Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!

11,991 görüntüleme • 9 ay önce •via X (Twitter)

31 Yorum

0xaudron profil fotoğrafı
0xaudron9 ay önce

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Pamphile Roy profil fotoğrafı
Pamphile Roy9 ay önce

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

Haris Ebrat profil fotoğrafı
Haris Ebrat9 ay önce

hackers right now watching Patrick

Patrick Collins profil fotoğrafı
Patrick Collins9 ay önce

Nah, this is a pretty well-documented exploit.

Mate Soos profil fotoğrafı
Mate Soos9 ay önce

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Patrick Collins profil fotoğrafı
Patrick Collins9 ay önce

Yes!!!

0xBreak profil fotoğrafı
0xBreak9 ay önce

I have a wild desire to enter this private key and see what's inside.

Patrick Collins profil fotoğrafı
Patrick Collins9 ay önce

@ZeroNewLif It’s the anvil default key

0xBreak profil fotoğrafı
0xBreak9 ay önce

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

NFT_Dreww.eth profil fotoğrafı
NFT_Dreww.eth9 ay önce

Literally this!!!

invoker🎮 profil fotoğrafı
invoker🎮9 ay önce

wild seeing exploits bridge web2 gaps straight into web3 risk

SKYLINE🥷 profil fotoğrafı
SKYLINE🥷9 ay önce

attack surface feels bigger.

souilos profil fotoğrafı
souilos9 ay önce

Thanks for this, Web3 is nothing without Web2.

Joshua Poddoku profil fotoğrafı
Joshua Poddoku9 ay önce

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

VERITAS PROTOCOL profil fotoğrafı
VERITAS PROTOCOL9 ay önce

The old layers always matter 💯

Tim profil fotoğrafı
Tim9 ay önce

Thanks for the clarity

Jatique P profil fotoğrafı
Jatique P9 ay önce

So we should all learn nextjs now as web3 devs ???

Patrick Collins profil fotoğrafı
Patrick Collins9 ay önce

Noooo - just a reminder to keep your key hygiene up

Stephen Clais profil fotoğrafı
Stephen Clais9 ay önce

🤔

John profil fotoğrafı
John9 ay önce

❤️

Lovro | Smart Contracts & Web3 profil fotoğrafı
Lovro | Smart Contracts & Web38 ay önce

This is a good reminder that attack surfaces extend far beyond smart contracts.

Adarsh 🦀 profil fotoğrafı
Adarsh 🦀9 ay önce

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

Patrick Collins profil fotoğrafı
Patrick Collins9 ay önce

No, you have the same issue no matter what language you write the back end in

Adarsh 🦀 profil fotoğrafı
Adarsh 🦀9 ay önce

Thank You :)

Artur Inspector profil fotoğrafı
Artur Inspector9 ay önce

I think we will write sites with WASM ))) daamn react is literally revealing framework

Dulce profil fotoğrafı
Dulce9 ay önce

PATCH FASTTTT

💥Spartan Steve💥 profil fotoğrafı
💥Spartan Steve💥9 ay önce

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

Lynn profil fotoğrafı
Lynn9 ay önce

react2shell sounds like a nightmare on tap

Pensar profil fotoğrafı
Pensar9 ay önce

Wild times

Triny profil fotoğrafı
Triny9 ay önce

This is nice 💯

Divy Raj profil fotoğrafı
Divy Raj8 ay önce

thats wild gotta be more careful out there

Benzer Videolar