sábado, 29 de agosto de 2020

How To Start | How To Become An Ethical Hacker

Are you tired of reading endless news stories about ethical hacking and not really knowing what that means? Let's change that!
This Post is for the people that:

  • Have No Experience With Cybersecurity (Ethical Hacking)
  • Have Limited Experience.
  • Those That Just Can't Get A Break


OK, let's dive into the post and suggest some ways that you can get ahead in Cybersecurity.
I receive many messages on how to become a hacker. "I'm a beginner in hacking, how should I start?" or "I want to be able to hack my friend's Facebook account" are some of the more frequent queries. Hacking is a skill. And you must remember that if you want to learn hacking solely for the fun of hacking into your friend's Facebook account or email, things will not work out for you. You should decide to learn hacking because of your fascination for technology and your desire to be an expert in computer systems. Its time to change the color of your hat 😀

 I've had my good share of Hats. Black, white or sometimes a blackish shade of grey. The darker it gets, the more fun you have.

If you have no experience don't worry. We ALL had to start somewhere, and we ALL needed help to get where we are today. No one is an island and no one is born with all the necessary skills. Period.OK, so you have zero experience and limited skills…my advice in this instance is that you teach yourself some absolute fundamentals.
Let's get this party started.
  •  What is hacking?
Hacking is identifying weakness and vulnerabilities of some system and gaining access with it.
Hacker gets unauthorized access by targeting system while ethical hacker have an official permission in a lawful and legitimate manner to assess the security posture of a target system(s)

 There's some types of hackers, a bit of "terminology".
White hat — ethical hacker.
Black hat — classical hacker, get unauthorized access.
Grey hat — person who gets unauthorized access but reveals the weaknesses to the company.
Script kiddie — person with no technical skills just used pre-made tools.
Hacktivist — person who hacks for some idea and leaves some messages. For example strike against copyright.
  •  Skills required to become ethical hacker.
  1. Curosity anf exploration
  2. Operating System
  3. Fundamentals of Networking
*Note this sites





Related news


  1. Hacking Tools For Windows Free Download
  2. Pentest Automation Tools
  3. Hack Tools Download
  4. Top Pentest Tools
  5. Hack Tools For Games
  6. Hacks And Tools
  7. Hacker Tools Software
  8. Hack Website Online Tool
  9. Best Pentesting Tools 2018
  10. Hacker Tools Linux
  11. Hacking Tools Name
  12. Game Hacking
  13. Github Hacking Tools
  14. Hacker Tools Software
  15. Best Hacking Tools 2020
  16. Physical Pentest Tools
  17. Hacking Tools Pc
  18. Hack Tool Apk
  19. Pentest Tools Nmap
  20. Hacking Tools Mac
  21. Hack Tools Github
  22. Kik Hack Tools
  23. Termux Hacking Tools 2019
  24. Black Hat Hacker Tools
  25. Pentest Tools Open Source
  26. Hacker
  27. Hacker Tools For Pc
  28. Wifi Hacker Tools For Windows
  29. Pentest Tools For Android
  30. Ethical Hacker Tools
  31. Hacker Tools Apk
  32. Pentest Tools Review
  33. Hacking Tools Windows
  34. Hacker Tools Online
  35. Pentest Tools Website
  36. Pentest Tools For Mac
  37. Github Hacking Tools
  38. Hacking Tools Software
  39. Hack Tools For Mac
  40. Hacker Tools Github
  41. Hacking Tools Windows 10
  42. Hacker Hardware Tools
  43. Hack Tools For Mac
  44. Hacker Tools Software
  45. Hacker Tools
  46. Hacking Tools Usb
  47. Hack Tools Pc
  48. What Is Hacking Tools
  49. Nsa Hack Tools
  50. Pentest Automation Tools
  51. Hacker Security Tools
  52. Hacker Tools Hardware
  53. Hacker Tools Software
  54. Hacking Tools For Beginners
  55. Pentest Tools Website Vulnerability
  56. Hacking App
  57. Hacker Tools For Mac
  58. Hacking Tools For Pc
  59. Hak5 Tools
  60. Underground Hacker Sites
  61. Hack And Tools
  62. Hacker Tools For Pc
  63. Pentest Tools For Windows
  64. Hacker Techniques Tools And Incident Handling
  65. Termux Hacking Tools 2019
  66. Pentest Tools Open Source
  67. How To Hack
  68. Black Hat Hacker Tools
  69. Pentest Automation Tools
  70. Hack Tools For Mac
  71. Pentest Tools List
  72. Easy Hack Tools
  73. Pentest Tools Find Subdomains
  74. Pentest Automation Tools
  75. Pentest Tools Github
  76. Hacking Apps
  77. Hacking Tools Software
  78. Hacker Tools Free
  79. How To Install Pentest Tools In Ubuntu
  80. Best Hacking Tools 2019
  81. Hacker Tools 2020
  82. Pentest Tools Framework
  83. Hacking Tools Mac
  84. Tools For Hacker

viernes, 28 de agosto de 2020

Change Passwords Regularly - A Myth And A Lie, Don'T Be Fooled, Part 1


TL;DR: different passwords have different protection requirements, and different attackers using various attacks can only be prevented through different prevention methods. Password security is not simple. For real advise, checking the second post (in progress).

Are you sick of password advices like "change your password regularly" or "if your password is password change it to pa$$w0rd"? This post is for you!

The news sites are full of password advises nowadays due to recent breaches. When I read/watch these advise (especially on CNN), I am usually pissed off for a lot of reasons. Some advises are terrible (a good collection is here), some are good but without solutions, and others are better, but they don't explain the reasons. Following is my analysis of the problem. It works for me. It might not work for you. Comments are welcome!

Password history

Passwords have been used since ancient times.


Because it is simple. When I started using the Internet, I believe I had three passwords. Windows login, webmail, and IRC. Now I have ~250 accounts/passwords to different things, like to my smartphone, to my cable company (this password can be used to change the channels on the TV), to my online secure cloud storage, to full disk encryption to start my computer, to my nude pictures, to my WiFi router, to my cloud server hosting provider, etc etc etc. My money is protected with passwords, my communication is protected with passwords/encryption, my work is protected with passwords. It is pretty damn important. But yet people tend to choose lame passwords. Pretty lame ones. Because they don't think it can be significant. But what is not essential today will be relevant tomorrow. The service you used to download music (iTunes) with the lame password will one day protect all your Apple devices, where attackers can download your backup files, erase all your devices, etc. The seven-character and one capital rule is not enough anymore. This advice is like PDF is safe to open, Java is secure. Old, outdated, untrue.

Now, after this lengthy prologue, we will deep dive into the analysis of the problem, by checking what we want to protect, against whom (who is the attacker), and only after that, we can analyze the solutions. Travel with me, I promise it will be fun! ;)

What to protect?

There are different services online, and various services need different ways to protect. You don't use the same lock on your Trabant as you do on your BMW.

Internet banking, online money

For me, this is the most vital service to protect. Luckily, most of the internet banking services use two-factor authentication (2FA), but unfortunately, not all of them offer transaction authorization/verification with complete transactions. 2FA is not effective against malware, it just complicates the attack. Transaction authorization/verification is better, but not perfect (see Zitmo). If the access is not protected with 2FA, better choose the best password you have (long, real random, sophisticated, but we will get to this later). If it is protected with 2FA, it is still no reason not to use the best password ;) This is what I call the "very high-level password" class.


Credit card data

This system is pretty fucked up bad. Something has to be secret (your credit card number), but in the meantime that is the only thing to identify your credit card. It is like your username is your password. Pretty bad idea, huh? The problem is even worse with a lot of different transaction types, especially when the hotel asks you to fax both sides of your CC to them. Unfortunately, you can't change the password on your credit card, as there is no such thing, but Verified by VISA or 3-D Secure with 2FA might increase the chances your credit card won't get hacked. And on a side note, I have removed the CVV numbers from my credit/debit cards. I only read it once from the card when I received it, I don't need it anymore to be printed there.
And sometimes, you are your own worst enemy. Don't do stupid things like this:


Work related passwords (e.g. Windows domain)

This is very important, but because the attack methods are a bit different, I created this as a different category. Details later.

Email, social sites (Gmail/Facebook/Twitter), cloud storage, online shopping

This is what I call the "high level password" class.
Still, pretty important passwords. Some people don't understand "why would attackers put any energy to get his Facebook account?" It is simple. For money. They can use your account to spread spam all over your Facebook wall. They can write messages to all of your connections and tell them you are in trouble and send money via Western Union or Bitcoin.


They can use your account in Facebook votes. Your e-mail, cloud storage is again very important. 20 years ago you also had letters you didn't want to print and put in front of the nearest store, neither want you to do that with your private photo album. On a side note, it is best to use a cloud storage where even the cloud provider admin can't access your data. But in this case, with no password recovery option, better think about "alternative" password recovery mechanisms.

Other important stuff with personal data (e.g. your name, home address)

The "medium level password" class. This is a personal preference to have this class or not, but in the long run, I believe it is not a waste of energy to protect these accounts. These sites include your favorite pizza delivery service, your local PC store, etc.

Not important stuff

This is the category other. I usually use one-time disposable e-mail to these services. Used for the registration, get what I want, drop the email account. Because I don't want to spread my e-mail address all over the internet, whenever one of these sites get hacked. But still, I prefer to use different, random passwords on these sites, although this is the "low level password" class.

Attackers and attack methods

After categorizing the different passwords to be protected, let's look at the different attackers and attack methods. They can/will/or actively doing it now:

Attacking the clear text password 

This is the most effective way of getting the password. Bad news is that if there is no other factor of protection, the victim is definitely not on the winning side. The different attack methods are:

  • phishing sites/applications,


  • social engineering,
  • malware running on the computer (or in the browser), 
  • shoulder surfing (check out for smartphones, hidden cameras), 
  • sniffing clear-text passwords when the website is not protected with SSL,
  • SSL MiTM,
  • rogue website administrator/hacker logging clear text passwords,
  • password reuse - if the attacker can get your password in any way, and you reuse it somewhere else, that is a problem,
  • you told your password to someone and he/she will misuse it later,
  • hardware keyloggers,
  • etc.

The key thing here is that no matter how long your passwords are, no matter how complex it is, no matter how often do you change it (except when you do this every minute ... ), if it is stolen, you are screwed. 2FA might save you, or might not.

Attacking the encrypted password 

This is the usual "hack the webserver (via SQL injection), dump the passwords (with SQLMap), post hashes on pastebin, everybody starts the GPU farm to crack the hashes" scenario. This is basically the only scenario where the password policies makes sense. In this case the different level of passwords need different protection levels. In some cases, this attack turns out to be the same as the previous attack, when the passwords are not hashed, or are just encoded.

The current hash cracking speeds for hashes without any iterations (this is unfortunately very common) renders passwords like Q@tCB3nx (8 character, upper-lowercase, digit, special characters) useless, as those can be cracked in hours. Don't believe me? Let's do the math.

Let's say your password is truly random, and randomly choosen from the 26 upper, 26 lower, 10 digit, 33 special characters. (Once I tried special passwords with high ANSI characters inside. It is a terrible idea. Believe me.). There are 6 634 204 312 890 620 different, 8 character passwords from these characters. Assuming a 2 years-old password cracking rig, and MD5 hash cracking with 180 G/s speed, it takes a worst case 10 hours (average 5) to crack the password, including upgrading your bash to the latest, but still vulnerable bash version. Had the password been 10 characters long, it would take 10 years to crack with today hardware. But if the password is not truly random, it can be cracked a lot sooner.

A lot of common hashing algorithms don't use protections against offline brute-force attacks. This includes LM (old Windows hashes), NTLM (modern Windows hashes), MD-5, SHA1-2-512. These hashing algorithms were not developed for password hashing. They don't have salting, iterations, etc. out of the box. In the case of LM, the problem is even worse, as it converts the lowercase characters to uppercase ones, thus radically decreasing the key space. Out of the box, these hashes are made for fast calculation, thus support fast brute-force.


Another attack is when the protected thing is not an online service, but rather an encrypted file or crypto-currency wallet.

Attacking the authentication system online

This is what happened in the recent iCloud hack (besides phishing). Attackers were attacking the authentication system, by either brute-forcing the password, or bypassing the password security by answering the security question. Good passwords can not be brute-forced, as it takes ages. Good security answers have nothing to do with the question in first place. A good security answer is as hard to guess as the password itself. If password recovery requires manual phone calls, I know, it is a bit awkward to say that your first dog name was Xjg.2m`4cJw:V2= , but on the other hand, no one will guess that!


Attacking single sign on

This type of attack is a bit different, as I was not able to put the "pass the hash" attacks anywhere. Pass the hash attack is usually found in Windows domain environments, but others might be affected as well. The key thing is single sign on. If you can login to one system (e.g. your workstation), and access many different network resources (file share, printer, web proxy, e-mail, etc.) without providing any password, then something (a secret) has to be in the memory which can be used to to authenticate to the services. If an attacker can access this secret, he will be able to access all these services. The key thing is (again) it does not matter, how complex your passwords are, how long it is, how often do you change, as someone can easily misuse that secret.

 

Attacking 2FA

As already stated, 2 factor authentication raises the efforts from an attacker point of view, but does not provide 100% protection. 
  • one time tokens (SecurID, Yubikey) can be relayed in a man-in-the-middle attack
  • smartcard authentication can be relayed with the help of a malware to the attacker machine - or simply circumvented in the browser malware, 
  • text based (SMS) messages can be stolen by malware on the smartphone or rerouted via SS7, 
  • bio-metric protection is constantly bypassed,
  • SSH keys are constantly stolen,
  • but U2F keys are pretty good actually, even though BGP/DNS hijack or similar MiTM can still circumvent that protection,
  • etc. 


Others

Beware that there are tons of other attack methods to access your online account (like XSS/CSRF), but all of these have to be handled on the webserver side. The best you can do is to choose a website where the Bug Bounty program is running 24/7. Otherwise, the website may be full of low hanging, easy-to-hack bugs.

Now that we have covered what we want to protect against what, in the next blog post, you will see how to do that. Stay tuned. I will also explain the title of this blog post.Related word
  1. Hacking Tools
  2. Hack Tools Github
  3. Hacker Tools Windows
  4. Hack Rom Tools
  5. Pentest Tools For Ubuntu
  6. Growth Hacker Tools
  7. Hack Tools For Mac
  8. Hacker Tools Software
  9. Hacker Tools Free
  10. Hacking Tools Online
  11. Hacking Tools 2020
  12. Tools For Hacker
  13. Blackhat Hacker Tools
  14. Tools For Hacker
  15. Hacker Tools For Ios
  16. Pentest Tools Website
  17. Best Hacking Tools 2020
  18. Blackhat Hacker Tools
  19. Wifi Hacker Tools For Windows
  20. New Hacker Tools
  21. Hacker
  22. Hacking Tools Windows 10
  23. Bluetooth Hacking Tools Kali
  24. Tools For Hacker
  25. Pentest Tools Linux
  26. Usb Pentest Tools
  27. Hacker Tools
  28. Android Hack Tools Github
  29. Hack Tools Online
  30. Hacker Tools Software
  31. Hacker Tools Github
  32. Tools Used For Hacking
  33. Hacking Tools For Windows Free Download
  34. Pentest Tools For Ubuntu
  35. Termux Hacking Tools 2019
  36. Pentest Tools Tcp Port Scanner
  37. Hacking Tools 2020
  38. Pentest Tools For Ubuntu
  39. Pentest Tools Github
  40. Pentest Tools For Ubuntu
  41. Wifi Hacker Tools For Windows
  42. What Are Hacking Tools
  43. Hacker
  44. Hacker Tools
  45. Pentest Tools Open Source
  46. Hack Tools Pc
  47. Hacker Tools 2020
  48. Hacking Tools 2020
  49. Hacking Tools Windows 10
  50. Pentest Tools Linux
  51. Hackrf Tools
  52. Pentest Tools Subdomain
  53. Hack Rom Tools
  54. Hacking Tools For Kali Linux
  55. What Is Hacking Tools
  56. Pentest Tools Framework
  57. Pentest Tools Port Scanner
  58. Pentest Tools Nmap
  59. Underground Hacker Sites

AutoNSE - Massive NSE (Nmap Scripting Engine) AutoSploit And AutoScanner


Massive NSE (Nmap Scripting Engine) AutoSploit and AutoScanner. The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features. It allows users to write (and share) simple scripts (using the Lua programming language ) to automate a wide variety of networking tasks. Those scripts are executed in parallel with the speed and efficiency you expect from Nmap. Users can rely on the growing and diverse set of scripts distributed with Nmap, or write their own to meet custom needs. For more informations https://nmap.org/book/man-nse.html

Installation
$ git clone https://github.com/m4ll0k/AutoNSE.git
$ cd AutoNSE
$ bash autonse.sh

Exmaples
$ bash autonse.sh




Read more
  1. Hacker Tools Linux
  2. New Hack Tools
  3. Game Hacking
  4. Hacking Tools For Pc
  5. Pentest Tools Subdomain
  6. Pentest Tools Tcp Port Scanner
  7. Pentest Tools Linux
  8. Hack Tools
  9. Hacker Tools 2019
  10. Wifi Hacker Tools For Windows
  11. Pentest Tools List
  12. Nsa Hack Tools Download
  13. Hacking Tools For Games
  14. Hacker Tools Github
  15. Hack Tools
  16. Pentest Tools Framework
  17. Physical Pentest Tools
  18. Hacker Tools For Pc
  19. Hacker Tool Kit
  20. Hacking Tools 2019
  21. Pentest Tools Framework
  22. Pentest Recon Tools
  23. Pentest Tools
  24. Hacking Tools For Windows 7
  25. Tools 4 Hack
  26. Hack Tools For Mac
  27. Pentest Tools Url Fuzzer
  28. What Is Hacking Tools
  29. Pentest Tools Website
  30. Hacking Tools And Software
  31. Hack Tools For Windows
  32. Hacker Tools For Ios
  33. Free Pentest Tools For Windows
  34. Hacking Tools For Windows 7
  35. What Is Hacking Tools
  36. Hack Tools
  37. Pentest Tools Open Source
  38. Pentest Tools Open Source
  39. Pentest Recon Tools
  40. Install Pentest Tools Ubuntu
  41. Hacking Tools Github
  42. Bluetooth Hacking Tools Kali
  43. Hacking Tools Online
  44. Hacking Tools Usb
  45. Hack Tools For Games
  46. Hack Tools For Windows
  47. Hacking Tools Free Download
  48. Hack Tools For Windows
  49. Bluetooth Hacking Tools Kali
  50. Hacking App
  51. Hack And Tools
  52. Pentest Tools Website Vulnerability
  53. Hack Tool Apk
  54. Hacker Security Tools
  55. Pentest Tools Free
  56. Pentest Tools Linux
  57. Hack Tools Github
  58. What Is Hacking Tools
  59. Pentest Tools Github
  60. Nsa Hack Tools Download
  61. Hacking Tools For Windows 7
  62. Hacking Tools Mac
  63. Hacking Tools 2019
  64. Hacking Tools Free Download
  65. Hack Apps
  66. Hack Tools Online
  67. Pentest Tools Framework
  68. Install Pentest Tools Ubuntu
  69. Hacker Tools Online
  70. Best Hacking Tools 2020
  71. Kik Hack Tools
  72. Hack Tools For Windows
  73. Hack Tools For Windows
  74. Top Pentest Tools
  75. Hackers Toolbox
  76. Computer Hacker
  77. Tools Used For Hacking
  78. Pentest Tools For Mac
  79. Pentest Tools For Ubuntu
  80. Pentest Tools List
  81. Pentest Tools Download
  82. Pentest Tools Review
  83. Top Pentest Tools
  84. Tools For Hacker
  85. Android Hack Tools Github
  86. Blackhat Hacker Tools
  87. Hacking Tools Free Download
  88. Pentest Tools Online
  89. Hack Tools Pc
  90. Underground Hacker Sites
  91. Hacking Tools Github
  92. Hacking Tools For Windows Free Download
  93. Hacking Tools 2020
  94. Pentest Tools Github
  95. Hacker Tools Linux
  96. Hacker Security Tools
  97. Pentest Tools Url Fuzzer
  98. Hacking Tools Windows 10
  99. Hack Tools For Games
  100. Hacker Tools Software
  101. Pentest Tools Website Vulnerability
  102. Hacking Tools And Software
  103. Android Hack Tools Github
  104. Hacker Tools For Pc
  105. Tools Used For Hacking
  106. Hack Website Online Tool
  107. Hacker Tools 2019
  108. Hack Tools For Windows
  109. Pentest Reporting Tools
  110. Hacking Tools And Software
  111. Hacking Tools For Windows Free Download
  112. Free Pentest Tools For Windows
  113. Pentest Tools Tcp Port Scanner
  114. Hacker Tools For Mac
  115. Github Hacking Tools
  116. Pentest Tools Free
  117. Pentest Tools Online
  118. Hacker Tool Kit
  119. Hack Tools For Mac
  120. Hacker Tools
  121. Hacking Tools Pc
  122. Hacker Tools 2020
  123. Hacking Tools Name
  124. Hacking Tools Name
  125. Hacking Tools For Games
  126. Hacker Tools Software
  127. Hacker Tools Windows
  128. Pentest Tools Download
  129. How To Install Pentest Tools In Ubuntu
  130. Hacking Tools For Kali Linux
  131. Hacker Search Tools
  132. Hacker Techniques Tools And Incident Handling
  133. Hacker Tools Mac
  134. Best Hacking Tools 2020
  135. Hacking Tools Kit
  136. Nsa Hacker Tools
  137. Hack Tools For Ubuntu
  138. Hacking Tools Github
  139. Hack Rom Tools
  140. Hacker Tools For Mac
  141. How To Make Hacking Tools
  142. Hacker Tools Software
  143. Hacking Tools For Windows 7
  144. Hacker Tools
  145. Hack Rom Tools
  146. Hacking Tools Github
  147. Pentest Reporting Tools
  148. Computer Hacker
  149. Best Hacking Tools 2020
  150. Hacker Tools Apk
  151. Hack Tools For Games

Smart Contract Hacking Chapter 1 - Solidity For Penetration Testers Part 1 (Hello World)

 

Note: We will start off our Smart Contract Hacking journey with some basic solidity programming in the first two weeks. After that we will ramp things up and get a little crazy deploying blockchains and liquidating funds from accounts. But since the purpose of this series is to share the information I have learned over the last two years.  I do not want to alienate those new to Smart Contracts and programming so we will take these first few weeks a bit slow. 

Also note the text was taken from a book I was / am writing, I retrofitted it for this blog, and placed videos where screenshots may otherwise exist. If something seems off.. Just DM me on twitter and I will update it anything I might have missed during editing, but I tried to edit it as best as possible to meet this format rather then a book. 

Cheers  @Fiction 

http://cclabs.io

Thanks to @GarrGhar for helping me edit/sanity check info for each of the chapters. 


About Solidity

The solidity programming language is the language used to write smart contracts on the Ethereum blockchain. As of my initial writing of this chapter the current compiler version was 0.6.6. However, the versions change rapidly. For example, when I started coding in solidity 2 years ago, solidity was in version 4 and now its version 7 with major library and coding stylistic requirement updates in version 5. 

So, note that when compiling your code for labs its best to use the version sited in that particular example. This is easily achieved in the online compilers, by selecting the compiler version from the dropdown menu. If you would like to give yourself a small challenge, use the latest compiler version and try to modify the code to work with it. Usually this just requires a few minor modifications and can be a good learning experience under the hood of how Solidity works and what has changed.

Solidity is very similar to writing JavaScript and is fully object oriented. In the intro chapters we will attempt to provide a quick overview of solidity understanding needed for a penetration tester. This will not be full guide to programming, as programming is considered to be a pre-requisite to application hacking. Instead this chapter will be a gentle introduction of needed concepts you will use throughout this book. Solidity is also a needed pre-requisite for understanding the rest of the information and its associated exploitation course. 

However, as long as you understand general programming concepts then you should have no trouble understanding solidity. It is a relatively easy language to get up and running with quickly in comparison to more mature languages like C++ and Java which may take a more significant amount of time to learn.

The most important thing to understand with solidity is that unlike traditional languages, solidity handles transactions of monetary value by default. Meaning you don't need to attach to a payment API to add transactions to your applications. Payment functionality is baked into the language as its primary purpose and for usage with the Ethereum blockchain.  All that's needed for financial transactions in solidity is a standard library transfer function, and you can easily send value to anyone's public address. 

For example, the following simple function will transfer a specified amount of Ether to the user calling the function provided they have a large enough balance to allow the transfer. But lets not dive into that just yet. 

 

1.  function withdraw (uint amount) {
2.     require (amount <= balances[msg.sender]);
3.     msg.sender.transfer(amount);
4.  }

 

Structure of a Smart Contract

Rather than discuss payments at this point, let's not jump to far ahead of ourselves. We need to understand the structure of a smart contract. Let's take a look at a Hello World example. We will analyze all of the key aspects that make solidity different then other languages you may currently understand.

You can easily follow along with this on http://remix.ethereum.org which is a free online IDE and compiler for coding in solidity. A full video walk through of Remix is included later on in this chapter.  Remix contains in-browser compilers and virtual environments that emulate block creation and allow you to send and receive transactions.  This is a powerful development tool and absolutely free to use. 

Below is the simple code example we will analyze before moving on to a live walk through. 

1.  pragma solidity 0.6.6; 
2.   
3.  contract HelloWorld {
4.           
5.     constructor () public payable {
6.           //This is a comment
7.           //You can put your configuration information here
8.     }
9.   
10.   function hello () public pure returns (string memory) {
11.                  return "Hello World";
12.         }
13.}

 

There is a lot going on in this small program so I will try to break it down as simple as possible. In the first line, we have the pragma statement which is required at the top of each program to let the compiler know which version of solidity this code was written for.  As I said earlier, these versions change rapidly due to the evolving technology and many changes are implemented into each new version. So, the compiler needs to know which version you intended this to run on.

On line 3 is the word "contract" followed by whatever name you wish to call your contract. The contract's functionality is then enclosed in curly braces. This is similar to creating a class in any other language. It's a block of associated code that can be inherited, or interfaced with and contains its own variables and methods.

On line 5 contained within the contract curly braces we have a constructor denoted by the word "constructor".  The constructor is run one time at contract creation and used to setup any variables or details of the smart contract. This is often used for creating an administrator of the contract or other items that are needed prior to contract usage. 

Functions and variables within Solidity also have various types and visibility set with their creation.  In this case also on line 5 you will see the words "public" and "payable" used to describe the constructor. 

Public you may be familiar with as it's a common visibility keyword used in other languages denoting that anyone can call this function. There are other visibility types in Solidity listed below, we will cover each of these in more detail as we use them to our advantage when hacking smart contracts:

 

Public

This allows anyone to call and use this function

 

Private

This allows only the current contract and its functions to call it directly.

 

Internal

This is similar to private except it also allows derived contracts to use its functionality

 

External

External can only be called externally by other contracts unless the "this" keyword is used with the function call.

 

The second keyword in the constructor definition "payable" you may not be familiar with unless you have worked on blockchain projects. The word payable within solidity is needed on any item that can receive Ether. So, by setting the constructor as payable we can send a base amount of Ether to the contract when its deployed. This will add an initial monetary liquidity for whatever functionality the contract is providing. For example, if this were a gambling game, we would need some initial Ethereum to payout our winners before our revenues catch up with our payouts and we start collecting large sums of failed gambling revenue. 

Within the constructor is an example of how comments are handled in solidity, the simple double forward slash is used like in most languages. Comments function in the same way as any other language in that they are not processed and they are ignored by the compiler but are useful for understanding the code you wrote later after you have taking time apart from reading your code.

Finally, we have our simple hello function starting on line 10. Again, there is a lot going on here. First is the name of the function with parentheses that can contain arguments like in any other language. However, this function does not take arguments.

You will notice two more keywords in the function definition "pure" and "returns". Returns is simply the way the function denotes that it will return a value to the user, which it then states directly after it what type of variable it returns. In this case, it returns a string in memory.  We will talk about memory and storage later on and the security implications of them.

Next is the word "Pure" there are a couple types of functions in Solidity which will list below with a brief description.


View

This type of function does not modify or change the state of the contract but may return values and use global variables.

Pure

A pure function is a function which is completely self-contained in that it only uses local variables and it does not change the state of the smart contract.


Finally, in line 11 we return our string to the user who called the function. In the context of a user, this could be a physical user using an application or smart contract functionality or it could actually be another smart contract calling the function.

 

Hands on Lab – Remix HelloWorld

Now that we talked over in detail all the new concepts to solidity programs using a small example, lets compile and run this code on remix.ethereum.org.

Action Steps:

ü Browse to remix.etherum.org
ü Type out the the code from above (Do not copy Paste it)
ü Compile and deploy the code
ü Review the transaction in the log window

 

Intro to the Remix Development Environment Video


In Remix create a new file and type out the example helloworld code.  I would suggest that you actually type out all of the examples in this book. They will not be exhaustive or long and will provide you great value and make you comfortable when it comes to writing your own exploits and using the compilers and tools. These are all essential tools to your understanding.

Within your remix environment, you will want to select the compiler version 0.6.6 to ensure that this code runs correctly. If you typed out the code correctly you should not receive any errors and you will be able to deploy and interact with it. In the following video we will walk you through that process and explain some nuances of solidity. 


Explaining and Compiling HelloWorld Video: 




     

    Lets now quickly review a few key points about the transaction that you saw within the video when compiling your code. This transaction is shown below. 

    __________________________________________________________________________________

    call to HelloWorld.hello

    CALL

    from      0xBF8B5A94eD4dFB45089b455B1A0e296D6669c625

     to           HelloWorld.hello() 0xADe285e11e0B9eE35167d1E25C3605Eba1778C86

     transaction cost               21863 gas (Cost only applies when called by a contract)

                                             execution cost 591 gas (Cost only applies when called by a contract)

     hash     0x14557f9552d454ca865deb422ebb50a853735b57efaebcfc9c9abe57ba1836ed

     input    0x19f...f1d21

     decoded input {}

     decoded output               {

                    "0": "string: Hello World"

    }

     logs       []

    _________________________________________________________________________________

     

    The output above is a hello transaction which contains the relevant data retrieved when you executed the hello function in the video. The first important thing to notice is the word "CALL". In solidity there are call and send transactions. The difference between the two is whether they change the state of the blockchain or not. In this case we did not change the state, we only retrieved information so a CALL was issued.  If we were changing variables and sending values then a SEND transaction would have been issued instead.

    Next you will see the "From" address which should correspond with the address you used to call the transaction.  The "To" field should be the address the smart contract was given when you deployed the smart contract. You can view this on your deployment screen next to the deployed contract name by hitting the copy button and pasting it somewhere to see the full value.

    You will then see the costs and gas associated with the transaction. Costs change based on the size of the contracts and the assembly code created by the compiler. Each instruction has a cost. We will cover that later when we do a bit of debugging and decompiling. 

    Finally take note of the Decoded Output which contains the return string of "Hello World".

     

    Summary

    If you are new to solidity or new to programming in general this might have been a lot of information.  In the next chapter we cover a few more key solidity concepts before moving on to exploiting vulnerabilities where a much more in depth understanding of how solidity works and its security implications will be explored. For more solidity resources and full-length free tutorials check out the following references

      

    Homework:

    https://cryptozombies.io/en/course/

    More information