5 ms·
XSS Attack Embedded in an ERC20 Token Contract Steals Thousands
- chroem- 9y ago>thousands of dollars The article is out of date. People are saying the amount is now $6 billion.
- RcouF1uZ4gsC 9y agoDo you have a link to that. Seems like a huge difference if it is thousands of dollars vs billions of dollars?
- recursive 9y agoPeople are saying. The best people! Believe me.
- sv123 9y agoYou know it, I know it, everybody knows it!
- trophycase 9y agoUh no, there is literally no chance.
- thephyber 9y agoIt is out of date, but the author created a followup post[1] on Medium: > Which as of this writing, has over $130,000 worth of Ethereum and over 88,000 transactions. [1] https://medium.com/@decktonic/following-the-trail-what-we-know-about-the-hacker-behind-the-etherdelta-attack-9ac6015fc2e1 https://medium.com/@decktonic/following-the-trail-what-we-kn...
- CryptoPunk 9y agoThis linked to an 'unlisted' token (a token which doesn't have enough recognition to be 'officially listed' on Etherdelta, and thus doesn't have its own ticker symbol), which the vast majority of token buyers have no interest in, so there's no chance that many people were interested in purchasing it, let alone through Etherdelta (which still has very little volume relative to centralized exchanges).
- jdp23 9y ago> I want to make one point clear: I believe that EtherDelta, in concept, is safer and more “trustworthy” than a traditional exchange. Everything about how EtherDelta functions is transparent and verifiable by users.... The attack detailed in this piece could have been identified by anyone before it was exploited, and if there had been a security review protocol in place, it would have been easily prevented. Even "in concept", releasing fintech software without doing the security basics verges on professional misconduct.
- imaginenore 9y agoThis blows my mind. These programmers can implement quite complex contacts-financial-exchanges on top of a quite complex distributed system, but then fail to sanitize user input in their web interface. It makes no sense.
- vosper 9y agoThey're pretty different programming disciplines, though. For a company as a whole it's not really excusable, but I'm sure there are plenty of fintech or distributed systems programmers who aren't up on web attack vectors, just as there are lots of web people who're well aware of them but who know nothing about fintech.
- mike_hearn 9y agoWell, from my blog post three days ago, discussed here: https://news.ycombinator.com/item?id=15321015 https://news.ycombinator.com/item?id=15321015 "I put it to you that it’s impossible to write secure web apps."
- KekDemaga 9y agoThis is like saying "It's impossible to perfectly secure a bike on a city steet" when it gets stolen because you forgot to engage the lock. I have fuzzers that would of likely found this pretty quickly.
- 9y ago
- davewritescode 9y agoThe smart contracts in Ethereum sounds awesome in practice and way more useful than Bitcoin mining but it seems like a giant security hole.
- thephyber 9y agoKinda like a knife -- it's a very useful tool if used well and a very painful tool if mishandled.
- pdkl95 9y agoYou're assuming it's possible to "use well". It's delusional to believe it's possible to understand the subtle interactions within and between "smart contracts". Even if we ignore the ambiguity of the real world, malicious actors, and other complexity multipliers, we already know it isn't possible to know if a "smart contract" will halt. Code will always have bugs, and you cannot truly understand how something written in a Turing complete language will behave without running it. > very painful tool if mishandled Part of being a skilled craftsman is choosing the right tools, which includes understanding and respecting their limits. The language for writing contracts makes all state mutable by default, has ambiguous operators that change behavior depending on storage location or if the operand was a literal, and doesn't defined the order of evaluation for expressions, to name just a few of it's design problems[1]. This isn't a "useful tool:", it's a strong indicator of a another fractal of bad design[2]. [1] https://news.ycombinator.com/item?id=14810008 https://news.ycombinator.com/item?id=14810008 [2] https://blog.codinghorror.com/the-php-singularity/ https://blog.codinghorror.com/the-php-singularity/
- alphast0rm 9y agoIsn't that something that can be helped by having a good standard library though (e.g. STL)? OpenZeppelin [1] is one example that comes to mind. There are also other contract languages aimed to solve some of the limitations you mention, like Tezos/Michelson [2][3], which facilitate formal verification. The issues you point out are certainly valid, but I believe people in the space are cognizant of them and are working on solutions. [1] https://openzeppelin.org/ https://openzeppelin.org/ [2] https://www.tezos.com/ https://www.tezos.com/ [3] https://www.tezos.com/static/papers/language.pdf https://www.tezos.com/static/papers/language.pdf
- AgentME 9y agoI'm surprised and disappointed that EtherDelta doesn't use Content-Security-Policy headers. They pretty much solve XSS. Google has a good introduction to using them here: https://csp.withgoogle.com/ https://csp.withgoogle.com/
- codedokode 9y agoYou will need to disable inline scripts which is inconvenient. CSP looks more like as hack for broken sites.
- lol768 9y agoIt's only inconvenient if you didn't write your code properly in the first place - and even then you can still use nonces for <script> and <style> elements which is better than nothing.
- AgentME 9y agoPersonally and from experience, I think inline scripts are generally a bad idea often abused for hacky one-off tweaks, so the fact that CSP blocks them by default is a bonus to me. But for the cases that they do make sense, there are ways to allow them with the nonce property. CSP doesn't mean that people should forget about proper HTML encoding of user input, but it means that when a developer messes that up somewhere, the issue is generally a minor formatting glitch rather than an exploitable flaw that lets attackers do whatever they want with users' browsers within your domain (like steal thousands of dollars). It's some invaluable defense-in-depth.
- KGIII 9y agoI read the headline and my immediate guess was cryptocurrency. I clicked and, sure enough, there it was. Maybe it's time to refine some of these ideas? While regular money does get stolen, maybe storing it online isn't the best method? Maybe requiring some human interaction is a good idea? At this point, I can't really justify investing in any cryptocurrency. I'm absolutely unable to justify investing in any ICO. If I opened a contract and my PayPal balance disappeared, I'd be pretty angry and might have some recourse. I'd absolutely have some options if it were with my credit/debit card or directly through my bank. Good luck, folks. I'm still going to maintain the wait-and-see approach.
- srcmap 9y agoThe story is almost like the 2008 time where wall street wiz kids package the mortgages to special mortgages back securities/contacts and resell them over and over again to banks, mutual funds, etc. Hugh hype was created. Last time: It was safe because it was back by mortgage. This time: It is safe because it is back by crypto algorithm. Last time few smart insiders got billions richer and unload everything before the bubble burst. And the time ...... (Love to see all imaginable endings to this time's story - good or bad)
- KGIII 9y agoIn 2007, I sold my business. In 2008, I put a bunch into the stock market and property. It was comparatively dirt cheap. I made a killing. I'd do the same with cryptocurrency, but I can't figure out how. My 2008 investments were pretty risk-free. Of course the economy was going to recover. It always does. I've no idea how to do that with cryptocurrency.
- foota 9y agoDon't you also have to trust that the person running EtherDelta hasn't modified what's running on the site...?
- AgentME 9y agoIf you use EtherDelta through MetaMask or Mist, then EtherDelta doesn't have direct access to your private keys, and you're given a prompt outside of EtherDelta's control to confirm any action you take, so you're much less vulnerable to malicious behavior from the EtherDelta admin.
- deleted 9y ago[deleted]
- detailyang 9y agothe etherdelta owner can change the js code then send you founds to faker contract:)
- AgentME 9y agoThe contract address is shown in the Mist/MetaMask prompt. Checking that when you first deposit would be sufficient. (Sure, it's probably true that many users would fail to check that, but I think it counts for something that there is an obvious way that anyone could verify what they were committing their funds to.)
- foota 9y agoAw, so there's some local client you run that you use to do the cryptographic bits, and the web client is just used to display results and let you navigate things?
- AgentME 9y agoOptionally yes, but EtherDelta specifically does let you instead use it in a normal browser if you give it an Ethereum private key. The hack only affected people who used it that way.
- meowface 9y ago>Thus, users of EtherDelta must enter their public wallet address and private key when using the site, meaning their private key could be captured from the browser session by a malicious code injection. This isn't some sort of fancy cryptocontract based attack. The private key is just stored as a JavaScript object in the session and an attacker found and exploited a reflected XSS vulnerability to send off the key. Even if you're not sending your private key to the server directly surely some people must have made these users aware of the risks they were taking? Not only XSS risks, but risks of a rogue admin or backend compromise injecting malicious JS.
- meowface 9y ago(Persistent XSS actually, but exploited similarly to a reflected XSS vulnerability because you have to send a specific link to your victims. It has a much higher exploitation success chance than reflected XSS since pesky browser XSS auditors won't be able to step in.)