Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!

11,991 Aufrufe • vor 9 Monaten •via X (Twitter)

31 Kommentare

Profilbild von 0xaudron
0xaudronvor 9 Monaten

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Profilbild von Pamphile Roy
Pamphile Royvor 9 Monaten

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

Profilbild von Haris Ebrat
Haris Ebratvor 9 Monaten

hackers right now watching Patrick

Profilbild von Patrick Collins
Patrick Collinsvor 9 Monaten

Nah, this is a pretty well-documented exploit.

Profilbild von Mate Soos
Mate Soosvor 9 Monaten

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Profilbild von Patrick Collins
Patrick Collinsvor 9 Monaten

Yes!!!

Profilbild von 0xBreak
0xBreakvor 9 Monaten

I have a wild desire to enter this private key and see what's inside.

Profilbild von Patrick Collins
Patrick Collinsvor 9 Monaten

@ZeroNewLif It’s the anvil default key

Profilbild von 0xBreak
0xBreakvor 9 Monaten

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

Profilbild von NFT_Dreww.eth
NFT_Dreww.ethvor 9 Monaten

Literally this!!!

Profilbild von invoker🎮
invoker🎮vor 9 Monaten

wild seeing exploits bridge web2 gaps straight into web3 risk

Profilbild von SKYLINE🥷
SKYLINE🥷vor 9 Monaten

attack surface feels bigger.

Profilbild von souilos
souilosvor 9 Monaten

Thanks for this, Web3 is nothing without Web2.

Profilbild von Joshua Poddoku
Joshua Poddokuvor 9 Monaten

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

Profilbild von VERITAS PROTOCOL
VERITAS PROTOCOLvor 9 Monaten

The old layers always matter 💯

Profilbild von Tim
Timvor 9 Monaten

Thanks for the clarity

Profilbild von Jatique P
Jatique Pvor 9 Monaten

So we should all learn nextjs now as web3 devs ???

Profilbild von Patrick Collins
Patrick Collinsvor 9 Monaten

Noooo - just a reminder to keep your key hygiene up

Profilbild von Stephen Clais
Stephen Claisvor 9 Monaten

🤔

Profilbild von John
Johnvor 9 Monaten

❤️

Profilbild von Lovro | Smart Contracts & Web3
Lovro | Smart Contracts & Web3vor 8 Monaten

This is a good reminder that attack surfaces extend far beyond smart contracts.

Profilbild von Adarsh 🦀
Adarsh 🦀vor 9 Monaten

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

Profilbild von Patrick Collins
Patrick Collinsvor 9 Monaten

No, you have the same issue no matter what language you write the back end in

Profilbild von Adarsh 🦀
Adarsh 🦀vor 9 Monaten

Thank You :)

Profilbild von Artur Inspector
Artur Inspectorvor 9 Monaten

I think we will write sites with WASM ))) daamn react is literally revealing framework

Profilbild von Dulce
Dulcevor 9 Monaten

PATCH FASTTTT

Profilbild von 💥Spartan Steve💥
💥Spartan Steve💥vor 9 Monaten

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

Profilbild von Lynn
Lynnvor 9 Monaten

react2shell sounds like a nightmare on tap

Profilbild von Pensar
Pensarvor 9 Monaten

Wild times

Profilbild von Triny
Trinyvor 9 Monaten

This is nice 💯

Profilbild von Divy Raj
Divy Rajvor 8 Monaten

thats wild gotta be more careful out there

Ähnliche Videos