Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nebPay转账金额小数位超越边界后溢出 #42

Open
dabdevelop opened this issue Jun 4, 2018 · 5 comments
Open

nebPay转账金额小数位超越边界后溢出 #42

dabdevelop opened this issue Jun 4, 2018 · 5 comments

Comments

@dabdevelop
Copy link

screen shot 2018-06-04 at 15 49 20
screen shot 2018-06-04 at 15 49 38

钱包显示的转账金额是0.03333....但是实际上却是超大额的转账,存在风险。

@dabdevelop
Copy link
Author

screen shot 2018-06-04 at 16 45 44
如果把转账金额是填为0.00000000000000000022,那么可以作为有效的诱骗攻击,导致用户转账26w+NAS,存在巨大的风险。

@dabdevelop
Copy link
Author

dabdevelop commented Jun 4, 2018

如果把转账金额是填为0.000000000000000000022,将导致用户转账24178 NAS,对大户造成很大的威胁。

@ChengOrangeJu
Copy link

@dabdevelop Very helpful information, we will fix it today

@jnoodle
Copy link

jnoodle commented Jun 4, 2018

高危漏洞,奖励奖励!

@ChengOrangeJu
Copy link

ChengOrangeJu commented Jun 4, 2018

The minimum unit of value should be wei (1nas = 1^18 wei). We will throw an error when the minimum value of wei is not an integer now :) Thanks for pointing it out

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants