市值: $2.8559T 0.10%
體積(24小時): $103.5716B 30.79%
  • 市值: $2.8559T 0.10%
  • 體積(24小時): $103.5716B 30.79%
  • 恐懼與貪婪指數:
  • 市值: $2.8559T 0.10%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$83957.731555 USD

1.09%

ethereum
ethereum

$2707.672309 USD

2.28%

tether
tether

$0.999601 USD

0.01%

bnb
bnb

$767.737573 USD

0.59%

xrp
xrp

$1.504228 USD

1.61%

usd-coin
usd-coin

$1.000070 USD

0.02%

solana
solana

$119.467955 USD

0.71%

tron
tron

$0.334923 USD

0.34%

zcash
zcash

$1422.665327 USD

-8.02%

hyperliquid
hyperliquid

$88.309849 USD

-0.91%

dogecoin
dogecoin

$0.094847 USD

2.10%

chainlink
chainlink

$15.113620 USD

9.67%

monero
monero

$542.499853 USD

1.68%

cardano
cardano

$0.249405 USD

1.76%

unus-sed-leo
unus-sed-leo

$9.063597 USD

-0.10%

加密貨幣新聞文章

Io.net 果斷行動平息網路安全漏洞,維護網路完整性

2024/04/28 19:03

在惡意行為者利用漏洞更改圖形處理單元 (GPU) 網路設備元資料後,安全漏洞迫使實體基礎設施網路 Io.net 實施更嚴格的措施。該攻擊於 4 月 25 日被偵測到,利用 SQL 注入和使用者 ID 令牌的暴露,但並未影響實際的 GPU 硬體。 Io.net 透過實施增強的身份驗證、SQL 注入檢查和增加日誌記錄來回應。

Io.net 果斷行動平息網路安全漏洞,維護網路完整性

Cybersecurity Breach: Io.net Decisive Action Maintains Network Integrity

網路安全漏洞:Io.net 採取果斷行動維護網路完整性

[Date] - Io.net, the decentralized physical infrastructure network (DePIN) provider, swiftly responded to a cybersecurity breach, protecting its network and mitigating potential damage. Malicious users exploited exposed user ID tokens to execute a SQL injection attack, leading to unauthorized changes in device metadata within the graphics processing unit (GPU) network.

[日期] - 去中心化實體基礎設施網路 (DePIN) 供應商 Io.net 迅速回應網路安全漏洞,保護其網路並減輕潛在損害。惡意使用者利用暴露的使用者 ID 令牌執行 SQL 注入攻擊,導致圖形處理單元 (GPU) 網路內的裝置元資料發生未經授權的變更。

Upon detection at 1:05 am Pacific Standard Time on April 25, Husky.io, Io.net's chief security officer, initiated immediate remedial actions to safeguard the network. Robust permission layers prevented the attack from compromising the GPUs' actual hardware, ensuring their continued security.

太平洋標準時間 4 月 25 日凌晨 1:05 發現這一情況後,Io.net 首席安全官 Husky.io 立即採取了補救措施來保護網路。強大的權限層可防止攻擊損害 GPU 的實際硬件,從而確保其持續的安全性。

Swift Response and Security Upgrades

快速回應和安全升級

Io.net's swift response included implementing SQL injection checks on APIs, enhancing logging for unauthorized attempts, and deploying a user-specific authentication solution using Auth0 with OKTA. These measures effectively addressed vulnerabilities related to universal authorization tokens.

Io.net 的快速回應包括對 API 實作 SQL 注入檢查、增強對未經授權嘗試的日誌記錄,以及使用 Auth0 和 OKTA 部署特定於使用者的驗證解決方案。這些措施有效解決了與通用授權令牌相關的漏洞。

Challenges and Mitigations

挑戰和緩解措施

Coincidentally, the security update overlapped with a snapshot of the rewards program, leading to a temporary decrease in supply-side participants. Legitimate GPUs that did not restart and update encountered difficulties accessing the uptime API, resulting in a drop in active GPU connections from 600,000 to 10,000.

無獨有偶,安全更新與獎勵計劃快照重疊,導致供應方參與者暫時減少。未重新啟動和更新的合法 GPU 在存取正常運行時間 API 時遇到困難,導致活動 GPU 連線從 600,000 下降至 10,000。

To address these challenges, Io.net initiated Ignition Rewards Season 2 in May to encourage supply-side participation. Ongoing efforts include collaborating with suppliers to upgrade, restart, and reconnect devices to the network.

為了應對這些挑戰,Io.net 於 5 月啟動了 Ignition Rewards 第二季,以鼓勵供應方參與。持續的努力包括與供應商合作升級、重新啟動設備並將其重新連接到網路。

Root Cause Analysis and Continuous Improvement

根本原因分析和持續改進

The breach originated from vulnerabilities introduced during the implementation of a proof-of-work mechanism designed to identify counterfeit GPUs. Aggressive security patches prior to the incident prompted an escalation in attack methods, necessitating continuous security reviews and improvements.

此次外洩源自於實施旨在識別仿冒 GPU 的工作量證明機制期間引入的漏洞。事件發生前的激進安全修補程式促使攻擊方法升級,需要持續的安全審查和改進。

Attacker Methodology

攻擊者方法論

Attackers exploited a vulnerability in an API to display content in the input/output explorer, inadvertently revealing user IDs when searching by device IDs. They compiled this leaked information into a database weeks before the breach.

攻擊者利用 API 中的漏洞在輸入/輸出瀏覽器中顯示內容,在按裝置 ID 搜尋時無意中洩漏使用者 ID。他們在洩漏事件發生前幾週將這些洩漏的資訊編譯到資料庫中。

Using a valid universal authentication token, attackers accessed the "worker-API," enabling them to modify device metadata without requiring user-level authentication.

使用有效的通用身份驗證令牌,攻擊者可以存取“worker-API”,使他們能夠修改裝置元數據,而無需用戶級身份驗證。

Ongoing Security Enhancements

持續的安全增強

Husky.io emphasizes ongoing thorough reviews and penetration tests on public endpoints to proactively detect and neutralize threats. Despite the challenges encountered, efforts are underway to incentivize supply-side participation and restore network connections, ensuring the platform's integrity while serving tens of thousands of compute hours per month.

Husky.io 強調對公共端點進行持續的徹底審查和滲透測試,以主動檢測和消除威脅。儘管遇到了挑戰,但仍在努力激勵供應方參與並恢復網路連接,確保平台的完整性,同時每月提供數萬個運算小時的服務。

Future Plans

未來的計劃

Io.net plans to integrate Apple silicon chip hardware in March to enhance its artificial intelligence and machine learning services, underscoring its commitment to providing a secure and performant platform for its users.

Io.net 計劃於 3 月份整合 Apple 晶片硬件,以增強其人工智慧和機器學習服務,強調其致力於為用戶提供安全、高性能平台的承諾。

原始來源:io

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年09月30日 其他文章發表於