Weak isolation levels allowed to steal BTC using plain SQL(blog.ydb.tech) |
Weak isolation levels allowed to steal BTC using plain SQL(blog.ydb.tech) |
> They analyzed “12 popular self-hosted eCommenrce applications written in four languages and deployed on over 2M websites” and identified and verified “22 critical ACIDRain attacks that allow attackers to corrupt store inventory, over-spend gift cards, and steal inventory”. According to the paper, “Of the 22 vulnerabilities, five were level-based, meaning that the default weak isolation level led to the anomalies behind the vulnerabilities.
Because, even having re-read the article you linked, it does not support the conclusion that "[an] exchange[...] was totally ruined because of [weak isolation]" at all?
The goal of the post is to highlight this problem, as cited research papers clearly demonstrate that such issues occur more frequently than commonly perceived.
Again, I'm sorry that the title might be misleading and you have expected a different content.
[0] https://hackingdistributed.com/2014/04/06/another-one-bites-...
[1] https://www.reddit.com/r/Bitcoin/comments/1wtbiu/how_i_stole...