By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
softwareprosoftwarepro
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Search
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Softwareproz.com/knowledge resources for software developers. All Rights Reserved.
Reading: Attackers can reveal identities of those using the largest NFT marketplace, research finds
Share
Notification Show More
Latest News
Colorful films could help buildings, cars keep their cool
Automotive Business Computer Sciences Consumer & Gadgets Electronics & Semiconductors Energy & Green Tech Engineering Hardware Hi Tech & Innovation Internet Machine learning & AI
Technical issues at Lufthansa cause delays in Frankfurt
Automotive Business Computer Sciences Consumer & Gadgets Electronics & Semiconductors Energy & Green Tech Engineering Hardware Hi Tech & Innovation Internet Machine learning & AI
All businesses will soon be able to offer their own debit cards
Audio Digital Home Gaming Home Cinema Mobile Computing
Quordle today – hints and answers for Sunday, March 26 (game #426)
Audio Digital Home Gaming Home Cinema Mobile Computing
Shells of dead crabs could be used to make cheaper optical components
Audio Digital Home Gaming Home Cinema Mobile Computing
Aa
softwareprosoftwarepro
Aa
Search
  • Home
  • A/B Testing Tools
    • Accounting Software
    • Ad Serving & Retargeting Platforms
    • All-in-One Marketing Platforms
    • Applicant Tracking Systems (ATS)
    • Business Intelligence (BI) Tools
    • Cloud Storage Systems
    • Collaboration Tools
    • Content Management(CMS)
    • Corporate Learning Management
  • Agile
    • AI
    • Big Data
    • Cloud
    • Database
    • Devops
    • Integration
    • IoT
    • Java
    • Guest Posting
  • Customer Relationship (CRM)
    • Email Marketing Software
    • Fraud Detection Software
    • Help Desk Software
    • HR Management Software
    • Integration Platform as a Software
    • Marketing Automation Software
    • Network Performance Monitoring
    • Payroll Software
  • Project Management Software
    • SEO Software
    • Social Media Management Tools
    • Talent Intelligence Tools Solutions
    • Talent Management
    • Web Analytics Tools
    • Web and Video Conferencing
    • Workforce Analytics Software
    • Workforce Management Software
  • Accessibility Testing Tools
    • Agile Development Software
    • Augmented Development Platforms
    • Automation Testing Tools
    • Batch Management Software
    • Beta Testing Software
    • Bug Tracking Software
  • More
    • Microservices
    • Open Source
    • Performance
    • Security
    • Web Dev
    • Automotive
    • Business
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
Follow US
  • Consumer & Gadgets
  • Electronics & Semiconductors
  • Energy & Green Tech
  • Engineering
  • Hardware
  • Hi Tech & Innovation
  • Internet
  • Machine learning & AI
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
softwarepro > Blog > Audio > Attackers can reveal identities of those using the largest NFT marketplace, research finds
AudioDigital HomeGamingHome CinemaMobile Computing

Attackers can reveal identities of those using the largest NFT marketplace, research finds

Last updated: 2023/03/13 at 7:00 PM
Share
SHARE

OpenSea, arguably the world’s most popular marketplace for non-fungible tokens (NFT) was carrying a vulnerability that allowed hackers to deanonymize users and possibly even reveal their full identities. 

This is according to a new report from cybersecurity researchers part of the Red Team at Imperva, who notified OpenSea, and later confirmed that the vulnerability had been properly addressed.

In a blog post detailing the findings, Imperva’s researchers said that the OpenSea website carried a cross-site search vulnerability, as it didn’t restrict cross-origin communication. At the root of the problem was the iFrame-resizer library.

Exposing NFT owners

The researchers explained: “The iFrame-resizer library broadcasts the width and height of the page, which can be used as an “oracle” to determine when a given search returns results because the page is smaller when a search returns zero results. By continuously searching the user’s assets, which is done cross-origin through a tab or popup, an attacker can leak the name of an NFT created by the user, thereby revealing their public wallet address. This information can associate the user’s identity with the leaked NFT and public wallet address.” 

Read more

> Another top NFT marketplace may have a serious security flaw

> NFT marketplace OpenSea had some serious security flaws

> Check out the best firewalls right now

As a result, the victims might have their identities exposed, the researchers concluded.

To exploit the flaw, an attacker could send a link to the victim, be it via email, SMS, or any other communication channel. By clicking on the link, the victim reveals valuable information such as IP address, user agent, device details, software versions, ad similar.

Next, the attacker would exploit the cross-site search vulnerability to extract one of the target’s NFT names. And by associating the leaked NFT/public wallet address with the target, the attacker might expose the victim’s true identity.

After disclosing the flaw to the marketplace, OpenSea “quickly” released a patch, the researchers said. The flaw was addressed by restricting cross-origin communication, thus mitigating the risk of further exploitation, they concluded.

Here’s our list of the best anonymous browsers at the moment

You Might Also Like

All businesses will soon be able to offer their own debit cards

Quordle today – hints and answers for Sunday, March 26 (game #426)

Shells of dead crabs could be used to make cheaper optical components

New Pixel Tablet leaks include images of the Pixel Stand accessory

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article Sorry Microsoft: not even a full-page ad will make people want to use Edge
Next Article SYS01 stealer targets Facebook business accounts and browser credentials
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow
banner banner
Create an Amazing Newspaper
Discover thousands of options, easy to customize layouts, one-click to import demo and much more.
Learn More

Latest News

Colorful films could help buildings, cars keep their cool
Automotive Business Computer Sciences Consumer & Gadgets Electronics & Semiconductors Energy & Green Tech Engineering Hardware Hi Tech & Innovation Internet Machine learning & AI
Technical issues at Lufthansa cause delays in Frankfurt
Automotive Business Computer Sciences Consumer & Gadgets Electronics & Semiconductors Energy & Green Tech Engineering Hardware Hi Tech & Innovation Internet Machine learning & AI
All businesses will soon be able to offer their own debit cards
Audio Digital Home Gaming Home Cinema Mobile Computing
Quordle today – hints and answers for Sunday, March 26 (game #426)
Audio Digital Home Gaming Home Cinema Mobile Computing
//

We influence 20 million users and is the number one business and technology news network on the planet

Quick Link

  • Audio
  • Digital Home
  • Emerging Technology
  • Enterprise Application
  • Gaming
  • Mobile and Wireless
  • Networking
  • Operating System
  • Photography Video Capture

Blog Categories

  • Environment
  • Health
  • science
  • Technology
  • Amazon
  • Analyst Insights
  • Android
  • Apple
  • Ecommerce

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!
softwareprosoftwarepro
Follow US

© 2022 Software Pro News Network. Software Pro Design Company. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Register Lost your password?