EthSecurity
5.22K subscribers
112 photos
20 files
761 links
Download Telegram
❀6πŸ‘1
Forwarded from Rektoff
Gm Rektoffians!
We’ve prepared an alpha-only web3 security telegram pack so you can always stay up to date with market trends, cool articles and useful groups πŸ‘₯

Add it with the following link:
https://t.me/addlist/b0NZzSm3Q9gxYTMy

And feel free to share your gem channels under this post in case we missed something.

Stay RektoffπŸ˜€
Please open Telegram to view this post
VIEW IN TELEGRAM
🫑5
still stuck using csv? well there’s a new tool for anyone that enjoys rust, parquet, or crypto data…

β„οΈπŸ§ŠcryoπŸ§Šβ„οΈ

you can use cryo to easily extract:
- blocks
- txs
- logs
- call traces
- slot traces
- balance traces
- nonce traces
- code traces
- vm traces

cryo can extract all historical uniswap trades with this command:

cryo logs --topic0 0xc42079f94a6350d7e6235f29174924f928cc2ac818eb64fed8004e115fbcca67

@EthSecurity1
πŸ”₯6πŸ‘2
Differential Fuzzing On Solidity Fixed-Point Libraries link


Pre-deployment Analysis of Smart Contracts -- A Survey link


With Trail to Follow: Measurements of Real-world Non-fungible Token Phishing Attacks on Ethereum. link

@EthSecurity1
πŸ‘3
πŸ‘2❀1πŸ”₯1
Forwarded from Daily Security
What is Caracal?
Caracal is a static analyzer tool over the SIERRA representation for Starknet smart contracts.

What about its Features?
πŸ‘‰Detectors to detect vulnerable Cairo code
πŸ‘‰Printers to report information
πŸ‘‰Taint analysis
πŸ‘‰Data flow analysis framework
πŸ‘‰Easy to run in Scarb projects

Any overview of its detectors?

1) controlled-library-call
Library calls with a user controlled class hash

2) unchecked-l1-handler-from
Detect L1 handlers without from address check

3) reentrancy
Detect when a storage variable is read before an external call and written after

4) unused-events
Events defined but not emitted

5) unused-return
Unused return values

6) unenforced-view
Function has view decorator but modifies state

7) unused-arguments
Unused arguments

8) reentrancy-benign
Detect when a storage variable is written after an external call but not read before

9) reentrancy-events
Detect when an event is emitted after an external call leading to out-of-order events

10) dead-code
Private functions never used


More info on how to install it and its limitations can be found in the repo below πŸ‘‡
https://github.com/crytic/caracal

@ethers_security
❀2πŸ”₯2
Unveiling Transaction Simulation Challenges: Blowfish Case Study by Tiago Assumpcao (Coinspect).

An Empirical Study of Impact of Solidity Compiler Updates on Vulnerabilities in Ethereum Smart Contracts.

Typical vulnerabilities in LSD protocols by kasimonagasaki (Decurity)

@EthSecurity1
πŸ”₯3❀2πŸ‘1
EVM CFG - a fast and accurate CFG generator for EVM bytecode using symbolic stack analysis

CheckTheChain - a ChatGPT plugin that lets AI do blockchain analysis.

Uniswap V3 TWAP: Assessing TWAP Market Risk by Omer Goldberg.

Immunefi Bug Bounty Writeups List by sayan011.

@EthSecurity1
πŸ‘3πŸ”₯3