ENS contest - RustyRabbit's results

Decentralised naming for wallets, websites, & more.

General Information

Platform: Code4rena

Start Date: 12/07/2022

Pot Size: $75,000 USDC

Total HM: 16

Participants: 100

Period: 7 days

Judge: LSDan

Total Solo HM: 7

Id: 145

League: ETH

ENS

Findings Distribution

Researcher Performance

Rank: 82/100

Findings: 1

Award: $78.87

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2022-07-ens/blob/ff6e59b9415d0ead7daf31c2ed06e86d9061ae22/contracts/dnssec-oracle/DNSSECImpl.sol#L49

Vulnerability details

Impact

Trust anchors are specified during deployment of the DNS oracle and no functionality is provided to add, update or deactivate trust anchors. If the DNS root server keys are changed for whatever reason (planned roll over, new keys added or compromised) there is no other way to update the DNS oracle than to deploy a new one and change the ENS registry (if this functionality will be provided in the new DNS registrar, which is unclear as it out of scope).

Proof of Concept

NA

Tools Used

NA

Add functionality to remove and add trust anchors when needed. If this is by design the anchors can be set to immutable.

#0 - makoto

2022-07-27T10:42:03Z

#1 - dmvt

2022-08-04T23:03:01Z

See comments on #60. This is not a duplicate of #34. Downgraded to QA.

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter