Загрузка видео...

Не удалось загрузить видео

На главную

You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!

11,991 просмотров • 9 месяцев назад •via X (Twitter)

Комментарии: 31

Фото профиля 0xaudron
0xaudron9 месяцев назад

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Фото профиля Pamphile Roy
Pamphile Roy9 месяцев назад

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

Фото профиля Haris Ebrat
Haris Ebrat9 месяцев назад

hackers right now watching Patrick

Фото профиля Patrick Collins
Patrick Collins9 месяцев назад

Nah, this is a pretty well-documented exploit.

Фото профиля Mate Soos
Mate Soos9 месяцев назад

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Фото профиля Patrick Collins
Patrick Collins9 месяцев назад

Yes!!!

Фото профиля 0xBreak
0xBreak9 месяцев назад

I have a wild desire to enter this private key and see what's inside.

Фото профиля Patrick Collins
Patrick Collins9 месяцев назад

@ZeroNewLif It’s the anvil default key

Фото профиля 0xBreak
0xBreak9 месяцев назад

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

Фото профиля NFT_Dreww.eth
NFT_Dreww.eth9 месяцев назад

Literally this!!!

Фото профиля invoker🎮
invoker🎮9 месяцев назад

wild seeing exploits bridge web2 gaps straight into web3 risk

Фото профиля SKYLINE🥷
SKYLINE🥷9 месяцев назад

attack surface feels bigger.

Фото профиля souilos
souilos9 месяцев назад

Thanks for this, Web3 is nothing without Web2.

Фото профиля Joshua Poddoku
Joshua Poddoku9 месяцев назад

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

Фото профиля VERITAS PROTOCOL
VERITAS PROTOCOL9 месяцев назад

The old layers always matter 💯

Фото профиля Tim
Tim9 месяцев назад

Thanks for the clarity

Фото профиля Jatique P
Jatique P9 месяцев назад

So we should all learn nextjs now as web3 devs ???

Фото профиля Patrick Collins
Patrick Collins9 месяцев назад

Noooo - just a reminder to keep your key hygiene up

Фото профиля Stephen Clais
Stephen Clais9 месяцев назад

🤔

Фото профиля John
John9 месяцев назад

❤️

Фото профиля Lovro | Smart Contracts & Web3
Lovro | Smart Contracts & Web38 месяцев назад

This is a good reminder that attack surfaces extend far beyond smart contracts.

Фото профиля Adarsh 🦀
Adarsh 🦀9 месяцев назад

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

Фото профиля Patrick Collins
Patrick Collins9 месяцев назад

No, you have the same issue no matter what language you write the back end in

Фото профиля Adarsh 🦀
Adarsh 🦀9 месяцев назад

Thank You :)

Фото профиля Artur Inspector
Artur Inspector9 месяцев назад

I think we will write sites with WASM ))) daamn react is literally revealing framework

Фото профиля Dulce
Dulce9 месяцев назад

PATCH FASTTTT

Фото профиля 💥Spartan Steve💥
💥Spartan Steve💥9 месяцев назад

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

Фото профиля Lynn
Lynn9 месяцев назад

react2shell sounds like a nightmare on tap

Фото профиля Pensar
Pensar9 месяцев назад

Wild times

Фото профиля Triny
Triny9 месяцев назад

This is nice 💯

Фото профиля Divy Raj
Divy Raj8 месяцев назад

thats wild gotta be more careful out there

Похожие видео