Тёмный

My Study Methodology 

Andy Li
Подписаться 13 тыс.
Просмотров 8 тыс.
50% 1

My note taking methodology for studying previous audit findings on code4rena.
Code4rena reports:
code4rena.com/...
Tomo's Blog:
tom-sol.notion...
Joplin:
joplinapp.org/

Опубликовано:

 

15 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 44   
@neoliu3125
@neoliu3125 2 года назад
Great video, your video helped me a lot on my web3 learning journey
@andyli
@andyli 2 года назад
Excellent
@loop4303
@loop4303 2 года назад
Thank you. This is what I need. 🙏
@andyli
@andyli 2 года назад
You’re welcome 😊
@erayack
@erayack 2 года назад
As far as I understand, you don't just index the errors you find in the reports on Joplin. You also try to understand and learn from mistakes. Joplin actually becomes a checklist for your own audits.
@andyli
@andyli 2 года назад
Yep that is a good description
@sye3193
@sye3193 2 года назад
Thank you, that was great and quick advice:)
@andyli
@andyli 2 года назад
Glad it was helpful!
@soaphornseuo8630
@soaphornseuo8630 2 года назад
Thank brother for your sharing
@andyli
@andyli 2 года назад
Welcome
@tangjunnz
@tangjunnz 2 года назад
Thanks for your video 👍
@andyli
@andyli 2 года назад
👍
@Jansen-Moreira
@Jansen-Moreira 2 года назад
Thanks! It helped a lot
@andyli
@andyli 2 года назад
Awesome!
@user-dm7bw9os7w
@user-dm7bw9os7w 2 года назад
informative !
@andyli
@andyli 2 года назад
cheers!
@satyabratadash2858
@satyabratadash2858 2 года назад
I recently joined code arena, what is the proper way to right the bugs and submit them.
@andyli
@andyli 2 года назад
Combine QA/Gas findings into a single report, submit medium and highs individually. There is no set guideline, refer to the previous reports for how other people are formatting it
@satyabratadash2858
@satyabratadash2858 2 года назад
Hi, sorry for bothering you again, In Contest, under the Attack Surface section they list down a no. Of possible hacks for a .Sol file, Is that means when auditor try to auditing that perticular .Sol file he have to take extra concern about those bugs.
@andyli
@andyli 2 года назад
Yes, correct
@satyabratadash2858
@satyabratadash2858 2 года назад
Hi Andy, I'm bigginer to SmartContract Auditing, i have previous experience as a contract developer but not that much, When i try to audit contract especially which are very large where many Sol file interacts with each other, I got more confused, at a point all my energy drain out. At this point of time i only able to find gas optimization and some low level, some or all popular findings that mentioned on secureum, I want to learn how to find vulnerabilities related core functionality of contract, like high and medium findings listed on reports on Codearena, Can you guide me, what should my approch to find those high and medium when i got a large contract ?? Thank you .
@andyli
@andyli 2 года назад
I know what code base you are talking about😂 I would recommend some visualization tools to help understand the project. A lot of experienced auditors talk about reading the base contract first then the derived contracts that inherit from it. Sol2uml helps with that: github.com/naddison36/sol2uml Another tool you can use to understand call flows is: github.com/ConsenSys/surya
@satyabratadash2858
@satyabratadash2858 2 года назад
Thanks for reply
@jiggle546
@jiggle546 10 месяцев назад
Can you repost your Anki Study video? I found that video very helpful when it came to earning my A+.
@theybecameus
@theybecameus 2 года назад
What is the salary range in Perth for a person who has OSWE and has 1.5 years working experience in a company. Asking u coz u work there
@andyli
@andyli 2 года назад
I think 100-110k
@justiceessiel6123
@justiceessiel6123 Год назад
Do you have a course on your channel that is on smart contract auditing that would make one get a job from a web3 dev to smart contract auditor
@andyli
@andyli Год назад
I made a beginner road map video where I basically shared all the resources I used
@satyabratadash2858
@satyabratadash2858 2 года назад
What is the meaning of context in Scops and their corresponding percentage for .Sol file in CodeArena contents
@andyli
@andyli 2 года назад
Test coverage
@lacag-lacag
@lacag-lacag 2 года назад
Next video how do you choose which vulnerability should look for in the project Code
@andyli
@andyli 2 года назад
Be focused when studying, but when bug hunting I look for everything 😁
@andywang4189
@andywang4189 Год назад
Thanks, very helpful
@andyli
@andyli Год назад
No worries!
@sye3193
@sye3193 2 года назад
Will you please make a video on ZIION VM its tools, use, and all other cool stuff as a security testing perspective
@andyli
@andyli 2 года назад
I have not tried ZIION VM yet, will check it out
@andyli
@andyli 2 года назад
I'll be happy if it just comes with solc-select pre installed
@sye3193
@sye3193 2 года назад
@@andyli yea it's included XD
@andyli
@andyli 2 года назад
love it
@erayack
@erayack 2 года назад
What do you think about Paradigm CTF? a video will be good.
@andyli
@andyli 2 года назад
Paradigm CTF is great, will look into making a video of it
@erayack
@erayack 2 года назад
@@andyli I guess we can still enter and see the challenges. it would be really great
@sudonoodle1773
@sudonoodle1773 2 года назад
Hi Andy. Are you still doing traditional penetration testing as your day job? Or have you transitioned towards Web3? Like you’ve mentioned in your previous videos, Web3 security is becoming (just as) saturated as traditional pentesting. I’ve been avoiding Web3 because I’m worried it’s just an industry phase… but now I’m not too sure. What are your thoughts? Perhaps a video on this would be great. Love your videos, thanks very much! :)
@andyli
@andyli 2 года назад
Yeah I am still working as a traditional pentester, honestly I am thinking about transitioning though. It is getting saturated in terms of getting a quick buck from these bounties, but long-term it is still going to pay massive dividends. I also used to think web3 it was a fad too due to the scammy nature of the space, but realized there are legit work being done as well.
Далее
Reading Audit Reports - Cally
21:33
Просмотров 3,1 тыс.
Beginner Roadmap to Smart Contract Auditing
28:31
Просмотров 34 тыс.
КОГДА МАМА НАШЛА ТЕБЕ НЕВЕСТУ
00:55
БЕРЕМЕННАЯ БЕЛКА ЗЛИТСЯ#cat
00:11
Просмотров 339 тыс.
Complete Smart Contract Auditing System
24:52
Просмотров 5 тыс.
My First Bounty Award
11:39
Просмотров 9 тыс.
Learn from Reading Audit Reports (Sturdy Report)
18:15
First Month of Bug Hunting
11:54
Просмотров 3,5 тыс.
My Smart Contract Audit Process (Part 1)
17:06
Просмотров 8 тыс.
First Month as a Smart Contract Auditor
8:46
Просмотров 12 тыс.
How to become the #1 Auditor in Web3
8:11
Просмотров 20 тыс.
КОГДА МАМА НАШЛА ТЕБЕ НЕВЕСТУ
00:55