Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attackers to always win and get rewards.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
All For One 安全漏洞
Vulnerability Description
All For One是一款基于以太坊的赌博游戏。 All For One的智能合约实现中的‘maxRandom’函数存在安全漏洞,该漏洞源于程序使用公开可读取的变量来生成任意值。攻击者可利用该漏洞推测生成的任意数,进而获得奖励。
CVSS Information
N/A
Vulnerability Type
N/A