BHIS | Getting Started in Blockchain Security and Smart Contract Auditing | Beau Bullock

Поделиться
HTML-код
  • Опубликовано: 7 июл 2024
  • Join us in the Black Hills InfoSec Discord server here: / discord to keep the security conversation going!
    Learn breaching the cloud with Beau Bullock from Antisyphon
    Training: www.antisyphontraining.com/br...
    0:00:00 - PreShow Banter™ - Beau Has a Fan Club
    0:32:39 - FEATURE PRESENTATION: Getting Started in Blockchain Security and Smart Contract Auditing
    0:36:39 - Roadmap
    0:37:51 - Why Blockchain Security
    0:39:21 - Growing Use Cases for Blockchain
    0:43:23 - Blockchain Elements That Need Securing
    0:49:00 - What Are Smart Contracts
    0:51:22 - EVM : Ethereum Virtual Machine
    0:54:00 - Solidity
    0:59:55 - Smart Contract Vulns
    1:04:00 - - Reentrancy
    1:05:54 - - Front-Running
    1:07:41 - - Inter Overflow and Underflow
    1:09:15 - - Denial-of-Service
    1:10:43 - - Access Control
    1:12:46 - - Timestamp Dependence
    1:15:23 - Case Studies - Uranium Finance Hack
    1:17:26 - - Poly Network Hack
    1:21:07 - - Cream Finance Hack
    1:24:42 - DEMO: Live Exploit
    1:35:44 - Exploit Recap
    1:36:14 - Security Tools - VS Code + Solidity Visual Developer
    1:37:08 - - Slither
    1:37:26 - - Mythril & MythX
    1:37:57 - Get-Started Resources
    1:39:03 - Bug Bounties
    1:39:19 - Key Takeaways
    1:40:29 - This is the End - Q & A
    Description: In this Black Hills Information Security (BHIS) webcast, we'll use case studies about recent blockchain hacks to introduce the underlying issues that occur in writing/engineering smart contracts that have ultimately lead to the loss of millions of dollars to attackers.
    Slides:s1hb.sharepoint.com/Content&C...
    BlockchainHAX QuickStart Guide
    • start.blockchainhax.com
    Follow me on Twitter
    • Beau Bullock - @dafthack
    CoinSec Podcast - Weekly show about blockchain security
    • coinsecpodcast.com • @coinsecpodcast
    • CoinSec Podcast Discord: / discord
    Black Hills Infosec Socials
    Twitter: / bhinfosecurity
    Mastodon: infosec.exchange/@blackhillsi...
    LinkedIn: / antisyphon-training
    Discord: / discord
    Black Hills Infosec Shirts & Hoodies
    spearphish-general-store.mysh...
    Black Hills Infosec Services
    Active SOC: www.blackhillsinfosec.com/ser...
    Penetration Testing: www.blackhillsinfosec.com/ser...
    Incident Response: www.blackhillsinfosec.com/ser...
    Backdoors & Breaches - Incident Response Card Game
    Backdoors & Breaches: www.backdoorsandbreaches.com/
    Play B&B Online: play.backdoorsandbreaches.com/
    Antisyphon Training
    Pay What You Can: www.antisyphontraining.com/pa...
    Live Training: www.antisyphontraining.com/co...
    On Demand Training: www.antisyphontraining.com/on...
    Educational Infosec Content
    Black Hills Infosec Blogs: www.blackhillsinfosec.com/blog/
    Wild West Hackin' Fest RUclips: / wildwesthackinfest
    Active Countermeasures RUclips: / activecountermeasures
    Antisyphon Training RUclips: / antisyphontraining
    Join us at the annual information security conference in Deadwood, SD (in-person and virtually) - Wild West Hackin' Fest: wildwesthackinfest.com/
    #bhis #infosec

Комментарии • 34

  • @333Jessica
    @333Jessica 2 года назад +15

    This was exactly what I was looking for as I want to focus on blockchain offensive security. Super helpful 💯

  • @calebnaugle6613
    @calebnaugle6613 2 года назад +9

    I'm already on the smart contract rabbit hole, and this is great fuel for the fire!

    • @sharonlima8913
      @sharonlima8913 Год назад

      Hey Caleb, howdy? and how far have you come along in your SC rabbit hole?

  • @user-pg9te8ug1j
    @user-pg9te8ug1j 2 года назад +1

    Great content - thanks a lot for sharing your knowledge!

  • @0xDevelopers
    @0xDevelopers Год назад

    Loved it! It was such a pleasure to watch, succinct and very well done! Please make more of these

  • @baroonjha3160
    @baroonjha3160 2 года назад +1

    Before this video ,i just know that cypto is based on blockchain but now i know what blockchain is .Thanks for the video ❤️.

  • @liza3941
    @liza3941 2 года назад

    thank you for sharing !

  • @KayA-go9nr
    @KayA-go9nr Год назад +4

    Great Content Guys! Currently Writing a Master's Dissertation on Some of the Smart Contract Vulnerabilities and this has helped alot!

    • @sharonlima8913
      @sharonlima8913 Год назад

      Hey Kay, have you finished writing the dissertation project?

  • @fakermankumar1327
    @fakermankumar1327 2 года назад

    Thanks for sharing. Please keep sharing stuff like this.

  • @yourdailyblockchain
    @yourdailyblockchain Год назад

    Awesome content

  • @bensacc
    @bensacc Год назад

    man, you guys have the coolest t-shirts (and great talk!)

  • @thisisnotfinancialadvice3803
    @thisisnotfinancialadvice3803 2 года назад

    Thanks for the shoutout guys !😂😎

  • @muhammadhaashir7489
    @muhammadhaashir7489 Год назад

    So helpful

  • @wzrdk3lly
    @wzrdk3lly 2 года назад

    Gold!

  • @legrandesleepy8298
    @legrandesleepy8298 2 года назад +5

    Been waiting for this since the webcast ended.😂

  • @xclusivetech118
    @xclusivetech118 2 года назад

    really very good and informative session...it's definitely super super helpful.
    🤣camera focusing issue was miserable though...

  • @user-xl9zi5yj8h
    @user-xl9zi5yj8h Год назад

    I’ll b there soon

  • @crazyrobot10
    @crazyrobot10 Год назад

    Thanks for the info. I want to get into blockchain security but have no cyber background. How should I approach?

  • @synoopspentest900
    @synoopspentest900 2 года назад

    Can someone tell me name of a website which is solely dedicated to blockchain security and has smart contract boxes just like in hack the box or is their a website which has regular updates on ctfs and bug bounty for blockchain 🤔.

  • @steiner254
    @steiner254 2 месяца назад

    Interesting

  • @MrEpicdream
    @MrEpicdream 2 года назад

    Hi, do you know where to start the technical part of block chains ?

    • @BlackHillsInformationSecurity
      @BlackHillsInformationSecurity  2 года назад +1

      You can jump into Beau's new CoinSec Podcast discord to ask this question. It just launched! : discord.gg/EdUFBtR9nz

  • @iampromesa
    @iampromesa Год назад

    How do i get the Cybersecurity guys channel

  • @MarKac9090
    @MarKac9090 2 года назад

    get this guy to talk about Solana smart contracts vulns pls

  • @soulsongs5272
    @soulsongs5272 4 месяца назад

    Hi sir, I need help with a project in the Blockchain security field, which is about implementing SQL injection and XSS on a decentralized application, if you have any idea or you know anyone that can help and guide me please let me know, many thanks

  • @nellsawere
    @nellsawere 2 года назад

    Great content guys. I am in Toronto Canada and looking to get into blockchain technology/developer. Would love to connect with Black Hills. What’s the best way to join the community?

    • @BlackHillsInformationSecurity
      @BlackHillsInformationSecurity  2 года назад +1

      Join the InfoSec Knowledge Sharing Community Discord: discord.gg/bhis

    • @nellsawere
      @nellsawere 2 года назад

      @@BlackHillsInformationSecurity thank you! Can’t wait to connect