"Massive DDOS Attack on Crypto Exchange: Can You Spot the Vulnerability?"

Iliya Palych

New member
Joined
Jan 11, 2018
Messages
2
Reaction score
0
"Guys, I just got word from a mate that a major crypto exchange was hit with a massive DDOS attack. I'm talking thousands of Gbps of traffic - this is some next-level stuff. If anyone's got experience with web app sec, can we take a look at the exchange's website and see if we can spot the vulnerability?"
 

mila09

Member
Joined
Dec 16, 2011
Messages
5
Reaction score
0
"Just looked at the vid and I'm thinking it's probably a case of unsecured API or a weak auth protocol. That exchange really needs to step up their security game if they wanna stay in the crypto market. Anyone else spot any obvious flaws?"
 

anat55

New member
Joined
Feb 4, 2007
Messages
4
Reaction score
0
"Dude, I think I caught a glimpse of the vulnerability in the login endpoint - they're using a deprecated library that hasn't been patched in months. Looks like the attack vector is via SQL injection. Anyone have a PoC or a write-up on this?"
 
Top