<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>natasha008のブログ</title>
<link>https://ameblo.jp/natasha008/</link>
<atom:link href="https://rssblog.ameba.jp/natasha008/rss20.xml" rel="self" type="application/rss+xml" />
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
<description>ブログの説明を入力します。</description>
<language>ja</language>
<item>
<title>Zero Day BlockChain Timezone Exploit discovered!</title>
<description>
<![CDATA[ <p>Couple weeks ago, a new Blockchain exploit was found by a hacker named: Zer0dayxploit</p><p>It appears to be exploiting a badly designed payment system, which allows a user to unilaterally cancel a payment by altering the timezone.</p><p>This leads the payment processor to think too much time has elapsed (many payment processors impose a time limit by which a deposit must be made to avoid price fluctuations and other issues). Per normal procedure for an expired invoice, any payment is refunded to the user.</p><p>The site mentioned in the link appears to credit the user regardless of whether an invoice is expired or not. This is entirely the fault of a poor system design/integration between the payment processor and the integrating website, and exploits absolutely nothing in the Bitcoin protocol, node software, or wallet implementations.</p><p>It's basically the equivalent of you selling me something for $1000 on the condition that I pay you within 10 minutes, and cancelling our transaction because I showed you the time on my phone (which I can change as I want to) which indicates more than 10 minutes has passed. Then, you refund me $1000 if I pay you (since you think the transaction is cancelled), but your accountant considers it complete and ships out the goods anyways.</p><p>This exploit is still working, I have tested it with 500$, after 3 confirmations, my wallet was refunded with 1000$</p><p>He wrote a paper about this exploit, u can find it here:</p><p>&nbsp;</p><div class="ogpCard_root"><article class="ogpCard_wrap" contenteditable="false" style="display:inline-block;max-width:100%"><a class="ogpCard_link" data-ogp-card-log="" href="https://gofile.io/d/bQ09at" rel="noopener noreferrer" style="display:flex;justify-content:space-between;overflow:hidden;box-sizing:border-box;width:620px;max-width:100%;height:120px;border:1px solid #e2e2e2;border-radius:4px;background-color:#fff;text-decoration:none" target="_blank"><span class="ogpCard_content" style="display:flex;flex-direction:column;overflow:hidden;width:100%;padding:16px"><span class="ogpCard_title" style="-webkit-box-orient:vertical;display:-webkit-box;-webkit-line-clamp:2;max-height:48px;line-height:1.4;font-size:16px;color:#333;text-align:left;font-weight:bold;overflow:hidden">Gofile</span><span class="ogpCard_description" style="overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:1.6;margin-top:4px;color:#757575;text-align:left;font-size:12px">Gofile is a free and anonymous file-sharing platform. You can store and share data of all types (files, images, music, videos etc...). There is no limit, you download at the maximu…</span><span class="ogpCard_url" style="display:flex;align-items:center;margin-top:auto"><span class="ogpCard_iconWrap" style="position:relative;width:20px;height:20px;flex-shrink:0"><img alt="リンク" class="ogpCard_icon" height="20" loading="lazy" src="https://c.stat100.ameba.jp/ameblo/symbols/v3.20.0/svg/gray/editor_link.svg" style="position:absolute;top:0;bottom:0;right:0;left:0;height:100%;max-height:100%" width="20"></span><span class="ogpCard_urlText" style="overflow:hidden;text-overflow:ellipsis;white-space:nowrap;color:#757575;font-size:12px;text-align:left">gofile.io</span></span></span></a></article></div><p>&nbsp;</p>
]]>
</description>
<link>https://ameblo.jp/natasha008/entry-12624167630.html</link>
<pubDate>Fri, 11 Sep 2020 15:05:29 +0900</pubDate>
</item>
</channel>
</rss>
