3 ms·
The "bug" is that some developers think of matching function signatures as some form of authN / authZ. A few years back I wrote https://medium.com/coinmonks/la
by decentralised 5y ago
The "bug" is that some developers think of matching function signatures as some form of authN / authZ.
A few years back I wrote https://medium.com/coinmonks/lashing-out-at-a-spank-channel-2b42b23f0dc6 https://medium.com/coinmonks/lashing-out-at-a-spank-channel-... about a similar hack where a contract "trusted" a given (user input) contract based on nothing other than verifying a function signature. This latest hack was smarter but ultimately it still exploited a 4 bytes hash "security" feature...