Skip to content
This repository has been archived by the owner on Feb 24, 2023. It is now read-only.

Add bad use of tx.origin #23

Open
montyly opened this issue Sep 14, 2018 · 7 comments
Open

Add bad use of tx.origin #23

montyly opened this issue Sep 14, 2018 · 7 comments

Comments

@montyly
Copy link
Member

montyly commented Sep 14, 2018

tx.origin should not be called for authorization.

See slither testcase to have examples of incorrect and legitimate usages:
https://github.com/trailofbits/slither/blob/2aea762600ebdb46798f53c7dd65ac375783c5dc/tests/tx_origin.sol

@gitcoinbot
Copy link

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


This issue now has a funding of 100.0 DAI (100.0 USD @ $1.0/DAI) attached to it as part of the Ethereum Community Fund via ECF Web 3.0 Infrastructure Fund fund__.__

@gitcoinbot
Copy link

gitcoinbot commented Oct 11, 2018

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


Work has been started.

These users each claimed they can complete the work by 7 months from now.
Please review their action plans below:

1) adamskrodzki has been approved to start work.

I will fork repository and example of wallet using tx.origin "Authorisation" and write the attacker smart contract and also smart contract that deploys both and allow for attack

Learn more on the Gitcoin Issue Details page.

@adamskrodzki
Copy link

adamskrodzki commented Oct 12, 2018

@montyly

Please view PR
#33

@gitcoinbot
Copy link

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


Work for 100.0 DAI (100.0 USD @ $1.0/DAI) has been submitted by:

  1. @adamskrodzki

@mkosowsk please take a look at the submitted work:


@PixelantDesign
Copy link

@montyly you have a submission! Please take a few minutes to review.

@montyly
Copy link
Member Author

montyly commented Oct 24, 2018

Hi, sorry for the late reply. The PR looks good, I added a small feedback to it.

@gitcoinbot
Copy link

Issue Status: 1. Open 2. Started 3. Submitted 4. Done


The funding of 100.0 DAI (100.0 USD @ $1.0/DAI) attached to this issue has been approved & issued to @adamskrodzki.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants