-, Web 2.0. , , . Positive Hack Days 12 .
, , -, DNS hijacking BGP hijacking. , , . , :
, ( );
- ;
, ;
, (, , );
, , .
2022 20 - DNS hijacking BGP hijacking. (Allbrigde, Celer Network, Ribbon Finance, Convex Finance ) . SlowMist, -, 2022 3 ( DNS). DeFi-, .
, DNS hijacking BGP hijacking . :
SSL-;
, , ;
.
, , - (, ).
1.
.
, , . , , .
:
UX- UI- (, MetaMask);
( );
.
, ( vanity address). , .
MetaMask, . MetaMask .
- UX UI MetaMask . MetaMask , ( 10.25.0). (. . 2) , , . , , .
2. MetaMask
. (. . 3) , -, (. . 4).
3.
3.
4. -
View full transaction details MetaMask (. . 2), , : , .
5. View full transaction details
MetaMask. 10.30.4 : .
, ( ),
, . , .
DNS- ( DNS hijacking ), , (), IP-, . , BGP hijacking. IP-, . , DNS-, . , , , . , , , .
, , . , , .
.
Celer Network (cBridge)
(12.08.2022) -. - . :
Ethereum: 0x2A2aA50450811Ae589847D670cB913dF763318E8 ( Etherscan)
BSC: 0x5895da888Cbf3656D8f51E5Df9FD26E8E131e7CF
Fantom: 0x458f4d7ef4fb1a0e56b36bf7a403df830cfdf972
Polygon: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Avalanche: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Arbitrum: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Astar: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
Aurora: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Optimism: 0x9c8b72f0d43ba23b96b878f1c1f75edc2beec9f9
Metis: 0x9c8B72f0D43BA23B96B878F1c1F75EdC2Beec9F9
, , , .
17.08.2022 19:25 ( UTC) BGP hijacking. bgplay (. . 5). BGP, . BGP hijacking ( 23:13, . . 6).
6. BGP hijacking
BGP hijacking SlowMist, -.
. crt.sh , cbridge-prod2.celer.network 17.08.2022 19:42:27 18.08.2022 09:10:12. , , BGP hijacking, -. , , ( , ).
22:33:30 17.08.2022 01:17:22 18.08.2022 Ethereum Tornado Cash, 15 , 0xb0f5fa0cd2726844526e3f70e76f54c6d91530dd, , ( Tornado Cash).
Etherscan - , Ethereum, . Vyper. Solidity, dedaub.com. , , cBridge, . send() sendNative(). _addNativeLiquidity, . , , Tenderly Etherscan. , : 0xb0f5fa0cd2726844526e3f70e76f54c6d91530dd.
, 12 - , sendNative() ( ETH) . 37 62 , send() .
0x9c307de6(). , Approve. Etherscan , (, , ). Approve (, ). 0x9c307de6() , . , , .
19.08.2022 Celer Network , , : DNS .
SlowMist 128,4 ETH ( 18.08.2022). SlowMist , , . , .
Mad Meerkat Finance
Mad Meerkat Finance DNS IP- . , 2 000 000 . , 04.05.2022 19:28. , Cronos. , . . crt.sh , 04.05.2022 19:25 mm.finance. (02.08.2022).
04.05.2022 10:51, 3,5 . rekt.news. , , . . , 4 5 . 6 11 . Mad Meerkat Finance 05.05.2023 , . 6 11 . , DNS- ( ).
- dedaub.com. , . __addLiquidityETH, . Cronoscan . , Tenderly: 0xb3065fe2125c413e973829108f23e872e1db9a6b.
, .
Allbridge
DNS- Namecheap, Allbridge. CEO Namecheap , , DNS-, . Allbridge , , . , .
rt.sh , 23.06.2022 08:09 app.allbridge.io. C (21.09.2022).
, 12:00, (, ).
(Ethereum, Binance Smart Chain, Polygon), Allbridge. - .
, : .
Allbridge Ethereum
Ethereum
0xBBbD1BbB4f9b936C3604906D7592A644071dE884
0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884
Allbridge Binance Smart Chain
Binance Smart Chain
0xBBbD1BbB4f9b936C3604906D7592A644071dE884
0xbbbd2ec2dc8c067b7e0dc403ecae865466d7e884
Allbridge Polygon
Polygon
0xBBbD1BbB4f9b936C3604906D7592A644071dE884
0xbbbd2139ed16a4075df7c303d8d69e6413f3e884
0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884 Ethereum 20.06.2022. , , .
, DNS , .
- Allbridge Binance Smart Chain ( 2,5 ) Approve , 0xbbbde5d09e0ac4c32938efa3cbc0cb55d5c7e884. . , . , , - WayBackMachine. (23.06.2022).
, Approve , , allowance USDC. , 0xbbbde5d09e0ac4c32938efa3cbc0cb55d5c7e884 , USDC- 0x32ac4fd012f0d455e5bb9394d0355e571d86f022 (. . 7). , - , Approve: ERC20 BEP20 Approve .
7. USDC, ,
0x624301090700ea1e3c5b5224f89adfae405412c1: Approve 23.06.2022, , ABR. Approve. , , ABR. , allowance ABR (. . 8).
8. ABR
, IP- (app.allbridge.io) , IP- DNS History, SecurityTrails, RiskIQ, VirusTotal, Censys ( 2022 ). , , SafeDNS, : The accuracy of the SafeDNS threat intelligence system is achieved through the companys own technology for automatic categorization of internet resources and one for detection of botnets and malicious sites. To add data to Octopus we also use DNS requests collected via the SafeDNS cloud service, over 1B requests processed daily. By now the company has 180M domains in web crawler index and 1.2B records of passive DNS data.
Ribbon Finance
DNS- Namecheap, Ribbon Finance. , . 16,5 BTC.
crt.sh , 23.06.2022 06:28 app.ribbon.finance.
(21.09.2022). , . SlowMist, . , Approve .
Ribbon Finance Ethereum
Ethereum
0x65a833afDc250D9d38f8CD9bC2B1E3132dB13B2F
0x65a8ec2c367a2d60efc1944c6eab614d73453b2f
.
Convex Finance
DNS- Namecheap, Convex Finance. , 15,968 cvxCRV 433 CRV. , DNS hijacking convexfinance.com. . crt.sh , 23.06.2022 : convexfinance.com 00:58 wwwconvexfinance.com 01:15.
(20 21 2022), , Convex Finance .
Convex Finance , , , 23.06.2023 23:00 10 .
Convex Finance Ethereum
Ethereum
0xf403a2c10b0b9fef8f0d4f931df5d86ad187ae31
0xF403C135812408BFbE8713b5A23a04b3D48AAE31
(20.06.2022). , , .
, DNS (, , ).
Allbridge, Ribbon Finance Convex Finance
Namecheap, . Etherscan -. (0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884), Allbridge. 15 . 20.06.2022 22.06.2022.
Ethereum
0x8014ae6574cace1f2435a86d4ea0472f466786ae
0x8014fb4882b1f99a3e60aece1d39400560d986ae
0xcf50193c27df08423bfe813676541b2268789332
CRV Depositor Convex: 0x8014595F2AB54cD7c604B00E9fb932176fDc86Ae
CVX Rewards Convex: 0xCF50b810E57Ac33B91dCF525C6ddd9881B139332
0xf403a2c10b0b9fef8f0d4f931df5d86ad187ae31
Convex. Booster: 0xF403C135812408BFbE8713b5A23a04b3D48AAE31
0x65a8135596ae13c0dd5c17ba1059c61bc42d3b2f
0x65a8e56ee6b549456fd8927db3fa526b8d143b2f
Ribbon Finance: 0x65a833afDc250D9d38f8CD9bC2B1E3132dB13B2F
0xbbbd2ed360dac9f6e005fc6a4398d7d6beabe884 ( Allbridge)
Allbridge
0xbbbd89e4cd6c0ac07f164b84546b6439d415e884
Allbridge:
0xBBbD1BbB4f9b936C3604906D7592A644071dE884
0x7d2740418e8dc4f8de88ead063f737b93d58c7a9
0x7d27e89cf5981cf6827a6195928169ebd885c7a9
0xccf4a3a9adf9b2cf594e02e3ef4929dfaa1edd6a
0x917598efb39ccd3271f0f8abf717d1d2bc3399b6
0x685bd1d8747c91151f0b98ea8e5c6275994293af
0x5d3ada4aa5bf6125a091b27ed8cbc94518633643
0x4da2ca63312464f675cb3d04a7a79e5c4f2270f5 0x7b85d24d2d0de912acadeaa019277ee0e7b6209c
, ( ) , Ribbon Finance. , . , . , .
, 0x8014ae6574cace1f2435a86d4ea0472f466786ae 0x8014fb4882b1f99a3e60aece1d39400560d986ae, : . , , -, , Namecheap. .
- Dedaub. , 0xcdc0f019f0ec0a903ca689e2bced3996efc53939 deposit() (. . 9).
9. deposit()
, - , MetaMask. , Ethereum Blockchain Explorer, . , .
10.
́ (201 ETH) 0xcdc0f019f0ec0a903ca689e2bced3996efc53939 Ethereum 24.06.2022 Tornado Cash . 27.06.2022 17,39 ETH Multichain , Binance Smart Chain. Binance Smart Chain Tornado Cash, .
Allbridge 23.06.2022 Polygon (0xbbbd2139ed16a4075df7c303d8d69e6413f3e884), , (. . 11)
11.
- 15-.
1 . CEO deBridge Finance bash- DNS. , :
#!/bin/bash cd /tmp wget -r -k -l 7 -p -E -nc -nv https://$1/ 1>&2 2>/dev/null || true find $1 -type f | grep -v robots.txt | xargs md5sum | md5sum | cut -d\ -f1
#!/bin/bash date >> /tmp/dns_$1.log host $1 | grep address | awk '{print $NF}' | sort | uniq | xargs echo | tee -a /tmp/dns_$1.log > /tmp/dns_new_$1 if [ $? -eq 0 ] then cp /tmp/dns_new_$1 /tmp/dns_$1 else echo 'Resolve ERROR' >> /tmp/dns_$1.log fi cat /tmp/dns_$1
BGP hijacking: DNS- , IPv6 IPv4 . , IPv6 IPv4, , , IPv6 IPv4, IPv6 ( ). BGP hijacking IPv4.
12. - IPv6 IPv4 Wget IPv6
, BGP hijacking, DNS hijacking. -, - IPv6 IPv4 ( DNS hijacking DNS- IPv4) (. . 12). -, - --no-dns-cache DNS.
, DNS-, . IPv6 IPv4. .. 2 : IPv6, - IPv4 ( wget --inet4-only --inet6-only).
, DNS-, CAA-. , CAA- account, SSL- (. RFC6844). ( CAA-). BGP hijacking.
DNS-, . , SOC-, , BGP hijacking, DNS. .
. . DNS , ( .. ) DNS-. , itnan.ru DNS, DNS- (77.88.8.8) dig, 20 (. . 13).
, DNS DNS ( ). :
TTL DNS;
, DNS.
, DNS hijacking, . - DNS, . , ( ) . . DNS . TTL DNS (, ), . , DNS-, TTL.
, , . , DNS cache poisoning; . , 2019 RouterOS 6.45.6, MikroTik. , DNSSEC.
: - ( DOMAIN ). JSON .
wget -O DOMAIN -nv "https://crt.sh/?CN=DOMAIN&output=json" 1>&2 2>/dev/null | md5sum DOMAIN >DOMAIN.md5
:
wget -O DOMAIN -nv "https://crt.sh/?CN=DOMAIN&output=json" 1>&2 2>/dev/null | md5sum DOMAIN|md5sum -c DOMAIN.md5
. -, crt.sh . -, , 2 . precertificate , precertificate, leaf certificate. , CT Logs.
, HTTPS. . , . , CVE-2014-0160 CVE-2019-9621 .. ( - , - - ). . (- ), . , . . .
aka shanker
C Positive Technologies