¾¯ÌèÖÇÄܺÏÔ¼·ì϶£º£º£ºÇø¿éÁ´Éϵġ°¿ÕÆø¡±±Ò
°ä²¼¹¦·ò 2018-07-13
²¼¾°
Çø¿éÁ´ÊǽüÄêÀ´×î¾ß¸ïÃüÐÔµÄÐÂÐ˼¼ÊõÖ®Ò»£¬£¬£¬ÒÔÆäÈ¥ÖÐÐÄ»¯¡¢¡¢²»³É´Û¸ÄµÈÌØµã£¬£¬£¬µß¸²Á˽ðÈÚµÈÖî¶àÐÐÒµµÄÔÓй涨¡£¡£Çø¿éÁ´ÏÖÒѽøÈë3.0½×¶Î£¬£¬£¬¡°´ú±ÒºÏÔ¼¡±×÷ÎªÇø¿éÁ´ÖÇÄܺÏÔ¼ÖÐÀûÓÃ×î¿í·ºµÄÒ»À࣬£¬£¬Ò²³ÉΪ¹¥»÷ÕßÃǵÄÖØÒª¹¥»÷¶ÔÏ󡣡£
ÓÉÓÚ¼¼Êõ·¢Õ¹Ê±ºöÂÔÁ˰²È«ÏÈÐеÄÀíÄ£¬£¬µ¼ÖÂÖڶ༼Êõ´æÔÚ´óÁ¿°²È«ÎÊÌ⣬£¬£¬Ó봫ͳ·¨Ê½Ò»Ñù£¬£¬£¬´ú±ÒºÏÔ¼ÎÞ·¨Ô¤·ÀÏß´æÔÚ°²È«·ì϶¡£¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶µÃÐÄÓ¦ÊֵؽÚÖÆÊг¡ÉϵÄÇ®±Ò×ÜÁ¿»òËÁÒâÕË»§µÄÇ®±ÒÁ¿£¬£¬£¬ÕâÑùʹÕý±¾¾ÍÎÞêµÄÇ®±Ò³¹µ×ʧȥÐÅÓþ£¬£¬£¬³ÉΪ¡°¿ÕÆø¡±±Ò¡£¡£
ÖÇÄܺÏÔ¼Éó¼Æ
OG¶«·½ÌüADLab½üÄêÀ´³ÖÐø¹Ø×¢Çø¿éÁ´¼¼Êõ°²È«ÎÊÌ⣬£¬£¬Í¨¹ý¶ÔÒÔÌ«·»Ö÷Á´[1]ÖÇÄܺÏÔ¼½øÐÐ×êÑУ¬£¬£¬·¢ÏÖÁË400¶à¸öCVE·ì϶¡£¡£
ÖÇÄܺÏÔ¼·ì϶»á´øÀ´Öî¶à¶ñÐÔÁ˾֣¬£¬£¬ADLab½áºÏÏÖʵµÄ°²È«ÊÂÎñ£¬£¬£¬ÒÔ¼°×ÔÖ÷·¢Ïֵķì϶£¬£¬£¬¶ÔÆäÖеÄÈý¸öÀà´ËÍâ·ì϶¸ø¸÷ÈË×öÁ˷ֽ⡣¡£
ÖØÈë·ì϶
2016Äê6Ô£¬£¬£¬DAO¹¥»÷ÊÂÎñÔÚÇø¿éÁ´º¹ÇàÉÏÁôÏÂÁË·±ÖصÄÒ»±Ê£¬£¬£¬ºÚ¿ÍÀûÓÃÖØÈë·ì϶£¬£¬£¬Ö±½Óµ¼ÖÂÒÔÌ«·»µÄÓ²·Ö²æ¡£¡£OG¶«·½ÌüADLab¾¹ý×êÑз¢ÏÖ£¬£¬£¬ÒÔÌ«·»µÄÖÇÄܺÏÔ¼ÀïÃæÒÀÈ»´æÔÚÖØÈë·ì϶¡£¡£ÏÂÃæÒÔBANK_SAFEºÏԼΪÀý½øÐоÙÀý×¢Ã÷¡£¡£
¡ñ ·ì϶ʾÀý
BANK_SAFEºÏÔ¼ÖдæÔÚµäÐ͵ĴúÂëÖØÈë·ì϶£¬£¬£¬µ±Í¨³£Óû§ÕË»§Å²ÓÃCollectº¯Êýʱ£¬£¬£¬Collectº¯ÊýµÄÂ߼ûÓÐÈκÎÎÊÌ⣬£¬£¬Óû§Äܹ»Ë³ÀûµÄÖ´ÐÐÈ¡¿î²Ù×÷£»£»µ«Êǵ±ÁíÒ»¸öÖÇÄܺÏԼŲÓÃBANK_SAFEºÏÔ¼µÄCollectº¯Êýʱ£¬£¬£¬»á²úÉúÑÏÖØµÄ°²È«Òþ»¼¡£¡£
¡ñ Ô¤·À¼¼Êõ[2]
1. ʹÓÃÄÚÖõÄtransfer()º¯Êý½øÐÐתÕË¡£¡£ÓÉÓÚtranfer()º¯ÊýÖ»·¢ËÍ2300gas£¬£¬£¬Òò¶ø²»¼°ÒÔºÏÔ¼Ö®¼äµÄÑ»·Å²Óᣡ£
2. ѡȡcheck-effects-interactionsģʽµÄ±àÂë¡£¡£ÔÚBANK_SAFEºÏÔ¼ÖУ¬£¬£¬[49]ÐеÄ×ʽð¿Û³ý²Ù×÷Ó¦¸Ã·Åµ½[47]ÐÐ֮ǰ¡£¡£
3. ÒýÈë»¥Ëø»úÖÆ¡£¡£Ôö³¤Ò»¸ö״̬±äÁ¿Ëø¶¨ºÏÔ¼£¬£¬£¬Ô¤·ÀÖØÈëŲÓᣡ£
³¬¶îÖý±Ò
2018Äê2Ô³õ£¬£¬£¬»ùÓÚÒÔÌ«·»µÄMonero Gold(XMRG) TokenÔÚÂòÂôËùµÄ¼ÛÖµÏÈÃÍÕÇ787%£¬£¬£¬ºóѸËÙ±©µøÖÁ±ÀÅÌ£¬£¬£¬Ôì³É´óÁ¿Óû§¾¼ÃËðʧ£¬£¬£¬Æä±³ºó¾ÍÊÇÖÎÀíÍŶÓÀûÓÃÔ¤ÁôµÄÕûÊýÒç³ö·ì϶½øÐ㬶îÖý±Ò£¬£¬£¬²¢ÔÚÂòÂôËùÅ×ÊÛÔì³É¶ñÐÔͨ»õÅòÕÍ£¬£¬£¬×îºó¼ÛÖµÏÕЩ¹éÁã¡£¡£ADLabʹÓÃ×Ô¶¯»¯É󼯹¤¾ß·¢ÏÖ´óÁ¿ÖÇÄܺÏÔ¼ÒÀÈ»´æÔÚͬÀà·ì϶¡£¡£ÏÂÃæÒÔGenesis VisionºÏÔ¼½øÐоÙÀý×¢Ã÷¡£¡£
¡ñ ·ì϶ʾÀý£º£º£ºCVE-2018-11335
Genesis VisionÖÇÄܺÏÔ¼¹ÌÈ»ÒýÈëÁËOpenZepplinµÄSafeMathÊýѧÔËËã¿â£¬£¬£¬µ«Æä¿¯ÐÐÇ®±ÒµÄº¯Êýmint()ȴûÓÐʹÓð²È«ÔËË㺯Êý£¬£¬£¬¶øÊÇÖ±½ÓʹÓÃÊýѧÔËËã·û¡£¡£ÈôÊǾ«ÐÄ»ú¹ØÊäÈë²ÎÊývalue£¬£¬£¬ÔÚ[188]ÐвúÉúÕûÊýÒç³ö£¬£¬£¬Òç³öºóÔËËãÁ˾ÖСÓÚTOKEN_LIMIT£¬£¬£¬¾ÍÄܹ»Èƹýtoken¿¯ÐÐÉÏÏÞ£¬£¬£¬ÊµÏÖ³¬¶îÖý±Ò£¬£¬£¬×îÖÕµ¼Ö¶ñÐÔͨ»õÅòÕÍ¡£¡£ÕâÀàÖý±Òº¯ÊýµÄÖ´ÐÐͨ³£±ØÒªÖÎÀíԱȨÏÞ£¬£¬£¬Òò¶øÄܹ»¿´×÷ÊÇÒ»ÖÖºóÃÅ·ì϶¡£¡£
¡ñ Ô¤·À¼¼Êõ
²»ÈÝʹÓÃÊýѧÔËËã·û£¬£¬£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£¡£
ÅúÁ¿×ªÕË
2018Äê4Ô£¬£¬£¬ºÚ¿ÍÀûÓÃBECÖÇÄܺÏÔ¼·ì϶¹¥»÷ÃÀÁ´BEC(ÃÀÃÛ±Ò)£¬£¬£¬³É¹¦ÏòÁ½¸öµØÖ·×ª³öÁËÌìÁ¿¼¶´ËÍâ BEC´ú±Ò£¬£¬£¬µ¼Öº£Á¿BEC±»Å×ÊÛ£¬£¬£¬Ê¹Çе±ÈÕBECµÄ¼ÛÖµÏÕЩ¹éÁ㣬£¬£¬64ÒÚÈËÃñ±Ò˲¼äÕô·¢¡£¡£2018Äê7Ô£¬£¬£¬AMRºÏÔ¼Öеķì϶±»ºÚ¿Í¶ñÒâÀûÓ㬣¬£¬µ¼ÖÂAMR´óÁ¿Ôö·¢¡£¡£ÕâÁ½´Î¹¥»÷ÊÂÎñ¶¼ÊÇÓÉÓÚÅúÁ¿×ªÕ˺¯ÊýÖдæÔÚÕûÊýÒç³ö·ì϶£¬£¬£¬¾ADLab×êÑз¢ÏÖ£¬£¬£¬Ï±íÖеÄÖÇÄܺÏÔ¼ÒÀÈ»´æÔÚͬÀà·ì϶¡£¡£
¡ñ ·ì϶ʾÀý£º£º£ºCVE-2018-13836
Rocket Coin (XRC)ºÏÔ¼ÖеÄmultiTransferº¯Êý´æÔÚÕûÊýÒç³ö·ì϶£¬£¬£¬ÓÉÓڸú¯ÊýµÄÊôÐÔÊÇpublic£¬£¬£¬ËÁÒâÓû§Äܹ»Å²Óøú¯Êý½øÐÐÅúÁ¿×ª±Ò²Ù×÷£¬£¬£¬²»±ØÒªÖÎÀíԱȨÏÞ¡£¡£
´ÓRocket Coin´ú±ÒµÄTokenHoldersÁбíÄܹ»¿´³öºÚ¿Í¹¥»÷³É¹¦µÄºÛ¼£¡£¡£¡£
´Óetherscan.ioÄܹ»²é¿´ºÚ¿Í¹¥»÷ʱÂòÂô¼Í¼£º£º£º
https://etherscan.io/tx/0x606316fc06922ae34e6be865e64b23598d74a5e94712447dca37a7ac4c8b30a8#decodetab
´ÓInput DataÄܹ»¿´³ö¹¥»÷Õß¾«ÐÄ»ú¹ØÁË_amountsÊý×飬£¬£¬Êý×éÖÐÔ̺¬Á½¸öÔªËØ£¬£¬£¬ÔªËØÖµ½ÔΪ¼«´óÖµ£¬£¬£¬µ±Ö´Ðе½[72]ÐÐʱ½«²úÉúÕûÊýÒç³ö¡£¡£Òò¶ø¹¥»÷ÕßÖ»ÆÆ·ÑÁ˼«ÉÙµÄtoken£¬£¬£¬±ãʵÏÖÅúÁ¿´ó¶îתÕË¡£¡£
¡ñ Ô¤·À´ëÊ©
²»ÈÝʹÓÃÊýѧÔËËã·û£¬£¬£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£¡£
×ܽá
ÓÉÓÚÖÇÄܺÏÔ¼ÊÇÒ»´ÎÐÔ°ä²¼ÉÏÁ´µÄ£¬£¬£¬Ò»µ©³öÏÖ·ì϶½«ÄÑÒÔÖ±½ÓÐÞ²¹¡£¡£
¶ÔÓÚ¿ª·¢Õß¶øÑÔ£¬£¬£¬·¢ÏÖ·ì϶ºóÖ»Äܰ䲼еÄÖÇÄܺÏÔ¼¶øºó×öÊÖ¶¯Ó³É䣬£¬£¬ÔÚ¹¦·ò¡¢¡¢ÈËÁ¦¡¢¡¢²ÆÁ¦ÉÏ»áÖ§³öºÜ´óµÄ¼ÛÖµ¡£¡£
¶ÔÓÚͶ×ÊÕß¶øÑÔ£¬£¬£¬ÖÇÄܺÏÔ¼Éϵķì϶ºÜ¿ÉÄÜ»áʹÏàÓ¦µÄ´ú±ÒÔì³É¡°¿ÕÆø¡±±Ò£¬£¬£¬´øÀ´¸üΪֱ½ÓµÄ²Æ¸»Ëðʧ¡£¡£
ÎÂܰÌáÐÑ£º£º£º
1¡¢¡¢Çø¿éÁ´ÊÇÐÂÐ˼¼Êõ£¬£¬£¬»¹Ðè¼ÓÇ¿¶ÔÆä°²È«Éó¼ÆºÍ¼à¹ÜÄÜÁ¦µÄÆ÷ÖØ¡£¡£
2¡¢¡¢³´±ÒÓзçÏÕ£¬£¬£¬ÈëÊÐÐèÉóÉ÷£¬£¬£¬Ïàʶ¶ÔÐÐÇ飬£¬£¬»Ø¾ø×ö¡°¾Â²Ë¡±¡£¡£
3¡¢¡¢Æ÷ÖØ¹ú¶È˾·¨Âɹ棬£¬£¬ºÏÀíͶ×Ê£¬£¬£¬½¡¿µÀí²Æ¡£¡£
²Î¿¼Á´½Ó
[1]
https://etherscan.io/contractsVerified
[2]
https://blog.sigmaprime.io/solidity-security.html
[3]
https://github.com/OpenZeppelin/zeppelin-solidity
²¼¾°
Çø¿éÁ´ÊǽüÄêÀ´×î¾ß¸ïÃüÐÔµÄÐÂÐ˼¼ÊõÖ®Ò»£¬£¬£¬ÒÔÆäÈ¥ÖÐÐÄ»¯¡¢¡¢²»³É´Û¸ÄµÈÌØµã£¬£¬£¬µß¸²Á˽ðÈÚµÈÖî¶àÐÐÒµµÄÔÓй涨¡£¡£Çø¿éÁ´ÏÖÒѽøÈë3.0½×¶Î£¬£¬£¬¡°´ú±ÒºÏÔ¼¡±×÷ÎªÇø¿éÁ´ÖÇÄܺÏÔ¼ÖÐÀûÓÃ×î¿í·ºµÄÒ»À࣬£¬£¬Ò²³ÉΪ¹¥»÷ÕßÃǵÄÖØÒª¹¥»÷¶ÔÏ󡣡£
ÓÉÓÚ¼¼Êõ·¢Õ¹Ê±ºöÂÔÁ˰²È«ÏÈÐеÄÀíÄ£¬£¬µ¼ÖÂÖڶ༼Êõ´æÔÚ´óÁ¿°²È«ÎÊÌ⣬£¬£¬Ó봫ͳ·¨Ê½Ò»Ñù£¬£¬£¬´ú±ÒºÏÔ¼ÎÞ·¨Ô¤·ÀÏß´æÔÚ°²È«·ì϶¡£¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶µÃÐÄÓ¦ÊֵؽÚÖÆÊг¡ÉϵÄÇ®±Ò×ÜÁ¿»òËÁÒâÕË»§µÄÇ®±ÒÁ¿£¬£¬£¬ÕâÑùʹÕý±¾¾ÍÎÞêµÄÇ®±Ò³¹µ×ʧȥÐÅÓþ£¬£¬£¬³ÉΪ¡°¿ÕÆø¡±±Ò¡£¡£
ÖÇÄܺÏÔ¼Éó¼Æ
OG¶«·½ÌüADLab½üÄêÀ´³ÖÐø¹Ø×¢Çø¿éÁ´¼¼Êõ°²È«ÎÊÌ⣬£¬£¬Í¨¹ý¶ÔÒÔÌ«·»Ö÷Á´[1]ÖÇÄܺÏÔ¼½øÐÐ×êÑУ¬£¬£¬·¢ÏÖÁË400¶à¸öCVE·ì϶¡£¡£
ÖÇÄܺÏÔ¼·ì϶»á´øÀ´Öî¶à¶ñÐÔÁ˾֣¬£¬£¬ADLab½áºÏÏÖʵµÄ°²È«ÊÂÎñ£¬£¬£¬ÒÔ¼°×ÔÖ÷·¢Ïֵķì϶£¬£¬£¬¶ÔÆäÖеÄÈý¸öÀà´ËÍâ·ì϶¸ø¸÷ÈË×öÁ˷ֽ⡣¡£
ÖØÈë·ì϶
2016Äê6Ô£¬£¬£¬DAO¹¥»÷ÊÂÎñÔÚÇø¿éÁ´º¹ÇàÉÏÁôÏÂÁË·±ÖصÄÒ»±Ê£¬£¬£¬ºÚ¿ÍÀûÓÃÖØÈë·ì϶£¬£¬£¬Ö±½Óµ¼ÖÂÒÔÌ«·»µÄÓ²·Ö²æ¡£¡£OG¶«·½ÌüADLab¾¹ý×êÑз¢ÏÖ£¬£¬£¬ÒÔÌ«·»µÄÖÇÄܺÏÔ¼ÀïÃæÒÀÈ»´æÔÚÖØÈë·ì϶¡£¡£ÏÂÃæÒÔBANK_SAFEºÏԼΪÀý½øÐоÙÀý×¢Ã÷¡£¡£
¡ñ ·ì϶ʾÀý
BANK_SAFEºÏÔ¼ÖдæÔÚµäÐ͵ĴúÂëÖØÈë·ì϶£¬£¬£¬µ±Í¨³£Óû§ÕË»§Å²ÓÃCollectº¯Êýʱ£¬£¬£¬Collectº¯ÊýµÄÂ߼ûÓÐÈκÎÎÊÌ⣬£¬£¬Óû§Äܹ»Ë³ÀûµÄÖ´ÐÐÈ¡¿î²Ù×÷£»£»µ«Êǵ±ÁíÒ»¸öÖÇÄܺÏԼŲÓÃBANK_SAFEºÏÔ¼µÄCollectº¯Êýʱ£¬£¬£¬»á²úÉúÑÏÖØµÄ°²È«Òþ»¼¡£¡£
¡ñ Ô¤·À¼¼Êõ[2]
1. ʹÓÃÄÚÖõÄtransfer()º¯Êý½øÐÐתÕË¡£¡£ÓÉÓÚtranfer()º¯ÊýÖ»·¢ËÍ2300gas£¬£¬£¬Òò¶ø²»¼°ÒÔºÏÔ¼Ö®¼äµÄÑ»·Å²Óᣡ£
2. ѡȡcheck-effects-interactionsģʽµÄ±àÂë¡£¡£ÔÚBANK_SAFEºÏÔ¼ÖУ¬£¬£¬[49]ÐеÄ×ʽð¿Û³ý²Ù×÷Ó¦¸Ã·Åµ½[47]ÐÐ֮ǰ¡£¡£
3. ÒýÈë»¥Ëø»úÖÆ¡£¡£Ôö³¤Ò»¸ö״̬±äÁ¿Ëø¶¨ºÏÔ¼£¬£¬£¬Ô¤·ÀÖØÈëŲÓᣡ£
³¬¶îÖý±Ò
2018Äê2Ô³õ£¬£¬£¬»ùÓÚÒÔÌ«·»µÄMonero Gold(XMRG) TokenÔÚÂòÂôËùµÄ¼ÛÖµÏÈÃÍÕÇ787%£¬£¬£¬ºóѸËÙ±©µøÖÁ±ÀÅÌ£¬£¬£¬Ôì³É´óÁ¿Óû§¾¼ÃËðʧ£¬£¬£¬Æä±³ºó¾ÍÊÇÖÎÀíÍŶÓÀûÓÃÔ¤ÁôµÄÕûÊýÒç³ö·ì϶½øÐ㬶îÖý±Ò£¬£¬£¬²¢ÔÚÂòÂôËùÅ×ÊÛÔì³É¶ñÐÔͨ»õÅòÕÍ£¬£¬£¬×îºó¼ÛÖµÏÕЩ¹éÁã¡£¡£ADLabʹÓÃ×Ô¶¯»¯É󼯹¤¾ß·¢ÏÖ´óÁ¿ÖÇÄܺÏÔ¼ÒÀÈ»´æÔÚͬÀà·ì϶¡£¡£ÏÂÃæÒÔGenesis VisionºÏÔ¼½øÐоÙÀý×¢Ã÷¡£¡£
¡ñ ·ì϶ʾÀý£º£º£ºCVE-2018-11335
Genesis VisionÖÇÄܺÏÔ¼¹ÌÈ»ÒýÈëÁËOpenZepplinµÄSafeMathÊýѧÔËËã¿â£¬£¬£¬µ«Æä¿¯ÐÐÇ®±ÒµÄº¯Êýmint()ȴûÓÐʹÓð²È«ÔËË㺯Êý£¬£¬£¬¶øÊÇÖ±½ÓʹÓÃÊýѧÔËËã·û¡£¡£ÈôÊǾ«ÐÄ»ú¹ØÊäÈë²ÎÊývalue£¬£¬£¬ÔÚ[188]ÐвúÉúÕûÊýÒç³ö£¬£¬£¬Òç³öºóÔËËãÁ˾ÖСÓÚTOKEN_LIMIT£¬£¬£¬¾ÍÄܹ»Èƹýtoken¿¯ÐÐÉÏÏÞ£¬£¬£¬ÊµÏÖ³¬¶îÖý±Ò£¬£¬£¬×îÖÕµ¼Ö¶ñÐÔͨ»õÅòÕÍ¡£¡£ÕâÀàÖý±Òº¯ÊýµÄÖ´ÐÐͨ³£±ØÒªÖÎÀíԱȨÏÞ£¬£¬£¬Òò¶øÄܹ»¿´×÷ÊÇÒ»ÖÖºóÃÅ·ì϶¡£¡£
¡ñ Ô¤·À¼¼Êõ
²»ÈÝʹÓÃÊýѧÔËËã·û£¬£¬£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£¡£
ÅúÁ¿×ªÕË
2018Äê4Ô£¬£¬£¬ºÚ¿ÍÀûÓÃBECÖÇÄܺÏÔ¼·ì϶¹¥»÷ÃÀÁ´BEC(ÃÀÃÛ±Ò)£¬£¬£¬³É¹¦ÏòÁ½¸öµØÖ·×ª³öÁËÌìÁ¿¼¶´ËÍâ BEC´ú±Ò£¬£¬£¬µ¼Öº£Á¿BEC±»Å×ÊÛ£¬£¬£¬Ê¹Çе±ÈÕBECµÄ¼ÛÖµÏÕЩ¹éÁ㣬£¬£¬64ÒÚÈËÃñ±Ò˲¼äÕô·¢¡£¡£2018Äê7Ô£¬£¬£¬AMRºÏÔ¼Öеķì϶±»ºÚ¿Í¶ñÒâÀûÓ㬣¬£¬µ¼ÖÂAMR´óÁ¿Ôö·¢¡£¡£ÕâÁ½´Î¹¥»÷ÊÂÎñ¶¼ÊÇÓÉÓÚÅúÁ¿×ªÕ˺¯ÊýÖдæÔÚÕûÊýÒç³ö·ì϶£¬£¬£¬¾ADLab×êÑз¢ÏÖ£¬£¬£¬Ï±íÖеÄÖÇÄܺÏÔ¼ÒÀÈ»´æÔÚͬÀà·ì϶¡£¡£
¡ñ ·ì϶ʾÀý£º£º£ºCVE-2018-13836
Rocket Coin (XRC)ºÏÔ¼ÖеÄmultiTransferº¯Êý´æÔÚÕûÊýÒç³ö·ì϶£¬£¬£¬ÓÉÓڸú¯ÊýµÄÊôÐÔÊÇpublic£¬£¬£¬ËÁÒâÓû§Äܹ»Å²Óøú¯Êý½øÐÐÅúÁ¿×ª±Ò²Ù×÷£¬£¬£¬²»±ØÒªÖÎÀíԱȨÏÞ¡£¡£
´ÓRocket Coin´ú±ÒµÄTokenHoldersÁбíÄܹ»¿´³öºÚ¿Í¹¥»÷³É¹¦µÄºÛ¼£¡£¡£¡£
´Óetherscan.ioÄܹ»²é¿´ºÚ¿Í¹¥»÷ʱÂòÂô¼Í¼£º£º£º
https://etherscan.io/tx/0x606316fc06922ae34e6be865e64b23598d74a5e94712447dca37a7ac4c8b30a8#decodetab
´ÓInput DataÄܹ»¿´³ö¹¥»÷Õß¾«ÐÄ»ú¹ØÁË_amountsÊý×飬£¬£¬Êý×éÖÐÔ̺¬Á½¸öÔªËØ£¬£¬£¬ÔªËØÖµ½ÔΪ¼«´óÖµ£¬£¬£¬µ±Ö´Ðе½[72]ÐÐʱ½«²úÉúÕûÊýÒç³ö¡£¡£Òò¶ø¹¥»÷ÕßÖ»ÆÆ·ÑÁ˼«ÉÙµÄtoken£¬£¬£¬±ãʵÏÖÅúÁ¿´ó¶îתÕË¡£¡£
¡ñ Ô¤·À´ëÊ©
²»ÈÝʹÓÃÊýѧÔËËã·û£¬£¬£¬Ê¹ÓÃSafeMathÔËËã¿â[3]¡£¡£
×ܽá
ÓÉÓÚÖÇÄܺÏÔ¼ÊÇÒ»´ÎÐÔ°ä²¼ÉÏÁ´µÄ£¬£¬£¬Ò»µ©³öÏÖ·ì϶½«ÄÑÒÔÖ±½ÓÐÞ²¹¡£¡£
¶ÔÓÚ¿ª·¢Õß¶øÑÔ£¬£¬£¬·¢ÏÖ·ì϶ºóÖ»Äܰ䲼еÄÖÇÄܺÏÔ¼¶øºó×öÊÖ¶¯Ó³É䣬£¬£¬ÔÚ¹¦·ò¡¢¡¢ÈËÁ¦¡¢¡¢²ÆÁ¦ÉÏ»áÖ§³öºÜ´óµÄ¼ÛÖµ¡£¡£
¶ÔÓÚͶ×ÊÕß¶øÑÔ£¬£¬£¬ÖÇÄܺÏÔ¼Éϵķì϶ºÜ¿ÉÄÜ»áʹÏàÓ¦µÄ´ú±ÒÔì³É¡°¿ÕÆø¡±±Ò£¬£¬£¬´øÀ´¸üΪֱ½ÓµÄ²Æ¸»Ëðʧ¡£¡£
ÎÂܰÌáÐÑ£º£º£º
1¡¢¡¢Çø¿éÁ´ÊÇÐÂÐ˼¼Êõ£¬£¬£¬»¹Ðè¼ÓÇ¿¶ÔÆä°²È«Éó¼ÆºÍ¼à¹ÜÄÜÁ¦µÄÆ÷ÖØ¡£¡£
2¡¢¡¢³´±ÒÓзçÏÕ£¬£¬£¬ÈëÊÐÐèÉóÉ÷£¬£¬£¬Ïàʶ¶ÔÐÐÇ飬£¬£¬»Ø¾ø×ö¡°¾Â²Ë¡±¡£¡£
3¡¢¡¢Æ÷ÖØ¹ú¶È˾·¨Âɹ棬£¬£¬ºÏÀíͶ×Ê£¬£¬£¬½¡¿µÀí²Æ¡£¡£
²Î¿¼Á´½Ó
[1]
https://etherscan.io/contractsVerified
[2]
https://blog.sigmaprime.io/solidity-security.html
[3]
https://github.com/OpenZeppelin/zeppelin-solidity


¾©¹«Íø°²±¸11010802024551ºÅ