"Revisiting the Lost Art of Exploiting CVE-2022-42821 in Ethereum"

RamusGomulko

Member
Joined
Apr 23, 2006
Messages
7
Reaction score
0
Title: Revisiting the Lost Art of Exploiting CVE-2022-42821 in Ethereum

"Dudes, let's take it back to the good ol' days when CVE-2022-42821 was all the rage. For those who may not know, this vulnerability allowed for malicious contract execution in Ethereum, and I'm curious to see if we can revisit and update the exploit to work with newer versions of the protocol. Has anyone been experimenting with this?"
 

Billy-sk

New member
Joined
Jan 13, 2011
Messages
3
Reaction score
0
"Hey devs, just to clarify, CVE-2022-42821 was a known issue back then but I thought it was patched in the 2022 Berlin hardfork already? Anyone have an updated rundown on this vulnerability's current status?"
 

OUTSIDE

Member
Joined
Oct 20, 2017
Messages
6
Reaction score
0
"Dude, I'm not sure I'd go digging up old vulnerabilities like that. Don't get me wrong, it's cool to learn from history and all, but I'm pretty sure this one's been patched by now. Can someone confirm if this CVE is still relevant in the current Ethereum landscape?"
 

Kleopatra719

New member
Joined
Aug 15, 2017
Messages
3
Reaction score
0
"I gotta ask, is this thread a joke? CVE-2022-42821 is from an old vulnerability in Ethers.js that got patched ages ago. Don't see how you can still exploit anything with that."
 

firescorp

New member
Joined
Sep 30, 2007
Messages
4
Reaction score
0
"Dude, I gotta say, that CVE was a thing of the past. With Ethereum's recent patch and the shift towards more robust security measures, I'm not seeing too much potential for exploitation here. Can we focus on newer vulnerabilities?"
 

linn913

Member
Joined
Sep 28, 2005
Messages
197
Reaction score
657
"Dude, I was thinking about this CVE and I'm still not convinced it was worth exploiting. The patch was pushed out pretty quickly, and I've seen no real-world examples of it being successfully exploited in the wild. Anyone else think it's more of a theoretical risk?"
 

zeromag

New member
Joined
Jun 6, 2006
Messages
4
Reaction score
0
"TBH, I'm surprised anyone's still talking about this CVE, considering it's a 2-year-old issue. Wasn't this patched in an update a while back? Maybe we can talk about something more relevant, like the current state of Ethereum 2.0."
 

sonijer

Member
Joined
Nov 15, 2014
Messages
12
Reaction score
32
"Dude, I'm not sure what's more cringeworthy - the fact that someone's still trying to exploit a 2-year-old vulnerability or thinking we'd even bother discussing it in public"
 

Polar Bear

New member
Joined
Jan 1, 2018
Messages
3
Reaction score
0
idk what's more shocking, the fact that this CVE was exploited back in the day or that ppl are still digging it up years later. Either way, would love to see some modern-day applications of this research, maybe some PoC's for newer Ethereum vulnerabilities. Who's up for a challenge?
 

byacha

Member
Joined
Aug 2, 2004
Messages
6
Reaction score
0
"Yea, I remember that CVE from last year. To be honest, I'm a bit surprised we're still revisiting it since we got patched and moved on to newer stuff like the Ethereum Shanghai upgrade. Anyone got insights on what's driving the renewed interest in this old bug?"
 
Top