Friday 21 August 2020

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.

More articles


  1. Hacking Apps
  2. Blackhat Hacker Tools
  3. Hacking Tools Mac
  4. Pentest Tools Tcp Port Scanner
  5. Hack Tools
  6. Pentest Tools Nmap
  7. Pentest Tools
  8. Hacking App
  9. What Is Hacking Tools
  10. Physical Pentest Tools
  11. Nsa Hack Tools Download
  12. What Is Hacking Tools
  13. How To Make Hacking Tools
  14. Pentest Tools For Ubuntu
  15. Usb Pentest Tools
  16. Hack Tools Mac
  17. How To Make Hacking Tools
  18. Hacker Tools List
  19. Nsa Hack Tools
  20. Pentest Reporting Tools
  21. Hacking Tools 2020
  22. Game Hacking
  23. Hack App
  24. Hacking Tools For Windows 7
  25. Hackrf Tools
  26. Nsa Hacker Tools
  27. Nsa Hack Tools
  28. Hackers Toolbox
  29. New Hack Tools
  30. Kik Hack Tools
  31. Underground Hacker Sites
  32. Wifi Hacker Tools For Windows
  33. Hacker Tools Apk
  34. Pentest Tools Kali Linux
  35. Pentest Tools Port Scanner
  36. Nsa Hack Tools Download
  37. Bluetooth Hacking Tools Kali
  38. Pentest Tools For Mac
  39. New Hacker Tools
  40. How To Make Hacking Tools
  41. Hacker Tool Kit
  42. Hack Tools
  43. Hack Apps
  44. Pentest Tools Alternative
  45. Hacker Tools List
  46. Computer Hacker
  47. Best Hacking Tools 2020
  48. Hacker Hardware Tools
  49. Pentest Tools Kali Linux
  50. Physical Pentest Tools
  51. Hacking Tools For Windows Free Download
  52. Pentest Tools Windows
  53. Hacking Tools Name
  54. Hacker Tools Free Download
  55. Hacker Tools Free
  56. Pentest Tools For Windows
  57. Hacker Tools Apk
  58. Hack Tools
  59. Wifi Hacker Tools For Windows
  60. Pentest Tools Open Source
  61. Pentest Tools Apk
  62. Hacker Tools Linux
  63. Hacker Tools For Mac
  64. Pentest Recon Tools
  65. Hackers Toolbox
  66. Pentest Tools Online
  67. Pentest Tools Android
  68. Pentest Tools For Mac
  69. Hacking Tools For Windows 7
  70. Pentest Recon Tools
  71. Hack Tools Github
  72. Hacking App
  73. Nsa Hacker Tools
  74. Pentest Tools Bluekeep
  75. Hacking Tools For Windows 7
  76. Hacking Tools Usb
  77. Hacking Tools Kit
  78. Hacking Tools Hardware
  79. How To Install Pentest Tools In Ubuntu
  80. How To Install Pentest Tools In Ubuntu
  81. Pentest Tools List
  82. Hacker Tools 2020
  83. Hak5 Tools
  84. Pentest Reporting Tools
  85. Hacker Tools Software
  86. Hack Tools
  87. Black Hat Hacker Tools
  88. Hacker
  89. Free Pentest Tools For Windows
  90. Hacker Hardware Tools
  91. Beginner Hacker Tools
  92. Hacker Tools 2019
  93. Hack Tools Mac
  94. Hacker Tool Kit
  95. Hacker Tools For Mac
  96. Hacker Tools Hardware
  97. Hacking Tools Software
  98. Hacker Tools For Windows
  99. Hacker Tools Github
  100. Free Pentest Tools For Windows
  101. Hacking Tools Hardware
  102. Hacker Tools Hardware
  103. Hacking Tools Online
  104. Hacker Tool Kit
  105. Hack Tools Github
  106. Hacker Tools
  107. Hacking Tools For Pc
  108. Hacker Tools For Mac
  109. Hacker Tools Linux
  110. Top Pentest Tools
  111. Hack Tools Online
  112. Pentest Tools For Ubuntu
  113. Best Hacking Tools 2019
  114. Hack Tools For Pc
  115. Hacking Tools Free Download
  116. Easy Hack Tools
  117. Hack Tools For Ubuntu
  118. Hack Tools For Ubuntu
  119. Hack Tools For Pc
  120. Usb Pentest Tools
  121. Game Hacking
  122. Pentest Tools Kali Linux
  123. Pentest Tools For Windows
  124. Kik Hack Tools
  125. Hacking Tools 2019
  126. Best Pentesting Tools 2018
  127. Hack Tools Pc
  128. Hack Tools Download
  129. Tools For Hacker
  130. Hak5 Tools
  131. Pentest Tools Tcp Port Scanner
  132. Hacker Tools Linux
  133. Hacking Tools Usb
  134. Pentest Automation Tools
  135. Game Hacking
  136. Hack Tools Online
  137. Hacking Tools 2020
  138. Hacker Tools
  139. Tools 4 Hack
  140. Pentest Tools Website Vulnerability
  141. Computer Hacker
  142. Hack App
  143. Tools 4 Hack
  144. Hackers Toolbox
  145. Hacking Tools For Games
  146. Computer Hacker
  147. Hacking App
  148. Hacker Tools Github
  149. Termux Hacking Tools 2019
  150. Hacker Tools For Mac
  151. Pentest Tools For Ubuntu
  152. Pentest Tools Website Vulnerability
  153. Pentest Tools Subdomain
  154. Hacker Techniques Tools And Incident Handling
  155. Best Hacking Tools 2019
  156. Computer Hacker
  157. Hacking Tools For Windows Free Download
  158. Android Hack Tools Github
  159. Pentest Tools Framework
  160. Hacker Tools Linux
  161. Hacking Tools And Software
  162. Hacking Tools Software
  163. Wifi Hacker Tools For Windows
  164. Hacking Tools Windows 10
  165. Pentest Tools Bluekeep
  166. Hacker Tools For Windows
  167. Pentest Box Tools Download
  168. Best Pentesting Tools 2018
  169. Hacking Tools For Kali Linux
  170. Hack Tools For Pc
  171. Hacking Tools Download
  172. Hacking Tools Online
  173. How To Make Hacking Tools

No comments: