¾¯ÌèÖÇÄܺÏԼ©¶´£ºÇø¿éÁ´Éϵġ°¿ÕÆø¡±±Ò

Ðû²¼Ê±¼ä 2018-07-13


 Åä¾°


Çø¿éÁ´ÊǽüÄêÀ´×î¾ß¸ïÃüÐÔµÄÐÂÐ˼¼ÊõÖ®Ò»£¬ÒÔÆäÈ¥ÖÐÐÄ»¯¡¢²»ÐиĶ¯µÈÌص㣬µß¸²Á˽ðÈÚµÈÖî¶àÐÐÒµµÄÔ­ÓйæÔò¡£Çø¿éÁ´ÏÖÒѽøÈë3.0½×¶Î£¬¡°´ú±ÒºÏÔ¼¡±×÷ΪÇø¿éÁ´ÖÇÄܺÏÔ¼ÖÐÓ¦ÓÃ×î¹ã·ºµÄÒ»À࣬Ҳ³ÉΪ¹¥»÷ÕßÃǵÄÖØÒª¹¥»÷¹¤¾ß¡£


ÓÉÓÚ¼¼ÊõÉú³¤Ê±ºöÂÔÁËÄþ¾²ÏÈÐеÄÀíÄµ¼ÖÂÖڶ༼Êõ´æÔÚ´óÁ¿Äþ¾²ÎÊÌ⣬Ó봫ͳ·¨Ê½Ò»Ñù£¬´ú±ÒºÏÔ¼ÎÞ·¨ÖÆÖ¹µØ´æÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÒÔÀûÓ鶴ËæÐÄËùÓûµØ¿ØÖÆÊг¡ÉϵĻõ±Ò×ÜÁ¿»òÈÎÒâÕË»§µÄ»õ±ÒÁ¿£¬ÕâÑùʹԭÀ´¾ÍÎÞêµÄ»õ±Ò³¹µ×ʧȥÐÅÓ㬳ÉΪ¡°¿ÕÆø¡±±Ò¡£



ÖÇÄܺÏÔ¼Éó¼Æ


¶«É­Æ½Ì¨ADLab½üÄêÀ´Á¬Ðø¹Ø×¢Çø¿éÁ´¼¼ÊõÄþ¾²ÎÊÌ⣬ͨ¹ý¶ÔÒÔÌ«·»Ö÷Á´[1]ÖÇÄܺÏÔ¼½øÐÐÑо¿£¬·¢ÏÖÁË400¶à¸öCVE©¶´¡£


ÖÇÄܺÏԼ©¶´»á´øÀ´Öî¶à¶ñÐÔ½á¹û£¬ADLab½áºÏʵ¼ÊµÄÄþ¾²Ê¼þ£¬ÒÔ¼°×ÔÖ÷·¢Ïֵĩ¶´£¬¶ÔÆäÖеÄÈý¸öÀà´ËÍ⩶´¸ø¸÷ÈË×öÁËÆÊÎö¡£


 ÖØÈ멶´


2016Äê6Ô£¬DAO¹¥»÷ʼþÔÚÇø¿éÁ´ÀúÊ·ÉÏÁôÏÂÁ˼«ÖصÄÒ»±Ê£¬ºÚ¿ÍÀûÓÃÖØÈ멶´£¬Ö±½Óµ¼ÖÂÒÔÌ«·»µÄÓ²·Ö²æ¡£¶«É­Æ½Ì¨ADLab¾­¹ýÑо¿·¢ÏÖ£¬ÒÔÌ«·»µÄÖÇÄܺÏÔ¼ÀïÃæÈÔÈ»´æÔÚÖØÈ멶´¡£ÏÂÃæÒÔBANK_SAFEºÏԼΪÀý½øÐоÙÀý˵Ã÷¡£


¡ñ Â©¶´Ê¾Àý


BANK_SAFEºÏÔ¼ÖдæÔÚµäÐ͵ĴúÂëÖØÈ멶´£¬µ±ÆÕͨÓû§ÕË»§µ÷ÓÃCollectº¯Êýʱ£¬Collectº¯ÊýµÄÂß¼­Ã»ÓÐÈκÎÎÊÌ⣬Óû§¿ÉÒÔ˳ÀûµÄÖ´ÐÐÈ¡¿î²Ù×÷£»µ«Êǵ±ÁíÒ»¸öÖÇÄܺÏÔ¼µ÷ÓÃBANK_SAFEºÏÔ¼µÄCollectº¯Êýʱ£¬»á·¢ÉúÑÏÖصÄÄþ¾²Òþ»¼¡£

 


¡ñ Ô¤·À¼¼Êõ[2]


1. Ê¹ÓÃÄÚÖõÄtransfer()º¯Êý½øÐÐתÕË¡£ÓÉÓÚtranfer()º¯ÊýÖ»·¢ËÍ2300gas£¬Òò´Ë²»×ãÒÔºÏÔ¼Ö®¼äµÄÑ­»·µ÷Óá£


2. ½ÓÄÉcheck-effects-interactionsģʽµÄ±àÂë¡£ÔÚBANK_SAFEºÏÔ¼ÖУ¬[49]ÐеÄ×ʽð¿Û³ý²Ù×÷Ó¦¸Ã·Åµ½[47]ÐÐ֮ǰ¡£


3. ÒýÈ뻥Ëø»úÖÆ¡£Ìí¼ÓÒ»¸ö״̬±äÁ¿Ëø¶¨ºÏÔ¼£¬Ô¤·ÀÖØÈëµ÷Óá£


³¬¶îÖý±Ò


2018Äê2Ô³õ£¬»ùÓÚÒÔÌ«·»µÄMonero Gold(XMRG) TokenÔÚ½»Ò×ËùµÄ¼Û¸ñÏÈÃÍÕÇ787%£¬ºóѸËÙ±©µøÖÁ±ÀÅÌ£¬Ôì³É´óÁ¿Óû§¾­¼ÃËðʧ£¬Æä±³ºó¾ÍÊǹÜÀíÍŶÓÀûÓÃÔ¤ÁôµÄÕûÊýÒç³ö©¶´½øÐ㬶îÖý±Ò£¬²¢ÔÚ½»Ò×ËùÅ×ÊÛÔì³É¶ñÐÔͨ»õÅòÕÍ£¬×îºó¼ÛÖµ¼¸ºõ¹éÁã¡£ADLabʹÓÃ×Ô¶¯»¯Éó¼Æ¹¤¾ß·¢ÏÖ´óÁ¿ÖÇÄܺÏÔ¼ÈÔÈ»´æÔÚͬÀ੶´¡£ÏÂÃæÒÔGenesis VisionºÏÔ¼½øÐоÙÀý˵Ã÷¡£


¡ñ Â©¶´Ê¾Àý£ºCVE-2018-11335


Genesis VisionÖÇÄܺÏÔ¼ËäÈ»ÒýÈëÁËOpenZepplinµÄSafeMathÊýѧÔËËã¿â£¬µ«Æ俯Ðлõ±ÒµÄº¯Êýmint()ȴûÓÐʹÓÃÄþ¾²ÔËË㺯Êý£¬¶øÊÇÖ±½ÓʹÓÃÊýѧÔËËã·û¡£Èç¹û¾«ÐĽṹÊäÈë²ÎÊývalue£¬ÔÚ[188]Ðз¢ÉúÕûÊýÒç³ö£¬Òç³öºóÔËËã½á¹ûСÓÚTOKEN_LIMIT£¬¾Í¿ÉÒÔÈƹýtoken¿¯ÐÐÉÏÏÞ£¬ÊµÏÖ³¬¶îÖý±Ò£¬×îÖÕµ¼Ö¶ñÐÔͨ»õÅòÕÍ¡£ÕâÀàÖý±Òº¯ÊýµÄÖ´ÐÐÒ»°ãÐèÒª¹ÜÀíԱȨÏÞ£¬Òò´Ë¿ÉÒÔ¿´×÷ÊÇÒ»ÖÖºóÃÅ©¶´¡£

 


¡ñ Ô¤·À¼¼Êõ


½ûֹʹÓÃÊýѧÔËËã·û£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£


ÅúÁ¿×ªÕË


2018Äê4Ô£¬ºÚ¿ÍÀûÓÃBECÖÇÄܺÏԼ©¶´¹¥»÷ÃÀÁ´BEC(ÃÀÃÛ±Ò)£¬ÀÖ³ÉÏòÁ½¸öµØַת³öÁËÌìÁ¿¼¶´ËÍâ BEC´ú±Ò£¬µ¼Öº£Á¿BEC±»Å×ÊÛ£¬Ê¹Ç¡µ±ÈÕBECµÄ¼ÛÖµ¼¸ºõ¹éÁ㣬64ÒÚÈËÃñ±Ò˲¼äÕô·¢¡£2018Äê7Ô£¬AMRºÏÔ¼ÖеÄ©¶´±»ºÚ¿Í¶ñÒâÀûÓ㬵¼ÖÂAMR´óÁ¿Ôö·¢¡£ÕâÁ½´Î¹¥»÷ʼþ¶¼ÊÇÓÉÓÚÅúÁ¿×ªÕ˺¯ÊýÖдæÔÚÕûÊýÒç³ö©¶´£¬¾­ADLabÑо¿·¢ÏÖ£¬Ï±íÖеÄÖÇÄܺÏÔ¼ÈÔÈ»´æÔÚͬÀ੶´¡£


   

¡ñ Â©¶´Ê¾Àý£ºCVE-2018-13836


Rocket Coin (XRC)ºÏÔ¼ÖеÄmultiTransferº¯Êý´æÔÚÕûÊýÒç³ö©¶´£¬ÓÉÓڸú¯ÊýµÄÊôÐÔÊÇpublic£¬ÈÎÒâÓû§¿ÉÒÔµ÷Óøú¯Êý½øÐÐÅúÁ¿×ª±Ò²Ù×÷£¬²»ÐèÒª¹ÜÀíԱȨÏÞ¡£

 


´ÓRocket Coin´ú±ÒµÄTokenHoldersÁбí¿ÉÒÔ¿´³öºÚ¿Í¹¥»÷Àֳɵĺۼ£¡£

 


´Óetherscan.io¿ÉÒÔ¼ì²ìºÚ¿Í¹¥»÷ʱ½»Ò׼Ǽ£º


https://etherscan.io/tx/0x606316fc06922ae34e6be865e64b23598d74a5e94712447dca37a7ac4c8b30a8#decodetab


´ÓInput Data¿ÉÒÔ¿´³ö¹¥»÷Õß¾«ÐĽṹÁË_amountsÊý×飬Êý×éÖаüÂÞÁ½¸öÔªËØ£¬ÔªËØÖµ½ÔΪ¼«´óÖµ£¬µ±Ö´Ðе½[72]ÐÐʱ½«·¢ÉúÕûÊýÒç³ö¡£Òò´Ë¹¥»÷ÕßÖ»»¨·ÑÁ˼«ÉÙµÄtoken£¬±ãÍê³ÉÅúÁ¿´ó¶îתÕË¡£



¡ñ Ô¤·À´ëÊ©


½ûֹʹÓÃÊýѧÔËËã·û£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£



×ܽá


ÓÉÓÚÖÇÄܺÏÔ¼ÊÇÒ»´ÎÐÔÐû²¼ÉÏÁ´µÄ£¬Ò»µ©·ºÆ𩶴½«ÄÑÒÔÖ±½ÓÐÞ²¹¡£


¶ÔÓÚ¿ª·¢Õ߶øÑÔ£¬·¢ÏÖ©¶´ºóÖ»ÄÜÐû²¼ÐµÄÖÇÄܺÏԼȻºó×öÊÖ¶¯Ó³É䣬ÔÚʱ¼ä¡¢ÈËÁ¦¡¢²ÆÁ¦ÉÏ»áÖ§¸¶ºÜ´óµÄ´ú¼Û¡£


¶ÔÓÚͶ×ÊÕ߶øÑÔ£¬ÖÇÄܺÏÔ¼ÉϵÄ©¶´ºÜ¿ÉÄÜ»áʹÏàÓ¦µÄ´ú±ÒÄð³É¡°¿ÕÆø¡±±Ò£¬´øÀ´¸üΪֱ½ÓµÄ¹¤ÒµËðʧ¡£

 

ÎÂÜ°Ìáʾ£º


1¡¢Çø¿éÁ´ÊÇÐÂÐ˼¼Êõ£¬»¹Ðè¼ÓÇ¿¶ÔÆäÄþ¾²Éó¼ÆºÍ¼à¹ÜÄÜÁ¦µÄÖØÊÓ¡£

2¡¢³´±ÒÓзçÏÕ£¬ÈëÊÐÐè½÷É÷£¬Á˽â¶ÔÐÐÇ飬¾Ü¾ø×ö¡°¾Â²Ë¡±¡£

3¡¢ÖØÊÓ¹ú¼ÒÖ´·¨¹æÔò£¬ºÏÀíͶ×Ê£¬½¡¿µÀí²Æ¡£

 


²Î¿¼Á´½Ó


[1] 

https://etherscan.io/contractsVerified

[2] 

https://blog.sigmaprime.io/solidity-security.html

[3] 

https://github.com/OpenZeppelin/zeppelin-solidity


 Åä¾°


Çø¿éÁ´ÊǽüÄêÀ´×î¾ß¸ïÃüÐÔµÄÐÂÐ˼¼ÊõÖ®Ò»£¬ÒÔÆäÈ¥ÖÐÐÄ»¯¡¢²»ÐиĶ¯µÈÌص㣬µß¸²Á˽ðÈÚµÈÖî¶àÐÐÒµµÄÔ­ÓйæÔò¡£Çø¿éÁ´ÏÖÒѽøÈë3.0½×¶Î£¬¡°´ú±ÒºÏÔ¼¡±×÷ΪÇø¿éÁ´ÖÇÄܺÏÔ¼ÖÐÓ¦ÓÃ×î¹ã·ºµÄÒ»À࣬Ҳ³ÉΪ¹¥»÷ÕßÃǵÄÖØÒª¹¥»÷¹¤¾ß¡£


ÓÉÓÚ¼¼ÊõÉú³¤Ê±ºöÂÔÁËÄþ¾²ÏÈÐеÄÀíÄµ¼ÖÂÖڶ༼Êõ´æÔÚ´óÁ¿Äþ¾²ÎÊÌ⣬Ó봫ͳ·¨Ê½Ò»Ñù£¬´ú±ÒºÏÔ¼ÎÞ·¨ÖÆÖ¹µØ´æÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÒÔÀûÓ鶴ËæÐÄËùÓûµØ¿ØÖÆÊг¡ÉϵĻõ±Ò×ÜÁ¿»òÈÎÒâÕË»§µÄ»õ±ÒÁ¿£¬ÕâÑùʹԭÀ´¾ÍÎÞêµÄ»õ±Ò³¹µ×ʧȥÐÅÓ㬳ÉΪ¡°¿ÕÆø¡±±Ò¡£



ÖÇÄܺÏÔ¼Éó¼Æ


¶«É­Æ½Ì¨ADLab½üÄêÀ´Á¬Ðø¹Ø×¢Çø¿éÁ´¼¼ÊõÄþ¾²ÎÊÌ⣬ͨ¹ý¶ÔÒÔÌ«·»Ö÷Á´[1]ÖÇÄܺÏÔ¼½øÐÐÑо¿£¬·¢ÏÖÁË400¶à¸öCVE©¶´¡£


ÖÇÄܺÏԼ©¶´»á´øÀ´Öî¶à¶ñÐÔ½á¹û£¬ADLab½áºÏʵ¼ÊµÄÄþ¾²Ê¼þ£¬ÒÔ¼°×ÔÖ÷·¢Ïֵĩ¶´£¬¶ÔÆäÖеÄÈý¸öÀà´ËÍ⩶´¸ø¸÷ÈË×öÁËÆÊÎö¡£


 ÖØÈ멶´


2016Äê6Ô£¬DAO¹¥»÷ʼþÔÚÇø¿éÁ´ÀúÊ·ÉÏÁôÏÂÁ˼«ÖصÄÒ»±Ê£¬ºÚ¿ÍÀûÓÃÖØÈ멶´£¬Ö±½Óµ¼ÖÂÒÔÌ«·»µÄÓ²·Ö²æ¡£¶«É­Æ½Ì¨ADLab¾­¹ýÑо¿·¢ÏÖ£¬ÒÔÌ«·»µÄÖÇÄܺÏÔ¼ÀïÃæÈÔÈ»´æÔÚÖØÈ멶´¡£ÏÂÃæÒÔBANK_SAFEºÏԼΪÀý½øÐоÙÀý˵Ã÷¡£


¡ñ Â©¶´Ê¾Àý


BANK_SAFEºÏÔ¼ÖдæÔÚµäÐ͵ĴúÂëÖØÈ멶´£¬µ±ÆÕͨÓû§ÕË»§µ÷ÓÃCollectº¯Êýʱ£¬Collectº¯ÊýµÄÂß¼­Ã»ÓÐÈκÎÎÊÌ⣬Óû§¿ÉÒÔ˳ÀûµÄÖ´ÐÐÈ¡¿î²Ù×÷£»µ«Êǵ±ÁíÒ»¸öÖÇÄܺÏÔ¼µ÷ÓÃBANK_SAFEºÏÔ¼µÄCollectº¯Êýʱ£¬»á·¢ÉúÑÏÖصÄÄþ¾²Òþ»¼¡£

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡ñ Ô¤·À¼¼Êõ[2]


1. Ê¹ÓÃÄÚÖõÄtransfer()º¯Êý½øÐÐתÕË¡£ÓÉÓÚtranfer()º¯ÊýÖ»·¢ËÍ2300gas£¬Òò´Ë²»×ãÒÔºÏÔ¼Ö®¼äµÄÑ­»·µ÷Óá£


2. ½ÓÄÉcheck-effects-interactionsģʽµÄ±àÂë¡£ÔÚBANK_SAFEºÏÔ¼ÖУ¬[49]ÐеÄ×ʽð¿Û³ý²Ù×÷Ó¦¸Ã·Åµ½[47]ÐÐ֮ǰ¡£


3. ÒýÈ뻥Ëø»úÖÆ¡£Ìí¼ÓÒ»¸ö״̬±äÁ¿Ëø¶¨ºÏÔ¼£¬Ô¤·ÀÖØÈëµ÷Óá£


³¬¶îÖý±Ò


2018Äê2Ô³õ£¬»ùÓÚÒÔÌ«·»µÄMonero Gold(XMRG) TokenÔÚ½»Ò×ËùµÄ¼Û¸ñÏÈÃÍÕÇ787%£¬ºóѸËÙ±©µøÖÁ±ÀÅÌ£¬Ôì³É´óÁ¿Óû§¾­¼ÃËðʧ£¬Æä±³ºó¾ÍÊǹÜÀíÍŶÓÀûÓÃÔ¤ÁôµÄÕûÊýÒç³ö©¶´½øÐ㬶îÖý±Ò£¬²¢ÔÚ½»Ò×ËùÅ×ÊÛÔì³É¶ñÐÔͨ»õÅòÕÍ£¬×îºó¼ÛÖµ¼¸ºõ¹éÁã¡£ADLabʹÓÃ×Ô¶¯»¯Éó¼Æ¹¤¾ß·¢ÏÖ´óÁ¿ÖÇÄܺÏÔ¼ÈÔÈ»´æÔÚͬÀ੶´¡£ÏÂÃæÒÔGenesis VisionºÏÔ¼½øÐоÙÀý˵Ã÷¡£


¡ñ Â©¶´Ê¾Àý£ºCVE-2018-11335


Genesis VisionÖÇÄܺÏÔ¼ËäÈ»ÒýÈëÁËOpenZepplinµÄSafeMathÊýѧÔËËã¿â£¬µ«Æ俯Ðлõ±ÒµÄº¯Êýmint()ȴûÓÐʹÓÃÄþ¾²ÔËË㺯Êý£¬¶øÊÇÖ±½ÓʹÓÃÊýѧÔËËã·û¡£Èç¹û¾«ÐĽṹÊäÈë²ÎÊývalue£¬ÔÚ[188]Ðз¢ÉúÕûÊýÒç³ö£¬Òç³öºóÔËËã½á¹ûСÓÚTOKEN_LIMIT£¬¾Í¿ÉÒÔÈƹýtoken¿¯ÐÐÉÏÏÞ£¬ÊµÏÖ³¬¶îÖý±Ò£¬×îÖÕµ¼Ö¶ñÐÔͨ»õÅòÕÍ¡£ÕâÀàÖý±Òº¯ÊýµÄÖ´ÐÐÒ»°ãÐèÒª¹ÜÀíԱȨÏÞ£¬Òò´Ë¿ÉÒÔ¿´×÷ÊÇÒ»ÖÖºóÃÅ©¶´¡£

 

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡ñ Ô¤·À¼¼Êõ


½ûֹʹÓÃÊýѧÔËËã·û£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£


ÅúÁ¿×ªÕË


2018Äê4Ô£¬ºÚ¿ÍÀûÓÃBECÖÇÄܺÏԼ©¶´¹¥»÷ÃÀÁ´BEC(ÃÀÃÛ±Ò)£¬ÀÖ³ÉÏòÁ½¸öµØַת³öÁËÌìÁ¿¼¶´ËÍâ BEC´ú±Ò£¬µ¼Öº£Á¿BEC±»Å×ÊÛ£¬Ê¹Ç¡µ±ÈÕBECµÄ¼ÛÖµ¼¸ºõ¹éÁ㣬64ÒÚÈËÃñ±Ò˲¼äÕô·¢¡£2018Äê7Ô£¬AMRºÏÔ¼ÖеÄ©¶´±»ºÚ¿Í¶ñÒâÀûÓ㬵¼ÖÂAMR´óÁ¿Ôö·¢¡£ÕâÁ½´Î¹¥»÷ʼþ¶¼ÊÇÓÉÓÚÅúÁ¿×ªÕ˺¯ÊýÖдæÔÚÕûÊýÒç³ö©¶´£¬¾­ADLabÑо¿·¢ÏÖ£¬Ï±íÖеÄÖÇÄܺÏÔ¼ÈÔÈ»´æÔÚͬÀ੶´¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

   

¡ñ Â©¶´Ê¾Àý£ºCVE-2018-13836


Rocket Coin (XRC)ºÏÔ¼ÖеÄmultiTransferº¯Êý´æÔÚÕûÊýÒç³ö©¶´£¬ÓÉÓڸú¯ÊýµÄÊôÐÔÊÇpublic£¬ÈÎÒâÓû§¿ÉÒÔµ÷Óøú¯Êý½øÐÐÅúÁ¿×ª±Ò²Ù×÷£¬²»ÐèÒª¹ÜÀíԱȨÏÞ¡£

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ÓRocket Coin´ú±ÒµÄTokenHoldersÁбí¿ÉÒÔ¿´³öºÚ¿Í¹¥»÷Àֳɵĺۼ£¡£

 

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

´Óetherscan.io¿ÉÒÔ¼ì²ìºÚ¿Í¹¥»÷ʱ½»Ò׼Ǽ£º


https://etherscan.io/tx/0x606316fc06922ae34e6be865e64b23598d74a5e94712447dca37a7ac4c8b30a8#decodetab


´ÓInput Data¿ÉÒÔ¿´³ö¹¥»÷Õß¾«ÐĽṹÁË_amountsÊý×飬Êý×éÖаüÂÞÁ½¸öÔªËØ£¬ÔªËØÖµ½ÔΪ¼«´óÖµ£¬µ±Ö´Ðе½[72]ÐÐʱ½«·¢ÉúÕûÊýÒç³ö¡£Òò´Ë¹¥»÷ÕßÖ»»¨·ÑÁ˼«ÉÙµÄtoken£¬±ãÍê³ÉÅúÁ¿´ó¶îתÕË¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


 

¡ñ Ô¤·À´ëÊ©


½ûֹʹÓÃÊýѧÔËËã·û£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£



×ܽá


ÓÉÓÚÖÇÄܺÏÔ¼ÊÇÒ»´ÎÐÔÐû²¼ÉÏÁ´µÄ£¬Ò»µ©·ºÆ𩶴½«ÄÑÒÔÖ±½ÓÐÞ²¹¡£


¶ÔÓÚ¿ª·¢Õ߶øÑÔ£¬·¢ÏÖ©¶´ºóÖ»ÄÜÐû²¼ÐµÄÖÇÄܺÏԼȻºó×öÊÖ¶¯Ó³É䣬ÔÚʱ¼ä¡¢ÈËÁ¦¡¢²ÆÁ¦ÉÏ»áÖ§¸¶ºÜ´óµÄ´ú¼Û¡£


¶ÔÓÚͶ×ÊÕ߶øÑÔ£¬ÖÇÄܺÏÔ¼ÉϵÄ©¶´ºÜ¿ÉÄÜ»áʹÏàÓ¦µÄ´ú±ÒÄð³É¡°¿ÕÆø¡±±Ò£¬´øÀ´¸üΪֱ½ÓµÄ¹¤ÒµËðʧ¡£

 

ÎÂÜ°Ìáʾ£º


1¡¢Çø¿éÁ´ÊÇÐÂÐ˼¼Êõ£¬»¹Ðè¼ÓÇ¿¶ÔÆäÄþ¾²Éó¼ÆºÍ¼à¹ÜÄÜÁ¦µÄÖØÊÓ¡£

2¡¢³´±ÒÓзçÏÕ£¬ÈëÊÐÐè½÷É÷£¬Á˽â¶ÔÐÐÇ飬¾Ü¾ø×ö¡°¾Â²Ë¡±¡£

3¡¢ÖØÊÓ¹ú¼ÒÖ´·¨¹æÔò£¬ºÏÀíͶ×Ê£¬½¡¿µÀí²Æ¡£

 


²Î¿¼Á´½Ó


[1] 

https://etherscan.io/contractsVerified

[2] 

https://blog.sigmaprime.io/solidity-security.html

[3] 

https://github.com/OpenZeppelin/zeppelin-solidity