Close Menu
    X (Twitter)
    Blockchain Journal
    • News
      • Blockchain News
      • Bitcoin News
      • Ethereum News
      • NFT
      • DeFi News
      • Polkadot News
      • Chainlink News
      • Ripple News
      • Cardano News
      • EOS News
      • Litecoin News
      • Monero News
      • Stellar News
      • Tron News
      • Press Releases
      • Opinion
      • Sponsored
    • Price Analisys
    • Learn Crypto
    • Contact
    • bandera
    Facebook X (Twitter) Instagram
    Blockchain Journal
    Home » Critical vulnerability found in the NEO blockchain, comments from the NEO

    Critical vulnerability found in the NEO blockchain, comments from the NEO

    0
    By BlockchainJournal on December 3, 2018 News
    Share
    Facebook Twitter LinkedIn Pinterest Email

    chapter

    The Chinese technology corporation Tencent informed the developers of the blockchain protocol NEO and the node operators in their network about the presence of a vulnerability that could theoretically allow an attacker to remotely steal tokens or, as the researchers themselves call it, to engage in "remote piracy". About this he writes Blockmanity with reference to the publication posted by Tencent division in the social network Weibo.

    According to a statement by Tencent Security Lab, when a user launches a node on a network with a standard configuration, he is at risk. The company recommends all NEO node operators and GAS holders to pay attention to the security of their wallets and to update customers in a timely manner.

    Tencent proposes the following actions to protect itself from this vulnerability :

    • Upgrade to the latest version of the NEO-CLI client;
    • Try not to use remote procedure call (RPC) and manually change “BindAddress” to “127.0.0.1”;
    • If RPC is to be activated due to the need, try to change the port number of the RPC using the https port of JSON-PRC or install a firewall.

    The founder of the cryptocurrency NEO startup Eric Zhang commented on a vulnerability in the project protocol that allows attackers to steal users' tokens through the remote procedure call function.

    Zhang argues that the vulnerability does not threaten "regular users", since for its operation the RPC function must be activated in the NEO-CLI client, "the use of which is excluded by such users."

    Zhang Erik @neoerikzhang , founder and core developer of #NEO , denied the risk of theft for remote token normal users and explained the reasons from the technical point of view. See report below? pic.twitter.com/yKfXYbD8bs

    – NEO Smart Economy (@NEO_Blockchain) December 2, 2018

    He also draws attention to the fact that RPC is activated not by default, but only under certain conditions and through the command line. The same applies to the “BindAddress” option, which by default corresponds to the value “127.0.0.1”.

    "If the user does not attempt to change the configuration manually, the likelihood of associated risks may be excluded," the publication says.

    Accordingly, users who decide to change the configuration manually, Zhang can not guarantee anything. In mid-June, Chinese antivirus software developer Qihoo 360 reported that the incorrect configuration of certain applications and farms in the Ethereum network resulted in their users losing over $ 20 million at the exchange rate at that time.

    Late last week, NEO announced the opening of the Competence Center in St. Petersburg and the beginning of the development of a distributed file storage.


    blockchain Economy ethereum Featured GAS NEO Network Report Twitter
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    BlockchainJournal

    Related Posts

    ARK Invest Unloads Coinbase and GBTC Shares by Millions Amid Market Boom

    December 6, 20232 Mins Read

    GBTC Discount Shrinks as Bitcoin Price Surges

    December 6, 20232 Mins Read

    IBM Introduces OSO, Designed for Cold Storage of Digital Assets

    December 6, 20232 Mins Read

    Marathon Digital Produced 1,187 Bitcoins in November and Held 14,025 Unrestricted BTC

    December 5, 20232 Mins Read

    Volume Counterfeiting Allegations Rock RATS Token on Gate Exchange

    December 5, 20232 Mins Read

    A New Era for Cryptocurrency: Zodia Custody’s Integration with Harmonize

    December 4, 20232 Mins Read

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blockchain Journal

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.