7 ms·
Earn $200K by fuzzing for a weekend: Part 1
- pseudo0 4y agoSolid writeup, but that bug bounty policy... > DoS Attacks: $100,000 USD in locked SOL tokens (locked for 12 months) Apparently they made an exception in this case by donating in USD, but I certainly wouldn't trust an altcoin to be worth anywhere near the original $100k in 12 months.
- deleted 4y ago[deleted]
- fsckboy 4y agoyou don't trust the SOL coin, even after doing your own research? https://www.urbandictionary.com/define.php?term=SOL https://www.urbandictionary.com/define.php?term=SOL
- mooktakim 4y agoWouldn't you just exchange it immediately to USD and not be affected by market.
- willcipriano 4y ago> (locked for 12 months) I think that means you have to wait a year.
- twelve40 4y agogreat point, which makes the title clickbaity. more like "earn a donation or some monopoly money" instead.
- bawolff 4y agoCrypto is certainly taking the bug bounty thing to the next level.
- redisman 4y agoBounty: all the liquidity on the platform
- yata69420 4y agoBounties do actually work to secure things. I understand why most people wouldn't want to be earlier adopters of smart contracts. A lot of people are going to lose a lot of money to a lot of contract bugs for a lot of years. But eventually that will stop, and the contracts will be stable, and the lessons will be learned. At some point along the bounty x time curve, there's a threshold where you'll have a greater confidence trusting contracts than centrally managed institutions. There was a time when banking over the internet was laughably insecure, but it saved so much time that people did it anyway. It took about 15 years before 2FA became standard practice and we're still weening people off of SMS. Securing contracts may take 10 years to happen, but posts like this show me that it's going to happen.
- bawolff 4y agoWhen was banking over the internet particularly insecure?
- yjftsjthsd-h 4y agoHonestly, I have mixed feelings about cryptocurrencies, but I love the way it's pumping money into parts of the tech ecosystem by tying things directly to money. IMO it's done more than anything else to popularize FPGAs, GPGPU, and custom ASICs, and a lot to drive functional programming, nix, and fuzzing.
- goodpoint 4y ago> popularize FPGAs, GPGPU The very opposite: it made GPUs and many other components more expensive.
- yjftsjthsd-h 4y ago
- krnlpnc 4y ago“Earn”
- justinjlynn 4y agoDon't confuse the act of earning money for spending a certain time acquiring a proportionally certain quantity of money. Money is not time and time is not money. Money, in this case, represents coercive power held by the security researcher and bug bounties are a means of buying that coercive power from those researchers who would otherwise find another mechanism of extracting value from that knowledge.
- xbar 4y agoSecurity research viewed exclusively as coercion is passe.
- doopy1 4y agoIt's an absurd take. Plenty of folks who work in tech can make money doing hackery dark magic, but guess what? It's not their day job that keeps them from doing so.
- spacemanmatt 4y agoThis. I am quite weary of the default dim view of humanity. We're not anywhere as bad as that on average.
- Thorrez 4y agoThe company has something it wants: security audits. It pays people who do audits and find things.
- esjeon 4y agoA big absurdity I sense here. I'm talking about Solana here, btw. * Considering the money flying around Solana and its heavy dependency on BPF, $100k payout per vuln is reasonable. * Considering the money flying around Solana and its heavy dependency on BPF, 2 major vulns with a fuzzer over a weekend is 100% unacceptable. If it was a usual startup, I would not be concerning, but, this is a blockchain that handles tons of money. It's such a complete failure of technical leadership. * Note that bounty will not always solve the problem. If the vuln could be exploited for profit, Solana would've been already doomed.
- dijonman2 4y agothis is elitism and not technical management
- defen 4y agoWell, the question you might ask is "Why didn't someone at Solana spend a weekend writing a fuzzer for this extremely important component that deals with billions of dollars"? OP is obviously incredibly talented, fine, but maybe someone at Solana could have spent a month working on it full time?
- esjeon 4y ago> OP is obviously incredibly talented, fine, but maybe someone at Solana could have spent a month working on it full time? Exactly. OP certainly is talented and did a great job up there. However, Solana is simply too important to fail like this. Literally billions of dollars are on stake, and running a fuzzer for 2 days should NOT be this much impactful. It would not be this absurd if OP had to spend much more time and effort than this. In other words, Solana should have adopted advanced security measures far before this happened. Using BPF requires a compiler toolchain and VM, which are sophisticated by nature. There's no security-by-correctness here, so one should fallback to the next line of defense - practical correctness by stress test - where fuzzer becomes a necessity. There have to be various fuzzers running regularly somewhere in Solana. Also, one should note that how Solana uses BPF is well outside the original intention of BPF, which is mainly used deep inside system. BPF in system has much smaller attack surface, much easier recovery scenario, and relatively smaller impact upon failure. When it comes to Solana, BPF is wide open to the wild, a faulty BPF program can cause a lot of damage, which are often (or mostly) irreversible. That mean Solana has to be the one who perform extensive researches on BPF. No one else needs to harden BPF to the level that Solana needs it to be.
- zenincognito 4y ago>>It would be bad form of me to not explain the incredible flexibility shown by Solana in terms of how they handled my payout. I intended to donate the funds to the Texas A&M Cybersecurity Club, at which I gained a lot of the skills necessary to perform this research and these exploits, and Solana was very willing to sidestep their listed policy and donate the funds directly in USD rather than making me handle the tokens on my own, which would have dramatically affected how much I could have donated due to tax. So, despite my concerns regarding their policy, I was very pleased with their willingness to accommodate my wishes with the bounty payout. I am not sure how old the author is but I find these donations incredibly generous and sometimes fail to comrehend such generosity. Sure you got an education at this place but was it worth 200K ? I am not trying to look at the action of the author in any disdain but am genuinely amazed at how such a young person will have such tremendous generosity.
- bsilvereagle 4y agoIt looks like this donation went directly to a student organization. In my experience student organizations receive a nominal (~1k) amount of funding from the University per year, which could then be supplemented by company sponsorships, fundraising, etc. So while the University at large has an endowment, the specific Cybersecurity Club does not.
- totetsu 4y agoSounds like a headache for that club's executive members
- phdelightful 4y agoAs an executive member of a nonprofit, this was exactly the kind of headache I hoped for. You can do as lot of good with $100K. Definitely worth the trouble.
- joncrane 4y agoThis is one of those "great problems to have" that people talk about.
- orangepurple 4y agoConsider the $200k is effectively amortized over the individual's lifetime of learning and research
- curiousgal 4y agoThe most amazing part is that he's quite young!
- Copenjin 4y agoIsn't that true for every job?
- deleted 4y ago[deleted]
- abainbridge 4y agoCan someone explain the CVS 2021 46102 bug? Various sources tell me it was an integer overflow in some Rust. The faulty line was: let addr = (sym.st_value + refd_pa) as u64; I guess, the + is evaluated using 32-bit arithmetic and then it is cast to a u64, and thus overflow is possible? And in release mode, Rust doesn't trap integer overflow. Shouldn't something as critical as the EBF compiler be trapping integer overflow?
- password4321 4y agoThey must have enabled trapping integer overflow somehow, unless they were testing with a debug build(?), per https://blocksecteam.medium.com/new-integer-overflow-bug-discovered-in-solana-rbpf-7729717159ee https://blocksecteam.medium.com/new-integer-overflow-bug-dis...: > every validator would run the target ELF file and the rBPF would get panic with “add with overflow” I did not see overflow-checks = true in the cargo.toml though.
- cahoot_bird 4y agoThis is interesting -- I generally think of memory bugs being harder to exploit because of memory protections (stack canaries, ASLR, etc) and code execution being the goal. A quick read of this article it seems from the nature of crypto it was enough for reward to just crash the network (denial of service).
- jokethrowaway 4y agoI wish I was so rich I could donate 200k