DEF CON 32聚焦:CertiK安全工程师揭秘dApp的安全挑战

币界网2024-08-15 tarihinde yayınlandı2024-08-15 tarihinde güncellendi

币界网报道:

IBKWHYY43lzqNa4Baqpi4gP3LzMd3KWZf4fr1v0L.png

8月10日,CertiK的安全工程师Wang Peiyu在DEF CON 32会上发表了题为“Web2遇见Web3:黑客攻击去中心化应用”的演讲,通过Dapp漏洞和攻击手段的真实示例,深入分析了Web2与Web3集成所带来的新型安全问题,并提出了如何识别和防范这些风险。

演讲不仅揭示了去中心化应用(dApp)所面临的独特安全挑战,还分享了CertiK安全工程师Wang Peiyu在dApps渗透测试过程中积累的宝贵经验。他强调了恶意行为者如何利用dApps的漏洞,通过窃取种子短语、私钥、签名和API密钥等敏感信息来控制加密资产和托管人,进而操纵合约状态。

此外,演讲还深入讨论了dApp威胁建模,通过一系列实际案例,展示了客户端和服务器端的常见漏洞,包括跨站脚本攻击(XSS)、子域接管、DNS劫持、供应链攻击以及服务器配置错误等。他还提出了几个关键的安全建议,包括进行渗透测试和智能合约审计,以确保dApps的安全性。他强调,开发者需要对Web2和Web3的安全知识有全面的了解,以防止漏洞的引入,并保护用户资产不受侵害。

DEF CON是历史悠久的年度黑客大会之一,自1993年首次举办以来,一直面向白帽黑客群体举办,以其前沿的演讲、研讨会和竞赛而闻名。今年,CertiK的安全工程师Wang Peiyu受到特别邀请,参与了这场盛会,与全球网络安全领域的顶尖专家一道,深入探讨并分享了最新的安全技术进展和行业趋势。

İlgili Okumalar

DeepSeek No Longer Wants to Focus Only on Large Models

DeepSeek, a leading Chinese AI company, has released its new model series DeepSeek-V4, featuring two versions: the high-performance V4-Pro with 1.6 trillion parameters and the cost-efficient V4-Flash. Both support 1 million token context windows and use Mixture-of-Experts (MoE) architecture to improve efficiency. The company continues its strategy of offering competitive pricing, with input tokens priced as low as ¥0.2 per million tokens. A key revelation is DeepSeek’s explicit link between future price reductions and the mass availability of Huawei’s Ascend 950 AI chips in the second half of the year. This signals a strategic shift from relying solely on algorithmic and engineering optimizations to integrating domestic computing power into its core cost structure. DeepSeek has adapted its inference system to run efficiently on both NVIDIA GPUs and Huawei NPUs, potentially challenging NVIDIA's CUDA ecosystem dominance. Concurrently, DeepSeek is reportedly seeking significant external investment, with a pre-money valuation of around ¥300 billion. This move highlights growing pressures in scaling compute infrastructure, retaining top talent—amid recent departures of key researchers—and accelerating commercialization efforts. The company has also updated its consumer app with tiered model access, indicating a stronger product focus. The V4 release underscores that China's AI competition is evolving beyond pure model capability into a broader contest involving compute supply chains, engineering systems, financing, and talent strategy.

marsbit17 dk önce

DeepSeek No Longer Wants to Focus Only on Large Models

marsbit17 dk önce

İşlemler

Spot
Futures
活动图片