🌐 Affected Application: ArcBlock Marketplace 📍 URL: https://marketplace.arcblock.io/auctions https://marketplace.arcblock.io/auctions 📂 Module: Auction → Purchase Function 🧾 Summary: When attempting to purchase an item from the auction section, the transaction fails to process and displays an error
#security
带有此标签的讨论
社区指南
最新发布
🐛 Summary When users change the language setting in the DID Wallet, the app automatically logs them out. This disrupts the user experience and forces re authentication. 🔁 Steps to Reproduce 1. Open the DID Wallet mobile app . 2. Log in to your account. 3. Navigate to Settings → Language. 4. Change t
1. Description The DID Wallet app enables TouchID for authentication without requiring the user to first enter their password. This bypasses the standard security flow, creating a risk of unauthorized access if the device is stolen or shared. 2. Steps to Reproduce Open the DID Wallet app. Attempt to
小A有一份教育学习资料文件A 在平台上传用于自己的备份资料,然后平台就有一份文件A 小A私下发给小B,然后小B想分享出去,但是又不想让别人知道是小A的文件,小B于是将文件修改名字为文件B 现在的问题是:小B分享出去的时候,文件命名为文件B,但是,发送文件出去的时候,显示的是小A的文件A ! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreidrirpydfycos4tra2q7khmehrmld72shxxasmzuio2uzfqvv77m4.webp
! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreigz6yriqs4wtwjzl4gqrc34nkw6yzhvbnzsjz6pfkwk734znxhrrq.webp https://community.arcblock.io/api/chat/chats/1 1 https://community.arcblock.io/api/chat/chats/1 1 javascript {"code": 1,"message":"Chat 1 1 does not exist."} 虽然没有
! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreib2ejbluhwjfejcjyqgyi767oxuuks5iufs7lxcefquyigwbnnkoa.webp https://community.arcblock.io/api/embed/og?url=https%3A%2F%2Fwww.baidu.com%2Ftest?dd=og1255 https://community.arcblock.io/api/embed/og?url=https%3A%2F%2Fwww.baidu
看下面帖子评论 今天发帖子没有积分 /posts/db919ae4 3c45 4078 b25d 9834dae42e19/ ! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreiglrnkwc5x2fs2pnijxxz2mv2n3lfgzo2ldpqybtohmees7naii7i.webp
这个地址 https://www.arcblock.io/content/docs/arcblock/zh/android engineer career /zh/docs/arcblock/android engineer career/ 的评论里面有个插件可被执行xss攻击
https://www.arcblock.io/.well known/service/blocklet/og.html?title=%3Ca%20href=http://www.baidu.com%3E%E6%81%AD%E5%96%9C%E4%BD%A0%E8%8E%B7%E5%BE%97100Abt&description=%3Ca%20href=http://www.baidu.com%3E%E7%82%B9%E5%87%BB%E8%8E%B7%E5%8F%96 https://www.arcblock.io/.well known/service/blocklet/og.html?t
In relation to this comment, the team said we’ll be rewarded more for further identifying fake accounts that bypassed the AIGNE test: ! IMG 5555.jpeg https://media.arcblock.community/blocklets/discuss kit/media/bafkreicmgo4xnotpgwetf5jv3f5k4azjzwtca3lja52la2mvt6sae64jjy.webp Overall, AIGNE did a goo
As mentioned earlier this month, since the event is approaching a closing time: this event has been joined by now hundreds of fake accounts, likely made by same user. Majority of the fake profiles look like this example below, all joined DID wallet this month and have no posts: ! IMG 5403.png https:
Similar situation as to this previous rewards exploit: https://community.arcblock.io/discussions/b033052c 588a 4e97 88ac 7393f7d5a7ec /posts/b033052c 588a 4e97 88ac 7393f7d5a7ec/ KYC didn’t stop this person to keep doing the same thing now for the 2025 reward pool, 80% of those accounts entered are
容易被当成图床私人使用 https://community.arcblock.io/uploads/d110aef3dac0a61326955a2cd6286f73.mp4 https://community.arcblock.io/uploads/d110aef3dac0a61326955a2cd6286f73.mp4
这个接口不需要鉴权,而且返回了别人邮箱数据,会被别人遍历一波,窃取对应的邮箱数据,钓鱼 https://community.arcblock.io/api/profile/user/z1WnD78zE8z24B27SiDqBo2PryG1oaQttPw https://community.arcblock.io/api/profile/user/z1WnD78zE8z24B27SiDqBo2PryG1oaQttPw javascript {"did":"z1WnD78zE8z24B27SiDqBo2PryG1oaQttPw","fullName":"ystat","avatar":"/.wel
Summary: I've found a TEXT/CODE injection Bug on your site https://www.arcblock.io https://www.arcblock.io . /.well known/service/blocklet/og.png?title= parameter is vulnerable to TEXT/CODE injection. Steps To Reproduce: 1. Go to https://www.arcblock.io/.well known/service/blocklet/og.png?title=You%
Link : https://www.aigne.io/en https://www.aigne.io/en Brief Description: I found that this site is missing several important security headers: Content Security Policy , Referrer Policy , and Permissions Policy . The lack of these headers may increase security risks and reduce user privacy. Details
did:abt:z1eXeSQCEUf45SHqLm1AcSB9E7ggoGRFmAN Hey everyone, I’ve noticed some unusual activity regarding the monthly 200 ABT reward pool. It seems that multiple accounts are funneling rewards to a single wallet, potentially exploiting the system. I’m not a detective, so I apologize if I get this wrong
! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreiek7yeemxkygdq6xusjza37hoda2nh46xwimzzize2denpw4yuiky.webp link : https://www.aigne.io/en https://www.aigne.io/en While analyzing the backlinks for a specific page, I noticed that the system seems to show a disproportiona
! image.png https://media.arcblock.community/blocklets/discuss kit/media/bafkreifa4ct7ok2uzu776vaur622vtfzmq5j2oo4mqh3rokosfsivmlfwy.webp Vulnerability description: i found the robots.txt on the target server. This file instructs web crawlers what URLs and endpoints of the web application they can v