Тёмный
No video :(

Unhacked CTF - Reaper 

Andy Li
Подписаться 13 тыс.
Просмотров 3,6 тыс.
50% 1

Recreating a 1.7M smart contract hack with the Reaper challenge from Unhacked CTF - based on the Reaper Farm hack that occurred in Aug 2022.
Links:
unhackedctf.su...
github.com/and...

Опубликовано:

 

4 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 37   
@Studiom44
@Studiom44 2 года назад
Please keep making these Andy. They're so invaluable for someone like me trying to understand this area of security.
@andyli
@andyli 2 года назад
Thanks a lot! 🇳🇿🥝
@cowsecurity
@cowsecurity 2 года назад
i've joined code arena as a warden , still havent found any issue yet, I'm trying to use code arena to get some money to buy a decent laptop (current one is just 2011 trash) so i thought it would be easy money in auditing. but ive been proven wrong still havent found any bug so far . I wont give up tho. Great videos!!!
@andyli
@andyli 2 года назад
keep it up, it will come in time!
@droneblaster1665
@droneblaster1665 2 года назад
Amazing video... It looks easy when you code the exploit. But we all know the toughest part was the audit part of it...
@andyli
@andyli 2 года назад
Thanks! It gets easier with time
@mujtabaaltayib7417
@mujtabaaltayib7417 2 года назад
You are making the road map for me, I don't know how to thank you
@andyli
@andyli 2 года назад
You are most welcome
@sye3193
@sye3193 2 года назад
Thank you so much Andy, please make tips and recommendations video too on web3 security, your content is amazing !
@andyli
@andyli 2 года назад
Thanks! Will do more web3 security videos
@noname5046
@noname5046 2 года назад
You are making a great content. Hope the more people would get involved into web3 and smart contract security in particular the more subscribers your channel will get
@andyli
@andyli 2 года назад
Thanks, appreciate it!
@nathantice-officialchannel7358
Love how you pick apart anomalies
@validyor
@validyor 2 года назад
Andy, I love your content which I consider as being a public good for the whole blockchain ecosystem! To get the current list of all holders of a given token (here the rfDAI), I use python, fetch the api of Covalent and parse the result. I've learned the theory from almost all available resources online but now I want to start practicing. If I should select only one option, what would you recommend to focus on between Truffle, Hardhat, Brownie and Foundry? The language doesn't matter, but I want something practical. Thank you!
@andyli
@andyli 2 года назад
Thanks, good idea using python. I was hoping there was a way in the block explorer itself ☹️ I would recommend Foundry, a lot of security folks seem to be moving to it. Writing tests in Solidity is the best part. Also, I hate JavaScript
@internetkids5813
@internetkids5813 2 года назад
Great video. Thanks
@andyli
@andyli 2 года назад
Thanks
@danielcawley1051
@danielcawley1051 2 года назад
Hey Andy, you're content is awesome! I want to start doing code4rena audit contests, I've gone through all of d-squared's ethernaut videos and a couple months ago I completed the python full stack solidity course on freecodecamp by patrick collins. Would it be worth it to complete some damn vulnerable defi or should I get some experience by participating in the contests?
@andyli
@andyli 2 года назад
Go through the secureum materials too, then start participating in audits and reading past audit reports
@jt3660
@jt3660 2 года назад
Thanks for your gteat video
@andyli
@andyli 2 года назад
No worries!
@bertrandfossung1216
@bertrandfossung1216 2 года назад
Please keep solving more CTF challenges . These are really eye openers for me
@andyli
@andyli 2 года назад
yeah will do!
@luce36
@luce36 Год назад
Amazing!
@andyli
@andyli Год назад
Thanks!
@Jansen-Moreira
@Jansen-Moreira 2 года назад
Hey Andy, could you make a Video or just give a quick overview on how you start your contests? You said in one of your videos that you usually spend 3h per content, but I'm taking this time just to get the context of the contest. I don't know if you already talked about it, sorry if you did, but I'm worried about my performance at c4. I'm taking several hours just to take notes on every function of the contest's contracts. Could you talk a little bit about how you start every challenge? If you take notes about everything or just read, and stuff like that. I know it depends on how you work, but it could help me find a way out of it. However, thanks for your content. I started now into c4. You helped me a lot =)
@andyli
@andyli 2 года назад
Understanding the code base fully is an area I also still find challenging, perhaps due to time constraints? I have heard a few top auditors talk about reading code from the top down (cmichel, gpersoon), ie read the base class contract first before reading the derived class contract, so that is what I have been doing as well. A few tools that help in that regard: UML tool for Solidity contracts: github.com/naddison36/sol2uml Visualize function call graphs: github.com/ConsenSys/surya I think speed will come in time as you get familiar with the different types of code bases and read more audit reports. Hope that helps =)
@Jansen-Moreira
@Jansen-Moreira 2 года назад
​@@andyli Thanks for the answer! I checked the links and they seem awesome! I will read more reports and maybe do a checklist with common bugs to speed up my reading skills. Thanks for your support, your videos helped me a lot, mainly when you give an overview of past reports, they are fantastic =)
@sanvidpathak6214
@sanvidpathak6214 Год назад
you could run the addresses through checksum function
@andyli
@andyli Год назад
Still need to manually write a script for that right?
@priteshpatil5363
@priteshpatil5363 2 года назад
1st viewer 😌
@andyli
@andyli 2 года назад
🥳
@matthewlee112
@matthewlee112 2 года назад
Now you just need to find these contracts first
@andyli
@andyli 2 года назад
Blackhat but pretend to be whitehat when caught 😂
@nathantice-officialchannel7358
Why not double audit? 2 teams versus 1
@nathantice-officialchannel7358
Outside of in-house
@andyli
@andyli Год назад
Yeah some are auditing as a team on code4rena
Далее
My CV - Getting a JOB as a Smart Contract Auditor
18:58
لدي بط عالق في أذني😰🐤👂
00:17
Просмотров 1,8 млн
small vs big heart 💖 #tiktok
00:13
Просмотров 4,6 млн
Web3 Security Hangout: Hake, Pashov & Andy
1:18:56
Просмотров 3 тыс.
LIVE STREAM solving offsec BOX | OSCP exam preparation
53:20
Learning Resources for Web3 Devs and Auditors
5:04
Просмотров 1,7 тыс.
لدي بط عالق في أذني😰🐤👂
00:17
Просмотров 1,8 млн