Quantcast
Channel: Raz0r — Web3 Security
Browsing index pages (37 articles)

How We Detect DeFi Exploits in Under One Second

Shared some insights on how @DefimonAlerts works under the hood on the @Quicknode blog. New on the Quicknode blog: @DecurityHQ's CTO on how Streams let them rebuild Defimon from polling to push, cut...

View Article


Keeping hackers out of your DeFi wallet

Took part in the latest episode of the Unseen Money podcast with Paul Amery and Timur Yunusov to discuss the current state of DeFi security. Tune in! The decentralised finance (#DeFi) market is...

View Article


New tool: tx-coverage

Finished a weekend project that may be useful for onchain vulnerability analysis of deployed smart contracts: https://github.com/Decurity/tx-coverage tx-coverage allows to reveal unused code of live...

View Article

Building scalable monitoring infrastructure from scratch

Video and slides from my talk at TrustX 2023 in Istanbul about how we built https://defimon.xyz The post Building scalable monitoring infrastructure from scratch first appeared on Raz0r.name.

View Article

Upgradeable smart contracts security

Slides & video from my talk about the security of proxies in smart contracts at OFFZONE 2022 The post Upgradeable smart contracts security first appeared on Raz0r.name.

View Article


Сушите вёсла #20

Принял участие в новом эпизоде подкаста «Сушите вёсла», посвященном блокчейну, смарт-контрактам и их безопасности. Приятного прослушивания! The post Сушите вёсла #20 first appeared on Raz0r.name.

View Article

Image may be NSFW.
Clik here to view.

contract-diff: find bugs in smart contract forks

There has been plenty of hacks when a smart contract was forked and some things were changed without full understanding of the code. To help auditors I have built https://contract-diff.xyz This is how...

View Article

Безопасность web3: уязвимости на стыке блокчейна и веб-технологий

The post Безопасность web3: уязвимости на стыке блокчейна и веб-технологий first appeared on Raz0r.name.

View Article


Image may be NSFW.
Clik here to view.

Using CodeQL to detect client-side vulnerabilities in web applications

GitHub’s CodeQL is a robust query language originally developed by Semmle that allows you to look for vulnerabilities in the source code. CodeQL is known as a tool to inspect open source repositories,...

View Article


Image may be NSFW.
Clik here to view.

DeFi Hack solutions: DiscoLP

This is a series of write-ups on DeFi Hack, a wargame based on real-world DeFi vulnerabilities. Other posts: DeFi Hack solutions: May The Force Be With You DiscoLP DiscoLP is a brand new liquidity...

View Article

Image may be NSFW.
Clik here to view.

DeFi Hack solutions: May The Force Be With You

Back in 2018 I hosted the contest EtherHack which featured a set of vulnerable smart contracts. At that time the tasks were focused primarily on the EVM peculiarities like insecure randomness or...

View Article

Image may be NSFW.
Clik here to view.

Takeaways from solving CryptoHack

Just over a month ago I learnt about a new “fun platform for learning modern cryptography” called CryptoHack. The platform looked fun indeed offering a gamified experience to master cryptography. A...

View Article

Image may be NSFW.
Clik here to view.

Writeup: pwnable.kr “unlink”

Pretty easy task from pwnable.kr but took me waaay too long. #include <stdio.h> #include <stdlib.h> #include <string.h> typedef struct tagOBJ{ struct tagOBJ* fd; struct tagOBJ* bk;...

View Article


Image may be NSFW.
Clik here to view.

Why you should not use GraphQL schema generators

It has been quite a while since GraphQL has been introduced by Facebook, lots of tools and frameworks has appeared and are being used in the wild now. In 2017 I made an overview of the technology from...

View Article

Image may be NSFW.
Clik here to view.

PolySwarm Smart Contract Hacking Challenge Writeup

This is a walk through for the smart contract hacking challenge organized by PolySwarm for CODE BLUE conference held in Japan on November 01–02. Although the challenge was supposed to be held on-site...

View Article


Image may be NSFW.
Clik here to view.

Adobe Experience Manager Vulnerability Scanner

Adobe Experience Manager is content management system that is based on Apache Sling – a framework for RESTful web-applications based on an extensible content tree. Apache Sling in its turn is...

View Article

Image may be NSFW.
Clik here to view.

Predicting Random Numbers in Ethereum Smart Contracts

Slides from my AppSec California 2018 talk “Predicting Random Numbers in Ethereum Smart Contracts” Detailed blog post:...

View Article


Image may be NSFW.
Clik here to view.

Looting GraphQL Endpoints for Fun and Profit

In one of the previous posts about the state of modern web applications security I mentioned GraphQL – a new technology for building APIs developed by Facebook. GraphQL is rapidly gaining popularity,...

View Article

Image may be NSFW.
Clik here to view.

Arbitrary File Reading in Next.js < 2.4.1

Next.js is a quite popular (>13k stars on GitHub) framework for server-rendered React applications. It includes a NodeJS server which allows to render HTML pages dynamically. While digging into...

View Article

Image may be NSFW.
Clik here to view.

Database Firewall from Scratch

Slides from our talk with Denis Kolegov at PHDays 7 “Database Firewall from Scratch” (+ bonus). Database Firewall from Scratch from Denis Kolegov

View Article
Browsing index pages (37 articles)


Latest Images