Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungWhy Claude Code keeps writing shell commands that fail on your Mac(20.09.2026 um 21:06 Uhr)
Sichere Programmierungllms.txt v2: What the Spec Says, and What 137,000 Domains Show(20.09.2026 um 21:17 Uhr)
Sicherheitslücken (CVE)NiceTryGPT: Less pattern matching. More actual hacking.(20.09.2026 um 21:19 Uhr)
IT Security VideoActivities BoF (kde2026)(20.09.2026 um 00:00 Uhr)
IT Security Toolsirdoc-app(20.09.2026 um 20:33 Uhr)
Sichere ProgrammierungWhy Claude Code keeps writing shell commands that fail on your Mac(20.09.2026 um 21:06 Uhr)
Sichere Programmierungllms.txt v2: What the Spec Says, and What 137,000 Domains Show(20.09.2026 um 21:17 Uhr)
Sicherheitslücken (CVE)NiceTryGPT: Less pattern matching. More actual hacking.(20.09.2026 um 21:19 Uhr)
IT Security VideoActivities BoF (kde2026)(20.09.2026 um 00:00 Uhr)
IT Security Toolsirdoc-app(20.09.2026 um 20:33 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Web3 will bite you in the Web 2 0 exploring IPFS threats - Morton Swimmer (Trend Micro)

Reagiere als Erste:r — dein Feedback zählt!

Author: Virus Bulletin - Bewertung: 0x - Views:1

Presented at the VB2023 conference in London, 4 - 6 October 2023. ↓ Slides: N/A ↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2023/papers/Web3-will-bite-you-in-the-Web-20-exploring-IPFS-threats.pdf → Details: https://www.virusbulletin.com/conference/vb2023/abstracts/web3-will-bite-you-web-20-exploring-ipfs-threats/ ✪ PRESENTED BY ✪ • Morton Swimmer (Trend Micro) ✪ ABSTRACT ✪ Even though Web3 usage is still tiny compared with Web 2.0, that has not stopped bad actors from misusing some of its technology stack. Without the clear client-server architecture we are used to, the peer-to-peer nature of the storage layer of Web3 is able to fly under the radar and prevent normal methods of content filtering. In this presentation we will dive into IPFS as a technology to understand the idiosyncrasies of it and the ways in which it can be abused. Along the way, we have statistics that document the mounting dangers we have identified, and we will discuss how we can mitigate these. Objects in IPFS are content-addressed and not location-addressed. For this reason, blocking IP addresses or domains cannot work.We access an IPFS object by asking a distributed hash table to locate someone with a copy of the object we can pull it from in a peer-to-peer manner, not unlike how BitTorrent works. Objects can be both file-like as well as directory-like, making distributed web hosting a reality. But content-addressing, by design, is not mutable, so there exists a mutable addressing scheme as well, called IPNS, that enables a constant 'name' to point to current content. Ensuring that content is well replicated requires the pinning method to be used and that is supported by services like Pinata or FileCoin. For those not willing to run the IPFS daemon, access is also available through a variety of IPFS gateways. Despite the lacklustre uptake of IPFS for legitimate applications, we have seen a steady increase in phish and malware hosting, which will be discussed in this presentation, as well as why some of the problems for legitimate use of IPFS turn out to be positive for bad actors. We are also seeing increasing support for IPFS in browsers and application platforms, which may lead to increasing legitimate use and therefore greater difficulty in distinguishing bad from good IPFS usage. Further developments of Web3 technology will also be discussed as many may become dangers to our users in the future. Finally, we look at options for blocking malicious IPFS content.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Web3 will bite you in the Web 2 0 exploring IPFS threats - Morton Swimmer (Trend Micro)

Thematisch verwandte Begriffe: Web3, will, bite, exploring · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick