|
8 | 8 | ## 目录 |
9 | 9 | - [Knowledge Base 慢雾安全团队知识库](#knowledge-base-慢雾安全团队知识库) |
10 | 10 | - [目录](#目录) |
11 | | - - [基础研究](#基础研究) |
12 | | - - [EOS Security of SlowMist](#eos-security-of-slowmist) |
13 | | - - [EOS 攻击手法分析](#eos-攻击手法分析) |
| 11 | + - [生态安全研究](#区块链生态安全研究) |
14 | 12 | - [翻译资料](#翻译资料) |
15 | 13 | - [开放报告](#开放报告) |
16 | 14 | - [思维导图](#思维导图) |
17 | 15 | - [技术分析](#技术分析) |
18 | 16 | - [DeFi 攻击手法分析](#defi-攻击手法分析) |
| 17 | + - [EOS 攻击手法分析](#eos-攻击手法分析) |
19 | 18 | - [链上追踪技术分析](#链上追踪技术分析) |
20 | 19 | - [其他区块链技术分析](#其他区块链技术分析) |
21 | 20 | - [:fire: 针对数字货币交易平台充值入账的攻击手法](#fire-针对数字货币交易平台充值入账的攻击手法) |
22 | 21 | - [其他资料](#其他资料) |
23 | 22 |
|
24 | | -## 基础研究 |
25 | | -Basic research of blockchain security, include: `Bitcoin`, `Monero`, `Ethereum`, `EOS` and other top blockchains. |
| 23 | +## 区块链生态安全研究 |
| 24 | +Blockchain ecological security research, include: `Bitcoin`, `Monero`, `Ethereum`, `EOS` and other top blockchains. |
26 | 25 |
|
| 26 | +* [:fire: cryptocurrency security](https://github.com/slowmist/cryptocurrency-security) |
| 27 | +* [:fire: Blockchain-dark-forest-selfguard-handbook](https://github.com/slowmist/Blockchain-dark-forest-selfguard-handbook) |
27 | 28 | * [Paper of SlowMist](https://github.com/slowmist/papers) |
28 | 29 | * [Threat Intelligence of SlowMist](https://slowmist.io/disclosure/) |
29 | 30 | * [Public topic of SlowMist HackingTime](https://github.com/slowmist/HackingTime_Public) |
30 | 31 | * [Ontology Triones Service Node security checklist](https://github.com/slowmist/Ontology-Triones-Service-Node-security-checklist) |
31 | 32 | * [vechain core nodes security checklist](https://github.com/slowmist/vechain-core-nodes-security-checklist) |
32 | | -* [:fire: cryptocurrency security](https://github.com/slowmist/cryptocurrency-security) |
33 | | -* [:fire: Blockchain-dark-forest-selfguard-handbook](https://github.com/slowmist/Blockchain-dark-forest-selfguard-handbook) |
34 | | -* [Open of SlowMist](https://github.com/slowmist/) |
35 | | - |
36 | | -### EOS Security of SlowMist |
37 | | - |
38 | | -* [EOS 超级节点安全执行指南](https://github.com/slowmist/eos-bp-nodes-security-checklist) |
39 | | -* [EOS 超级节点安全审计方案](https://github.com/slowmist/eos-bp-nodes-security-checklist/blob/master/audit.md) |
40 | | -* [EOS 智能合约最佳安全开发指南](https://github.com/slowmist/eos-smart-contract-security-best-practices) |
| 33 | +* [EOS BP nodes security checklist](https://github.com/slowmist/eos-bp-nodes-security-checklist) |
| 34 | +* [EOS BP nodes security audit](https://github.com/slowmist/eos-bp-nodes-security-checklist/blob/master/audit.md) |
| 35 | +* [EOS smart contract security best practices](https://github.com/slowmist/eos-smart-contract-security-best-practices) |
41 | 36 | * [EOS 天眼(EOS MonKit)](https://eos.slowmist.io/) |
42 | | -* [FireWall.X — 强大的 EOS 智能合约防火墙](https://firewallx.io/) & [FireWall.X GitHub](https://github.com/firewall-x) |
| 37 | +* [FireWall.X — 强大的 EOS 智能合约防火墙](https://firewallx.io/) |
| 38 | +* [FireWall.X GitHub](https://github.com/firewall-x) |
| 39 | +* [Open of SlowMist](https://github.com/slowmist/) |
43 | 40 |
|
44 | | -#### EOS 攻击手法分析 |
45 | | -慢雾安全团队对 EOSIO 生态的各类新型攻击手法进行分析,如下是分析文章。 |
46 | | -* :pushpin: [EOS 回滚攻击手法分析之黑名单篇](https://mp.weixin.qq.com/s/WyZ4j3O68qfN5IOvjx3MOg) |
47 | | -* [EOS 回滚攻击手法之重放篇](https://mp.weixin.qq.com/s/gqzkBTxKf7kwL5OgCtMgvQ) |
48 | | -* [EOS 新型攻击手法之 hard_fail 状态攻击](https://mp.weixin.qq.com/s/qsqqPB24fEjBgnq3Xr3xjQ) |
49 | | -* [EOS 假充值\(hard_fail 状态攻击\)红色预警细节披露与修复方案](https://mp.weixin.qq.com/s/fKINfZLW65LYaD4qO-21nA) |
50 | | -* [随机数之殇 — EOS 新型随机数攻击手法技术分析](https://mp.weixin.qq.com/s/6qb6nYLIUeUJViaFgHVX_A) |
51 | | -* :pushpin: [EOS DApp 现新型交易排挤攻击及通用防御建议](https://mp.weixin.qq.com/s/1-SvoY-kNhH2YllNZdKyOA) |
52 | 41 |
|
53 | 42 | ## 翻译资料 |
54 | | - |
55 | 43 | Some translated blockchain security documents. |
56 | 44 |
|
57 | 45 | * [DASP Top10 中文版](./translations/DASP-top10-chinese.pdf) |
58 | 46 | * [Solidity 安全:已知攻击方法和常见防御模式综合列表](./translations/solidity-security-comprehensive-list-of-known-attack-vectors-and-common-anti-patterns_zh-cn.md) |
59 | 47 | * [全面解析公共区块链系统攻击面](./translations/Exploring-the-Attack-Surface-of-Blockchain-A-Systematic-Overview/Exploring-the-Attack-Surface-of-Blockchain-A-Systematic-Overview_zh-cn.md) |
60 | 48 |
|
61 | 49 | ## 开放报告 |
62 | | - |
63 | 50 | Some open security audit reports of SlowMist. |
| 51 | + |
64 | 52 | - [Open Security Audit Report](./open-report-V2/README.md) |
65 | 53 | * [Blockchain Security Audit Report](./open-report-V2/blockchain/) |
66 | 54 | * [Blockchain Application Security Audit Report](./open-report-V2/blockchain-application/) |
67 | 55 | * [Smart Contract Security Audit Report](./open-report-V2/smart-contract/) |
68 | 56 |
|
69 | 57 | ## 思维导图 |
70 | | - |
71 | 58 | Some mind maps of blockchain security. |
72 | 59 |
|
73 | 60 | * [DApp Attack & Defense](./mindmaps/dapp_attack_defense.png) |
@@ -134,6 +121,15 @@ Some mind maps of blockchain security. |
134 | 121 | * [智能合约安全审计入门篇 —— 自毁函数](https://mp.weixin.qq.com/s/exO9RCeUvysFQkBdMo3RgA) |
135 | 122 | * [智能合约安全审计入门篇 —— 访问私有数据](https://mp.weixin.qq.com/s/_DV6UaRdA_6pUFXt-EnTtA) |
136 | 123 |
|
| 124 | +### EOS 攻击手法分析 |
| 125 | +慢雾安全团队对 EOSIO 生态的各类新型攻击手法进行分析,如下是分析文章。 |
| 126 | +* :pushpin: [EOS 回滚攻击手法分析之黑名单篇](https://mp.weixin.qq.com/s/WyZ4j3O68qfN5IOvjx3MOg) |
| 127 | +* [EOS 回滚攻击手法之重放篇](https://mp.weixin.qq.com/s/gqzkBTxKf7kwL5OgCtMgvQ) |
| 128 | +* [EOS 新型攻击手法之 hard_fail 状态攻击](https://mp.weixin.qq.com/s/qsqqPB24fEjBgnq3Xr3xjQ) |
| 129 | +* [EOS 假充值\(hard_fail 状态攻击\)红色预警细节披露与修复方案](https://mp.weixin.qq.com/s/fKINfZLW65LYaD4qO-21nA) |
| 130 | +* [随机数之殇 — EOS 新型随机数攻击手法技术分析](https://mp.weixin.qq.com/s/6qb6nYLIUeUJViaFgHVX_A) |
| 131 | +* :pushpin: [EOS DApp 现新型交易排挤攻击及通用防御建议](https://mp.weixin.qq.com/s/1-SvoY-kNhH2YllNZdKyOA) |
| 132 | + |
137 | 133 | ### 链上追踪技术分析 |
138 | 134 | 慢雾安全团队对 DeFi 被黑事件保持跟进,协助被黑的项目方进行链上追踪,并深入研究各类混币平台,寻找突破混币进行追踪的可能。 |
139 | 135 | * [慢雾:复盘 Liquid 交易平台被盗 9000 多万美元事件](https://mp.weixin.qq.com/s/GIDGDsMo3nkkmS8yuhDOhg) |
@@ -186,8 +182,8 @@ Some mind maps of blockchain security. |
186 | 182 | * [terra 假充值手法-未公开](https://www.slowmist.com/?lang=zh#products) |
187 | 183 | * [BTC/dogcoin/LTC 假充值手法-未公开](https://www.slowmist.com/?lang=zh#products) |
188 | 184 |
|
189 | | -## 其他资料 |
190 | 185 |
|
| 186 | +## 其他资料 |
191 | 187 | Other awesome collections. |
192 | 188 |
|
193 | 189 | * [Hacked](https://hacked.slowmist.io) |
|
0 commit comments