DEF CON 32 - Web2 Meets Web3  Hacking Decentralized Applications - Peiyu Wang

DEF CON 32 - Web2 Meets Web3 Hacking Decentralized Applications - Peiyu Wang

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 24:15

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Web3 DApps face significant security risks due to integration of web2 components and developer knowledge gaps, exposing them to both client and server-side vulnerabilities. 0:00

Key Takeaways:
• Client-side attacks via malicious JavaScript or session hijacking can enable unauthorized transactions, especially in apps with weak wallet connection checks 10:01-10:57.
• Server-side vulnerabilities include gas consumption attacks, transaction race conditions, and missing smart contract validations, leading to fund loss or asset manipulation 13:06-19:46.
• A bridge contract flaw due to missing address validation allowed fake smart contract deposits, resulting in unauthorized token releases 18:10-19:46.
• A lightweight trading app failed to validate token types, enabling scammers to inject fake NFTs and inflate balances via detection of newly active addresses 20:16-21:40.

Understanding web2 security is essential for securing DApps, as many vulnerabilities stem from poor backend design and developer expertise gaps. Hands-on experimentation with small investments is recommended to build foundational skills before pursuing formal audits.

Sources:

  • 0:00 Introduction to speaker and web security context
  • 10:01 Client-side attack vectors and wallet session risks
  • 13:06 Case study on unregistered app with API accepting invalid addresses
  • 18:10 Bridge contract vulnerability due to missing address validation
  • 20:16 Token type

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

um yeah I hope my to can give guys a taste of web security so my name is p wayang I'm a security engineer uh so what I do is uh application P testing uh mostly web stre applications apps and wallet and I also do a smart contract Audits and security research U my past talk at Devcon are in the uh blockchain Village which I talk about uh exporting crypto wallets and uh divice scam ra pools so I outside like work I'm like a def apes and like a minan coin Traders so blockchain and DFS so since the first uh defi summer in 2020 uh the uh the blockchain ecosystem has exceptional growth there's a lot of thing being built and one way to catalyze them is like applications develop tools uh infrastructure and protocols which is the blockchain itself so apps aage and let's talk about applications uh so…