RSS Amplifier

Blog

h0wl's blog

Application Security | Vulnerability Research | Fuzzing | Browser Security | Smart Contract Security | Blockchain Security | Penetration Testing

h0wl.substack.comSource feed ↗6 posts

Dormant Last read · last published · next check
Read 6 days ago and current, but nothing has been published for 2 years.

Written by

Latest posts

SolChat Messages Insecure Encryption Method

The SolChat app stored its encryption key and implemented symmetric encryption logic client-side. This means anyone could decrypt every message sent and stored on the Solana blockchain.

New Bitcoin City Stored Cross-Site Scripting (XSS) in Mentions

Another stored XSS vulnerability in NBC that could result in draining user wallets, performing unauthorised transactions with the possibility to spread across the whole platform.

New Bitcoin City bypassing the top 100 restriction to post images

New Bitcoin City SocialFi app allows to make public posts but images can be uploaded only by the top 100 users, at least in theory.

Wormable Stored Cross-Site Scripting (XSS) in Alpha (New Bitcoin City)

A vulnerability in Alpha SocialFi app existed that could result in draining user wallets, performing unauthorised transactions with the possibility to easily spread across the whole platform.

Chat Room Messages Leak on Friend.tech

Accessing the most recent message sent to each of the chat rooms a particular user is part of is open to anyone. Ownership of shares or even an account within the app is not required.

The importance of Web UI security in decentralised applications

Abusing front-end to trick users into performing unintended interactions with the smart contract