Tuesday, January 23, 2024

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.
Related word
  1. Hacking Tools Online
  2. New Hacker Tools
  3. Hacker Hardware Tools
  4. Nsa Hack Tools
  5. Hack Tools For Mac
  6. Hacking Tools Software
  7. How To Install Pentest Tools In Ubuntu
  8. Hacker Tools Free
  9. Hacker Tools Linux
  10. What Is Hacking Tools
  11. Hacking Tools Download
  12. Hacking Tools Hardware
  13. Free Pentest Tools For Windows
  14. Pentest Tools Nmap
  15. Hacker Tools
  16. Hacks And Tools
  17. Hack Tools
  18. Pentest Tools Android
  19. Pentest Tools Framework
  20. Hack Tools For Windows
  21. Beginner Hacker Tools
  22. Top Pentest Tools
  23. Pentest Tools Port Scanner
  24. How To Hack
  25. Pentest Tools Framework
  26. Hacking Tools And Software
  27. Hacking Tools For Windows
  28. Hack Tools For Pc
  29. Pentest Tools Github
  30. Hacking Tools For Windows
  31. Pentest Recon Tools
  32. Pentest Tools List
  33. Pentest Tools Nmap
  34. Hacker Tools List
  35. Pentest Tools Bluekeep
  36. Hacking Tools 2020
  37. How To Hack
  38. Pentest Tools Find Subdomains
  39. Hacking Tools Online
  40. Tools For Hacker
  41. Best Hacking Tools 2020
  42. Hack Tools For Windows
  43. Computer Hacker
  44. Pentest Tools Free
  45. Hacking Tools 2019
  46. Hacker Tools Software
  47. Hack Rom Tools
  48. Hak5 Tools
  49. Install Pentest Tools Ubuntu
  50. Game Hacking
  51. Hacking App
  52. Pentest Tools Website Vulnerability
  53. Pentest Recon Tools
  54. Hack Tools For Pc
  55. Pentest Tools Online
  56. Nsa Hack Tools Download
  57. Hacker Tools Github
  58. Hacking Tools 2020
  59. Bluetooth Hacking Tools Kali
  60. Pentest Tools Android
  61. Hackrf Tools
  62. Pentest Tools Website
  63. New Hacker Tools
  64. Pentest Tools Online
  65. Pentest Tools For Android
  66. Physical Pentest Tools
  67. Hacking Tools 2019
  68. Hacking Tools Software
  69. Pentest Automation Tools
  70. Hack Website Online Tool
  71. Hack Tools Github
  72. Hacking Tools 2020
  73. Pentest Tools Online
  74. Hack Rom Tools
  75. Hacking Tools Github
  76. Hack Tools For Ubuntu
  77. Pentest Tools For Mac
  78. Hacking Tools Usb
  79. Free Pentest Tools For Windows
  80. Hacker Tools Free
  81. Hacker Techniques Tools And Incident Handling
  82. Hacker Security Tools
  83. Hackers Toolbox
  84. Hacking Tools Usb
  85. Wifi Hacker Tools For Windows
  86. Hack Tools
  87. Pentest Tools Url Fuzzer
  88. Pentest Tools Free
  89. How To Make Hacking Tools
  90. How To Install Pentest Tools In Ubuntu
  91. Hacking Tools Windows 10
  92. Hacking Tools Pc
  93. What Are Hacking Tools
  94. Pentest Tools Open Source
  95. Tools Used For Hacking
  96. Install Pentest Tools Ubuntu
  97. Hack Website Online Tool
  98. Hacking Apps
  99. Pentest Tools List
  100. Pentest Tools Open Source
  101. Kik Hack Tools
  102. Hack Tools For Games
  103. World No 1 Hacker Software
  104. Hacking Tools Pc
  105. World No 1 Hacker Software
  106. Hacking Tools Mac
  107. Pentest Automation Tools
  108. Hack Tools For Windows
  109. Pentest Tools Find Subdomains
  110. Hacking Tools 2019
  111. Hacking Tools Github
  112. Pentest Tools Framework
  113. Hack Tools Online
  114. Pentest Tools Android
  115. Hacking Tools For Games
  116. Hacker Tools For Windows
  117. Hacker Security Tools
  118. Underground Hacker Sites
  119. Best Pentesting Tools 2018
  120. Physical Pentest Tools
  121. Pentest Tools Url Fuzzer
  122. Hacking Tools Software
  123. Pentest Tools Apk
  124. Hack Tools For Ubuntu
  125. Hack Tools For Ubuntu
  126. Hacker Tools For Ios
  127. Pentest Tools Tcp Port Scanner
  128. Termux Hacking Tools 2019
  129. Hacking Tools For Mac
  130. Hacking Tools Kit
  131. Hacking Tools And Software
  132. Pentest Tools Find Subdomains
  133. Hacker Search Tools
  134. Hacker Tools Windows
  135. Hacker Tools
  136. Pentest Tools Alternative
  137. Pentest Tools Url Fuzzer
  138. Ethical Hacker Tools
  139. Pentest Tools Website Vulnerability
  140. Hacking Tools Online
  141. Hacking Tools Windows 10
  142. Pentest Reporting Tools
  143. Kik Hack Tools
  144. Hacks And Tools
  145. Hacking Tools Mac
  146. Pentest Tools
  147. Hacking Tools For Games
  148. Pentest Tools Tcp Port Scanner
  149. Hacking Tools For Windows
  150. Hacker Tools Windows
  151. Hack Tool Apk
  152. Hacking Tools Free Download
  153. Hacking Tools For Games
  154. Growth Hacker Tools
  155. Pentest Automation Tools
  156. Pentest Tools Windows
  157. Hacking Tools For Games
  158. Pentest Tools
  159. Pentest Tools For Ubuntu
  160. Hacking Tools Free Download
  161. Hacker Tools For Mac
  162. Hacker Techniques Tools And Incident Handling
  163. Pentest Recon Tools
  164. Hack Tools 2019
  165. Pentest Tools Online
  166. Pentest Box Tools Download
  167. Hacker Tools Windows
  168. Pentest Tools Url Fuzzer
  169. Hacking Tools Kit
  170. Hackrf Tools
  171. Hacking Tools Windows
  172. Bluetooth Hacking Tools Kali
  173. Hacker Search Tools
  174. Tools For Hacker

No comments:

Post a Comment