COVIL HACKER

, ! .



-

1 2 2

1

-, Web 2.0. , , . Positive Hack Days 12 .

, , -, DNS hijacking BGP hijacking. , , . , :
, ( );
- ;
, ;
, (, , );
, , .

2022 20 - DNS hijacking BGP hijacking. (Allbrigde, Celer Network, Ribbon Finance, Convex Finance ) . SlowMist, -, 2022 3 ( DNS). DeFi-, .

, DNS hijacking BGP hijacking . :
SSL-;
, , ;
.
, , - (, ).

https://forumupload.ru/uploads/001b/c9/09/2/t459415.png

1.
.

, , . , , .

:
UX- UI- (, MetaMask);
( );
.
, ( vanity address). , .

MetaMask, . MetaMask .

- UX UI MetaMask . MetaMask , ( 10.25.0). (. . 2) , , . , , .

https://forumupload.ru/uploads/001b/c9/09/2/t764364.png

2. MetaMask

. (. . 3) , -, (. . 4).
3.
3.

https://forumupload.ru/uploads/001b/c9/09/2/t359400.png

4. -

View full transaction details MetaMask (. . 2), , : , .

https://forumupload.ru/uploads/001b/c9/09/2/t209515.png

5. View full transaction details

MetaMask. 10.30.4 : .

https://forumupload.ru/uploads/001b/c9/09/2/t385358.png

, ( ),

https://forumupload.ru/uploads/001b/c9/09/2/t145825.png

, . , .

DNS- ( DNS hijacking ), , (), IP-, . , BGP hijacking. IP-, . , DNS-, . , , , . , , , .

, , . , , .

.

Celer Network (cBridge)​
(12.08.2022) -. - . :
Ethereum: 0x2A2aA50450811Ae589847D670cB913dF763318E8 ( Etherscan)
BSC: 0x5895da888Cbf3656D8f51E5Df9FD26E8E131e7CF
Fantom: 0x458f4d7ef4fb1a0e56b36bf7a403df830cfdf972
Polygon: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Avalanche: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Arbitrum: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Astar: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Aurora: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Optimism: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Metis: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
, , , .

17.08.2022 19:25 ( UTC) BGP hijacking. bgplay (. . 5). BGP, . BGP hijacking ( 23:13, . . 6).

https://forumupload.ru/uploads/001b/c9/09/2/t41225.png

6. BGP hijacking

BGP hijacking SlowMist, -.

. crt.sh , cbridge-prod2.celer.network 17.08.2022 19:42:27 18.08.2022 09:10:12. , , BGP hijacking, -. , , ( , ).

22:33:30 17.08.2022 01:17:22 18.08.2022 Ethereum Tornado Cash, 15 , 0xb0f5fa0cd2726844526e3f70e76f54c6d91530dd, , ( Tornado Cash).

Etherscan - , Ethereum, . Vyper. Solidity, dedaub.com. , , cBridge, . send() sendNative(). _addNativeLiquidity, . , , Tenderly Etherscan. , : 0xb0f5fa0cd2726844526e3f70e76f54c6d91530dd.

, 12 - , sendNative() ( ETH) . 37 62 , send() .

0x9c307de6(). , Approve. Etherscan , (, , ). Approve (, ). 0x9c307de6() , . , , .

19.08.2022 Celer Network , , : DNS .

SlowMist 128,4 ETH ( 18.08.2022). SlowMist , , . , .

Mad Meerkat Finance​
Mad Meerkat Finance DNS IP- . , 2 000 000 . , 04.05.2022 19:28. , Cronos. , . . crt.sh , 04.05.2022 19:25 mm.finance. (02.08.2022).

04.05.2022 10:51, 3,5 . rekt.news. , , . . , 4 5 . 6 11 . Mad Meerkat Finance 05.05.2023 , . 6 11 . , DNS- ( ).

- dedaub.com. , . __addLiquidityETH, . Cronoscan . , Tenderly: 0xb3065fe2125c413e973829108f23e872e1db9a6b.

, .

Allbridge​
DNS- Namecheap, Allbridge. CEO Namecheap , , DNS-, . Allbridge , , . , .

rt.sh , 23.06.2022 08:09 app.allbridge.io. C (21.09.2022).

, 12:00, (, ).

(Ethereum, Binance Smart Chain, Polygon), Allbridge. - .

, : .
Allbridge Ethereum​
Ethereum ​
0xBBbD1BbB4f9b936C3604906D7592A644071dE884​
0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884​


Allbridge Binance Smart Chain​
Binance Smart Chain​
0xBBbD1BbB4f9b936C3604906D7592A644071dE884​
0xbbbd2ec2dc8c067b7e0dc403ecae865466d7e884​


Allbridge Polygon​
Polygon​
0xBBbD1BbB4f9b936C3604906D7592A644071dE884​
0xbbbd2139ed16a4075df7c303d8d69e6413f3e884​

0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884 Ethereum 20.06.2022. , , .

, DNS , .

- Allbridge Binance Smart Chain ( 2,5 ) Approve , 0xbbbde5d09e0ac4c32938efa3cbc0cb55d5c7e884. . , . , , - WayBackMachine. (23.06.2022).

, Approve , , allowance USDC. , 0xbbbde5d09e0ac4c32938efa3cbc0cb55d5c7e884 , USDC- 0x32ac4fd012f0d455e5bb9394d0355e571d86f022 (. . 7). , - , Approve: ERC20 BEP20 Approve .

https://forumupload.ru/uploads/001b/c9/09/2/t867820.png

7. USDC, ,

0x624301090700ea1e3c5b5224f89adfae405412c1: Approve 23.06.2022, , ABR. Approve. , , ABR. , allowance ABR (. . 8).

https://forumupload.ru/uploads/001b/c9/09/2/t739801.png

8. ABR

, IP- (app.allbridge.io) , IP- DNS History, SecurityTrails, RiskIQ, VirusTotal, Censys ( 2022 ). , , SafeDNS, : The accuracy of the SafeDNS threat intelligence system is achieved through the companys own technology for automatic categorization of internet resources and one for detection of botnets and malicious sites. To add data to Octopus we also use DNS requests collected via the SafeDNS cloud service, over 1B requests processed daily. By now the company has 180M domains in web crawler index and 1.2B records of passive DNS data.

Ribbon Finance​
DNS- Namecheap, Ribbon Finance. , . 16,5 BTC.

crt.sh , 23.06.2022 06:28 app.ribbon.finance.

(21.09.2022). , . SlowMist, . , Approve .
Ribbon Finance Ethereum​
Ethereum ​
0x65a833afDc250D9d38f8CD9bC2B1E3132dB13B2F​
0x65a8ec2c367a2d60efc1944c6eab614d73453b2f​
.

Convex Finance​
DNS- Namecheap, Convex Finance. , 15,968 cvxCRV 433 CRV. , DNS hijacking convexfinance.com. . crt.sh , 23.06.2022 : convexfinance.com 00:58 wwwconvexfinance.com 01:15.

(20 21 2022), , Convex Finance .

Convex Finance , , , 23.06.2023 23:00 10 .
Convex Finance Ethereum​
Ethereum​
0xf403a2c10b0b9fef8f0d4f931df5d86ad187ae31​
0xF403C135812408BFbE8713b5A23a04b3D48AAE31​
(20.06.2022). , , .
, DNS (, , ).

Allbridge, Ribbon Finance Convex Finance​
Namecheap, . Etherscan -. (0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884), Allbridge. 15 . 20.06.2022 22.06.2022.
Ethereum​

0x8014ae6574cace1f2435a86d4ea0472f466786ae
0x8014fb4882b1f99a3e60aece1d39400560d986ae
0xcf50193c27df08423bfe813676541b2268789332​
CRV Depositor Convex: 0x8014595F2AB54cD7c604B00E9fb932176fDc86Ae
CVX Rewards Convex: 0xCF50b810E57Ac33B91dCF525C6ddd9881B139332​
0xf403a2c10b0b9fef8f0d4f931df5d86ad187ae31​
Convex. Booster: 0xF403C135812408BFbE8713b5A23a04b3D48AAE31​
0x65a8135596ae13c0dd5c17ba1059c61bc42d3b2f
0x65a8e56ee6b549456fd8927db3fa526b8d143b2f​
Ribbon Finance: 0x65a833afDc250D9d38f8CD9bC2B1E3132dB13B2F​
0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884 ( Allbridge)​
Allbridge​
0xbbbd89e4cd6c0ac07f164b84546b6439d415e884​
Allbridge:
0xBBbD1BbB4f9b936C3604906D7592A644071dE884​
0x7d2740418e8dc4f8de88ead063f737b93d58c7a9
0x7d27e89cf5981cf6827a6195928169ebd885c7a9
0xccf4a3a9adf9b2cf594e02e3ef4929dfaa1edd6a
0x917598efb39ccd3271f0f8abf717d1d2bc3399b6
0x685bd1d8747c91151f0b98ea8e5c6275994293af
0x5d3ada4aa5bf6125a091b27ed8cbc94518633643
0x4da2ca63312464f675cb3d04a7a79e5c4f2270f5 0x7b85d24d2d0de912acadeaa019277ee0e7b6209c

, ( ) , Ribbon Finance. , . , . , .

, 0x8014ae6574cace1f2435a86d4ea0472f466786ae 0x8014fb4882b1f99a3e60aece1d39400560d986ae, : . , , -, , Namecheap. .

- Dedaub. , 0xcdc0f019f0ec0a903ca689e2bced3996efc53939 deposit() (. . 9).

https://forumupload.ru/uploads/001b/c9/09/2/t773256.png

9. deposit()

, - , MetaMask. , Ethereum Blockchain Explorer, . , .

https://forumupload.ru/uploads/001b/c9/09/2/t820984.png

10.

́ (201 ETH) 0xcdc0f019f0ec0a903ca689e2bced3996efc53939 Ethereum 24.06.2022 Tornado Cash . 27.06.2022 17,39 ETH Multichain , Binance Smart Chain. Binance Smart Chain Tornado Cash, .

Allbridge 23.06.2022 Polygon (0xbbbd2139ed16a4075df7c303d8d69e6413f3e884), , (. . 11)

https://forumupload.ru/uploads/001b/c9/09/2/t284605.png

11.
- 15-.


1 . CEO deBridge Finance bash- DNS. , :

#!/bin/bash cd /tmp wget -r -k -l 7 -p -E -nc -nv https://$1/ 1>&2 2>/dev/null || true find $1 -type f | grep -v robots.txt | xargs md5sum | md5sum | cut -d\ -f1
#!/bin/bash date >> /tmp/dns_$1.log host $1 | grep address | awk '{print $NF}' | sort | uniq | xargs echo | tee -a /tmp/dns_$1.log > /tmp/dns_new_$1 if [ $? -eq 0 ] then cp /tmp/dns_new_$1 /tmp/dns_$1 else echo 'Resolve ERROR' >> /tmp/dns_$1.log fi cat /tmp/dns_$1

BGP hijacking: DNS- , IPv6 IPv4 . , IPv6 IPv4, , , IPv6 IPv4, IPv6 ( ). BGP hijacking IPv4.

https://forumupload.ru/uploads/001b/c9/09/2/t59538.png

12. - IPv6 IPv4 Wget IPv6

, BGP hijacking, DNS hijacking. -, - IPv6 IPv4 ( DNS hijacking DNS- IPv4) (. . 12). -, - --no-dns-cache DNS.


, DNS-, . IPv6 IPv4. .. 2 : IPv6, - IPv4 ( wget --inet4-only --inet6-only).

, DNS-, CAA-. , CAA- account, SSL- (. RFC6844). ( CAA-). BGP hijacking.

DNS-, . , SOC-, , BGP hijacking, DNS. .

. . DNS , ( .. ) DNS-. , itnan.ru DNS, DNS- (77.88.8.8) dig, 20 (. . 13).

, DNS DNS ( ). :
TTL DNS;
, DNS.
, DNS hijacking, . - DNS, . , ( ) . . DNS . TTL DNS (, ), . , DNS-, TTL.

, , . , DNS cache poisoning; . , 2019 RouterOS 6.45.6, MikroTik. , DNSSEC.

: - ( DOMAIN ). JSON .

wget -O DOMAIN -nv "https://crt.sh/?CN=DOMAIN&output=json" 1>&2 2>/dev/null | md5sum DOMAIN >DOMAIN.md5

:

wget -O DOMAIN -nv "https://crt.sh/?CN=DOMAIN&output=json" 1>&2 2>/dev/null | md5sum DOMAIN|md5sum -c DOMAIN.md5

. -, crt.sh . -, , 2 . precertificate , precertificate, leaf certificate. , CT Logs.

, HTTPS. . , . , CVE-2014-0160 CVE-2019-9621 .. ( - , - - ). . (- ), . , . . .

aka shanker
C Positive Technologies

0

2

семе156.3PERFBettШирвкадрлиниHeinXVIIGOLDБилаВласзолоUndeScotрукаNortШапоМаксЛесюКочипокр
ЕмелXVIIЕлкиВиноSympBrowармиУльяЯковстекавтоSchuЮскеЛивиПолфXVIIКобрИллюБориArthDionRemi
КурбФинкБуткОзерСкорLindЛаврОвсяФилиБутиElegкнопежегЖидкБрасиздаГолоМаевRossэнтусоздXVII
ФедоФранСталКомаПанкЗимеГубкЧайкAniaVashMircNeumИконЛапшФомиПелеCrazJeweКовасчассчитПоме
самоImpoСалмDaviZone9103полуSkudZoneЦиркврачСлавКаспLinuZoneфакуБутяЕвгеиллюZonesituБусы
ZoneтворZoneСтепКузьRossТункпродKOSSхоротеррCoreзолоWindкартСкреWillSur-2804ELITЧестРосс
М-32ARAGгодаВьетTentBossLouvАртиинстGlenстекMiniмагнWindШириWindязыкProWChouBeliЛевеЛитР
детеКрасАнтоЛитРCharЛитРЛитРJaneЛитРтеатУварОмелГурвКузнСерыСодеВалеЕргиДемеЛучшGramспек
ШиршMORGрозыPoweБатрХоккVIIILefeГузеМураДьячЧернСартШашуМакнМихеКузьСолоhousМироПимеНата
BriaМартAlcoEoinИллюMillрепеKOSSKOSSKOSSХамиAnotСмирАВВеокруПаншTimeOasiРусеDonaKOKOавто
tuchkasШтолиллю

0



|