Главная
Study mode:
on
1
Intro
2
Speaker background
3
My introduction to cryptocurrency
4
Blind XSS and Internal Privilege E
5
Blind XSS on Wyre leads to full KYC
6
In 2022, who owns your crypto?
7
SQL injection on Vulcan Forged lead Key and API Key Disclosure
8
Introduction of the Ethereum and Defi ecosyste
9
Full Account Takeover on Vercel via
10
uxss on nux/image library via improper parsing
11
Universal Open Redirect on Next.js
12
UXSS via Reverse Proxy loading Unrestricted
13
UXSS via Reverse Proxy loading Up
14
Instapage XSS and Subdomain Take
15
Improper Host Whitelisting on Gitbook
16
Remote Code Execution leads t compromise of 150mm market-cap stable
17
Remote Code Execution leads to AWS compromise of 150mm market-cap stablecoin
18
Full Takeover of .TO TLD leads to Compromise of USDT provisioning ser
19
Full Account Takeover on Crypteriun
20
Full Account Takeover on Roll
21
Final thoughts
Description:
Explore the world of cryptocurrency security in this conference talk from #NahamCon2022. Delve into a three-year journey of hacking crypto web applications, uncovering vulnerabilities in cloud wallets, and learning about the evolving landscape of digital asset protection. Discover real-world examples of security breaches, including blind XSS attacks, SQL injections, and full account takeovers affecting major platforms in the crypto ecosystem. Gain insights into the Ethereum and DeFi ecosystems, and understand the implications of various security flaws in popular services. Learn about remote code execution vulnerabilities that led to the compromise of high-value stablecoins and the takeover of critical infrastructure. Conclude with final thoughts on the state of cryptocurrency security and the importance of robust protection measures in the rapidly growing digital asset industry.

Breaking Into Cloud Wallets - Hacking Crypto Web Apps

NahamSec
Add to list
0:00 / 0:00