reNFT - bareli's results

Collateral-free, permissionless, and highly customizable EVM NFT rentals.

General Information

Platform: Code4rena

Start Date: 08/01/2024

Pot Size: $83,600 USDC

Total HM: 23

Participants: 116

Period: 10 days

Judge: 0xean

Total Solo HM: 1

Id: 317

League: ETH

reNFT

Findings Distribution

Researcher Performance

Rank: 59/116

Findings: 1

Award: $45.31

🌟 Selected for report: 0

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: 0xpiken

Also found by: Kalyan-Singh, OMEN, Topmark, bareli, evmboi32, hals, hash, kaden, peter, rbserver, trachev

Labels

bug
2 (Med Risk)
satisfactory
duplicate-162

Awards

45.3128 USDC - $45.31

External Links

Lines of code

https://github.com/re-nft/smart-contracts/blob/3ddd32455a849c3c6dc3c3aad7a33a6c9b44c291/src/packages/Signer.sol#L298

Vulnerability details

Impact

Detailed description of the impact of this finding. Signature Replay Attacks: The contract should ensure that signatures cannot be reused. This is typically handled by using nonces or by keeping track of used signatures, but the provided code does not show such mechanisms.

Proof of Concept

Provide direct links to all referenced code in GitHub. Add screenshots, logs, or any other relevant proof that illustrates the concept. https://github.com/re-nft/smart-contracts/blob/3ddd32455a849c3c6dc3c3aad7a33a6c9b44c291/src/packages/Signer.sol#L298

Tools Used

using nonces or by keeping track of used signatures, but the provided code does not show such mechanisms

Assessed type

Other

#0 - c4-pre-sort

2024-01-21T17:52:46Z

141345 marked the issue as duplicate of #179

#1 - c4-pre-sort

2024-01-21T17:53:46Z

141345 marked the issue as duplicate of #239

#2 - c4-judge

2024-01-28T21:05:18Z

0xean marked the issue as satisfactory

#3 - c4-pre-sort

2024-02-02T08:40:15Z

141345 marked the issue as not a duplicate

#4 - c4-pre-sort

2024-02-02T08:40:41Z

141345 marked the issue as duplicate of #162

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter