Bitcoin Forum
April 28, 2024, 12:15:04 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Critical security flaw discovered in EOS  (Read 107 times)
bbc.reporter (OP)
Legendary
*
Offline Offline

Activity: 2912
Merit: 1440



View Profile
May 30, 2018, 01:07:23 AM
 #1

The EOS community said that this was only FUD and that all the vulnerabilities were fixed. But there is another group saying that the EOS development team is not that confident on the platform's security.

Also, there are rumors that there might be a delay on the release of the mainnet.

After EOS dumped all their ETH, and the release of this critical vulnerability, I reckon the most skeptical of you might be thinking of 2 words. Exit Scam.



Security researchers have discovered a series of new vulnerabilities in EOS blockchain platform, one of which could allow remote hackers to take complete control over the node servers running the critical blockchain-based applications.

Discovered by Chinese security researchers at Qihoo 360—Yuki Chen of Vulcan team and Zhiniang Peng of Core security team—the vulnerability is a buffer out-of-bounds write issue which resides in the function used by nodes server to parse contracts.

To achieve remote code execution on a targeted node, all an attacker needs to do is upload a maliciously crafted WASM file (a smart contract) written in WebAssembly to the server.

As soon as the vulnerable process parser reads the WASM file, the malicious payload gets executed on the node, which could then also be used to take control over the supernode in EOS network—servers that collect transaction information and pack it into blocks.


Read the full article https://thehackernews.com/2018/05/eos-blockchain-smart-contract.html?m=1

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
"With e-currency based on cryptographic proof, without the need to trust a third party middleman, money can be secure and transactions effortless." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714263304
Hero Member
*
Offline Offline

Posts: 1714263304

View Profile Personal Message (Offline)

Ignore
1714263304
Reply with quote  #2

1714263304
Report to moderator
Javi_Anibarro
Sr. Member
****
Offline Offline

Activity: 1526
Merit: 282

tBTC - https://dapp.tbtc.network/


View Profile
May 30, 2018, 03:18:38 AM
 #2

lol yeah very funny seeing this actually.
their supporters always said ''it's fud from china" or "fixed" or something like that.
https://www.reddit.com/r/CryptoCurrency/comments/8mwo4c/eos_bugs_discovered_before_mainnet_launch/dzr1eb4/
well i am not surprising to see it because i already seen this on XVG too.
nothing new..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!