正在加载视频...

视频加载失败

You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!

11,991 次观看 • 9 个月前 •via X (Twitter)

31 条评论

0xaudron 的头像
0xaudron9 个月前

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Pamphile Roy 的头像
Pamphile Roy9 个月前

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

Haris Ebrat 的头像
Haris Ebrat9 个月前

hackers right now watching Patrick

Patrick Collins 的头像
Patrick Collins9 个月前

Nah, this is a pretty well-documented exploit.

Mate Soos 的头像
Mate Soos9 个月前

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Patrick Collins 的头像
Patrick Collins9 个月前

Yes!!!

0xBreak 的头像
0xBreak9 个月前

I have a wild desire to enter this private key and see what's inside.

Patrick Collins 的头像
Patrick Collins9 个月前

@ZeroNewLif It’s the anvil default key

0xBreak 的头像
0xBreak9 个月前

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

NFT_Dreww.eth 的头像
NFT_Dreww.eth9 个月前

Literally this!!!

invoker🎮 的头像
invoker🎮9 个月前

wild seeing exploits bridge web2 gaps straight into web3 risk

SKYLINE🥷 的头像
SKYLINE🥷9 个月前

attack surface feels bigger.

souilos 的头像
souilos9 个月前

Thanks for this, Web3 is nothing without Web2.

Joshua Poddoku 的头像
Joshua Poddoku9 个月前

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

VERITAS PROTOCOL 的头像
VERITAS PROTOCOL9 个月前

The old layers always matter 💯

Tim 的头像
Tim9 个月前

Thanks for the clarity

Jatique P 的头像
Jatique P9 个月前

So we should all learn nextjs now as web3 devs ???

Patrick Collins 的头像
Patrick Collins9 个月前

Noooo - just a reminder to keep your key hygiene up

Stephen Clais 的头像
Stephen Clais9 个月前

🤔

John 的头像
John9 个月前

❤️

Lovro | Smart Contracts & Web3 的头像
Lovro | Smart Contracts & Web38 个月前

This is a good reminder that attack surfaces extend far beyond smart contracts.

Adarsh 🦀 的头像
Adarsh 🦀9 个月前

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

Patrick Collins 的头像
Patrick Collins9 个月前

No, you have the same issue no matter what language you write the back end in

Adarsh 🦀 的头像
Adarsh 🦀9 个月前

Thank You :)

Artur Inspector 的头像
Artur Inspector9 个月前

I think we will write sites with WASM ))) daamn react is literally revealing framework

Dulce 的头像
Dulce9 个月前

PATCH FASTTTT

💥Spartan Steve💥 的头像
💥Spartan Steve💥9 个月前

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

Lynn 的头像
Lynn9 个月前

react2shell sounds like a nightmare on tap

Pensar 的头像
Pensar9 个月前

Wild times

Triny 的头像
Triny9 个月前

This is nice 💯

Divy Raj 的头像
Divy Raj8 个月前

thats wild gotta be more careful out there

相关视频