Sunday, August 30, 2020

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.

More information


  1. Hackers Toolbox
  2. Hacker Tools Online
  3. Hacker Tools Linux
  4. Install Pentest Tools Ubuntu
  5. New Hacker Tools
  6. Game Hacking
  7. Hacking Tools For Pc
  8. Pentest Tools Port Scanner
  9. Pentest Tools Framework
  10. New Hacker Tools
  11. Top Pentest Tools
  12. Pentest Tools Online
  13. Nsa Hack Tools
  14. Tools Used For Hacking
  15. Pentest Tools For Android
  16. Hack And Tools
  17. Usb Pentest Tools
  18. Hacking Tools Software
  19. What Are Hacking Tools
  20. Hacking Tools For Windows
  21. Hacker Tools Linux
  22. Hacker Tools For Windows
  23. Install Pentest Tools Ubuntu
  24. Hacker Tool Kit
  25. Beginner Hacker Tools
  26. Free Pentest Tools For Windows
  27. Hacker
  28. Hacking Tools For Games
  29. Hack Tools For Ubuntu
  30. Hacker Tool Kit
  31. Hack Tools Mac
  32. Pentest Tools For Android
  33. Hacking Tools Pc
  34. Best Hacking Tools 2020
  35. Hacking Tools For Pc
  36. New Hacker Tools
  37. Hack Tools
  38. Hacker Tools For Pc
  39. How To Make Hacking Tools
  40. Hack Tools For Pc
  41. Hacker Techniques Tools And Incident Handling
  42. Best Pentesting Tools 2018
  43. Hack Tools Mac
  44. Hack Tool Apk No Root
  45. Hacker Tools Hardware
  46. Growth Hacker Tools
  47. Hacking Tools Software
  48. Hacker Tools Mac
  49. Pentest Recon Tools
  50. Easy Hack Tools
  51. Hacking Tools Pc
  52. Game Hacking
  53. Hacker Tools Apk Download
  54. Install Pentest Tools Ubuntu
  55. Hack Tools Github
  56. Best Hacking Tools 2020
  57. Hacking Tools Hardware
  58. Hacker Tools
  59. What Is Hacking Tools
  60. Physical Pentest Tools
  61. Pentest Tools Free
  62. Hacking Apps
  63. Hacking Tools
  64. Tools Used For Hacking
  65. Hack Apps
  66. Pentest Tools Url Fuzzer
  67. Hack Tools
  68. Game Hacking
  69. Hack Rom Tools
  70. Hacker Tools Free Download
  71. Hacking Tools Hardware
  72. Hack Rom Tools
  73. Hacking Tools Download
  74. Hacks And Tools
  75. Hacking Tools For Windows 7
  76. Hacking Tools Windows 10
  77. Pentest Tools Url Fuzzer
  78. Pentest Tools Url Fuzzer
  79. Pentest Tools Nmap
  80. Termux Hacking Tools 2019
  81. Hacker Tools For Mac
  82. Hacking Tools For Windows
  83. Hack Tools Online
  84. Hacking Tools
  85. Hacker Tools Free Download
  86. Hacking Tools Windows 10
  87. Hacking Tools Kit
  88. Pentest Tools List
  89. Hacking Tools For Mac
  90. Hack Tools 2019
  91. Hacking Tools Github
  92. Wifi Hacker Tools For Windows
  93. Hack Tools
  94. Pentest Tools Port Scanner
  95. Usb Pentest Tools
  96. Hackrf Tools
  97. Hacking Tools For Windows
  98. Hack Rom Tools
  99. Hack Tools
  100. Pentest Tools Github
  101. Hacking Tools Download
  102. Hacking Apps
  103. Hack App
  104. Best Hacking Tools 2020
  105. Hacking Tools For Windows Free Download
  106. Hacking Tools
  107. Computer Hacker
  108. Hack Tools For Ubuntu
  109. Pentest Tools For Ubuntu
  110. Hacker Tools For Windows
  111. Hacking Tools Online
  112. Hack Tools Github
  113. Usb Pentest Tools
  114. Hacker Tools Free
  115. Hack Tools Online
  116. Pentest Tools Free
  117. Pentest Tools Linux
  118. Pentest Tools Alternative
  119. How To Make Hacking Tools
  120. How To Hack
  121. Pentest Tools Bluekeep
  122. Hacker Tools Apk
  123. Tools 4 Hack
  124. Hacker Tools Software
  125. Hacker Tools
  126. Physical Pentest Tools
  127. Hacker Tools For Ios
  128. Pentest Tools Windows
  129. Hacker Tools For Ios
  130. Physical Pentest Tools
  131. Hacker Tool Kit
  132. Best Hacking Tools 2020
  133. Pentest Tools For Windows
  134. Best Hacking Tools 2020
  135. Hacker Tools Free Download
  136. Hacker Tools 2019
  137. Hacking Tools Windows
  138. Hacking Tools Online
  139. Hacking Tools For Pc
  140. Hacking Tools And Software
  141. Pentest Tools Tcp Port Scanner
  142. Tools Used For Hacking
  143. Hack Tool Apk No Root
  144. Install Pentest Tools Ubuntu
  145. Best Hacking Tools 2020
  146. Hacker Techniques Tools And Incident Handling
  147. Physical Pentest Tools
  148. Free Pentest Tools For Windows
  149. Kik Hack Tools
  150. Hack Tool Apk
  151. Hacking Tools And Software
  152. Pentest Tools Url Fuzzer
  153. Pentest Tools Linux
  154. Pentest Reporting Tools
  155. Pentest Tools For Windows
  156. Pentest Tools Windows

APT Hackers Exploit Autodesk 3D Max Software For Industrial Espionage

It's one thing for APT groups to conduct cyber espionage to meet their own financial objectives. But it's an entirely different matter when they are used as "hackers for hire" by competing private companies to make away with confidential information. Bitdefender's Cyber Threat Intelligence Lab discovered yet another instance of an espionage attack targeting an unnamed international

via The Hacker News

Continue reading


  1. Easy Hack Tools
  2. Hacker Hardware Tools
  3. Hacking Tools Usb
  4. Kik Hack Tools
  5. Pentest Tools Open Source
  6. Pentest Tools Download
  7. Install Pentest Tools Ubuntu
  8. Free Pentest Tools For Windows
  9. Hacker Tools Apk Download
  10. Hack Website Online Tool
  11. Hacker Tools For Mac
  12. Usb Pentest Tools
  13. Pentest Tools For Ubuntu
  14. Pentest Tools Github
  15. Hack Tools For Ubuntu
  16. Pentest Tools Kali Linux
  17. Hacker Techniques Tools And Incident Handling
  18. Hacking Tools For Games
  19. Hacking Tools Download
  20. Hacking Tools For Games
  21. Hacker Tools For Mac
  22. Hacking Tools And Software
  23. Hacker Tools Software
  24. Hack Tools Download
  25. Hacks And Tools
  26. Hack Tool Apk No Root
  27. Hacking Tools For Pc
  28. Hacker Tools Hardware
  29. Pentest Tools Free
  30. Hack Tools Mac
  31. Pentest Tools Online
  32. Hack Tools For Games
  33. Hacker Tools Github
  34. Hacking Tools Online
  35. Hack Tool Apk No Root
  36. Hackrf Tools
  37. Hacker Tools Linux
  38. Hacker Tools For Mac
  39. Hack Tools Online
  40. Hacker Tools Github
  41. Hacking Tools Online
  42. Pentest Tools Subdomain
  43. Pentest Tools
  44. Hack Tool Apk No Root
  45. Easy Hack Tools
  46. Pentest Recon Tools
  47. Easy Hack Tools
  48. Hack Tool Apk
  49. Github Hacking Tools
  50. Hack Tool Apk
  51. Black Hat Hacker Tools
  52. Best Hacking Tools 2019
  53. Hacker Tools Linux
  54. Hacking Tools For Pc
  55. New Hack Tools
  56. Nsa Hack Tools
  57. Hacker Techniques Tools And Incident Handling
  58. Hacker Tools Hardware
  59. Ethical Hacker Tools
  60. Hacker Tools For Windows
  61. How To Hack
  62. Hacking Tools Github
  63. Nsa Hacker Tools
  64. Github Hacking Tools
  65. Hacker Search Tools
  66. Hacking Tools Download
  67. Pentest Tools For Ubuntu
  68. Hacker Tools Github
  69. Underground Hacker Sites
  70. Hacker Tools Hardware
  71. Pentest Recon Tools
  72. Easy Hack Tools
  73. Pentest Tools
  74. Hacking Tools Online
  75. Hacking Tools For Beginners
  76. Hacking Tools For Windows
  77. Hacking Tools For Windows
  78. Pentest Tools For Windows
  79. Kik Hack Tools
  80. Hacker Tools Apk
  81. Hacker Tools Hardware
  82. Hacking Tools Pc
  83. Pentest Tools Github
  84. Hacking Tools And Software
  85. Hack Tool Apk No Root
  86. Hacking Tools For Mac
  87. Nsa Hacker Tools
  88. Pentest Automation Tools
  89. Install Pentest Tools Ubuntu
  90. Pentest Tools Android
  91. Hacks And Tools
  92. World No 1 Hacker Software
  93. Nsa Hack Tools
  94. Pentest Tools Download
  95. Hacking Tools Hardware
  96. Hak5 Tools
  97. Tools 4 Hack
  98. Hacker Tools Hardware
  99. Install Pentest Tools Ubuntu
  100. Nsa Hack Tools Download
  101. Hack Website Online Tool
  102. Hacker Tools Software
  103. Computer Hacker
  104. Hacker Tools Hardware
  105. Hacking Tools Software
  106. Tools Used For Hacking
  107. Hacker Tools For Windows
  108. Hackers Toolbox
  109. Hacker Tools Free
  110. Pentest Tools Alternative
  111. Hacking Tools 2019
  112. Hacker Tools Apk Download
  113. Pentest Tools Tcp Port Scanner
  114. Pentest Tools For Mac
  115. Best Pentesting Tools 2018
  116. Hacking Tools For Windows 7
  117. Hacker Tools Hardware
  118. Physical Pentest Tools
  119. Termux Hacking Tools 2019
  120. Hacker Tools 2020
  121. Pentest Tools Open Source
  122. Pentest Tools Github
  123. Pentest Tools Online
  124. Hacker Tools For Ios
  125. Tools Used For Hacking
  126. Hacker Tools List
  127. Pentest Tools Free
  128. Hacking Tools For Windows
  129. Pentest Tools Review
  130. Hack Tool Apk No Root
  131. How To Make Hacking Tools
  132. Hacking Tools For Windows Free Download
  133. Bluetooth Hacking Tools Kali
  134. Pentest Tools Download
  135. Pentest Tools Tcp Port Scanner
  136. Hacking Tools Hardware
  137. Physical Pentest Tools
  138. Hacker Tools For Windows
  139. Pentest Tools For Windows
  140. Hacking Tools For Kali Linux
  141. Pentest Tools Free
  142. Hack Tools Github
  143. Pentest Tools Free
  144. Android Hack Tools Github
  145. Hacker Search Tools
  146. Easy Hack Tools
  147. Easy Hack Tools
  148. Pentest Tools Port Scanner
  149. Pentest Tools Windows
  150. Hacking Tools For Beginners
  151. Hacker Tools
  152. Pentest Tools Alternative
  153. Hack Tools Download
  154. Hacker Tools Github
  155. Hackrf Tools
  156. How To Install Pentest Tools In Ubuntu
  157. Hack And Tools
  158. Tools 4 Hack
  159. Hacking Tools For Games
  160. Wifi Hacker Tools For Windows
  161. Hacker Tools Mac
  162. New Hack Tools
  163. Hacker Tools
  164. Computer Hacker
  165. Hacker Tools Github

How To Fetch Data From The Database | Tutorial 4


Welcome to my another PHP and MYSQL tutorial. In the previous I've discussed about the data insertion into database by using PHP and MYSQL. So i did successfully in the previous video.

In this video tutorial I'll discuss How to fetch data from the database called as data fetching. It's really a simple thing to access your data which is in database. You just have to do a little work for this. For fetching data you have follow some steps.

How to Fetch Data from Database

Step 1:

Make a connection with your database which i did in the previous blog.

Step 2:

If you wanna fetching a values in "form" or in a table so just have to create a form, table or whatever you want in HTML. I've created a table where I'll show you how to fetch data in table form.

Step 3:

Write a query SELECT * FROM table_Name;

Step 4:

Create a Loop for fetching all the data on a single click. 

Step 5:

Create variables for the sake of storing a different values from the combined values in the loop variable like:

//while loop to fetch all the values from the database and stored in the variable named "row".
while($row = mysql_fetch_array(mysql_query($conn,$query))){

$name = $row['username']; //$name will save all the username values from the loop variable 'row'.
$pass = $row['password']; //$pass will save the password values from the loop variable 'row'.

}

Now watch the video for better understanding.

Blog Archive