Learn Smart Contract Auditing 2023

Поделиться
HTML-код
  • Опубликовано: 4 июл 2024
  • Discussing how to get into Smart Contract Auditing and Web3 Security with Tyrese Tetteh and Amaechi Okolobi - Chainlink Developer Advocates and Students at Brunel University.
    Links:
    code4rena.com/
    secureum.substack.com/
    yacademy.dev/
    spearbit.com/
    Full podcast: • Q&A - Getting into Web...

Комментарии • 22

  • @ArjunJagadeeshV
    @ArjunJagadeeshV Год назад +4

    Thanks for the generous knowledge, Andy....

  • @manav2003
    @manav2003 Год назад +2

    Great knowledge 😍

  • @MichelLedig
    @MichelLedig Год назад +1

    just subscribed, thanks for sharing your journey man

  • @MoCrits
    @MoCrits Год назад +1

    You are very helpful, i am a test automation engineer (QA). Do you think quality control is a helpful background for being an auditor. I am being very calculative before making such transition.

    • @MoCrits
      @MoCrits Год назад

      Your background is penetration testing. So do you think Smart contract auditing is more QA related or cyber security related in your opinion.

    • @andyli
      @andyli  Год назад

      I imagine you would be writing a lot of unit tests day to day? That is a big part of auditing. The thought process from pentesting carried over, ie. attackers mindset.
      Generally I would say this field is still very early and if you have a technical background you shouldn't have too much issues getting started.

    • @MoCrits
      @MoCrits Год назад

      @@andyli thansk, for replying. You know that can be a great video idea alot of people are very careful when transition ing. You can rank backgrounds and how they be helpful for auditing.

  • @mdsathees3747
    @mdsathees3747 Год назад +2

    Is automation tools ( slither, mythril) help us during audit?

    • @andyli
      @andyli  Год назад

      It can catch some low hanging fruit issues, but no serious bugs. (Developers will also usually run them and fix any issues before the audit)

    • @mdsathees3747
      @mdsathees3747 Год назад

      @@andyli Thank you.

    • @mdsathees3747
      @mdsathees3747 Год назад

      Do you have any methodologies to check the vulnerability in automation way?
      Since we have stipulated timeline for auditing, automation could save some time.

    • @andyli
      @andyli  Год назад

      @@mdsathees3747 yeah you can make a custom script. Check c4udit on github

    • @mdsathees3747
      @mdsathees3747 Год назад

      @@andyli thanks 🙏

  • @KundanKumar-uj2in
    @KundanKumar-uj2in Год назад +1

    Hi I am new here started ethernaut complete 14 challenges.. what should I do after ethernaut

    • @andyli
      @andyli  Год назад

      go through this github.com/x676f64/secureum-mind_map

    • @KundanKumar-uj2in
      @KundanKumar-uj2in Год назад

      @@andyli thanks 🌻

  • @hari17130
    @hari17130 Год назад

    Why do we learn when there's no monetary benefits for this and there are existing automation tools for this?
    PS: I'm new to Web3

    • @andyli
      @andyli  Год назад +2

      Automation can only find a small proportion of low hanging fruit issues. Learning manual audit can land you a job paying 150-300k

    • @hari17130
      @hari17130 Год назад

      @@andyli Thanks for replying back! See you soon on the leaderboard! 😁