优惠论坛
Well123
注册
找回密码 |
天策评选的优秀公司,所有会员与公司发生的问题我们将负责尽力协助处理。
收起/展开
新晋公司
 

新晋公司具有驻站代表,并不在论坛纠纷服务范围内,请会员自行判断选择

  • 356
S级信誉公司
ManBetX万博
YZ
乐投
taptap(点点)
E世博
瑞丰国际
A级信誉公司
吉祥坊
星宝合营
乐动体育
B级信誉公司
bet365
C级合作公司
CMP
金星
LOKI
平博
  • 推荐主题
  • 热门活动
  • 币圈快讯
  • 商城动态
重要通知
 
论坛搜索
              搜索
Array ( [fid] => 6974 [description] => 专注于币圈最新最快资讯,数字货币应用及知识普及 [password] => [icon] => b1/common_6974_icon.png [redirect] => [attachextensions] => [creditspolicy] => Array ( [post] => Array ( [usecustom] => 1 [cycletype] => 1 [cycletime] => 0 [rewardnum] => 5 [extcredits1] => 1 [extcredits2] => 1 [extcredits3] => 0 [extcredits4] => 0 [extcredits5] => 0 [extcredits6] => 0 [extcredits7] => 0 [extcredits8] => 0 [rid] => 1 [fid] => 6974 [rulename] => 发表主题 [action] => post [fids] => 32,52,67,447,1120,1151,1156,6750,6762,6763,6766,6769,6772,6773,6787,6796,6808,6809,6810,6813,6814,6820,6829,6830,6846,6856,6864,6865,6827,6930,6931,6776,6858,6880,6764,6932,6871,6758,6905,1116,6788,6812,6798,6736,6759,6842,6966,6767,6828,6924,6935,6936,6938,6940,6941,6826,6909,6803,6919,6911,6908,6881,6920,6912,6913,6921,6925,6922,6789,6818,6819,6872,6928,6969,6889,6888,6917,6939,6947,6961,6937,6943,6970,6869,6900,6902,6783,6817,1111,6870,6821,6876,6952,6954,6960,6942,6910,6949,6962,6963,6964,6927,6926,6973,6728,6929,6874,6894,6896,6885,6857,6868,1113,6778,56,6844,6878,6802,6933,6811,6923,6877,6875,6918,6892,6757,6832,6833,6795,6793,6848,6837,6849,6850,6851,6852,6853,6854,6863,6882,6836,6790,6838,6794,6791,6873,555,6934,6958,6944,6945,6907,6779,6886,6950,6904,6956,6862,6957,6855,6955,6959,6914,6965,6971,6972,6953,6976,6824,6815,6891,6866,6979,6977,6765,6903,6948,6980,6981,6983,6799,6982,6951,6984,6975,6895,6845,6879,1121,6974 ) [reply] => Array ( [usecustom] => 1 [cycletype] => 1 [cycletime] => 0 [rewardnum] => 0 [extcredits1] => 0 [extcredits2] => 1 [extcredits3] => 10 [extcredits4] => 0 [extcredits5] => 0 [extcredits6] => 0 [extcredits7] => 0 [extcredits8] => 0 [rid] => 2 [fid] => 6974 [rulename] => 发表回复 [action] => reply [fids] => 32,52,67,447,1120,1151,1156,6750,6763,6766,6769,6772,6773,6787,6796,6808,6809,6810,6813,6814,6820,6829,6830,6846,6856,6864,6865,6827,6930,6931,6776,6858,6880,6764,6932,6871,6758,1116,6788,6812,6798,6736,6759,6842,6966,6767,6828,6924,6935,6936,6938,6940,6941,6826,6909,6803,6919,6911,6908,6881,6920,6912,6913,6921,6925,6922,6789,6818,6819,6872,6928,6969,6889,6888,6917,6939,6947,6961,6937,6943,6970,6869,6900,6902,6783,6817,1111,6870,6821,6876,6952,6954,6960,6942,6910,6949,6962,6963,6964,6927,6926,6973,6728,6929,6874,6894,6896,6885,6857,6868,1113,6778,56,6844,6878,6802,6933,6811,6923,6877,6875,6918,6892,6757,6832,6833,6795,6793,6848,6837,6849,6850,6851,6852,6853,6854,6863,6836,6790,6838,6794,6791,6873,555,6934,6958,6944,6945,6907,6779,6886,6950,6904,6956,6862,6957,6855,6955,6959,6914,6965,6971,6972,6953,6976,6824,6815,6891,6866,6979,6977,6765,6903,6948,6980,6981,6983,6799,6982,6951,6984,6975,6895,6845,6879,1121,6974 ) ) [formulaperm] => a:5:{i:0;s:0:"";i:1;s:0:"";s:7:"message";s:0:"";s:5:"medal";N;s:5:"users";s:0:"";} [moderators] => 实习版主1 [rules] => [threadtypes] => Array ( [required] => 1 [listable] => 1 [prefix] => 1 [types] => Array ( [1590] => 论坛公告 [1752] => 公司优惠 [1603] => 虚拟币交流 [1753] => 数字钱包 [1754] => 虚拟币存提 [1755] => 交易所 [1655] => 虚拟币资讯 [1756] => 银行卡 [1757] => 第三方支付 [1760] => 币圈大佬 [1758] => 科技前沿 [1759] => 天策嗨聊 [1661] => 入驻合作 ) [icons] => Array ( [1590] => [1752] => [1603] => [1753] => [1754] => [1755] => [1655] => [1756] => [1757] => [1760] => [1758] => [1759] => [1661] => ) [moderators] => Array ( [1590] => 1 [1752] => [1603] => [1753] => [1754] => [1755] => [1655] => [1756] => [1757] => [1760] => [1758] => [1759] => 1 [1661] => ) ) [threadsorts] => Array ( ) [viewperm] => 9 26 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 31 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 7 8 [postperm] => 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 [replyperm] => 26 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 [getattachperm] => 26 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 [postattachperm] => 26 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 [postimageperm] => 26 22 11 12 13 14 15 27 43 44 60 61 62 63 64 19 67 68 69 73 75 76 83 84 87 90 91 92 33 38 57 58 65 66 74 77 79 80 85 86 1 2 3 [spviewperm] => [seotitle] => [keywords] => [seodescription] => [supe_pushsetting] => [modrecommend] => Array ( [open] => 0 [num] => 10 [imagenum] => 0 [imagewidth] => 300 [imageheight] => 250 [maxlength] => 0 [cachelife] => 0 [dateline] => 0 ) [threadplugin] => Array ( ) [replybg] => [extra] => a:2:{s:9:"namecolor";s:0:"";s:9:"iconwidth";s:2:"60";} [jointype] => 0 [gviewperm] => 0 [membernum] => 0 [dateline] => 0 [lastupdate] => 0 [activity] => 0 [founderuid] => 0 [foundername] => [banner] => [groupnum] => 0 [commentitem] => [relatedgroup] => [picstyle] => 0 [widthauto] => 0 [noantitheft] => 0 [noforumhidewater] => 0 [noforumrecommend] => 0 [livetid] => 0 [price] => 0 [fup] => 6729 [type] => forum [name] => 虚拟币讨论大厅 [status] => 1 [displayorder] => 3 [styleid] => 0 [threads] => 28243 [posts] => 459037 [todayposts] => 168 [yesterdayposts] => 237 [rank] => 2 [oldrank] => 1 [lastpost] => 2770290 参议员 Lummis 表示参议院正在就加密税规则取得进展(转) 1759255986 小钱儿 [domain] => [allowsmilies] => 1 [allowhtml] => 1 [allowbbcode] => 1 [allowimgcode] => 1 [allowmediacode] => 0 [allowanonymous] => 0 [allowpostspecial] => 21 [allowspecialonly] => 0 [allowappend] => 0 [alloweditrules] => 1 [allowfeed] => 0 [allowside] => 0 [recyclebin] => 1 [modnewposts] => 2 [jammer] => 1 [disablewatermark] => 0 [inheritedmod] => 0 [autoclose] => 0 [forumcolumns] => 3 [catforumcolumns] => 0 [threadcaches] => 0 [alloweditpost] => 1 [simple] => 16 [modworks] => 1 [allowglobalstick] => 1 [level] => 0 [commoncredits] => 0 [archive] => 0 [recommend] => 0 [favtimes] => 0 [sharetimes] => 0 [disablethumb] => 0 [disablecollect] => 0 [ismoderator] => 0 [threadtableid] => 0 [allowreply] => [allowpost] => [allowpostattach] => )
打印 上一主题 下一主题
卷土重来?黑客获利约130万美元,FEGexPRO合约被攻击事件分析
[复制链接]
avatar
跳转到指定楼层
1#
2022年5月16日,成都链安链必应-区块链安全态势感知平台舆情监测显示,Ethereum和BNB Chain上FEGtoken项目的FEGexPRO合约遭受黑客攻击,黑客获利约3280 BNB 以及144 ETH,价值约130万美元。成都链安技术团队对事件进行了分析,结果如下。' T% T, i" S7 p

  L0 X' T* W; p2 b# X  A' i2 h2 G8 d! }( U& {7 S2 x6 \% X
* _7 E3 D! b7 ^) f" p: [9 P

* O: O( y" K  E) p1 I. o
; @* Y, R6 v' B8 w! I$ {& M( u#1 事件相关信息
9 V  {4 _! Y$ @8 i" p3 M) ?9 h
- _8 d( e; p$ H8 Z7 F1 {+ o/ a1 z7 E% L7 T( @2 U' ^

- O6 k9 k. u( V& G# |' Y  i本次攻击事件包含多笔交易,部分交易信息如下所示:, O- s6 P! R: u+ ?. p3 J

$ m2 H8 N$ V$ I. V4 @+ r5 `* B# r. A5 `" P4 e% t) K

5 k! `" L) j" t( ]. n/ G5 H6 u攻击交易 (部分)" R5 C  e6 d: W

7 t3 Z- g' ?% K/ H% T0 e/ Y/ G0x77cf448ceaf8f66e06d1537ef83218725670d3a509583ea0d161533fda56c063 (BNB Chain)' D& {. b$ a; a8 B( o( C" @1 [

& ^; R$ }+ D$ V0x1e769a59a5a9dabec0cb7f21a3e346f55ae1972bb18ae5eeacdaa0bc3424abd2 (Ethereum)
7 q5 @8 S! ]: ?$ T& e" e8 U' R$ T4 Y$ ^

. |: D/ ^5 P) S( V, X. u- m& [  p/ T9 t3 P( Z4 {" e: p
攻击者地址" v9 Q* N, ^# E& W$ n
4 K2 p$ d% p: t: O  H( ^! }
0x73b359d5da488eb2e97990619976f2f004e9ff7c
6 Z. J3 k, U4 i, V: G2 `4 W7 |3 F  N1 w7 b  ?4 b0 @  G

  ?6 f( D, V; x9 w' B) O2 p8 m
& i& q4 j3 c$ l  @- d4 p% H9 O$ @7 Q攻击合约5 S8 q% L3 f5 K7 ~3 _, I3 _
" D$ o( a) x6 y! ~' W3 U, M
0x9a843bb125a3c03f496cb44653741f2cef82f445% x0 ]5 G$ v& r9 w% J
4 n' i" A+ e% i1 B9 E4 O. p6 n

6 c; p* l( h+ B. Y
& T$ z# p5 s4 z: n3 e" G. p1 x6 `被攻击合约(部分)
6 D- ?3 q5 [2 F4 [6 ]- h
3 q) z3 ]" c" u2 C+ Q  M1 Q% H0x818e2013dd7d9bf4547aaabf6b617c1262578bc7 (BNB Chain)% C+ V# L1 a( _! y6 o! O1 q. r
8 M, e2 G. U$ c5 M+ F7 _/ z
0xf2bda964ec2d2fcb1610c886ed4831bf58f64948 (Ethereum)
  D5 Z5 y# U% k* k8 @1 T* W' N4 W3 V# E$ b, `

  \4 T6 W! O( T
6 V, H0 f# m' p- @+ y% E: E#2 攻击流程5 e+ F3 u; |3 ]: u- V, E

- T7 Z& c7 F. e( o  u* T# c: d9 a- _/ Z% [) ^& D6 T* ~! g
Ethereum和BNB Chain上使用攻击手法相同,以下分析基于BNB Chain上攻击:, p% E+ t; v9 Q
4 j4 r( R+ {, \7 X

& Q9 S* y% t+ H# R' n7 k9 r& Q' ^$ a' a" O* W( o# Q
1. 攻击者调用攻击合约(0x9a84...f445)利用闪电贷从DVM合约(0xd534...0dd7)中借贷915.84 WBNB,然后将116.81 WBNB兑换成115.65 fBNB为后续攻击做准备。
! ]: `# l. C- t1 E9 _# T% F8 D6 d' X4 g1 _% W; J* O+ J

; b9 f5 s8 k# a6 y
6 G2 H( z1 @. E$ i2 i7 [" d& _3 N) Z" p2. 攻击者利用攻击合约创建了10个合约,为后续攻击做准备。# `4 A% L' Y, w( O, O+ c+ [

2 Y. t5 }! X1 H
* M8 F7 ]) \' f9 S2 n$ u. O7 d7 x# V
3 d! d  R# ]8 W/ t! z9 Y/ ^6 [, F4 c( j5 n" S0 P4 z) _
- d7 h0 c- l2 i3 s
3. 攻击者接下来将兑换得到的fBNB代币抵押到FEGexPRO合约(0x818e...8bc7)中。+ }7 b# q& u* p) i" F
" u' m& Q) Q) P9 f: A! B- x

  l9 h5 A. ]0 P" S6 d' y' V
$ h. r6 e) G/ U0 z% f4. 然后攻击者重复调用depositInternal和swapToSwap函数,让FEGexPRO合约授权fBNB给之前创建好的其他攻击合约。
7 H% |+ \2 v' ?9 f$ R( o- E
- Z1 O  u; V' d8 `" }/ Y8 G5 C, j6 w/ T: c5 ]

* U2 g  p* q3 i, Z& f& k! I0 E3 w( Z- `( U

0 T: z. W+ A/ ]3 n5. 然后利用其他攻击合约调用transferFrom函数将FEGexPRO合约中fBNB全部转移到攻击合约(0x9a84...f445)中。
, u* Y( Y6 u6 W4 J+ Q' B' c+ v. V$ H% r7 B0 M
; s- x) J5 l. |2 h3 T6 L

" P' ?- [3 x  \% z+ G7 @1 R% m
  g+ j2 i3 l! ^$ i0 g1 ]# }# j1 n- Q8 F, V; V1 n3 m4 t3 z
6. 接下来又在LP交易对合约(0x2aa7...6c14)中借贷31,217,683,882,286.007211154 FEG代币和423 WBNB。& [1 R1 [0 Y3 S/ }+ f/ a2 J
/ h  i- }9 [9 x1 z! j7 c! Z& k
: L7 n. e0 n' ?% E" \
0 ~0 A$ C/ E& A! @1 J  o, t! B
7. 然后重复3、4、5步骤的攻击手法,将FEGexPRO合约中大量FEG代币盗取到攻击合约中。) `' N( O( `: X
( [# M3 }0 L+ o# Y8 ~
& D2 `5 G# ]8 j# C: D% ?% J
* p/ o+ k; B7 I/ o5 m- t' ~* N

5 Z3 O/ Q( R3 q! w. S0 ]( p5 \8 {/ h6 s* }- k0 G& ]9 @
7 L: E* b" d- u# [- ^) {8 a$ Q
# H) ]5 v7 \0 W' o* i: c/ m) ?
8. 然后归还闪电贷,将获得的WBNB转入攻击合约中完成此笔攻击。$ c/ y5 U6 d8 o' u; p$ c, g* X4 B
! K/ K% {# s( }8 x* F  D. ?

/ b3 m; R! c- L- H- H
1 ]2 j7 I) _8 Q  V! b7 W+ ]" {2 x
  n+ S7 k) r4 h8 P6 @& B/ \0 ?$ w* x; i$ L; y6 ^& {* r2 e) c
9. 此后,又利用相同的原理,执行了50余笔相同的攻击,最获利约144 ETH和3280 BNB。; E+ E" @. e- B

3 h" J$ t. ?5 r) g% |
) h1 B" @9 h  k' {" |1 J/ Z0 ~, I$ T' c1 ]& ~7 v' P

! s: q0 j5 n8 Z, K' q: b# U0 H6 H1 U

2 A5 h' V, f$ g" t7 i& ]4 F+ c) ^. C+ Y
3 j' i0 u; }1 S# @
4 X1 n" f% P1 J2 h
0 ^1 ?( t4 G* m' _#3 漏洞分析" B& @2 ^2 v" B

# X: x$ |5 O3 d% L$ n6 U8 i9 f3 C) e' {( }, W, T
本次攻击主要利用了FEGexPRO合约中swapToSwap函数中path地址可控且合约中未对path地址进行有效性校验的漏洞。由于合约中depositInternal函数中更新用户余额时依赖于合约中当前代币余额,攻击者通过传入一个恶意的path地址,调用swapToSwap函数时合约中代币余额并未发生变化,导致攻击者可以反复重置攻击合约在FEGexPRO合约中记录的代币数量,从而让FEGexPRO合约将自身代币反复授权给攻击者所控制的多个恶意合约。
  q2 R. I: e4 y
% J$ K8 Z! B7 v  O9 X  z* x$ g' H# w- u1 A+ W: d9 k* s

: v; P* ]: q% {' b9 ]
/ M, y7 Q" b! s- Z9 c( F3 f( h# r( {: J) ~7 u/ k2 p
1 F) J, S  R4 [, k' A
9 i' z( p8 o& f$ L, w; L5 f
#4 资金追踪
, r! m8 |3 ?7 b
! r" @  c0 D7 b% @4 A/ B5 c1 t
截止发文时,被盗资金仍在攻击者地址(0x73b3...ff7c)中并未转移。5 p- [1 b0 I! w, a& p3 t
* h+ t/ o5 M. ]

, {+ q: E/ T; y% K2 E# S7 H+ p$ Y
8 H' B, L9 H4 K  C6 d8 p( M( T/ D
0 d  ^7 F6 ~$ L( i& M( W0 M8 J. Y  a8 ]9 M9 y/ G

$ f  D) H. e" k# Y0 i% }7 o$ u' V% P3 y$ G4 c+ Q

3 d1 U# _$ P5 C9 K; d: Z5 x9 O9 I3 C& x1 g
/ \% y: O: j7 u- y& ^: H  a# A

  g* w6 y. T" y6 [% l#5 总结' L3 T% ~+ g0 ^! R! v4 `- u4 P/ ?1 R

3 D' [) x# K* I4 M, H5 s$ L
7 R4 f% }' @. U, y$ q. J针对本次事件,成都链安技术团队建议:
5 ^- k( [3 W. l9 b& x+ H
, f. M" `5 s6 i/ A/ I, `3 ]. t5 H! f* R8 i
4 I2 [. E0 B7 `
项目开发时,应该注意与其他合约交互时可能存在的安全风险,尽量避免将关键参数设置为用户可控。如果业务需求如此,则需要严格判断用户输入的参数是否存在风险。此外建议项目上线前选择专业的安全审计公司进行全面的安全审计,规避安全风险。
( d+ R% d4 J7 y2 F9 }0 n/ |9 E
% v' ]! a1 ]- {- W4 W( a
avatar
2#
黑客也是厉害啊,又是赚到很多。
avatar
开始发新闻了,也是一堆吧
avatar
如果是行业内的人可以分析一下
avatar
5#
主题回复处广告图案-天策传媒
那你还赶紧的去出手赢个几百万的
avatar
6#
这类新闻适当看一看就可以了
avatar
7#
以后还是立志去干黑客比较赚钱
avatar
8#
黑客很厉害啊,又是赚到了不少的钱的咯
avatar
有门技术肯定是比较好赚钱的事
avatar
这也是要有技术的才能做到了
avatar
还是需要有技术才能够赚钱呢。
avatar
12#
这些黑客果然也是很厉害了
avatar
13#
黑客真的是牛逼哄哄了的哦。
avatar
14#
黑客的火力的那么多啊
avatar
15#
黑客,真厉害,无所不在啊,这是
avatar
16#
看来它还是挺引人注目的公司
您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

:) :( :D :'( :@ :o
:P :$ ;P :L :Q :lol
:loveliness: :funk: :curse: :dizzy: :shutup: :sleepy:
:hug: :victory: :time: :kiss: :handshake: :call:
{:8_286:} {:8_287:} {:8_288:} {:8_289:}
{:8_290:} {:8_291:} {:8_292:} {:8_293:}
{:8_294:} {:8_295:} {:8_296:} {:8_297:}
{:8_298:} {:8_299:} {:8_300:} {:8_301:}
{:8_302:} {:8_303:} {:8_304:} {:8_305:}
{:8_306:} {:8_307:} {:8_308:} {:8_309:}
{:8_310:} {:8_311:} {:8_312:}
{:8_313:} {:8_314:} {:8_315:} {:8_316:}
{:8_317:} {:8_318:} {:8_319:} {:8_320:}
:) :( :D :'( :@ :o
:P :$ ;P :L :Q :lol
:loveliness: :funk: :curse: :dizzy: :shutup: :sleepy:
:hug: :victory: :time: :kiss: :handshake: :call:
:) :( :D :'( :@ :o
:P :$ ;P :L :Q :lol
:loveliness: :funk: :curse: :dizzy: :shutup: :sleepy:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory:
:) :( :D :'( :@ :o
:P :$ ;P :L :Q :lol
:loveliness: :funk: :curse: :dizzy: :shutup: :sleepy:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory: :time: :kiss: :handshake: :call:
:hug: :victory: :time: :kiss: :handshake:
未有绑定记录
 


Powered by 天策论坛   © 2007-2025 天策论坛 | 小黑屋 | 手机|
1717 : 0