Cloud

4/25/2018
05:10 PM
50%
50%

Free New Tool for Building Blockchain Skills

Blockchain CTF helps pros build skills with simulations.

Blockchain is understood to be an inherently secure technology, but that doesn't mean every implementation of blockchain is secure. A new tool, Blockchain CTF, can help train software developers, security professionals, and blockchain experts to design and implement more secure blockchain applications.

Blockchain CTF (which stands for "capture the flag") is a simulator developed by Security Innovation, a company that provides security training, assessment, and consulting. Blockchain CTF is being released as a free resource for members of the security and blockchain communities.

With Blockchain CTF, participants see a series of vulnerable smart contracts and decentralized apps (DApps) in situations that range from initial coin offerings to open source lotteries. Participants are challenged to find and exploit the vulnerabilities and, in doing so, win points for placement on a leaderboard.

Within the simulations, Security Innovation provides tips and hints aimed at helping participants gain knowledge in developing and testing smart contracts and DApps. The platform is implemented as a client-side DApp on the Ethereum Testnet Blockchain, with states managed by the Ropsten Testnet Blockchain.

For more, see Blockchain CTF here.

Interop ITX 2018

Join Dark Reading LIVE for an intensive Security Pro Summit at Interop IT X and learn from the industry’s most knowledgeable IT security experts. Check out the agenda here.Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Mueller Probe Yields Hacking Indictments for 12 Russian Military Officers
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/13/2018
10 Ways to Protect Protocols That Aren't DNS
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Siri??  You're a guy?
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-10727
PUBLISHED: 2018-07-20
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive ...
CVE-2018-8018
PUBLISHED: 2018-07-20
Apache Ignite 2.5 and earlier serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a spe...
CVE-2018-14415
PUBLISHED: 2018-07-20
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-14418
PUBLISHED: 2018-07-20
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14419
PUBLISHED: 2018-07-20
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.