Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[TA-1796] APP-02 Potential Gas Fee Stealing and DoS Attack Due to Missing Check of Nested Messages in Authz Transaction #3

Closed
wants to merge 1 commit into from

Conversation

AdriaCarrera
Copy link
Contributor

No description provided.

…Check of Nested Messages in Authz Transaction
@AdriaCarrera AdriaCarrera changed the title fix: APP-02 Potential Gas Fee Stealing and DoS Attack Due to Missing Check of Nested Messages in Authz Transaction [TA-1796] APP-02 Potential Gas Fee Stealing and DoS Attack Due to Missing Check of Nested Messages in Authz Transaction Dec 12, 2023
Copy link

Copy link
Contributor

@jpeersyst jpeersyst left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sembla que el codi i els canvis son els correctes i que et demanen però no em queda clara un cosa.
En el report diuen el següent:

Recommend the fix in Ethermint and Evmos to reject the following message types, MsgEthereumTx and MsgCreateVestingAccount to be the nested message in authz

Diuen que hem de posar aquest disable al ante de ethermint i hi he mirat i ja està posat. Per tant, si continua fallant (tal i com sembla pel test que han fet), si que té sentit que sigui del ante de la app.
Jo crec que està bé però m'ha semblat raro que posi Ethermint and Evmos al report.
Has fet check que el que diuen no passa amb els canvis?

@AdriaCarrera
Copy link
Contributor Author

Closing as depecrated by #6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants