DEF CON 32聚焦:CertiK安全工程师揭秘dApp的安全挑战

币界网Published on 2024-08-15Last updated on 2024-08-15

币界网报道:

IBKWHYY43lzqNa4Baqpi4gP3LzMd3KWZf4fr1v0L.png

8月10日,CertiK的安全工程师Wang Peiyu在DEF CON 32会上发表了题为“Web2遇见Web3:黑客攻击去中心化应用”的演讲,通过Dapp漏洞和攻击手段的真实示例,深入分析了Web2与Web3集成所带来的新型安全问题,并提出了如何识别和防范这些风险。

演讲不仅揭示了去中心化应用(dApp)所面临的独特安全挑战,还分享了CertiK安全工程师Wang Peiyu在dApps渗透测试过程中积累的宝贵经验。他强调了恶意行为者如何利用dApps的漏洞,通过窃取种子短语、私钥、签名和API密钥等敏感信息来控制加密资产和托管人,进而操纵合约状态。

此外,演讲还深入讨论了dApp威胁建模,通过一系列实际案例,展示了客户端和服务器端的常见漏洞,包括跨站脚本攻击(XSS)、子域接管、DNS劫持、供应链攻击以及服务器配置错误等。他还提出了几个关键的安全建议,包括进行渗透测试和智能合约审计,以确保dApps的安全性。他强调,开发者需要对Web2和Web3的安全知识有全面的了解,以防止漏洞的引入,并保护用户资产不受侵害。

DEF CON是历史悠久的年度黑客大会之一,自1993年首次举办以来,一直面向白帽黑客群体举办,以其前沿的演讲、研讨会和竞赛而闻名。今年,CertiK的安全工程师Wang Peiyu受到特别邀请,参与了这场盛会,与全球网络安全领域的顶尖专家一道,深入探讨并分享了最新的安全技术进展和行业趋势。

Related Reads

A Hard-Fought Battle to Defend Par Value: STRC Drifts Further Away from $100

STRC, the dividend-paying stock issued by Michael Saylor's bitcoin reserve firm Strategy (formerly MicroStrategy), is trading far below its intended $100 par value, closing recently at $80.84. With a key dividend snapshot date approaching, Saylor aims to pull the price back to $100, as per SEC filings stating the company's goal to stabilize the stock near that level. The situation is complicated by the June volume-weighted average price (VWAP) falling below $95, triggering an internal rule that mandates the next dividend increase to be at least double the standard 0.25% per cycle, potentially pushing the annualized dividend yield to 12%. However, attracting buyers with this higher yield faces challenges: the payout is spread over 24 bi-monthly installments, the board can alter or suspend dividends at any time, and there is no guarantee against further price declines. Beyond raising dividends, Strategy has limited tools to boost the stock. These include direct share buybacks (never utilized), halting new share issuances above $100 (which currently cap the price), selling ordinary MSTR shares to build a cash buffer for dividends (with limited effect so far), or announcing special shareholder benefits. Historically, STRC has reclaimed the $100 mark, such as in October last year, driven by a combination of dividend fulfillment, a rate hike, and a pause in share sales. The core question remains how much cost and effort Strategy is willing to bear to attract the necessary buying pressure to restore the $100 par value.

Foresight News14m ago

A Hard-Fought Battle to Defend Par Value: STRC Drifts Further Away from $100

Foresight News14m ago

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

Fable 5, a previously restricted AI model from Anthropic, appears poised for a comeback. Evidence from leaked code in the Claude Code v2.1.190 version suggests a shift in its business model from a separate purchase to a potentially limited weekly usage allowance within standard Claude subscriptions. Furthermore, the model has reportedly reappeared in Amazon Bedrock documentation. This potential revival coincides with significant internal changes at Anthropic. According to a report by The Wired, CEO Dario Amodei was reportedly sidelined from negotiations with the Trump administration over Fable 5's export restrictions. Government officials found him difficult to communicate with. Co-founder Tom Brown and policy head Sarah Heck took over discussions, leading to more productive technical talks aimed at addressing White House security concerns about the model being "jailbroken." External pressure is mounting as a bipartisan group of US lawmakers has demanded answers from the Commerce Department by a June 26 deadline regarding the criteria and timeline for potentially reinstating public access to Fable 5. The potential return of Fable 5 comes as competitors OpenAI and Google have reportedly delayed their own major model releases. If Anthropic successfully navigates the government's security review, Fable 5 could gain a significant "safety-certified" advantage in the enterprise market. The countdown to the June 26 deadline is now underway.

marsbit46m ago

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

marsbit46m ago

Trading

Spot
Futures
活动图片