019
  10. Pentest Tools Online
  11. Pentest Tools For Ubuntu
  12. Hack Tool Apk No Root
  13. Hack Tools For Games
  14. Hacking Tools Mac
  15. Hacker Tools Github
  16. Hack Tools
  17. Hacking Apps
  18. Hack Tools For Games
  19. Hacker Tools 2019
  20. Pentest Tools For Android
  21. Tools 4 Hack
  22. New Hack Tools
  23. Pentest Automation Tools
  24. Hack Tools Online
  25. Beginner Hacker Tools
  26. Hacking Tools Download
  27. Pentest Tools Tcp Port Scanner
  28. Hack Tools Github
  29. Hack Tools Github
  30. Hack Tool Apk
  31. Hacker Tools 2020
  32. Pentest Tools Open Source
  33. Hacking Tools Mac
  34. Hacking Tools Free Download
  35. Pentest Tools Website Vulnerability
  36. Pentest Tools Free
  37. Hacking Tools Free Download
  38. Best Hacking Tools 2019
  39. Hacking Tools Windows 10
  40. Game Hacking
  41. Termux Hacking Tools 2019
  42. Hack Rom Tools
  43. Pentest Tools For Mac
  44. Android Hack Tools Github
  45. Wifi Hacker Tools For Windows
  46. Pentest Tools Online
  47. Hacker Tools 2019
  48. Hack Tools
  49. Pentest Tools For Ubuntu
  50. Pentest Tools Free
  51. Hacker
  52. Hacker Tools
  53. Pentest Recon Tools
  54. Hacking Tools For Windows Free Download
  55. Hack Tools
  56. Hacking Tools Free Download
  57. Hack Rom Tools
  58. Hacker Tools Free
  59. Hacking Tools 2020
  60. Growth Hacker Tools
  61. Pentest Tools Nmap
  62. Pentest Tools Android
  63. Hacking Tools For Windows Free Download
  64. Hacking Tools Windows
  65. Pentest Tools Bluekeep
  66. Pentest Tools Windows
  67. Hacker Tools 2019
  68. Nsa Hack Tools
  69. Hacker Tools 2019
  70. Pentest Automation Tools
  71. Hack Apps
  72. Pentest Tools For Ubuntu
  73. Hacking Tools Online
  74. Hack Tool Apk
  75. Pentest Tools Apk
  76. Hacker Tools For Windows
  77. Hack Rom Tools
  78. Hacker Tools
  79. Pentest Tools Open Source
  80. Computer Hacker
  81. Best Hacking Tools 2020
  82. Pentest Automation Tools
  83. New Hack Tools
  84. Hacking Tools 2020
  85. Blackhat Hacker Tools
  86. Hack Tool Apk
  87. Hacking Tools For Kali Linux
  88. Hacker Tools Linux
  89. Hack Tool Apk No Root
  90. Pentest Tools Linux
  91. Hacking Tools Download
  92. Hacking Tools Pc
  93. Top Pentest Tools
  94. Hacking Apps
  95. Pentest Tools Subdomain
  96. Nsa Hacker Tools
  97. Hacker Tools Software
  98. Hacking Tools Download
  99. Hacking Tools Pc
  100. Pentest Tools Nmap
  101. Ethical Hacker Tools
  102. Hack Tools For Ubuntu
  103. Best Hacking Tools 2020
  104. Hack Tools Github
  105. Hack Tools For Mac
  106. Hack Tools For Pc
  107. Pentest Tools Url Fuzzer
  108. Pentest Tools Port Scanner
  109. Pentest Tools Linux
  110. Hacker Tools For Pc
  111. Hacking Tools Download
  112. Hacker Tools Mac
  113. Hacking Tools Name
  114. Hack Apps
  115. Game Hacking
  116. How To Make Hacking Tools
  117. Hack Tools Online
  118. Pentest Tools Port Scanner
  119. Hacker Tools Software
  120. Hacking Tools Mac
  121. Hacker Tools For Pc
  122. How To Make Hacking Tools
  123. Hacking Tools Online
  124. Hack Tool Apk
  125. Install Pentest Tools Ubuntu
  126. Pentest Tools For Mac
  127. Pentest Tools Tcp Port Scanner
  128. Hacker Tools Github
  129. Tools Used For Hacking
  130. Pentest Tools Download
  131. Pentest Tools Free
  132. Hack Website Online Tool
  133. Hacker Tools Apk Download
  134. Hacking Tools And Software
  135. Pentest Tools Free
  136. Hacker Tools Software
  137. Best Hacking Tools 2019
  138. Pentest Box Tools Download
  139. Pentest Tools For Mac
  140. Hack Tools 2019
  141. Hacking Tools Free Download
  142. Kik Hack Tools
  143. Pentest Box Tools Download
  144. Pentest Tools Open Source
  145. Hacker Tools
  146. How To Make Hacking Tools
  147. Pentest Tools For Windows
  148. Termux Hacking Tools 2019
  149. Termux Hacking Tools 2019
  150. Hackrf Tools
  151. World No 1 Hacker Software
  152. Hacker Tools
  153. Hack App
  154. Pentest Tools Framework
  155. Hacking Tools Software
  156. Pentest Tools Free
  157. Nsa Hack Tools Download
  158. Hacker Tools Online
  159. Hacking Tools For Mac
  160. Hack Tools
  161. Hacking Tools Usb
  162. Hacking Tools For Games
  163. Hack Tools Online
  164. Best Hacking Tools 2019
  165. Pentest Tools Website Vulnerability
  166. World No 1 Hacker Software
  167. Install Pentest Tools Ubuntu

No comments:

Post a Comment

Post your comments here:

Dotnet-Interviews